URLhaus Database

You are currently viewing the URLhaus database entry for http://github.com/Mansure1337/fatality-loader/raw/refs/heads/main/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3519013
URL: http://github.com/Mansure1337/fatality-loader/raw/refs/heads/main/1.exe
URL Status:Offline
Host: github.com
Date added:2025-04-20 07:58:12 UTC
Last online:2025-04-29 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2025-04-20 08:00:44 UTC to noc{at}github[dot]com)
Takedown time:1 month, 16 days, 6 hours, 54 minutes Bad (down since 2025-06-05 14:53:34 UTC)
Tags:AgentTesla link CelestialStealer PythonStealer SalatStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-05-291.exeexe e206c3d5afabc02ac7a5afa3c2565e21ea30f98fc2a7a74f4b054af956120be6Virustotal results 54.93%SalatStealer
2025-05-291.exeexe 385894948de2710043f39d09202e2ba87c5f89eeda873a2a53e95e2a5fa89145Virustotal results 33.80% PythonStealer
2025-05-281.exeexe 8b6e8263a8383bd286bfda7aabba68a98242baae48d1f1252a8bb35a983f665bVirustotal results 36.11% PythonStealer
2025-05-271.exeexe 19b07e57d291f887429871a1b8c0c7acfbb6045e448a9919eaf190a4676408beVirustotal results 46.48%AgentTesla
2025-05-271.exeexe 5ce65bb2652a8039c866db082256d9b8f4456be5e1be5a04f2a0d7272568bc05Virustotal results 47.22%CelestialStealer
2025-04-291.exeexe c04b3dd3d88e44cc5a7ca108ab46e6f2c38131eeb0afc9136e129f6ed741532bn/aSalatStealer
2025-04-251.exeexe 203db062bf06693bd8fa554d48aa5320be17067dfd981d39866601b663828538n/a 
2025-04-251.exeexe 1765bec16940d9c773a2af945ae8c63aca8914093646b3457b859708f9c9dcc3n/a 
2025-04-241.exeexe 480cadf8c67d824057754a0b474be03cbbdb0562cdbab089fe06dae165ea16b4Virustotal results 47.22% 
2025-04-201.exeexe b78de98d767900d6747d3a69aa4c33ca7b6ce65e4e419b1ade27431f724a717cVirustotal results 75.00%SalatStealer