Threat Feed
beacon_windows_amd64_p_f916b8b840004d.exe
2026-09-25T20:52:49.758
malicious
Windows Exe (x86-64)
Close
beacon_windows_amd64_p_f916b8b840004d.exe
malicious
SHA256:
557d08df35639c87683d146da715c9310eb50a994c2ef794fe9a4a96285bb1eb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads the Security Account Manager (SAM) file
4/5
Malicious file detected via reputation
2/5
Sets up server that accepts incoming connections
2/5
Delays execution
2/5
Reads network adapter information
1/5
Content matched by YARA rules
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
Spyware
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SRaIZyCYha61Gs7IkHqxy0-ABlnMbBp1F-8ICheyF8sfP2lXvo1WdKgy6-ZbBbl9Jb7g2kT&dsh=S-180757609%3A1790366681171078
2026-09-25T20:23:52.067
malicious
URL
Close
http://49.51.43.12/v3/signin/identifier?amp%3Bfollowup=https%3A%2F%2Faccounts.google.com&%3Bifkv=AWnogHe_pDujLaO-hl3d_3DQFjS6PW6JGM3LRrD13mxmiaQWTJuHz9b6nwmaSIh76M5SMOelnJex7g&%3Bpassive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&flowName=GlifWebSignIn&flowEntry=ServiceLogin&ifkv=AWt06SRaIZyCYha61Gs7IkHqxy0-ABlnMbBp1F-8ICheyF8sfP2lXvo1WdKgy6-ZbBbl9Jb7g2kT&dsh=S-180757609%3A1790366681171078
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Malicious host or URL detected via reputation
2/5
Page uses exact same title as that of a popular online service
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
1/5
HTTPS page insecurely loads resources via HTTP
Phishing
Task7.exe
2026-09-25T20:11:36.140
malicious
Windows Exe (x86-64)
Close
Task7.exe
malicious
SHA256:
7bb3a38f362458257c4f7fbdcc99e7476f262c9fef4291749ed955c9828ca547
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Remcos configuration was extracted
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Known malicious mutex name is created
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Injects a file into another process
3/5
Captures clipboard data
3/5
Monitors keyboard input
2/5
Delays execution
2/5
Reads network adapter information
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Connects to remote host
1/5
Query OS Information
1/5
Performs DNS request
1/5
Installs system startup script or application
1/5
Resolves API functions dynamically
Spyware
Backdoor
diskpart.exe
2026-09-25T20:00:16.890
malicious
Windows Exe (x86-32)
Close
diskpart.exe
malicious
SHA256:
d452db15f48bd7d72ac3eb2896a8953e3fee1090994f5acbc91a384eec0ba814
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
NanoCore configuration was extracted
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Process Hollowing
3/5
Performs DNS request for known DDNS domain
2/5
Deletes file after execution
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Creates mutex
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
1/5
Reads system data
Backdoor
Injector
uuyc_4.exe
2026-09-25T19:55:42.704
malicious
Windows Exe (x86-32)
Close
uuyc_4.exe
malicious
SHA256:
daee18ba3ec4c763726b6c435f95f3fb2aa1ac1570fdba3cbcd83c8d501eb57e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Signed executable failed signature validation
1/5
Modifies operating system directory
1/5
Accesses Microsoft Security Software registry keys
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Accesses volumes directly
1/5
Queries system time
1/5
Enables process privileges
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Creates process with hidden window
Downloader
Injector