Threat Feed
file.exe
2026-07-27T19:32:07.441
malicious
Windows Exe (x86-64)
Close
file.exe
malicious
SHA256:
ab4394c429efc69b6927a5eb6ecfe7e2cc3df99dd2d279f96729d72a8283e85f
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
5/5
Tries to read cached credentials of various applications
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows configuration discovery
5/5
SalatStealer configuration was extracted
3/5
Takes screenshot
2/5
Delays execution
2/5
Searches for sensitive browser data
2/5
Reads network adapter information
2/5
Sets up server that accepts incoming connections
2/5
Suspicious content matched by YARA rules
2/5
Collects hardware properties
2/5
Schedules task
2/5
Queries OS info via WMI
2/5
Searches for sensitive application data
2/5
Searches for cryptocurrency wallet locations
2/5
Reads sensitive browser data
1/5
Executes dropped PE file
1/5
Content matched by YARA rules
1/5
Timestamp manipulation
1/5
Performs DNS request
1/5
Enumerates running processes
1/5
Reads system data
1/5
Queries system time
1/5
Modifies application directory
1/5
Tries to detect debugger
1/5
Creates process with hidden window
1/5
Accesses Microsoft Security Software registry keys
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Unusual large memory allocation
1/5
Possibly does reconnaissance
Spyware
file.exe
2026-07-27T19:27:37.891
malicious
Windows Exe (x86-32)
Close
file.exe
malicious
SHA256:
72da1a3abc1230fdbb9a1a7ac21b490b6482e14cbcfa9b8f5913af03d99fabde
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Phorpiex configuration was extracted
3/5
Obscures a file's origin
2/5
Delays execution
2/5
Connects to SMTP server
1/5
Creates mutex
1/5
Queries system time
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Checks external IP address
1/5
Content matched by YARA rules
Worm
KglNchm2izpHsz8m.exe
2026-07-27T19:01:26.928
malicious
Windows Exe (x86-32)
Close
KglNchm2izpHsz8m.exe
malicious
SHA256:
d2e9f95d58c56a2c000577b00a0d04bb96d8f9479e115c8dbd20e00195604971
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Prometei configuration was extracted
3/5
Redirects Standard Output
2/5
Query OS Information
2/5
Internet Connection Discovery
1/5
Modifies operating system directory
1/5
Creates process with hidden window
Bot
aDFgNBzGl5ALFhwv.exe
2026-07-27T18:48:32.090
malicious
Windows Exe (x86-32)
Close
aDFgNBzGl5ALFhwv.exe
malicious
SHA256:
59ebdce85134cd7e8a97c7637fcb2bb530bf5d09d105a98e4189dead286cd2e9
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Tries to read cached credentials of various applications
4/5
Malicious content matched by YARA rules
4/5
Makes indirect system call to possibly evade hooking based monitoring
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
3/5
Uses HTTP to upload a large amount of data
3/5
Captures clipboard data
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Delays execution
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
2/5
Queries OS info via WMI
2/5
Allows invalid SSL certificates
2/5
Searches for sensitive application data
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Query Firmware Information
2/5
Sets up server that accepts incoming connections
2/5
Searches for sensitive mail data
2/5
Tries to detect application sandbox
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Drops PE file
1/5
Creates process with hidden window
1/5
Unusual large memory allocation
1/5
Query OS Information
1/5
Modifies operating system directory
1/5
Kills process
1/5
Reads from memory of another process
1/5
Enumerates running processes
1/5
Creates a page with write and execute permissions
1/5
Modifies application directory
1/5
Creates mutex
1/5
Possibly does reconnaissance
1/5
Query CPU Properties
1/5
Reads system data
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Downloads file
1/5
Tries to connect using an uncommon port
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Queries system time
Spyware
http://facebooksignuplogin.blogspot.com
2026-07-27T18:44:08.199
malicious
URL
Close
http://facebooksignuplogin.blogspot.com
malicious
SHA256:
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
4/5
Phishing page detected via Machine Learning
2/5
Page title matches the name of a popular online service
2/5
Page is served from a service commonly used for temporary hosting
2/5
Unsecured data
1/5
Resource is loaded from a service commonly used for temporary hosting
1/5
Page presents itself as a logon page
1/5
Content matched by YARA rules
Phishing