Threat Feed
evCIHlxMictiHjdG.exe
2026-09-13T02:57:02.911
malicious
Windows Exe (x86-64)
Close
evCIHlxMictiHjdG.exe
malicious
SHA256:
17160ab604982ed13178aa56a0a390a3ca4a777e4635be7412055664c29ec3da
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Process Hollowing
4/5
Modifies control flow of another process
3/5
Suspicious content matched by YARA rules
1/5
Creates a page with write and execute permissions
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Tries to detect debugger
Injector
zyoiKUp1sJBmG7FS.exe
2026-09-13T02:53:36.864
malicious
Windows Exe (x86-32)
Close
zyoiKUp1sJBmG7FS.exe
malicious
SHA256:
2eaf1f0abb362c553e898fe9efec4a9f1d59a28367afc6092221e353d454b92f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
2/5
Searches for sensitive mail data
2/5
Reads network configuration
2/5
Deletes file after execution
2/5
Installs system monitor to detect memory accesses
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Suspicious content matched by YARA rules
1/5
Timestamp manipulation
1/5
Drops PE masquerading Filename
1/5
Installs system startup script or application
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Modifies operating system directory
1/5
Creates a page with write and execute permissions
1/5
Changes folder appearance
1/5
Query OS Information
1/5
Modifies application directory
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Drops PE file
1/5
Executes dropped PE file
Backdoor
Trojan
Worm
Injector
vGeyNOdiPvKyC57R.exe
2026-09-13T02:50:24.442
malicious
Windows Exe (x86-32)
Close
vGeyNOdiPvKyC57R.exe
malicious
SHA256:
905013fa7aa5a407693cab16809f04e489577fdf176c40d6e2528f9f6b519986
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Delays execution
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Enumerates running processes
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
Injector
77mDDRmgXPpMlyVn.exe
2026-09-13T02:50:19.189
malicious
Windows Exe (x86-32)
Close
77mDDRmgXPpMlyVn.exe
malicious
SHA256:
9b65b8950ea8c8f8ab549284ef805465e8d51679f6d09f3ef59bd4ad47567d82
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Schedules task
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
Injector
Vh0D1iC85RHetwnE.exe
2026-09-13T02:49:58.685
malicious
Windows Exe (x86-32)
Close
Vh0D1iC85RHetwnE.exe
malicious
SHA256:
bce58c22b68736edf7b1be4e4074c5cfe2b5eb9b64e3730d4fe0714ca4e303a4
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Schedules task
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Creates an unusually large number of files
1/5
Installs system service
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
Injector