Threat Feed
a62eb03d71fc258de678fbc84572db662dc05617aeb7caf192d031086e6b9feb.exe
2026-09-06T09:30:44.406
malicious
Windows Exe (x86-64)
Close
a62eb03d71fc258de678fbc84572db662dc05617aeb7caf192d031086e6b9feb.exe
malicious
SHA256:
a62eb03d71fc258de678fbc84572db662dc05617aeb7caf192d031086e6b9feb
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Tries to detect virtual machine
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Signed executable failed signature validation
2/5
Searches for cryptocurrency wallet locations
1/5
Tries to detect application sandbox
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Query CPU Properties
1/5
Query OS Information
1/5
Resolves API functions dynamically
Spyware
b4771127ab1f2e8b4a3a3d0f6d3c26b500322f1a1dac8d60d3fc78caeaa9b6e9.exe
2026-09-06T09:26:48.383
malicious
Windows Exe (x86-64)
Close
b4771127ab1f2e8b4a3a3d0f6d3c26b500322f1a1dac8d60d3fc78caeaa9b6e9.exe
malicious
SHA256:
b4771127ab1f2e8b4a3a3d0f6d3c26b500322f1a1dac8d60d3fc78caeaa9b6e9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Vidar configuration was extracted
5/5
Malicious content matched by YARA rules
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive mail data
2/5
Searches for cryptocurrency wallet locations
2/5
Tries to detect virtual machine
2/5
Searches for sensitive browser data
2/5
Signed executable failed signature validation
1/5
Tries to detect application sandbox
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Query CPU Properties
1/5
Resolves API functions dynamically
Spyware
76b32b96762234d459750b76cac9e937d027c9d08381c05c29daaa2ac3bc615e.exe
2026-09-06T09:21:56.530
malicious
Windows Exe (x86-64)
Close
76b32b96762234d459750b76cac9e937d027c9d08381c05c29daaa2ac3bc615e.exe
malicious
SHA256:
76b32b96762234d459750b76cac9e937d027c9d08381c05c29daaa2ac3bc615e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious content matched by YARA rules
2/5
Signed executable failed signature validation
1/5
Unusual large memory allocation
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates mutex
1/5
Resolves API functions dynamically
Spyware
f762090080981fe38899e90a2d4d70b9455b9e01fa1d394e12de493ee3f75b10.exe
2026-09-06T09:21:48.537
malicious
Windows Exe (x86-64)
Close
f762090080981fe38899e90a2d4d70b9455b9e01fa1d394e12de493ee3f75b10.exe
malicious
SHA256:
f762090080981fe38899e90a2d4d70b9455b9e01fa1d394e12de493ee3f75b10
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
3/5
Reads installed applications
3/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive mail data
2/5
Tries to detect virtual machine
2/5
Searches for sensitive browser data
2/5
Signed executable failed signature validation
2/5
Searches for cryptocurrency wallet locations
1/5
Tries to detect application sandbox
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Unusual large memory allocation
1/5
Query CPU Properties
1/5
Query OS Information
1/5
Resolves API functions dynamically
Spyware
5e7a1b9857320e185d0dc8724dac6944bfceb01951a03b0f6c99f929020be862.exe
2026-09-06T09:21:02.512
malicious
Windows Exe (x86-64)
Close
5e7a1b9857320e185d0dc8724dac6944bfceb01951a03b0f6c99f929020be862.exe
malicious
SHA256:
5e7a1b9857320e185d0dc8724dac6944bfceb01951a03b0f6c99f929020be862
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
5/5
Malicious content matched by YARA rules
4/5
Loads a known vulnerable file
4/5
Modifies Windows Update configuration
4/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Makes indirect system call to possibly evade hooking based monitoring
3/5
Modifies native system functions
3/5
SmartContract configuration was extracted
3/5
Disables a crucial system service
2/5
Reads network adapter information
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Disables automatic hibernation
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Deletes file after execution
2/5
Communicates with a Web3 service
2/5
Adds service dependency
2/5
Tries to detect virtual machine
2/5
Creates an unusually large number of processes
2/5
Sets up server that accepts incoming connections
1/5
Accesses volumes directly
1/5
Creates process with hidden window
1/5
Installs system service
1/5
Modifies operating system directory
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Reads from memory of another process
1/5
Creates mutex
1/5
Accesses Microsoft Security Software registry keys
1/5
Enables process privileges
1/5
Unusual large memory allocation
1/5
Performs DNS request
1/5
Connects to remote host
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Queries system time
PUA
Miner
Injector