Threat Feed
macho_b515ddfae69c
2026-10-01T21:34:14.688
malicious
macOS Executable
Close
macho_b515ddfae69c
malicious
SHA256:
b515ddfae69cd484d523feb2544704b2df62e029e00d9f646410eef4bd6832ba
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Reads ssh keys
5/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
3/5
Reads credential files of the keychain
3/5
Query SIP status
2/5
Reads sensitive browser data
2/5
Searches for sensitive application data
2/5
Searches for sensitive mail data
2/5
Searches for sensitive browser data
2/5
Reads sensitive mail data
2/5
Checks for existence of ssh keys
2/5
Creates an unusually large number of processes
2/5
Suspicious content matched by YARA rules
1/5
Tries to detect virtual machine
1/5
Creates hidden file or folder
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Reads system data
Spyware
MC-Cheats_Generator.exe
2026-10-01T21:16:20.217
malicious
Windows Exe (x86-64)
Close
MC-Cheats_Generator.exe
malicious
SHA256:
a2118ac64d8635189f6306a55f4b7def2a5b7791f533c994b09666556a91c506
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
4/5
Malicious file detected via reputation
3/5
Suspicious content matched by YARA rules
3/5
Searches for available drives
3/5
Suspicious file detected via reputation
2/5
Tries to detect application sandbox
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Suspicious content matched by YARA rules
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive application data
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive password manager data
2/5
Searches for sensitive VPN configuration data
2/5
Queries OS info via WMI
2/5
Collects hardware properties
1/5
Unusual large memory allocation
1/5
Tries to detect application sandbox
1/5
Resolves API functions dynamically
1/5
Tries to detect virtual machine
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Reads from memory of another process
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Creates process with hidden window
1/5
Creates mutex
1/5
Possibly does reconnaissance
1/5
Queries system time
1/5
Performs DNS request
1/5
Connects to remote host
1/5
Content matched by YARA rules
1/5
Tries to detect debugger
1/5
Enumerates running processes
1/5
Accesses volumes directly
Hacktool
152199ad31615934d73c235feb0722e8985767184d11cb8f2765bd17b1c997f0.sh
2026-10-01T21:15:30.539
malicious
Shell Script
Close
152199ad31615934d73c235feb0722e8985767184d11cb8f2765bd17b1c997f0.sh
malicious
SHA256:
152199ad31615934d73c235feb0722e8985767184d11cb8f2765bd17b1c997f0
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Mirai configuration was extracted
4/5
Downloads file
4/5
Malicious file detected via reputation
3/5
Creates an unusually large number of processes
2/5
Tries to execute downloaded binary of different architecture than the host
1/5
Connects to remote host
1/5
Content matched by YARA rules
Downloader
Bot
dda59dbef0743a6b662b129b2679d24eb759bce9526ef011648c367834dff02c
2026-10-01T21:11:43.257
malicious
Linux ELF Executable (x86-64)
Close
dda59dbef0743a6b662b129b2679d24eb759bce9526ef011648c367834dff02c
malicious
SHA256:
dda59dbef0743a6b662b129b2679d24eb759bce9526ef011648c367834dff02c
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Mirai configuration was extracted
4/5
Malicious file detected via reputation
2/5
Enumerates running processes
1/5
Tries to connect using an uncommon port
1/5
Queries system time
1/5
Connects to remote host
Bot
newisbest.exe
2026-10-01T21:02:30.282
malicious
Windows Exe (x86-64)
Close
newisbest.exe
malicious
SHA256:
d503855e73d729b687c9f3a18d686ecc40488a3f6d91a67e2d0b377b4554783c
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
4/5
Malicious file detected via reputation
2/5
Reads installed applications
2/5
Peripheral Device Discovery
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Queries system time
1/5
Creates a page with write and execute permissions
1/5
Tries to detect virtual machine
Injector