URLhaus Database

You are currently viewing the URLhaus database entry for https://github.com/FomaNory/Adobe-Substance-3D-Painter/releases/download/Release/Loader.msi which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3798785
URL: https://github.com/FomaNory/Adobe-Substance-3D-Painter/releases/download/Release/Loader.msi
URL Status:Offline
Host: github.com
Date added:2026-03-18 10:46:13 UTC
Last online:2026-04-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: tcains1
Abuse complaint sent (?): Yes (2026-04-15 02:26:10 UTC to noc{at}github[dot]com)
Takedown time:1 month, 9 days, 1 hours, 46 minutes Bad (down since 2026-04-26 12:34:00 UTC)
Tags:rustystealer SantaStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-19Loader.msimsi a43477acaedd5ec418bbd28f823db2eed67434c64cc558b88e8f7fe80c2c09e8n/a 
2026-04-16Loader.msimsi 1e303b25c724cab6e37c038ac83ee7cd86d967ee9305c3e22749d79e4bed8ca4n/a RustyStealer
2026-04-14Loader.msimsi 40b36d05de040e006567ed76b788aa25790b41ff6fc54567bf4996f4b7a89fccn/aSantaStealer
2026-04-10Loader.msimsi 147194874c74949be05a2d0831ba48b7de442ba01d0a65755cbb0a36df0cef18n/a RustyStealer
2026-03-23Loader.msimsi 3c4e0eb6d15354dc92bbbbca4ff5a937aa27b2ec9a0ebc915fcaef7a141dd3b8n/a RustyStealer
2026-03-19Loader.msimsi 503ece2710e50686704f6938be43ad955f1bd0f750984b29242a054823dd0c55n/a 
2026-03-18Loader.msimsi 7d70ea416d3ae180dd799422877d59179d8af34f24392da3b2e3088474d195ebn/a