Threat Feed
066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6.exe
2026-08-21T21:13:14.790
malicious
Windows Exe (x86-64)
Close
066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6.exe
malicious
SHA256:
066d83b98a2081e0bb075c94376aebc9b0fd6499025cab1762d83bbb4d7576c6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
3/5
Captures clipboard data
3/5
Uses HTTP to upload a large amount of data
2/5
Queries OS info via WMI
2/5
Schedules task
2/5
Query Firmware Information
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Collects hardware properties
1/5
Overwrites code
1/5
A monitored process crashed
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Executes WMI query
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Queries system time
Spyware
file.exe
2026-08-21T21:11:58.861
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
cbfb130de9c46cad99bc8ac1888f6993d5d0adf70853a90766c68244be44b75c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Reads a significant portion of browser memory
5/5
Tries to read cached credentials of various applications
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
2/5
Reads network adapter information
2/5
Reads sensitive browser data
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Searches for sensitive browser data
2/5
Sends control codes to a driver
1/5
Possibly does reconnaissance
1/5
Installs system startup script or application
1/5
Reads from memory of another process
1/5
Resolves API functions dynamically
1/5
Queries system time
1/5
Enumerates running processes
1/5
Accesses Microsoft Security Software registry keys
1/5
Accesses volumes directly
1/5
Reads system data
1/5
Creates mutex
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Query OS Information
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Creates process with hidden window
Spyware
1778b4f8e22bb823376dc908e331acab.exe
2026-08-21T20:32:58.633
malicious
Windows Exe (x86-32)
Close
1778b4f8e22bb823376dc908e331acab.exe
malicious
SHA256:
49304556bbedab691ed3aeccdb8cb4a5b5991b984015b1abae1aeb76ad5013e6
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Remcos configuration was extracted
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
3/5
Performs DNS request for known DDNS domain
2/5
Delays execution
1/5
Creates mutex
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Queries system time
1/5
Resolves API functions dynamically
1/5
Performs DNS request
1/5
Query OS Information
Backdoor
IWjJ0REgUlSpfCaD.exe
2026-08-21T19:37:06.434
malicious
Windows Exe (x86-32)
Close
IWjJ0REgUlSpfCaD.exe
malicious
SHA256:
6f8cbe2586d3d1afcaa95c5dc4a806e702ccf253d6d359687b5ac41e86096823
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
3/5
Reads installed applications
2/5
Reads sensitive browser data
2/5
Sends control codes to a driver
2/5
Deletes file after execution
2/5
Enables critical process privileges
2/5
Reads network adapter information
2/5
Reads network configuration
2/5
Executes dropped PE masquerading Filename
2/5
Tries to detect debugger
2/5
Schedules task
2/5
Searches for sensitive browser data
2/5
Masquerades file extension
1/5
Unusual large memory allocation
1/5
Creates process with hidden window
1/5
Reads system data
1/5
Enumerates running processes
1/5
Query OS Information
1/5
Creates a page with write and execute permissions
1/5
Reads mouse position
1/5
Accesses volumes directly
1/5
Monitors keyboard input
1/5
Tries to detect debugger
1/5
Possibly does reconnaissance
1/5
Network configuration discovery
1/5
Query CPU Properties
1/5
Tries to detect application sandbox
1/5
Installs system startup script or application
1/5
Queries system time
1/5
Performs DNS request
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Downloads executable
1/5
Executes downloaded executable
1/5
Creates mutex
Downloader
O995Vo2bZGPErh72.html
2026-08-21T19:28:12.527
malicious
HTML Document
Close
O995Vo2bZGPErh72.html
malicious
SHA256:
b4aa30c192bb167a974924cb0ab49dff344d9f6d04be4422f4a88fd7620f788c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing