Threat Feed
08ab8e89dd953a56cb1c443adc124b74edc3def3dc66a2e583b7a6c4ff9389b2.exe
2026-08-10T14:24:48.994
malicious
Windows Exe (x86-32)
Close
08ab8e89dd953a56cb1c443adc124b74edc3def3dc66a2e583b7a6c4ff9389b2.exe
malicious
SHA256:
08ab8e89dd953a56cb1c443adc124b74edc3def3dc66a2e583b7a6c4ff9389b2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Process Hollowing
4/5
Makes indirect system call to possibly evade hooking based monitoring
2/5
Tries to detect kernel debugger
2/5
Modifies control flow of a process started from a created or modified executable
1/5
A monitored process crashed
1/5
Enumerates running processes
1/5
Creates process with hidden window
1/5
Tries to detect debugger
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
Spyware
Injector
4d6e7f9441ab4ccd120dd621871c2f0dcd5d1a3679577fa0808c82b1cd434477.exe
2026-08-10T14:24:07.808
malicious
Windows Exe (x86-32)
Close
4d6e7f9441ab4ccd120dd621871c2f0dcd5d1a3679577fa0808c82b1cd434477.exe
malicious
SHA256:
4d6e7f9441ab4ccd120dd621871c2f0dcd5d1a3679577fa0808c82b1cd434477
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Process Hollowing
2/5
Tries to detect kernel debugger
2/5
Modifies control flow of a process started from a created or modified executable
1/5
Tries to detect debugger
1/5
Enumerates running processes
1/5
A monitored process crashed
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
Spyware
Injector
3165d5a8e90f522dd5d0cef3c1f00f21c0472928658626cd29680d424281a62b.exe
2026-08-10T14:22:06.110
malicious
Windows Exe (x86-32)
Close
3165d5a8e90f522dd5d0cef3c1f00f21c0472928658626cd29680d424281a62b.exe
malicious
SHA256:
3165d5a8e90f522dd5d0cef3c1f00f21c0472928658626cd29680d424281a62b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
5/5
Tries to read cached credentials of various applications
5/5
Malicious content matched by YARA rules
5/5
Agent Tesla configuration was extracted
4/5
Malicious file detected via reputation
4/5
Process Hollowing
3/5
Classifies external IP address
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Reads sensitive browser data
2/5
Searches for sensitive mail data
2/5
Reads sensitive mail data
2/5
Connects to SMTP server
2/5
Suspicious content matched by YARA rules
2/5
Modifies control flow of a process started from a created or modified executable
2/5
Tries to detect application sandbox
2/5
Searches for sensitive browser data
2/5
Searches for sensitive FTP data
2/5
Searches for sensitive application data
1/5
Creates a page with write and execute permissions
1/5
Query OS Information
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Queries system time
1/5
Possibly does reconnaissance
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Reads from memory of another process
1/5
Creates process with hidden window
Spyware
Injector
43dbea10a7c69096dbc8dd3bf31f982e4927f58b02b4be3c3d26432e5ff7c523.exe
2026-08-10T14:20:20.522
malicious
Windows Exe (x86-32)
Close
43dbea10a7c69096dbc8dd3bf31f982e4927f58b02b4be3c3d26432e5ff7c523.exe
malicious
SHA256:
43dbea10a7c69096dbc8dd3bf31f982e4927f58b02b4be3c3d26432e5ff7c523
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Modifies Windows Defender configuration
4/5
Process Hollowing
2/5
Tries to detect kernel debugger
2/5
Modifies control flow of a process started from a created or modified executable
1/5
Creates process with hidden window
1/5
Enables process privileges
1/5
Reads from memory of another process
1/5
Tries to detect debugger
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
A monitored process crashed
1/5
Creates a page with write and execute permissions
Spyware
Injector
3d87a298c1dcb34d5fd1221ef3991d138ea4708df1597ae32983a1883405a6d3.exe
2026-08-10T14:19:48.543
malicious
Windows Exe (x86-32)
Close
3d87a298c1dcb34d5fd1221ef3991d138ea4708df1597ae32983a1883405a6d3.exe
malicious
SHA256:
3d87a298c1dcb34d5fd1221ef3991d138ea4708df1597ae32983a1883405a6d3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Process Hollowing
2/5
Tries to detect kernel debugger
2/5
Modifies control flow of a process started from a created or modified executable
1/5
Tries to detect debugger
1/5
Enumerates running processes
1/5
A monitored process crashed
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
Spyware
Injector