Threat Feed
89346d1618092834ee2a105cba5a226c01bace09cc202e0a89ead9d97ee278d0.exe
2026-08-09T03:32:03.885
malicious
Windows Exe (x86-64)
Close
89346d1618092834ee2a105cba5a226c01bace09cc202e0a89ead9d97ee278d0.exe
malicious
SHA256:
89346d1618092834ee2a105cba5a226c01bace09cc202e0a89ead9d97ee278d0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
5/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Loads a known vulnerable file
4/5
Malicious host or URL detected via reputation
4/5
Modifies Windows Update configuration
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Writes into the memory of another process
3/5
Disables a crucial system service
3/5
SmartContract configuration was extracted
3/5
Modifies native system functions
2/5
Disables automatic hibernation
2/5
Reads network adapter information
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Tries to detect virtual machine
2/5
Creates an unusually large number of processes
2/5
Communicates with a Web3 service
2/5
Adds service dependency
2/5
Deletes file after execution
2/5
Sets up server that accepts incoming connections
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates process with hidden window
1/5
Modifies operating system directory
1/5
Unusual large memory allocation
1/5
Enumerates running processes
1/5
Reads from memory of another process
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Accesses volumes directly
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Installs system service
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner
Injector
291E68D417E3A13F19BD630EB5533CB5.exe
2026-08-09T03:06:55.179
malicious
Windows Exe (x86-32)
Close
291E68D417E3A13F19BD630EB5533CB5.exe
malicious
SHA256:
1ae9cd2b41297f16ce7dc361cae4b890a984c792351b198c1190d093a908e0e5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
NanoCore configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Obscures a file's origin
3/5
Monitors user input
2/5
Sets up server that accepts incoming connections
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Connects to remote host
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Reads system data
1/5
Modifies application directory
1/5
Performs DNS request
Backdoor
verygoodmorningeveryoneiamcoming.hta
2026-08-09T02:33:14.533
malicious
HTML Application
Close
verygoodmorningeveryoneiamcoming.hta
malicious
SHA256:
955381636f6e76e89b2aa81d387c765ee9e3687132ccb7d75a23d939b04b5641
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Remcos configuration was extracted
5/5
Malicious content matched by YARA rules
5/5
Known malicious mutex name is created
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
4/5
Process Hollowing
4/5
Attempts to connect through HTTP
4/5
Writes into the memory of another process
4/5
Reads from memory of another process
3/5
Delays execution
3/5
Performs DNS request for known DDNS domain
3/5
Suspicious content matched by YARA rules
3/5
Executes PowerShell commands from environment variables
2/5
Tries to connect using an uncommon port
2/5
Executes PowerShell without default profile
2/5
Performs DNS request
2/5
Suspicious content matched by YARA rules
1/5
Queries system time
1/5
Query OS Information
1/5
Accesses Microsoft Security Software registry keys
1/5
Unusual large memory allocation
1/5
Connects to remote host
Backdoor
Injector
https://ql5b30.info/kbyxydvaa/
2026-08-09T02:23:40.702
malicious
URL
Close
https://ql5b30.info/kbyxydvaa/
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page secured via a Domain Validated SSL certificate
1/5
Content matched by YARA rules
Phishing
PvZvCp6BtH3K3xDC.html
2026-08-09T01:58:02.669
malicious
HTML Document
Close
PvZvCp6BtH3K3xDC.html
malicious
SHA256:
9d464ec09385b85ed014bcfee1a91b720fba97bd5938e2c7fc9b1d34828893f6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing