Threat Feed
graphhelper.bin.dll
2026-08-27T03:30:29.553
malicious
Windows DLL (x86-64)
Close
graphhelper.bin.dll
malicious
SHA256:
4a175c98f045c98bf6de78b60645dba77466bbba7bbb4324edeaa69446e4d4a0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Cobalt Strike configuration was extracted
3/5
Tries to open an unusually high number of parallel network connections
3/5
Suspicious content matched by YARA rules
2/5
Delays execution
1/5
Creates a page with write and execute permissions
1/5
Tries to connect using an uncommon port
1/5
Overwrites code
1/5
Resolves API functions dynamically
Hacktool
1b8878881f88a0d48aabd9d5bd3478a9.exe
2026-08-27T03:25:17.245
malicious
Windows Exe (x86-32)
Close
1b8878881f88a0d48aabd9d5bd3478a9.exe
malicious
SHA256:
d8fab5c25edb14a58b247bbd8c432c75940fb9a8696ab6f96c6ee58e88468ba0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Event Triggered Execution
2/5
Collects hardware properties
2/5
Schedules task
2/5
Creates an unusually large number of processes
1/5
Possibly does reconnaissance
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Checks external IP address
1/5
Resolves API functions dynamically
1/5
Writes an unusually large amount of data to the registry
1/5
Query OS Information
1/5
Creates process with hidden window
1/5
Enables process privileges
1/5
Modifies operating system directory
1/5
Modifies application directory
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Queries system time
Backdoor
install_q0.exe
2026-08-27T03:18:50.181
malicious
Windows Exe (x86-64)
Close
install_q0.exe
malicious
SHA256:
f08db7c83551ffc187ab7eb7eba321af5d5d94fdb39da16fe9224315b7ce1597
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Modifies Windows Defender configuration
4/5
Malicious file detected via reputation
4/5
Masks file extension
3/5
Suspicious file detected via reputation
3/5
Modifies native system functions
3/5
Executes code with kernel privileges
2/5
Tries to detect virtual machine
2/5
Sends control codes to a driver
2/5
Masquerades file extension
2/5
Creates an unusually large number of processes
2/5
Schedules task
2/5
Makes direct system call to possibly evade hooking based monitoring
1/5
Loads a dropped DLL
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Unusual large memory allocation
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Modifies operating system directory
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Downloads file
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Overwrites code
1/5
Drops PE file
Downloader
Hacktool
V0xKRSrvAK0NzIVE.exe
2026-08-27T03:07:42.034
malicious
Windows Exe (x86-32)
Close
V0xKRSrvAK0NzIVE.exe
malicious
SHA256:
23f3662342008c4f5de76d858ea28de01948163ffb4cbfe0727ddaeb8c3523d6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
5/5
njRAT configuration was extracted
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Modifies Windows Firewall configuration
2/5
Hides files
2/5
Queries OS info via WMI
1/5
Installs system startup script or application
1/5
Reads mouse position
1/5
Executes WMI query
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Kills process
1/5
Creates process with hidden window
1/5
Accesses volumes directly
1/5
Reads from memory of another process
1/5
Query OS Information
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Monitors keyboard input
1/5
Writes an unusually large amount of data to the registry
Spyware
Backdoor
OzPL51O5OWnSf4Ow.exe
2026-08-27T01:23:34.866
malicious
Windows Exe (x86-64)
Close
OzPL51O5OWnSf4Ow.exe
malicious
SHA256:
2ed0a9b559eb1b80617d882e17c5d6931da22ec5705bda2837da501110aa03c3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Tries to read cached credentials of various applications
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Monitors keyboard input
3/5
Uses HTTP to upload a large amount of data
3/5
Modifies native system functions
3/5
SmartContract configuration was extracted
2/5
Delays execution
2/5
Suspicious content matched by YARA rules
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Tries to detect analyzer sandbox
2/5
Schedules task
2/5
Queries a host's domain name
2/5
Tries to detect virtual machine
1/5
Creates mutex
1/5
Communicates via JSON RPC protocol
1/5
Content matched by YARA rules
1/5
Accesses volumes directly
1/5
Creates process with hidden window
1/5
URL contains a TLD highly associated with phishing
1/5
Queries system time
1/5
Query OS Information
1/5
Enumerates running processes
Spyware