URLhaus Database

You are currently viewing the URLhaus database entry for https://raw.githubusercontent.com/presema/kersal/refs/heads/main/opyhjdase.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3331919
URL: https://raw.githubusercontent.com/presema/kersal/refs/heads/main/opyhjdase.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 27 days, 20 hours, 23 minutes)
Host: raw.githubusercontent.com
Date added:2024-12-05 17:02:58 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-20 07:37:43 UTC to abuse{at}github[dot]com)
Tags:exe github HackBrowser

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-22n/aexe f20de7137d64b1d8573e5fec446590a817b1ae5b82ec4c283fbfaa86dee1f863n/a 
2025-02-26n/aexe 907093a490da357422541825f1ed3bd55f2beeab0cdd6fc8bef8968c93811b5an/a
2025-01-28n/aexe 0acc19b9b85824ad172c41451e76c53afdf03e56256303623e37c3509b458b4en/a 
2024-12-21n/aexe 26f33b99f45cc9e2b704514a1106f1490b4ac376e97e27cf543c0a841dc44178n/a HackBrowser
2024-12-12n/aexe 366047660396612f09125b09f4cb0aac4edaf44a916b85471b8fb49375ecb333n/a 
2024-12-05n/aexe d336273cee697dec1b8f9e1643005a2cd8b80305e9f8dc257ab69d2322f38927Virustotal results 61.11%