Threat Feed
QuickFetch.exe
2026-08-10T10:15:02.959
malicious
Windows Exe (x86-64)
Close
QuickFetch.exe
malicious
SHA256:
843b927de18b16ef40abb48067b6be80e4c63a9e9600342ca672bc75e84e7a48
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
3/5
Takes screenshot
3/5
Captures clipboard data
3/5
Uses HTTP to upload a large amount of data
3/5
Tries to detect the presence of antivirus software
2/5
Query Firmware Information
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Queries a host's domain name
1/5
Connects to remote host
1/5
Unusual large memory allocation
1/5
Performs DNS request
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates process with hidden window
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Query OS Information
1/5
Resolves API functions dynamically
Spyware
48d66a8f0f2a7d144cfa1f6b7a006c69.exe
2026-08-10T10:12:44.935
malicious
Windows Exe (x86-64)
Close
48d66a8f0f2a7d144cfa1f6b7a006c69.exe
malicious
SHA256:
1d60903c4cf77503ae2ccbc0e1f33e455033bca93d1a289531df7e1a166a5449
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Tries to evade debugger
3/5
Reads installed applications
2/5
Searches for sensitive mail data
2/5
Searches for cryptocurrency wallet locations
2/5
Dead Drop Resolver
2/5
Searches for sensitive browser data
1/5
Unusual large memory allocation
1/5
Enumerates running processes
1/5
Queries system time
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Query OS Information
1/5
Query CPU Properties
1/5
URL contains a TLD highly associated with phishing
1/5
Resolves API functions dynamically
1/5
Overwrites code
Spyware
bEQ9CqFyX9TSeLe6.exe
2026-08-10T10:12:13.116
malicious
Windows Exe (x86-32)
Close
bEQ9CqFyX9TSeLe6.exe
malicious
SHA256:
6a0c2c8ee3057c6a9ea5c297799044abdf20b29ef13a8996fdb4f6603dc51d1e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
All network connection attempts failed
2/5
Allows invalid SSL certificates
1/5
Creates process with hidden window
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
Ransomware
e133b5904ecefb5b6c167539d02a918d.exe
2026-08-10T10:12:00.088
malicious
Windows Exe (x86-64)
Close
e133b5904ecefb5b6c167539d02a918d.exe
malicious
SHA256:
bb024a4c3e301b740e986aecf768d0d7947a75b33dccde6e52baf15c0b0a59fc
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Takes screenshot
3/5
Suspicious content matched by YARA rules
2/5
Sets up server that accepts incoming connections
2/5
Delays execution
1/5
Reads system data
1/5
Tries to connect using an uncommon port
1/5
Query OS Information
1/5
Query CPU Properties
1/5
Connects to remote host
1/5
Unusual large memory allocation
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
Backdoor
CsjgOv6yxw1boXpq.exe
2026-08-10T10:11:08.851
malicious
Windows Exe (x86-32)
Close
CsjgOv6yxw1boXpq.exe
malicious
SHA256:
9f5e201a4c43e5e258d1a1caaa1aaf258a1b88237e6245b9f392ea4f1b854d0a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Rename system utilities
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
2/5
Delays execution
2/5
Hides files
2/5
Accesses physical drive
2/5
Sends control codes to a driver
2/5
Deletes file after execution
1/5
Enumerates running processes
1/5
Query CPU Properties
1/5
Enables process privileges
1/5
Performs DNS request
1/5
Tries to connect using an uncommon port
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Modifies application directory
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
The binary file was created with a packer
1/5
Executes dropped PE file
1/5
Queries system time