Threat Feed
AdobeAcrobat.iso
2026-08-20T10:26:56.089
malicious
Windows Batch File (Shell Link)
Close
AdobeAcrobat.iso
malicious
SHA256:
075f4947c90362838528ac41015af47d27b7a4184fa3033bc26d8970f30e4dda
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Modifies operating system directory
5/5
Sets up server that accepts incoming connections
4/5
Malicious file detected via reputation
4/5
Installs system service
3/5
Modifies application directory
2/5
Executes dropped PE file
2/5
Reads network configuration
2/5
Enables process privileges
2/5
Drops PE file
2/5
Tries to connect using an uncommon port
2/5
Reads network adapter information
2/5
Collects hardware properties
2/5
Signed executable failed signature validation
1/5
Timestamp manipulation
1/5
Reads system data
1/5
Query OS Information
1/5
Accesses volumes directly
1/5
Executes WMI query
1/5
Enumerates running processes
1/5
Queries system time
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Unusual large memory allocation
Backdoor
Yqd62RfMkk1T10wM.html
2026-08-20T10:15:05.029
malicious
HTML Document
Close
Yqd62RfMkk1T10wM.html
malicious
SHA256:
07d8cf30fceb98167c0c011bea69f0a19976378f3c51443f59ffecff5929a4fa
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
c9iGofukMOs43JUB.exe
2026-08-20T10:08:31.815
malicious
Windows Exe (x86-32)
Close
c9iGofukMOs43JUB.exe
malicious
SHA256:
b9eabf9c1e7eda061eb824e4d6eee8dcebfa10e85a45bbfd623c87169c2f7a8e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Tries to detect the presence of antivirus software
3/5
Monitors keyboard input
3/5
Takes screenshot
3/5
Performs DNS request for known DDNS domain
3/5
Bypasses PowerShell execution policy
3/5
Injects a file into another process
2/5
Queries OS info via WMI
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Executes PowerShell without default profile
2/5
Collects hardware properties
1/5
Content matched by YARA rules
1/5
Tries to connect using an uncommon port
1/5
Connects to remote host
1/5
Accesses Microsoft Security Software registry keys
1/5
Enables process privileges
1/5
Performs DNS request
1/5
Creates process with hidden window
1/5
Writes an unusually large amount of data to the registry
1/5
Possibly does reconnaissance
1/5
Query OS Information
1/5
Queries system time
1/5
Creates mutex
1/5
A monitored process crashed
1/5
Resolves API functions dynamically
Spyware
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5.exe
2026-08-20T10:01:04.077
malicious
Windows Exe (x86-64)
Close
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5.exe
malicious
SHA256:
c66d2b77b9e85c53391891212413ad9a99eb66f4b11c6a431e78884a5b2651e5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
5/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Modifies Windows Defender configuration
4/5
Writes into the memory of another process
4/5
Modifies Windows Update configuration
4/5
Malicious host or URL detected via reputation
3/5
Modifies native system functions
3/5
SmartContract configuration was extracted
3/5
Disables a crucial system service
2/5
Disables automatic hibernation
2/5
Reads network adapter information
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Deletes file after execution
2/5
Communicates with a Web3 service
2/5
Adds service dependency
2/5
Tries to detect virtual machine
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates process with hidden window
1/5
Modifies operating system directory
1/5
Unusual large memory allocation
1/5
Enumerates running processes
1/5
Reads from memory of another process
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Accesses volumes directly
1/5
Installs system service
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Drops PE file
1/5
Enables process privileges
1/5
Queries system time
PUA
Miner
Injector
SwissArmySuite.exe
2026-08-20T10:01:02.527
malicious
Windows Exe (x86-32)
Close
SwissArmySuite.exe
malicious
SHA256:
bf73c67869db2375cc4e01202ad26edd9300eb00bf3fedd0f20c86848f32986c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
5/5
AsyncRAT configuration was extracted
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows configuration discovery
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Suspicious file detected via reputation
3/5
Takes screenshot
3/5
Redirect program startups
3/5
Tries to detect the presence of antivirus software
2/5
Searches for sensitive FTP data
2/5
Deletes file after execution
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive browser data
2/5
Enumerates running processes
2/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive application data
2/5
Network configuration discovery
2/5
Searches for sensitive mail data
2/5
Schedules task
2/5
Queries OS info via WMI
2/5
Reads network adapter information
2/5
Searches for cryptocurrency wallet locations
2/5
Collects hardware properties
1/5
Changes folder appearance
1/5
Possibly does reconnaissance
1/5
Modifies application directory
1/5
Enumerates running processes
1/5
Reads from memory of another process
1/5
Creates process with hidden window
1/5
Reads system data
1/5
Query OS Information
1/5
Modifies operating system directory
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Enables process privileges
1/5
Queries system time
Spyware
Backdoor
Virus