Threat Feed
d4hGdDkPEti1h8rI.exe
2026-09-02T04:12:21.547
malicious
Windows Exe (x86-32)
Close
d4hGdDkPEti1h8rI.exe
malicious
SHA256:
08017715ca32abeb3c8a9063d5e2113422084fc2e57cbd434e8c068eb3619fa2
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Delays execution
2/5
Schedules task
1/5
Creates a page with write and execute permissions
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates process with hidden window
Injector
Za8k8utJC8zY2KYg.exe
2026-09-02T04:09:53.349
malicious
Windows Exe (x86-32)
Close
Za8k8utJC8zY2KYg.exe
malicious
SHA256:
18b913f9e2a35b6c7fe0ae50d07d16de0f755361b288c94813966a2cf598abe4
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector
JLdSTc5GrzaQ7OUR.exe
2026-09-02T04:09:19.585
malicious
Windows Exe (x86-32)
Close
JLdSTc5GrzaQ7OUR.exe
malicious
SHA256:
1bfea28ad0131a1c91c68e54fbe85dfedecadbd52d685c88d3e98be8c59953b2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
5/5
Modifies Windows automatic backups
4/5
Tries to disable antivirus software
4/5
Disables a crucial system tool
4/5
Malicious file detected via reputation
4/5
Modifies Windows Update configuration
4/5
Modifies control flow of another process
4/5
Bypasses Windows User Account Control (UAC)
4/5
Malicious content matched by YARA rules
4/5
Writes into the memory of another process
3/5
Tries to evade debugger
3/5
Suspicious content matched by YARA rules
3/5
Monitors keyboard input
3/5
Injects a file into another process
3/5
Modifies system configuration
3/5
Captures clipboard data
3/5
Disables a crucial system service
3/5
Takes screenshot
2/5
Collects hardware properties
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Hides files
2/5
Changes the desktop wallpaper
2/5
Searches for sensitive FTP data
2/5
Creates an unusually large number of processes
2/5
Searches for sensitive browser data
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
2/5
Modifies network configuration
2/5
Query OS Information
2/5
Network configuration discovery
2/5
Searches for cryptocurrency wallet locations
2/5
Tries to detect analyzer sandbox
2/5
Queries a host's domain name
1/5
Creates a page with write and execute permissions
1/5
Accesses Microsoft Security Software registry keys
1/5
Modifies operating system directory
1/5
Executes WMI query
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Enumerates running processes
1/5
Reads from memory of another process
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Monitors keyboard input
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Enables process privileges
Spyware
Ransomware
Injector
gocl.sh
2026-09-02T04:08:24.555
malicious
Shell Script
Close
gocl.sh
malicious
SHA256:
4fb582653120dfc75f067c83f58825a07c335b672912bd0c0882dcd1c4576343
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Creates an unusually large number of processes
2/5
Tries to execute downloaded binary of different architecture than the host
2/5
Downloads file
1/5
Content matched by YARA rules
1/5
Connects to remote host
Trojan
Downloader
Bot
nyW2tG80SrsmiRwP.exe
2026-09-02T04:07:16.919
malicious
Windows Exe (x86-32)
Close
nyW2tG80SrsmiRwP.exe
malicious
SHA256:
6a6b07291fc2df02c5ee151c627c11f884fa431d74b273a55595eb008ad19696
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Schedules task
2/5
Delays execution
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Installs system service
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
Injector