Threat Feed
file.exe
2026-09-26T20:49:30.381
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
adba87668dd2d3be5c87672d8ce97105e0363a2d70f1c529a7a47b9701a2443b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
3/5
Tries to detect the presence of antivirus software
3/5
Modifies native system functions
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Query Firmware Information
2/5
Creates a new process from a system binary
1/5
A monitored process crashed
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Overwrites code
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
Downloader
Injector
138d14853a542ecda52bd9331eb988e40fc574d9e61574dc0a4b63e74a78c3a2.exe
2026-09-26T20:48:28.698
malicious
Windows Exe (x86-32)
Close
138d14853a542ecda52bd9331eb988e40fc574d9e61574dc0a4b63e74a78c3a2.exe
malicious
SHA256:
138d14853a542ecda52bd9331eb988e40fc574d9e61574dc0a4b63e74a78c3a2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Reads network adapter information
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
1/5
Enables process privileges
1/5
Connects to remote host
Backdoor
d6c6d8bf1ee8598e8c8c523618072f8b5e72f0dac12350c2404b369036b8f5d5.exe
2026-09-26T20:47:44.403
malicious
Windows Exe (x86-32)
Close
d6c6d8bf1ee8598e8c8c523618072f8b5e72f0dac12350c2404b369036b8f5d5.exe
malicious
SHA256:
d6c6d8bf1ee8598e8c8c523618072f8b5e72f0dac12350c2404b369036b8f5d5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Reads network adapter information
2/5
Delays execution
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
1/5
Enables process privileges
1/5
Connects to remote host
Backdoor
b0e64b17ad048ff0ce7c26bad9fd61e3e0fce02296e9c96e4247f7de62dbad1b.exe
2026-09-26T20:47:29.200
malicious
Windows Exe (x86-64)
Close
b0e64b17ad048ff0ce7c26bad9fd61e3e0fce02296e9c96e4247f7de62dbad1b.exe
malicious
SHA256:
b0e64b17ad048ff0ce7c26bad9fd61e3e0fce02296e9c96e4247f7de62dbad1b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Queries a host's domain name
2/5
Delays execution
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor
a694b5cf5c8de0a6cc6242e7535a47fdb6be5042c1df271b44f90753c02af952.exe
2026-09-26T20:47:26.583
malicious
Windows Exe (x86-32)
Close
a694b5cf5c8de0a6cc6242e7535a47fdb6be5042c1df271b44f90753c02af952.exe
malicious
SHA256:
a694b5cf5c8de0a6cc6242e7535a47fdb6be5042c1df271b44f90753c02af952
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Reads network adapter information
2/5
Delays execution
2/5
Queries a host's domain name
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Enumerates running processes
1/5
Enables process privileges
Backdoor