Threat Feed
ab2f3f0abf3e7ae2d95881965f8bc0e1a90e7447085648a04d9efee0399e974b.exe
2026-09-28T21:24:01.150
malicious
Windows Exe (x86-64)
Close
ab2f3f0abf3e7ae2d95881965f8bc0e1a90e7447085648a04d9efee0399e974b.exe
malicious
SHA256:
ab2f3f0abf3e7ae2d95881965f8bc0e1a90e7447085648a04d9efee0399e974b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Vidar configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Reads installed applications
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive mail data
2/5
Tries to detect virtual machine
2/5
Dead Drop Resolver
1/5
Query OS Information
1/5
Unusual large memory allocation
1/5
Content matched by YARA rules
1/5
Query CPU Properties
1/5
Enumerates running processes
1/5
Queries system time
1/5
Creates mutex
1/5
Resolves API functions dynamically
1/5
Tries to detect application sandbox
Spyware
fdcf294cb718b0b5699cd80d753bf65a2a81703d139808f1ed8e049b36bbfb6b.exe
2026-09-28T21:23:08.692
malicious
Windows Exe (x86-64)
Close
fdcf294cb718b0b5699cd80d753bf65a2a81703d139808f1ed8e049b36bbfb6b.exe
malicious
SHA256:
fdcf294cb718b0b5699cd80d753bf65a2a81703d139808f1ed8e049b36bbfb6b
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Vidar configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Dead Drop Resolver
2/5
Tries to detect virtual machine
2/5
Searches for cryptocurrency wallet locations
2/5
Reads installed applications
1/5
Query OS Information
1/5
Unusual large memory allocation
1/5
Creates mutex
1/5
Queries system time
1/5
Enumerates running processes
1/5
Tries to detect application sandbox
1/5
Query CPU Properties
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
313ca74c5a6fca97af609826c2d81450a7bb779477207115eb4bf6d3f616f469.exe
2026-09-28T21:22:48.400
malicious
Windows Exe (x86-64)
Close
313ca74c5a6fca97af609826c2d81450a7bb779477207115eb4bf6d3f616f469.exe
malicious
SHA256:
313ca74c5a6fca97af609826c2d81450a7bb779477207115eb4bf6d3f616f469
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Vidar configuration was extracted
4/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Tries to open an unusually high number of parallel network connections
3/5
Uses HTTP to upload a large amount of data
2/5
Delays execution
2/5
Tries to detect analyzer sandbox
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Creates mutex
1/5
Queries system time
1/5
Enumerates running processes
1/5
Tries to detect application sandbox
Spyware
e3831b39dffdefe129c6be4e0e0131ea19cdeea6575a44a6ef0386f4d138e77e.exe
2026-09-28T21:22:15.484
malicious
Windows Exe (x86-64)
Close
e3831b39dffdefe129c6be4e0e0131ea19cdeea6575a44a6ef0386f4d138e77e.exe
malicious
SHA256:
e3831b39dffdefe129c6be4e0e0131ea19cdeea6575a44a6ef0386f4d138e77e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Reads installed applications
2/5
Dead Drop Resolver
2/5
Tries to detect virtual machine
1/5
Resolves API functions dynamically
1/5
Unusual large memory allocation
1/5
Creates mutex
1/5
Queries system time
1/5
Enumerates running processes
1/5
Query CPU Properties
1/5
Query OS Information
1/5
Content matched by YARA rules
1/5
Tries to detect application sandbox
Spyware
84f2c1c0af5c666beb6ea67076cb5b26324d112eb1a29511eb59cc98c25ad5aa.exe
2026-09-28T21:21:41.607
malicious
Windows Exe (x86-64)
Close
84f2c1c0af5c666beb6ea67076cb5b26324d112eb1a29511eb59cc98c25ad5aa.exe
malicious
SHA256:
84f2c1c0af5c666beb6ea67076cb5b26324d112eb1a29511eb59cc98c25ad5aa
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Vidar configuration was extracted
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive browser data
2/5
Searches for sensitive mail data
2/5
Searches for cryptocurrency wallet locations
2/5
Reads installed applications
2/5
Dead Drop Resolver
2/5
Tries to detect virtual machine
1/5
Query OS Information
1/5
Queries system time
1/5
Creates mutex
1/5
Enumerates running processes
1/5
Tries to detect application sandbox
1/5
Unusual large memory allocation
1/5
Query CPU Properties
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware