Threat Feed
202d6cbb3d1c1f639d388b7bcc6c3f24566eb27f2d5e7fc6520b454e5f868d2c.exe
2026-09-12T02:24:44.771
malicious
Windows Exe (x86-64)
Close
202d6cbb3d1c1f639d388b7bcc6c3f24566eb27f2d5e7fc6520b454e5f868d2c.exe
malicious
SHA256:
202d6cbb3d1c1f639d388b7bcc6c3f24566eb27f2d5e7fc6520b454e5f868d2c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Tries to evade debugger
3/5
Uses HTTP to upload a large amount of data
2/5
Delays execution
2/5
Tries to detect analyzer sandbox
2/5
Dead Drop Resolver
1/5
Overwrites code
1/5
Queries system time
1/5
Tries to detect debugger
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Unusual large memory allocation
Spyware
611452d6c49d83db23602b9970923fe6b9af73502ccfedfc1ab03672d2e9a103.exe
2026-09-12T02:23:49.784
malicious
Windows Exe (x86-64)
Close
611452d6c49d83db23602b9970923fe6b9af73502ccfedfc1ab03672d2e9a103.exe
malicious
SHA256:
611452d6c49d83db23602b9970923fe6b9af73502ccfedfc1ab03672d2e9a103
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Uses HTTP to upload a large amount of data
3/5
Tries to open an unusually high number of parallel network connections
3/5
Tries to evade debugger
2/5
Delays execution
2/5
Tries to detect analyzer sandbox
1/5
Overwrites code
1/5
Queries system time
1/5
Tries to detect debugger
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Unusual large memory allocation
Spyware
qLVcmzTZXjPx0c36.exe
2026-09-12T02:11:52.955
malicious
Windows Exe (x86-32)
Close
qLVcmzTZXjPx0c36.exe
malicious
SHA256:
8c5ef4cee310759e3419577a3b94f314de2ccd42d13faf55f30e13684f60c3d3
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Creates process with hidden window
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector
4PChOwt4JseAKr97.exe
2026-09-12T02:09:49.269
malicious
Windows Exe (x86-32)
Close
4PChOwt4JseAKr97.exe
malicious
SHA256:
db83c08e005d5b9644c94c791aed61fa62d4e7c387b91691477869e84f78c901
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Modifies Windows automatic backups
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Modifies Windows Update configuration
4/5
Malicious host or URL detected via reputation
4/5
Writes into the memory of another process
4/5
Disables a crucial system tool
4/5
Modifies control flow of another process
4/5
Creates elevated child process
4/5
Tries to disable antivirus software
4/5
Malicious content matched by YARA rules
4/5
Bypasses Windows User Account Control (UAC)
3/5
Modifies system configuration
3/5
Injects a file into another process
3/5
Monitors keyboard input
3/5
Takes screenshot
3/5
Captures clipboard data
3/5
Disables a crucial system service
3/5
Suspicious content matched by YARA rules
2/5
Masquerades file extension
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
2/5
Hides files
2/5
Modifies network configuration
2/5
Searches for sensitive browser data
2/5
Query OS Information
2/5
Queries a host's domain name
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Changes the desktop wallpaper
1/5
URL contains a TLD highly associated with phishing
1/5
Installs system startup script or application
1/5
Modifies operating system directory
1/5
Executes WMI query
1/5
Accesses Microsoft Security Software registry keys
1/5
Enables process privileges
1/5
Monitors keyboard input
1/5
Queries system time
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Creates mutex
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
Ransomware
Injector
lxbFwVWuc2UvmUUB.exe
2026-09-12T02:08:48.231
malicious
Windows Exe (x86-64)
Close
lxbFwVWuc2UvmUUB.exe
malicious
SHA256:
3fa8a69337e75043f75c7f813299f88a7aba9060203c97e12cd904bb780e6ea0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
2/5
Searches for sensitive password manager data
2/5
Delays execution
2/5
Searches for sensitive remote access configuration data
1/5
Content matched by YARA rules
1/5
Modifies application directory
1/5
Tries to detect debugger
1/5
Possibly does reconnaissance
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
Ransomware