Threat Feed
QuickFetch.exe
2026-08-22T21:21:56.942
malicious
Windows Exe (x86-64)
Close
QuickFetch.exe
malicious
SHA256:
f48debf0e99b16130594458c82205af33785a97f7d3df4cfed7cd30acd266b2d
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious content matched by YARA rules
4/5
Malicious host or URL detected via reputation
3/5
Captures clipboard data
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
3/5
Modifies native system functions
2/5
Queries OS info via WMI
2/5
Collects hardware properties
2/5
Queries a host's domain name
2/5
Query Firmware Information
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Modifies control flow of a process started from a created or modified executable
2/5
Deletes file after execution
1/5
Performs DNS request
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Tries to detect debugger
1/5
Resolves API functions dynamically
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Queries system time
1/5
Drops PE file
1/5
Reads from memory of another process
1/5
Executes dropped PE file
1/5
Creates process with hidden window
Spyware
file.exe
2026-08-22T21:01:28.520
malicious
Windows Exe (x86-32)
Close
file.exe
malicious
SHA256:
20082d2052d2d406bb4193990d933dc9b78bf2ccc3f2618144ada1fb7e0a995e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious file detected via reputation
4/5
Malicious host or URL detected via reputation
4/5
Writes into the memory of another process
4/5
Modifies control flow of another process
3/5
Tries to detect the presence of antivirus software
3/5
Takes screenshot
3/5
Captures clipboard data
3/5
Uses HTTP to upload a large amount of data
2/5
Collects hardware properties
2/5
Query Firmware Information
2/5
Schedules task
2/5
Searches for sensitive browser data
2/5
Reads sensitive browser data
2/5
Queries OS info via WMI
2/5
Queries a host's domain name
1/5
Creates a page with write and execute permissions
1/5
Reads from memory of another process
1/5
Creates mutex
1/5
Queries system time
1/5
Tries to connect using an uncommon port
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
1/5
Drops PE file
1/5
Executes dropped PE file
1/5
Timestamp manipulation
1/5
Creates process with hidden window
Spyware
Injector
3USPqdEFVoLnmwoI.exe
2026-08-22T20:51:40.869
malicious
Windows Exe (x86-64)
Close
3USPqdEFVoLnmwoI.exe
malicious
SHA256:
efda1352c4eb91fe768535abef056dacdbebc990db714eb8d62ee7fe08bc60a3
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Malicious content matched by YARA rules
5/5
Tries to read cached credentials of various applications
4/5
Malicious host or URL detected via reputation
3/5
Reads installed applications
3/5
Uses HTTP to upload a large amount of data
3/5
Tries to evade debugger
2/5
Searches for sensitive mail data
2/5
Dead Drop Resolver
2/5
Searches for cryptocurrency wallet locations
2/5
Searches for sensitive browser data
2/5
Signed executable failed signature validation
2/5
Schedules task
1/5
Query CPU Properties
1/5
Creates process with hidden window
1/5
Creates a page with write and execute permissions
1/5
Enumerates running processes
1/5
Installs system startup script or application
1/5
Tries to detect debugger
1/5
Creates mutex
1/5
Queries system time
1/5
Query OS Information
1/5
Content matched by YARA rules
1/5
Resolves API functions dynamically
Spyware
8L4usWnwpC39iat0.html
2026-08-22T20:46:59.512
malicious
HTML Document
Close
8L4usWnwpC39iat0.html
malicious
SHA256:
d3e2bfe921c7de283d364b04b170832c3742e02dc83d5e8e4cda5ac50d1c34a1
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections indicates a phishing website
2/5
Page uses exact same title as that of a popular online service
2/5
The HTML file contains logon form
2/5
Branded Logon form detected via Computer Vision
1/5
Branding image detected via Computer Vision
1/5
Page presents itself as a logon page
Phishing
478a5d81892f27b5d5fb05e4667d16d86ee2c8dee5882c52e4377123cd88526e.exe
2026-08-22T19:29:41.751
malicious
Windows Exe (x86-64)
Close
478a5d81892f27b5d5fb05e4667d16d86ee2c8dee5882c52e4377123cd88526e.exe
malicious
SHA256:
478a5d81892f27b5d5fb05e4667d16d86ee2c8dee5882c52e4377123cd88526e
VMRay Threat Identifiers
Close
Severity
Operation
5/5
Combination of other detections shows multiple input capture behaviors
4/5
Malicious host or URL detected via reputation
4/5
Malicious file detected via reputation
3/5
SmartContract configuration was extracted
3/5
Monitors keyboard input
3/5
Modifies native system functions
2/5
Communicates with a Web3 service
2/5
Tries to detect analyzer sandbox
2/5
Queries a host's domain name
2/5
Makes direct system call to possibly evade hooking based monitoring
2/5
Tries to detect virtual machine
2/5
Delays execution
2/5
Searches for cryptocurrency wallet locations
2/5
Suspicious content matched by YARA rules
2/5
Searches for sensitive browser data
2/5
Schedules task
1/5
Query OS Information
1/5
Creates process with hidden window
1/5
Accesses volumes directly
1/5
Accesses Microsoft Security Software registry keys
1/5
Enumerates running processes
1/5
Creates mutex
1/5
URL contains a TLD highly associated with phishing
1/5
Content matched by YARA rules
1/5
A monitored process crashed
1/5
Queries system time
Spyware