Threat Feed
file.exe
2026-09-20T21:19:28.075
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
e6ead975285de8e7c0532069d9c4cb6f6d49acc59b21542b7347b40150430ff6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Tries to read cached credentials of various applications
3/5
Modifies native system functions
3/5
Uses HTTP to upload a large amount of data
3/5
Captures clipboard data
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive browser data
2/5
Searches for sensitive application data
2/5
Searches for sensitive FTP data
2/5
Dead Drop Resolver
2/5
Searches for sensitive mail data
2/5
Suspicious content matched by YARA rules
2/5
Searches for cryptocurrency wallet locations
1/5
Queries system time
1/5
Unusual large memory allocation
1/5
Possibly does reconnaissance
1/5
Enumerates running processes
1/5
Reads system data
1/5
Tries to detect application sandbox
1/5
Query CPU Properties
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
Spyware
e4057c11135a16608e7b8b15c2a856c1ff18906e104a987c56c528ff461182f2.sh
2026-09-20T20:59:59.487
malicious
Shell Script
Close
e4057c11135a16608e7b8b15c2a856c1ff18906e104a987c56c528ff461182f2.sh
malicious
SHA256:
e4057c11135a16608e7b8b15c2a856c1ff18906e104a987c56c528ff461182f2
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Mirai configuration was extracted
4/5
Downloads file
4/5
Malicious host or URL detected via reputation
2/5
Tries to execute downloaded binary of different architecture than the host
1/5
Connects to remote host
1/5
Creates hidden file or folder
1/5
Content matched by YARA rules
Bot
updater_fLvYdCLs.exe
2026-09-20T20:59:07.006
malicious
Windows Exe (x86-32)
Close
updater_fLvYdCLs.exe
malicious
SHA256:
e412a1e9c8de8d806cc27ab46974609dd0526b6591c08cd5b83d61ee52a0485d
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Known malicious mutex name is created
5/5
Combination of other detections shows configuration discovery
5/5
Tries to read cached credentials of various applications
5/5
SalatStealer configuration was extracted
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Searches for cryptocurrency wallet locations
2/5
Reads sensitive browser data
2/5
Sets up server that accepts incoming connections
2/5
Searches for sensitive application data
2/5
Searches for sensitive browser data
2/5
Collects hardware properties
2/5
Reads network adapter information
2/5
Suspicious content matched by YARA rules
2/5
Schedules task
2/5
Queries OS info via WMI
1/5
Timestamp manipulation
1/5
Possibly does reconnaissance
1/5
Modifies application directory
1/5
Reads system data
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Accesses volumes directly
1/5
Unusual large memory allocation
1/5
Accesses Microsoft Security Software registry keys
1/5
Queries system time
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Query OS Information
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Executes dropped PE file
Spyware
updater_fLvYdCLs.exe
2026-09-20T20:58:42.835
malicious
Windows Exe (x86-32)
Close
updater_fLvYdCLs.exe
malicious
SHA256:
def4ed166b78f608e57283ca29ceefa132d049606afbfb8ea32b6c5c27866087
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
5/5
Combination of other detections shows configuration discovery
5/5
Malicious content matched by YARA rules
5/5
Known malicious mutex name is created
5/5
SalatStealer configuration was extracted
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Reads sensitive browser data
2/5
Searches for sensitive browser data
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Collects hardware properties
2/5
Queries OS info via WMI
2/5
Schedules task
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
1/5
Reads system data
1/5
Queries system time
1/5
Modifies application directory
1/5
Creates process with hidden window
1/5
Possibly does reconnaissance
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Content matched by YARA rules
1/5
Performs DNS request
Spyware
updater_hvPrGfjL.exe
2026-09-20T20:51:10.456
malicious
Windows Exe (x86-32)
Close
updater_hvPrGfjL.exe
malicious
SHA256:
19fcf0739788f7f96ebcbe9d2800363e581215595e82b5c85776a042a408b704
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
5/5
Known malicious mutex name is created
5/5
Tries to read cached credentials of various applications
5/5
Malicious content matched by YARA rules
5/5
SalatStealer configuration was extracted
4/5
Malicious file detected via reputation
3/5
Takes screenshot
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
2/5
Schedules task
2/5
Delays execution
2/5
Sets up server that accepts incoming connections
2/5
Queries OS info via WMI
2/5
Suspicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Searches for sensitive application data
2/5
Collects hardware properties
1/5
Drops PE file
1/5
Accesses volumes directly
1/5
Reads system data
1/5
Accesses Microsoft Security Software registry keys
1/5
Queries system time
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Modifies application directory
1/5
Creates process with hidden window
1/5
Enumerates running processes
1/5
Possibly does reconnaissance
Spyware