Threat Feed
VsQrNOviyh5hFhZe.exe
2026-09-09T09:23:10.679
malicious
Windows Exe (x86-32)
Close
VsQrNOviyh5hFhZe.exe
malicious
SHA256:
a780d0e4a71aa20c2b43a70f3cee2c923781cfef965787e0b46e0682e07782d4
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows configuration discovery
3/5
Executes code with kernel privileges
3/5
Reads installed applications
2/5
Reads network adapter information
2/5
Tries to detect debugger
2/5
Collects hardware properties
2/5
Schedules task
2/5
Accesses physical drive
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Enables critical process privileges
2/5
Creates an unusually large number of processes
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Sends control codes to a driver
2/5
Reads network configuration
2/5
Deletes file after execution
2/5
Queries OS info via WMI
1/5
Reads system data
1/5
Enumerates running processes
1/5
Tries to detect application sandbox
1/5
Query OS Information
1/5
Query CPU Properties
1/5
Executes WMI query
1/5
Possibly does reconnaissance
1/5
Monitors keyboard input
1/5
Reads mouse position
1/5
Accesses volumes directly
1/5
Creates mutex
1/5
Creates a page with write and execute permissions
1/5
Tries to detect debugger
1/5
Enables process privileges
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Creates process with hidden window
1/5
Network configuration discovery
1/5
Downloads file
1/5
Content matched by YARA rules
1/5
Modifies application directory
1/5
Resolves API functions dynamically
1/5
A monitored process crashed
1/5
Drops PE file
1/5
Loads a dropped DLL
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Downloads executable
1/5
Executes downloaded executable
1/5
Unusual large memory allocation
Downloader
E-Statement(SI33488777).exe
2026-09-09T09:23:04.701
malicious
Windows Exe (x86-64)
Close
E-Statement(SI33488777).exe
malicious
SHA256:
9c2b14d26cea958757168f181d94098bcbeb6eb263b6bc9f93288e93a8b3029a
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Tries to read cached credentials of various applications
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Injected process sets up server that accepts incoming connections
4/5
Malicious file detected via reputation
4/5
Process Hollowing
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
2/5
Searches for sensitive browser data
2/5
Searches for sensitive FTP data
2/5
Searches for sensitive application data
2/5
Suspicious content matched by YARA rules
2/5
Modifies control flow of a process started from a created or modified executable
2/5
Searches for sensitive mail data
2/5
Searches for cryptocurrency wallet locations
2/5
Reads sensitive mail data
2/5
Reads network adapter information
2/5
Tries to detect debugger
2/5
Queries OS info via WMI
1/5
Uses encryption API
1/5
Creates mutex
1/5
Query OS Information
1/5
Creates a page with write and execute permissions
1/5
Enables process privileges
1/5
Enumerates running processes
1/5
Queries system time
1/5
Possibly does reconnaissance
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Creates process with hidden window
1/5
Tries to connect using an uncommon port
1/5
Downloads file
1/5
Connects to remote host
1/5
Installs system startup script or application
Spyware
Backdoor
Downloader
Injector
SwgMuYHn6mToMTuW.exe
2026-09-09T07:58:06.775
malicious
Windows Exe (x86-64)
Close
SwgMuYHn6mToMTuW.exe
malicious
SHA256:
73f8ef5a1c4989f3ad77d32aadf9f9ce63c69e421c5584656751aa5b80a99a3a
VMRay Threat Identifiers
Close
Severity
Operation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
Bypasses browser App-Bound Encryption
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Masquerades file extension
1/5
Resolves API functions dynamically
1/5
Content matched by YARA rules
1/5
Downloads file
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
Downloader
Injector
gdgraKQ1BmZjGP6f.exe
2026-09-09T07:57:21.084
malicious
Windows Exe (x86-64)
Close
gdgraKQ1BmZjGP6f.exe
malicious
SHA256:
ec4ec4fdc3a06b16aa851dee8b62f96dd96f125c00dc39a6936cae79bea952df
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Known malicious mutex name is created
4/5
Malicious file detected via reputation
2/5
Tries to detect virtual machine
1/5
Creates a page with write and execute permissions
1/5
A monitored process crashed
1/5
Resolves API functions dynamically
1/5
Possibly does reconnaissance
1/5
Modifies application directory
Ransomware
uxhwgQ1AVv3mOXRJ.exe
2026-09-09T07:57:02.487
malicious
Windows Exe (x86-32)
Close
uxhwgQ1AVv3mOXRJ.exe
malicious
SHA256:
5e04716cd06a5efd81fa457d0f49fef5c229633b4387b38cd4a4c0094547c269
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Combination of other detections shows multiple input capture behaviors
5/5
Modifies Windows automatic backups
4/5
Tries to disable antivirus software
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
4/5
Modifies control flow of another process
4/5
Writes into the memory of another process
4/5
Malicious content matched by YARA rules
4/5
Disables a crucial system tool
4/5
Bypasses Windows User Account Control (UAC)
4/5
Blocks network connection to security products
3/5
Injects a file into another process
3/5
Captures clipboard data
3/5
Takes screenshot
3/5
Disables a crucial system service
3/5
Suspicious content matched by YARA rules
3/5
All network connection attempts failed
3/5
Monitors keyboard input
2/5
Searches for sensitive password manager data
2/5
Locks the Windows desktop
2/5
Hides files
2/5
Changes the desktop wallpaper
2/5
Searches for sensitive remote access configuration data
2/5
Searches for sensitive browser data
2/5
Query OS Information
2/5
Masquerades file extension
2/5
Modifies Windows Firewall configuration
2/5
Executes PowerShell without default profile
2/5
Executes PowerShell with hidden window
2/5
Schedules task
1/5
Resolves API functions dynamically
1/5
Creates mutex
1/5
Monitors keyboard input
1/5
Enables process privileges
1/5
Creates process with hidden window
1/5
Modifies operating system directory
1/5
Query OS Information
1/5
Queries system time
1/5
Installs system startup script or application
1/5
Accesses Microsoft Security Software registry keys
1/5
Content matched by YARA rules
1/5
Performs DNS request
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
Spyware
Ransomware
Injector