Threat Feed
file.exe
2026-07-28T19:39:57.228
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
82fb67cb2438bd0265f4e06f974456a8b212b70d45f8f3fc18e04155fa45791a
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious content matched by YARA rules
3/5
Suspicious content matched by YARA rules
2/5
Tries to detect a forensic tool
2/5
Schedules task
2/5
Sends control codes to a driver
2/5
Tries to detect application sandbox
2/5
Accesses physical drive
2/5
Delays execution
2/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Creates a page with write and execute permissions
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Checks external IP address
1/5
Enables process privileges
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Content matched by YARA rules
1/5
Executes dropped PE file
Trojan
Injector
RFQ230092.js
2026-07-28T19:12:40.819
malicious
JScript
Close
RFQ230092.js
malicious
SHA256:
04812630dcb086af236a69d05fbd85d4e6359c118048cacf2a1964ee330c2204
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Injected process sets up server that accepts incoming connections
5/5
Combination of other detections shows configuration discovery
5/5
Tries to read cached credentials of various applications
5/5
Agent Tesla configuration was extracted
4/5
Reads from memory of another process
4/5
Writes into the memory of another process
4/5
Attempts to connect through HTTP
4/5
Tries to detect application sandbox
4/5
Process Hollowing
3/5
Reads sensitive mail data
3/5
Executes PowerShell commands from environment variables
3/5
Reads sensitive browser data
3/5
Classifies external IP address
2/5
Enables process privileges
2/5
Possibly does reconnaissance
2/5
Performs DNS request
2/5
Executes PowerShell without default profile
2/5
Tries to connect using an uncommon port
2/5
Reads network adapter information
2/5
Searches for sensitive mail data
2/5
Installs system startup script or application
2/5
Searches for sensitive browser data
2/5
Suspicious content matched by YARA rules
2/5
Queries OS info via WMI
2/5
Collects hardware properties
1/5
Executes WMI query
1/5
Connects to remote host
1/5
Enumerates running processes
1/5
Queries system time
1/5
Accesses Microsoft Security Software registry keys
1/5
Query OS Information
Spyware
Backdoor
Injector
FMOJZFLfIWFvJSlO.html
2026-07-28T19:12:02.605
malicious
HTML Document
Close
FMOJZFLfIWFvJSlO.html
malicious
SHA256:
28826daf338e7ededce8cc1c389150f57d2004be7ed2f447de93dd8772832c11
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
xdCbCyUZvjvYL63S.exe
2026-07-28T19:04:19.992
malicious
Windows Exe (x86-64)
Close
xdCbCyUZvjvYL63S.exe
malicious
SHA256:
6f1a14032ec243511602560ef70a308e80b22bc6cc98234143b41032be861943
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
3/5
Tries to evade debugger
3/5
Reads installed applications
2/5
Signed executable failed signature validation
2/5
Schedules task
2/5
Searches for cryptocurrency wallet locations
2/5
Delays execution
2/5
Searches for sensitive mail data
2/5
Searches for sensitive browser data
2/5
Dead Drop Resolver
1/5
Overwrites code
1/5
Tries to detect debugger
1/5
Executes WMI query
1/5
Query CPU Properties
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
IMG_20260728_160313.jpg.lnk
2026-07-28T18:58:54.528
malicious
PowerShell Script (Shell Link)
Close
IMG_20260728_160313.jpg.lnk
malicious
SHA256:
c9e890803179b42ad3086fccc4db2628ba6667a0c61edc74548aea2841ca1ee9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Creates an unusually large number of files
4/5
Reads from memory of another process
2/5
Enumerates running processes
2/5
Performs DNS request
2/5
Possibly does reconnaissance
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Creates mutex
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Accesses volumes directly