Threat Feed
j.dll
2026-07-23T19:26:51
malicious
Windows DLL (x86-32)
Close
j.dll
malicious
SHA256:
d0e33939f7f9336dc6c2108d187a71e26c8449d289dcb8f8d9fe7b9777bc373a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Uses AFD endpoint for network communication
4/5
Makes indirect system call to possibly evade hooking based monitoring
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Process Hollowing
4/5
Monitors clipboard content
3/5
SmartContract configuration was extracted
3/5
Takes screenshot
2/5
Collects hardware properties
2/5
Delays execution
2/5
Reads network adapter information
2/5
Searches for sensitive browser data
2/5
Searches for cryptocurrency wallet locations
2/5
Creates a new process from a system binary
2/5
Signed executable failed signature validation
2/5
Sends control codes to a driver
1/5
Resolves API functions dynamically
1/5
Connects to remote host
1/5
Performs DNS request
1/5
Possibly does reconnaissance
1/5
Reads system data
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Creates mutex
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Unusual large memory allocation
1/5
Creates a page with write and execute permissions
1/5
Network configuration discovery
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Reads from memory of another process
1/5
Content matched by YARA rules
1/5
Communicates via JSON RPC protocol
Spyware
Keylogger
Injector
https://buletsatrading.co.za/apexfab/
2026-07-23T18:45:20.404
malicious
URL
Close
https://buletsatrading.co.za/apexfab/
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious content matched by YARA rules
1/5
Checks external IP address
1/5
Content matched by YARA rules
1/5
Downloads executable
1/5
Branding image detected via Computer Vision
1/5
Page uses exact branding image of a popular online service
1/5
Page contains clickables with luring keywords
Downloader
Phishing
mR596imewMh11I34.exe
2026-07-23T17:49:45.123
malicious
Windows Exe (x86-32)
Close
mR596imewMh11I34.exe
malicious
SHA256:
52cf47ed479412878b74a060cda38c4e300c3dbf3f8edd4cc2e9ab8904d8a192
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Rename system utilities
2/5
Sends control codes to a driver
2/5
Hides files
2/5
Accesses physical drive
2/5
Delays execution
2/5
Deletes file after execution
2/5
Tries to detect virtual machine
1/5
Executes dropped PE file
1/5
Enumerates running processes
1/5
Timestamp manipulation
1/5
Queries system time
1/5
Creates process with hidden window
1/5
Connects to remote host
1/5
Tries to connect using an uncommon port
1/5
Modifies application directory
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Creates mutex
1/5
Query CPU Properties
1/5
Enables process privileges
Trojan
6qiqNZmsi3obF1RR.exe
2026-07-23T17:48:07.501
malicious
Windows Exe (x86-32)
Close
6qiqNZmsi3obF1RR.exe
malicious
SHA256:
aec149fed5c00cd3c19879f9689db77fb9ad4d492d57c743eb0aea990c817a5c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
3/5
Suspicious content matched by YARA rules
3/5
All network connection attempts failed
2/5
Deletes file after execution
2/5
Signed executable failed signature validation
2/5
Hides files
1/5
Drops PE file
1/5
Queries system time
1/5
Executes dropped PE file
1/5
Modifies application directory
1/5
Creates mutex
1/5
Possibly does reconnaissance
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Hacktool
AUTgwJ8CS0g3gKkO.exe
2026-07-23T17:46:58.827
malicious
Windows Exe (x86-32)
Close
AUTgwJ8CS0g3gKkO.exe
malicious
SHA256:
9e2228ad94dc07ed45e16c4dbe892466c44075ce77a753d0b86a23eda2caf4ae
VMRay Threat Identifiers
Close
Severity
Operation
5/5
XRed configuration was extracted
5/5
Malicious content matched by YARA rules
5/5
Deletes user files
3/5
Office macro uses a file I/O function
3/5
Performs DNS request for known DDNS domain
2/5
Searches for sensitive password manager data
2/5
Sets up server that accepts incoming connections
2/5
Office macro uses an execute function
2/5
Searches for sensitive remote access configuration data
2/5
Executes dropped PE masquerading Filename
2/5
Delays execution
2/5
Office macro uses a network function
2/5
Office macro uses a suspicious function
2/5
Suspicious content matched by YARA rules
1/5
Reads mouse position
1/5
Creates mutex
1/5
Installs system startup script or application
1/5
Performs DNS request
1/5
Resolves API functions dynamically
1/5
Contains suspicious Office macro
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Queries system time
1/5
Timestamp manipulation
1/5
Checks Internet connection
Backdoor
Wiper