Threat Feed
http://wvtransportes.com.br
2026-08-14T16:22:22.143
malicious
URL
Close
http://wvtransportes.com.br
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
3/5
SmartContract configuration was extracted
2/5
Communicates with a Web3 service
1/5
Checks external IP address
1/5
Content matched by YARA rules
1/5
URL does not use standard port
1/5
Suspicious page characteristics
1/5
Page contains clickables with luring keywords
1/5
URL contains a TLD highly associated with phishing
Downloader
prortonvpn_x64.exe
2026-08-14T16:21:33.815
malicious
Windows Exe (x86-32)
Close
prortonvpn_x64.exe
malicious
SHA256:
ec33732a50e0a655a89967e2145cb445f3b6aa95613e96b8392ac478f9a3dfc7
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Writes into the memory of another process
4/5
Malicious file detected via reputation
3/5
Modifies native system functions
2/5
Signed executable failed signature validation
1/5
Accesses Microsoft Security Software registry keys
1/5
Accesses volumes directly
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Creates an unusually large number of files
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Executes PowerShell commands
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Modifies application directory
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Modifies operating system directory
Downloader
Injector
9apoAGloia43RuEd.exe
2026-08-14T16:21:31.176
malicious
Windows Exe (x86-32)
Close
9apoAGloia43RuEd.exe
malicious
SHA256:
2c09a467ca6026d4210c3921a2b8dd3004ef990813adb5fabca05c52f4f5b3fb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Modifies content of user files
5/5
Appends new extensions to many filenames
5/5
Renames user files
4/5
Malicious file detected via reputation
4/5
Tries to disable antivirus software
3/5
Tries to evade debugger
3/5
Modifies native system functions
3/5
Disables a crucial system service
3/5
Possibly drops ransom note files
2/5
Writes into the memory of a process started from a created or modified executable
2/5
Suspicious content matched by YARA rules
2/5
Deletes file after execution
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive application data
2/5
Searches for sensitive remote access configuration data
1/5
Reads from memory of another process
1/5
Changes folder appearance
1/5
Creates mutex
1/5
Accesses volumes directly
1/5
Checks directory entry count
1/5
Executes WMI query
1/5
Installs system startup script or application
1/5
Installs system service
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Drops PE file
1/5
Executes dropped PE file
Ransomware
https://wvtransportes.com.br
2026-08-14T16:21:26.114
malicious
URL
Close
https://wvtransportes.com.br
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Possible Pastejacking attempt
4/5
Malicious host or URL detected via reputation
3/5
SmartContract configuration was extracted
2/5
Communicates with a Web3 service
1/5
Content matched by YARA rules
1/5
URL does not use standard port
1/5
Suspicious page characteristics
1/5
Page contains clickables with luring keywords
1/5
URL contains a TLD highly associated with phishing
1/5
Checks external IP address
Downloader
Zapret.exe
2026-08-14T16:17:26.579
malicious
Windows Exe (x86-32)
Close
Zapret.exe
malicious
SHA256:
04813c53d1a698ddcb0c6076b87425902c6e959d998a97cfd64b0d5c672a401a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Known malicious mutex name is created
5/5
SalatStealer configuration was extracted
4/5
Creates a Process with redirected Input
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Reads network adapter information
2/5
Collects hardware properties
2/5
Suspicious content matched by YARA rules
2/5
Queries OS info via WMI
2/5
Schedules task
2/5
Sets up server that accepts incoming connections
1/5
Performs DNS request
1/5
Reads system data
1/5
Queries system time
1/5
Modifies application directory
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
Spyware