Threat Feed
123.exe
2026-10-04T21:22:31.876
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
8e45d0e1fd795693ffe21775d4d95cf4584e2fa23869a2f873fb96c890f59004
VMRay Threat Identifiers
Close
Severity
Operation
5/5
XMRig configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Reads network adapter information
2/5
Creates an unusually large number of processes
2/5
Schedules task
2/5
Sends control codes to a driver
2/5
Sets up server that accepts incoming connections
1/5
Resolves API functions dynamically
1/5
Enables process privileges
1/5
Modifies operating system directory
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Query OS Information
1/5
Unusual large memory allocation
PUA
Miner
ok.exe
2026-10-04T21:22:10.199
malicious
Windows Exe (x86-64)
Close
ok.exe
malicious
SHA256:
e825606f8bf52575b5e987ecb07ef95b69c1464c2146621135693ecff22119f1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
XMRig configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Reads network adapter information
2/5
Creates an unusually large number of processes
2/5
Sends control codes to a driver
2/5
Schedules task
2/5
Sets up server that accepts incoming connections
1/5
Resolves API functions dynamically
1/5
Enables process privileges
1/5
Query OS Information
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Unusual large memory allocation
PUA
Miner
ok.exe
2026-10-04T21:21:52.020
malicious
Windows Exe (x86-64)
Close
ok.exe
malicious
SHA256:
d6ebfe870113878c3d534bd2d601d8d410ab410a23fc917e8a4590821845fbb9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
3/5
Executes code with kernel privileges
3/5
Suspicious file detected via reputation
2/5
Reads network adapter information
2/5
Creates an unusually large number of processes
2/5
Schedules task
2/5
Sends control codes to a driver
2/5
Sets up server that accepts incoming connections
1/5
Resolves API functions dynamically
1/5
Enables process privileges
1/5
Query OS Information
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Unusual large memory allocation
PUA
Miner
123.exe
2026-10-04T21:21:42.170
malicious
Windows Exe (x86-64)
Close
123.exe
malicious
SHA256:
66b890f7ef3d2967c9dee83e15f90ec423cc7723c48ce4886b39442492016599
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Loads a known vulnerable file
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Reads network adapter information
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
1/5
Content matched by YARA rules
1/5
Connects to remote host
1/5
Performs DNS request
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner
ok.exe
2026-10-04T21:21:39.263
malicious
Windows Exe (x86-64)
Close
ok.exe
malicious
SHA256:
5f4195ddbcb5927bb1ffc210123dca4a90d1e78fe3adfb69f33a8b1fd1c41571
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Creates elevated child process
4/5
Loads a known vulnerable file
4/5
Malicious content matched by YARA rules
3/5
Suspicious file detected via reputation
3/5
Executes code with kernel privileges
2/5
Creates a new process from a system binary
2/5
Sets up server that accepts incoming connections
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
2/5
Reads network adapter information
1/5
Query OS Information
1/5
Enables process privileges
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Unusual large memory allocation
1/5
Queries system time
PUA
Miner