Threat Feed
461E43DA65ED883C46B72C095FD72A3E.exe
2026-08-28T03:26:02.405
malicious
Windows Exe (x86-32)
Close
461E43DA65ED883C46B72C095FD72A3E.exe
malicious
SHA256:
33cc64e622a224df172252aad00278e8f085925414d5fac4e821f5f7596e8c8c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
QuasarRAT configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Injects a file into another process
3/5
Obscures a file's origin
3/5
Monitors keyboard input
2/5
Hides files
2/5
Queries OS info via WMI
2/5
Deletes file after execution
2/5
Collects hardware properties
2/5
Schedules task
2/5
Collects BIOS properties
1/5
Performs DNS request
1/5
Enables process privileges
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Query OS Information
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
Spyware
Backdoor
QuickFetch.exe
2026-08-28T03:25:15.269
malicious
Windows Exe (x86-64)
Close
QuickFetch.exe
malicious
SHA256:
f7eb82050604926b372ed7df21b9df90aa970eb20daec5d75d492a427a56e0d3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious content matched by YARA rules
3/5
Suspicious host or URL detected via reputation
3/5
Takes screenshot
3/5
Captures clipboard data
3/5
Tries to detect the presence of antivirus software
2/5
Queries OS info via WMI
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Query Firmware Information
1/5
Tries to connect using an uncommon port
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Resolves API functions dynamically
1/5
URL contains a TLD highly associated with phishing
Spyware
2feb91cf421d8e7c564b65e27315ae3c0b2f0df2496b97dfbaabc5ef216dbae4.exe
2026-08-28T02:56:25.813
malicious
Windows Exe (x86-64)
Close
2feb91cf421d8e7c564b65e27315ae3c0b2f0df2496b97dfbaabc5ef216dbae4.exe
malicious
SHA256:
2feb91cf421d8e7c564b65e27315ae3c0b2f0df2496b97dfbaabc5ef216dbae4
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Tries to detect virtual machine
2/5
Dead Drop Resolver
2/5
Searches for sensitive browser data
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Query CPU Properties
1/5
Tries to detect application sandbox
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Unusual large memory allocation
Spyware
3135BF9C620AEA1463C948D1BE481493.exe
2026-08-28T02:49:12.371
malicious
Windows Exe (x86-32)
Close
3135BF9C620AEA1463C948D1BE481493.exe
malicious
SHA256:
178b290d24527fda41dcaa0960b289e024e4fac39b96a3d8aebf9be14f51a635
VMRay Threat Identifiers
Close
Severity
Operation
5/5
QuasarRAT configuration was extracted
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
3/5
Obscures a file's origin
3/5
Monitors keyboard input
3/5
Injects a file into another process
2/5
Schedules task
2/5
Collects hardware properties
2/5
Collects BIOS properties
2/5
Queries OS info via WMI
1/5
Performs DNS request
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Queries system time
1/5
Enables process privileges
1/5
Query OS Information
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Resolves API functions dynamically
Spyware
Backdoor
3304B81686F03893B0A931F23C6665BA.exe
2026-08-28T02:48:47.553
malicious
Windows Exe (x86-32)
Close
3304B81686F03893B0A931F23C6665BA.exe
malicious
SHA256:
27d22c374ffa52ab63cfb05c09b7925100f6ccd0eb00e314cf8f20be231da250
VMRay Threat Identifiers
Close
Severity
Operation
5/5
QuasarRAT configuration was extracted
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Monitors keyboard input
3/5
Injects a file into another process
3/5
Obscures a file's origin
2/5
Collects hardware properties
2/5
Schedules task
2/5
Collects BIOS properties
2/5
Queries OS info via WMI
1/5
Performs DNS request
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Queries system time
1/5
Enables process privileges
1/5
Query OS Information
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
Spyware
Backdoor