Threat Feed
bgremzcyro.lnk
2026-09-29T20:20:14.812
malicious
PowerShell Script (Shell Link)
Close
bgremzcyro.lnk
malicious
SHA256:
523d6d2479a05d5a3c854fe6a76af1156afc05c9a46e1e8f74bea5c8b8d87aa0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
4/5
Reads from memory of another process
4/5
Tries to evade debugger
4/5
Attempts to connect through HTTP
4/5
Makes indirect system call to possibly evade hooking based monitoring
3/5
Captures clipboard data
3/5
Connects to a URL that contains a TLD highly associated with malicious actions
3/5
Reads sensitive browser data
3/5
Uses HTTP to upload a large amount of data
3/5
Takes screenshot
2/5
Downloads file
2/5
Executes dropped PE file
2/5
Tries to connect using an uncommon port
2/5
Executes PowerShell without default profile
2/5
Searches for sensitive browser data
2/5
Suspicious content matched by YARA rules
2/5
Possibly does reconnaissance
2/5
Performs DNS request
2/5
Drops PE file
1/5
Queries system time
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Creates mutex
1/5
Accesses Microsoft Security Software registry keys
Spyware
Downloader
bot
2026-09-29T20:05:28.502
malicious
Linux ELF Executable (x86-64)
Close
bot
malicious
SHA256:
5a3223401dc2beae0c5f64a24b417ac07ffd95a831c87ea5c4022c71bdeb3f5a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Connects to multiple remote hosts
3/5
Installs system startup script or application
3/5
Loads kernel extension
3/5
Tries to detect the presence of antivirus software
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
2/5
Enumerates running processes
2/5
Deletes logs
2/5
Schedules task with Cron
2/5
Delays execution
1/5
Creates hidden file or folder
1/5
Connects to remote host
1/5
Drops ELF file
1/5
Tries to connect using an uncommon port
1/5
Clones process
Bot
instapp.s.1.13.exe
2026-09-29T19:39:25.256
malicious
Windows Exe (x86-64)
Close
instapp.s.1.13.exe
malicious
SHA256:
eddb4a56a95bc35261f931e96e8a771398f65fc7feeb6646d7b705c570f695b6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Masks file extension
3/5
Modifies native system functions
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Tries to detect virtual machine
2/5
Masquerades file extension
2/5
Schedules task
2/5
Creates a new process from a system binary
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Modifies operating system directory
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Modifies application directory
1/5
Downloads file
Downloader
Hacktool
bot
2026-09-29T19:38:58.730
malicious
Linux ELF Executable (x86-64)
Close
bot
malicious
SHA256:
e419dc7e34ac9748188bb60f6e38d50cf1c2a1a5c632870591df6ed8231e5e63
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Connects to multiple remote hosts
4/5
Malicious file detected via reputation
3/5
Tries to detect the presence of antivirus software
3/5
Installs system startup script or application
3/5
Loads kernel extension
2/5
Creates an unusually large number of processes
2/5
Delays execution
2/5
Deletes logs
2/5
Sets up server that accepts incoming connections
2/5
Enumerates running processes
2/5
Schedules task with Cron
1/5
Tries to connect using an uncommon port
1/5
Creates hidden file or folder
1/5
Clones process
1/5
Connects to remote host
1/5
Drops ELF file
Bot
08665fcac5fb616960399a2a0a444122403ca537d073680e632f99422c5c2a7e.exe
2026-09-29T19:36:29.512
malicious
Windows Exe (x86-64)
Close
08665fcac5fb616960399a2a0a444122403ca537d073680e632f99422c5c2a7e.exe
malicious
SHA256:
08665fcac5fb616960399a2a0a444122403ca537d073680e632f99422c5c2a7e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Reads network adapter information
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor