URLhaus Database

You are currently viewing the URLhaus database entry for https://github.com/pbhhdf/12/raw/main/keepvid-pro_full2578.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:2817239
URL: https://github.com/pbhhdf/12/raw/main/keepvid-pro_full2578.exe
URL Status:flame Online (spreading malware for 2 years, 1 months, 18 days, 21 hours, 15 minutes)
Host: github.com
Date added:2024-04-18 17:01:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2024-12-20 07:39:00 UTC to noc{at}github[dot]com)
Tags:dropped-by-SmokeLoader LummaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-14keepvid-pro_full2578.exeexe a24a2614e5d9525c9d4fdfb89538a46bc2c97cee847e1bd4a5d177c6a3724febn/a 
2025-04-14keepvid-pro_full2578.exeexe 4f79d131b8667974ddc48435b0c219ee3e19f8f857e5858bf8cce6ee898435e6n/a 
2025-04-07keepvid-pro_full2578.exeexe 9ab6038797c27e238869c78f26fe7d23093b40179006933674643109962f71fcn/a 
2024-04-25n/aexe eeb80ff88ef385d2eeea67a087d0ff5cf075655d3f5e081dbe3b2b41b8224f2bn/a 
2024-04-18n/aexe 9e86e4796a51e2cae9487ec086aa2159b65a037808e70a0e7dbaf5a946a8801eVirustotal results 61.97% LummaStealer