Threat Feed
E41CA1DB2AD856A75B0AEC983E84A6B9.exe
2026-09-17T08:12:30.254
malicious
Windows Exe (x86-32)
Close
E41CA1DB2AD856A75B0AEC983E84A6B9.exe
malicious
SHA256:
0836288f79ff9a54a605a9e80642c0376f10afd312df84c6da12fce041388da1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
NanoCore configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Monitors user input
3/5
Obscures a file's origin
2/5
Sets up server that accepts incoming connections
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Connects to remote host
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Reads system data
1/5
Modifies application directory
1/5
Performs DNS request
Backdoor
DHL Inxpress Proposal.JS
2026-09-17T07:14:12.400
malicious
JScript
Close
DHL Inxpress Proposal.JS
malicious
SHA256:
a11a1508f79ba3ca99ef0b38dbd8439f5aa39c9877be9093c16b179614fc8e94
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
5/5
Agent Tesla configuration was extracted
5/5
Sets up server that accepts incoming connections
5/5
Combination of other detections shows configuration discovery
4/5
Tries to detect application sandbox
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Reads sensitive mail data
3/5
Classifies external IP address
3/5
Reads sensitive browser data
2/5
Suspicious content matched by YARA rules
2/5
Performs DNS request
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Searches for sensitive browser data
2/5
Possibly does reconnaissance
2/5
Searches for sensitive mail data
2/5
Enables process privileges
2/5
Reads network adapter information
2/5
Tries to connect using an uncommon port
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Connects to remote host
Spyware
Backdoor
Downloader
7rYLIVr3Pc5HsdO6.exe
2026-09-17T07:00:29.766
malicious
Windows Exe (x86-64)
Close
7rYLIVr3Pc5HsdO6.exe
malicious
SHA256:
757aea27c16170b05105794380912120d279e104a5c8a6512d813aea2efcf984
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Makes indirect system calls to hide process injection
4/5
Modifies Windows Update configuration
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Modifies Windows Defender configuration
3/5
Tries to open an unusually high number of parallel network connections
3/5
Uses HTTP to upload a large amount of data
3/5
SmartContract configuration was extracted
3/5
Disables a crucial system service
2/5
Allows invalid SSL certificates
2/5
Communicates with a Web3 service
2/5
Adds service dependency
2/5
Tries to detect virtual machine
2/5
Deletes file after execution
2/5
Disables automatic hibernation
2/5
Uses Alternate Data Stream (ADS) file attributes
2/5
Creates an unusually large number of processes
1/5
Accesses volumes directly
1/5
Creates a page with write and execute permissions
1/5
Creates process with hidden window
1/5
Installs system service
1/5
Modifies operating system directory
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Reads from memory of another process
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Accesses Microsoft Security Software registry keys
Injector
RE260903REDSEAAIRLINE.JS
2026-09-17T06:31:19.395
malicious
JScript
Close
RE260903REDSEAAIRLINE.JS
malicious
SHA256:
7cd0a912696add8b12ab99ac80ff41c3799812de22471a9d4e7f894e8065b4af
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
XWorm configuration was extracted
4/5
Tries to evade debugger
4/5
Tries to detect the presence of antivirus software
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
3/5
Obfuscates control flow
2/5
Enables process privileges
2/5
Queries OS info via WMI
2/5
Tries to detect debugger
2/5
Collects hardware properties
2/5
Writes an unusually large amount of data to the registry
2/5
Performs DNS request
2/5
Searches for sensitive browser data
2/5
Tries to connect using an uncommon port
2/5
Executes dropped PE file
1/5
Query OS Information
1/5
Reloads native system libraries
1/5
Connects to remote host
1/5
Creates mutex
1/5
Queries system time
Spyware
IMG_PKR-057091-KA BOOKING 2001-00-EP-IN-IR-7822- F&G - PO#02993.JS
2026-09-17T04:47:55.051
malicious
JScript
Close
IMG_PKR-057091-KA BOOKING 2001-00-EP-IN-IR-7822- F&G - PO#02993.JS
malicious
SHA256:
9f85627dbd4e78fef4a6f24fa96e944e19ad691d3dc4500937c4cccabf493557
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Monitors keyboard input
5/5
Tries to read cached credentials of various applications
5/5
Malicious content matched by YARA rules
5/5
Sets up server that accepts incoming connections
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Combination of other detections shows configuration discovery
4/5
Tries to detect the presence of antivirus software
4/5
Malicious content matched by YARA rules
4/5
Modifies control flow of another process
4/5
Malicious host or URL detected via reputation
4/5
Process Hollowing
4/5
Injects a file into another process
4/5
Writes into the memory of another process
4/5
Reads from memory of another process
4/5
Monitors clipboard content
4/5
Connects to SMTP server
3/5
Reads sensitive mail data
3/5
Suspicious content matched by YARA rules
3/5
Suspicious file detected via reputation
3/5
Takes screenshot
2/5
Checks external IP address
2/5
Enables process privileges
2/5
Suspicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Possibly does reconnaissance
2/5
Searches for sensitive FTP data
2/5
Executes dropped PE file
2/5
Performs DNS request
2/5
Collects hardware properties
2/5
Queries OS info via WMI
1/5
Connects to remote host
1/5
Enumerates running processes
1/5
Creates mutex
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Queries system time
Spyware
Backdoor
Keylogger
Downloader
Hacktool
Injector