Threat Feed
I95uZDRv57sPZqu3.msi
2026-07-25T19:12:27.306
malicious
MSI Setup
Close
I95uZDRv57sPZqu3.msi
malicious
SHA256:
11f03dd57cbc7c882dcb9ea5067726e3cd48a155eae3d185ce02dcd721066e0d
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Masks file extension
3/5
Modifies native system functions
2/5
Queries a host's domain name
2/5
Delays execution
2/5
Tries to detect virtual machine
2/5
Creates an unusually large number of processes
2/5
Creates a new process from a system binary
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Schedules task
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Accesses volumes directly
1/5
Creates mutex
1/5
Downloads file
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Executes dropped PE file
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Modifies application directory
1/5
Modifies operating system directory
Hacktool
Cw1vzm5u9Jx7GCjo.exe
2026-07-25T19:10:51.841
malicious
Windows Exe (x86-64)
Close
Cw1vzm5u9Jx7GCjo.exe
malicious
SHA256:
0be441080dca2a5d34bee8f90e107b837ace9070353f1b26f29389f08bb12268
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
5/5
Malicious content matched by YARA rules
4/5
Writes into the memory of another process
4/5
Modifies Windows Defender configuration
4/5
Loads a known vulnerable file
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Modifies Windows Update configuration
3/5
Modifies native system functions
3/5
SmartContract configuration was extracted
3/5
Executes code with kernel privileges
3/5
Disables a crucial system service
2/5
Creates an unusually large number of processes
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Deletes file after execution
2/5
Disables automatic hibernation
2/5
Tries to detect virtual machine
2/5
Sets up server that accepts incoming connections
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Reads network adapter information
2/5
Adds service dependency
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates process with hidden window
1/5
Modifies operating system directory
1/5
Performs DNS request
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Communicates via JSON RPC protocol
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Drops PE file
1/5
Installs system service
1/5
Enumerates running processes
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Reads from memory of another process
1/5
Enables process privileges
1/5
Accesses volumes directly
1/5
Unusual large memory allocation
1/5
Queries system time
PUA
Miner
Injector
3UqQ4yePJKJiKVXW.exe
2026-07-25T19:07:58.788
malicious
Windows Exe (x86-32)
Close
3UqQ4yePJKJiKVXW.exe
malicious
SHA256:
31a762fdce1008e635a5e6486d7bc50b4bce671c9232006216e70cd8f2a4a7fb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
5/5
Agent Tesla configuration was extracted
4/5
Injected process sets up server that accepts incoming connections
4/5
Process Hollowing
2/5
Collects hardware properties
2/5
Reads sensitive browser data
2/5
Searches for sensitive mail data
2/5
Reads sensitive mail data
2/5
Searches for sensitive application data
2/5
Searches for sensitive FTP data
2/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive browser data
2/5
Modifies control flow of a process started from a created or modified executable
2/5
Queries OS info via WMI
1/5
Connects to remote host
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Possibly does reconnaissance
1/5
Creates process with hidden window
1/5
Performs DNS request
1/5
Query OS Information
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
Spyware
Backdoor
Injector
mxpYZg4Y6aQANLw3.exe
2026-07-25T19:07:55.624
malicious
Windows Exe (x86-32)
Close
mxpYZg4Y6aQANLw3.exe
malicious
SHA256:
d1385115e76ee9953b959bfb963aaee1a77a2862842b6995dc057fef332bac10
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Process Hollowing
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
3/5
Captures clipboard data
2/5
Modifies control flow of a process started from a created or modified executable
2/5
Delays execution
2/5
Tries to detect kernel debugger
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Creates a page with write and execute permissions
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Enables process privileges
Spyware
Injector
file.exe
2026-07-25T17:34:54.605
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
e76d373869783dc10414994a1f2a052f8740e257372f4d4de17615cde3c87a3f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
3/5
Captures clipboard data
3/5
Uses HTTP to upload a large amount of data
3/5
Takes screenshot
3/5
Modifies native system functions
3/5
Tries to detect the presence of antivirus software
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Queries OS info via WMI
2/5
Tries to detect virtual machine
1/5
Query Firmware Information
1/5
Tries to connect using an uncommon port
1/5
Queries system time
Spyware