Threat Feed
file.exe
2026-09-10T08:09:20.544
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
b9a495f818d931c6ec2b967dab629976673f74a8795e6082b9d2d7901c12408d
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XWorm configuration was extracted
5/5
Tries to read cached credentials of various applications
5/5
Combination of other detections shows configuration discovery
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Creates a new process masquerading as a system process
4/5
Writes into the memory of another process
3/5
Monitors keyboard input
3/5
Sends data via a Telegram bot
3/5
Suspicious content matched by YARA rules
3/5
Uses HTTP to upload a large amount of data
3/5
Deletes file after execution
3/5
Tries to detect the presence of antivirus software
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Searches for sensitive application data
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive FTP data
2/5
Deletes file after execution
2/5
Sets up server that accepts incoming connections
2/5
Reads network adapter information
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Searches for sensitive mail data
2/5
Schedules task
2/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive remote access configuration data
2/5
Executes dropped PE masquerading Filename
2/5
Delays execution
2/5
Searches for cryptocurrency wallet locations
1/5
Checks external IP address
1/5
Possibly does reconnaissance
1/5
Creates mutex
1/5
Queries system time
1/5
Query OS Information
1/5
Enumerates running processes
1/5
Executes WMI query
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Unusual large memory allocation
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Drops PE masquerading Filename
Spyware
Downloader
Worm
Injector
uiNGvS6YNlPBzppL.exe
2026-09-10T07:43:05.181
malicious
Windows Exe (x86-64)
Close
uiNGvS6YNlPBzppL.exe
malicious
SHA256:
ddb7deaf4324d3aa3cb2de39b6a74446ca1cb4774b82e0e3b065d20773a87a02
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Modifies content of user files
4/5
Uses a double file extension
4/5
Malicious file detected via reputation
4/5
Masks file extension
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Masquerades file extension
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Tries to detect application sandbox
1/5
Timestamp manipulation
1/5
Unusual large memory allocation
1/5
Modifies application directory
1/5
Modifies operating system directory
1/5
Installs system startup script or application
1/5
Possibly does reconnaissance
1/5
Performs DNS request
Ransomware
KaBsOFjFyJpYcxEy.exe
2026-09-10T07:39:29.922
malicious
Windows Exe (x86-32)
Close
KaBsOFjFyJpYcxEy.exe
malicious
SHA256:
ddea9d452bee664362191d880939f6e2b13a1b68352b7bf0351aa2a551e672ac
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
All network connection attempts failed
3/5
Creates a subprocess to cleanup tracks
2/5
Deletes file after execution
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Resolves API functions dynamically
meJ6Fft0f70NUfWQ.exe
2026-09-10T07:38:39.981
malicious
Windows Exe (x86-64)
Close
meJ6Fft0f70NUfWQ.exe
malicious
SHA256:
8db12cdb17f13f3950af28bc7b29d93ade15a686768f8b7287fbc6c8363b0cd1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Modifies content of user files
5/5
Malicious content matched by YARA rules
5/5
Cobalt Strike configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Searches for available drives
3/5
Suspicious content matched by YARA rules
2/5
Sets up server that accepts incoming connections
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Queries system time
1/5
Changes folder appearance
1/5
Unusual large memory allocation
1/5
Enables process privileges
1/5
Creates a page with write and execute permissions
1/5
Accesses volumes directly
1/5
Modifies application directory
1/5
Tries to detect application sandbox
1/5
Performs DNS request
Ransomware
PUA
Hacktool
Miner
YWbsC313IzDGcvKC.exe
2026-09-10T07:34:59.996
malicious
Windows Exe (x86-32)
Close
YWbsC313IzDGcvKC.exe
malicious
SHA256:
fd6833d16617c2f0810f83b3dc635e5c0907aadee7ada4005fdef9fa70fb4f24
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Adds a hook to a web browser
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
2/5
Delays execution
2/5
Schedules task
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Creates a page with write and execute permissions
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Reads system data
1/5
Drops PE file
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Executes WMI query
Spyware
Injector