Threat Feed
88ce31fbb0484e01dff253120de38a2fd19d3cf9bdb6582db4de7b2cef6c75a0.exe
2026-09-20T08:06:14.847
malicious
Windows Exe (x86-64)
Close
88ce31fbb0484e01dff253120de38a2fd19d3cf9bdb6582db4de7b2cef6c75a0.exe
malicious
SHA256:
88ce31fbb0484e01dff253120de38a2fd19d3cf9bdb6582db4de7b2cef6c75a0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
2/5
Delays execution
2/5
Reads network adapter information
2/5
Queries a host's domain name
2/5
Sets up server that accepts incoming connections
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Enables process privileges
1/5
Queries system time
1/5
Connects to remote host
Backdoor
Downloader
33be6dbcff2e667772a97b1e2b5ac210.exe
2026-09-20T07:56:46.408
malicious
Windows Exe (x86-64)
Close
33be6dbcff2e667772a97b1e2b5ac210.exe
malicious
SHA256:
cb386097cb8dd56b769793a40673e4b7a2df878864d4ae123359a7fa6e9265b5
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows configuration discovery
5/5
Makes indirect system calls to hide process injection
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
3/5
Suspicious file detected via reputation
3/5
Bypasses browser App-Bound Encryption
2/5
Queries a host's domain name
2/5
Searches for sensitive browser data
2/5
Searches for sensitive password manager data
2/5
Reads installed applications
2/5
Searches for sensitive remote access configuration data
2/5
Network configuration discovery
2/5
Reads network adapter information
2/5
Reads sensitive browser data
1/5
Creates a page with write and execute permissions
1/5
A monitored process crashed
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Resolves API functions dynamically
1/5
Accesses Microsoft Security Software registry keys
1/5
Creates process with hidden window
1/5
Drops PE file
1/5
Possibly does reconnaissance
Hacktool
Injector
2141b9681ee7125495d13f5147f856c3.exe
2026-09-20T07:55:20.534
malicious
Windows Exe (x86-64)
Close
2141b9681ee7125495d13f5147f856c3.exe
malicious
SHA256:
e93511363f7781c4c7ff3ed0698db6c4634092fe7e93ca96d666509a9412e73e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Vidar configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Signed executable failed signature validation
2/5
Searches for sensitive mail data
2/5
Searches for sensitive browser data
2/5
Reads installed applications
2/5
Tries to detect virtual machine
2/5
Searches for cryptocurrency wallet locations
1/5
Query CPU Properties
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Tries to detect application sandbox
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
0e8117413e01170023089c95fd91dc6f.exe
2026-09-20T07:53:12.439
malicious
Windows Exe (x86-32)
Close
0e8117413e01170023089c95fd91dc6f.exe
malicious
SHA256:
db4b6c524cbbdb661779fbc66a2f4c7369df8babc733ef965b279542477b2aca
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
3/5
Takes screenshot
3/5
Tries to detect the presence of antivirus software
3/5
Modifies native system functions
3/5
Monitors keyboard input
3/5
System Binary Proxy Execution
2/5
Searches for sensitive browser data
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Searches for cryptocurrency wallet locations
1/5
Creates a page with write and execute permissions
1/5
Query OS Information
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Possibly does reconnaissance
1/5
Executes WMI query
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Enumerates running processes
1/5
Resolves API functions dynamically
1/5
Writes an unusually large amount of data to the registry
1/5
Reads from memory of another process
1/5
Enables process privileges
Spyware
Injector
f3002b8735e6ecb6a98ac22824fdbb62.exe
2026-09-20T07:45:26.881
malicious
Windows Exe (x86-64)
Close
f3002b8735e6ecb6a98ac22824fdbb62.exe
malicious
SHA256:
a4514ad23234dbbe40df14dfa9b1259d4c9d314561b681ac85b91feaa9edceae
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Modifies native system functions
3/5
Suspicious content matched by YARA rules
3/5
Monitors keyboard input
3/5
Injects a file into another process
2/5
Tries to detect application sandbox
2/5
Reads network adapter information
2/5
Schedules task
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Overwrites code
1/5
Installs system startup script or application
1/5
Reads system data
1/5
Query CPU Properties
1/5
Queries system time
1/5
Monitors keyboard input
1/5
Creates a page with write and execute permissions
1/5
Writes an unusually large amount of data to the registry
1/5
Query OS Information
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
Spyware
Backdoor
Hacktool