URLhaus Database

You are currently viewing the URLhaus database entry for https://codeload.github.com/sonriseclient/evilly/zip/refs/heads/main which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3310257
URL: https://codeload.github.com/sonriseclient/evilly/zip/refs/heads/main
URL Status:Offline
Host: codeload.github.com
Date added:2024-11-28 10:40:03 UTC
Last online:2024-12-07 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2024-12-05 08:13:10 UTC to noc{at}github[dot]com)
Takedown time:21 days, 9 hours, 5 minutes Bad (down since 2024-12-19 19:45:12 UTC)
Tags:sonriseclient stealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-12-08evilly-main.zipzip ad41ab22cd6aa45f288201d3291b98f62b75639fd6d1ae3dad4ceeaee7927fd6n/a 
2024-12-07evilly-main.zipzip 9e0ddecf786cc06af0922ec3277984fc7946131124a3dcac12d08333f617e492n/a 
2024-12-06evilly-main.zipzip 5a5134641418abe1eac845f9b33ede429e680a48a4cdb3ab2ebac80057e90d36n/a 
2024-12-04evilly-main.zipzip 5468619e4a989d94c735094f33bce22dcfd1d16ea5f65199daa2fa2b7aaa15f4n/a 
2024-12-03evilly-main.zipzip abb32f77f9b2cf719da4958def108a4911c2c588ee7862df1d3e9095270e094fn/a 
2024-11-28evilly-main.zipzip a61abf2cedb3b938694a56ed85fb7702941c9f84614cb55eafd7d34b51eef237n/a