URLhaus Database

You are currently viewing the URLhaus database entry for https://github.com/ExeXeam/Test/raw/main/Discord.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2841560
URL: https://github.com/ExeXeam/Test/raw/main/Discord.exe
URL Status:Offline
Host: github.com
Date added:2024-05-07 12:44:08 UTC
Last online:2024-05-14 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2024-05-07 12:47:07 UTC to noc{at}github[dot]com)
Takedown time:6 days, 22 hours, 39 minutes Bad (down since 2024-05-14 11:24:44 UTC)
Tags:AsyncRAT link exe njRAT link QuasarRAT link VenomRAT

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-05-13n/aexe e858ea725e2aaeb800365849a45248626e53eebf366f30e2ad34705680d14309Virustotal results 72.60% VenomRAT
2024-05-13n/aexe 6c7dd8aacaecedde1b47ec83fd5468b1bf57a7c05a8389d4ea8137e043a8da91Virustotal results 70.83% QuasarRAT
2024-05-13n/aexe ea181092a91ded552332bc2a41048176ab8d28cf6b492de0187b18dc81133d3bn/a njrat
2024-05-07n/aexe c2581f5f80995248435855de78cc4821630ae367d05fe204f032dda3e65abda8n/a AsyncRAT