URLhaus Database

You are currently viewing the URLhaus database entry for https://raw.githubusercontent.com/namblack666/zxqqw/refs/heads/main/main.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3333657
URL: https://raw.githubusercontent.com/namblack666/zxqqw/refs/heads/main/main.exe
URL Status:flame Online (spreading malware for 1 year, 5 month, 27 days, 7 hours, 34 minutes)
Host: raw.githubusercontent.com
Date added:2024-12-06 15:32:23 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2024-12-20 07:37:43 UTC to abuse{at}github[dot]com)
Tags:PythonStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-03-03n/aexe d1a47f2312f4754f51698726d74ead9bb886740b6f4f69f6bea7232787d201f6n/a 
2025-01-06n/aexe fc4840ec7d711834eb9907dda6f9cfdb713d77b8373f350e8f997281a72905adn/a 
2024-12-31n/aexe 8f84fbcdc2e53d8a5dd7e52e1d20be00dcca0ccd11ba069dcc1ba992efa64128n/a 
2024-12-31n/aexe 24d1fdb9bee62ccf05025733d3263908e47a02984737da05f0ebf9870b54289en/a 
2024-12-06n/aexe 2443d1fe25f8afbd5b9cd95fdb45e7c6c5b688e815f44f93158e534308d9f9fbVirustotal results 39.44%