Threat Feed
QIwYjGrfCfQNSjH8.exe
2026-08-02T19:40:22.116
malicious
Windows Exe (x86-64)
Close
QIwYjGrfCfQNSjH8.exe
malicious
SHA256:
7a7ad4ae347a3f99f3773a113d9f70ecfa967100c96e8275bd1df833caee68d1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads a significant portion of browser memory
4/5
Malicious file detected via reputation
2/5
Sends control codes to a driver
2/5
Reads network adapter information
2/5
Collects hardware properties
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Reads from memory of another process
1/5
Possibly does reconnaissance
1/5
Accesses volumes directly
1/5
Installs system startup script or application
SHBETAPP.exe
2026-08-02T19:28:59.065
malicious
Windows Exe (x86-32)
Close
SHBETAPP.exe
malicious
SHA256:
26d90f32df1cd821e0995026c4528b22ffacb0e6c6acfb07eec0fcb3eb7a03ac
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
1/5
Performs DNS request
1/5
Creates mutex
1/5
Connects to remote host
1/5
Query OS Information
1/5
Enables process privileges
Backdoor
2F347A1F58CC75B86E74C9EF63A1CE2A.exe
2026-08-02T19:28:02.368
malicious
Windows Exe (x86-32)
Close
2F347A1F58CC75B86E74C9EF63A1CE2A.exe
malicious
SHA256:
a5228e0087e7459608c1548b8e82328008fb37a5638b4317965520bdd37b918a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
NanoCore configuration was extracted
4/5
Malicious file detected via reputation
3/5
Obscures a file's origin
3/5
Monitors user input
2/5
Sets up server that accepts incoming connections
1/5
Performs DNS request
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Connects to remote host
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Reads system data
1/5
Modifies application directory
Backdoor
file.exe
2026-08-02T19:27:14.424
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
d36d08953cb47514a7d58a009161f0ad7fd5164bc1964a0b63c8ba1916ad218d
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
5/5
Malicious content matched by YARA rules
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Modifies Windows Defender configuration
4/5
Modifies Windows Update configuration
4/5
Loads a known vulnerable file
4/5
Malicious file detected via reputation
3/5
Disables a crucial system service
3/5
Executes code with kernel privileges
3/5
SmartContract configuration was extracted
3/5
Modifies native system functions
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Delays execution
2/5
Communicates with a Web3 service
2/5
Tries to detect virtual machine
2/5
Creates an unusually large number of processes
2/5
Reads network adapter information
2/5
Disables automatic hibernation
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Sets up server that accepts incoming connections
2/5
Adds service dependency
2/5
Deletes file after execution
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Installs system service
1/5
Accesses volumes directly
1/5
Modifies operating system directory
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Drops PE file
1/5
Reads from memory of another process
1/5
Creates mutex
1/5
Accesses Microsoft Security Software registry keys
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner
Injector
joxDdEMJxx6QRxLW.exe
2026-08-02T18:15:43.388
malicious
Windows Exe (x86-64)
Close
joxDdEMJxx6QRxLW.exe
malicious
SHA256:
02de47873fc4acafbd5b2e15f71dab56cebad91e630dc1f777b5ae16042c4631
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XMRig configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Loads a known vulnerable file
3/5
Executes code with kernel privileges
3/5
Suspicious file detected via reputation
2/5
Reads network adapter information
2/5
Schedules task
2/5
Sets up server that accepts incoming connections
2/5
Sends control codes to a driver
2/5
Creates an unusually large number of processes
1/5
Content matched by YARA rules
1/5
Enables process privileges
1/5
Query OS Information
1/5
Unusual large memory allocation
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
PUA
Miner