github.com
Checking live DNS resolution...
100/100
CRITICAL RISK
2266
Malware URLs
3
Resolved IPs
728
Abuse Reports
667
Active URLs

Threat Intelligence Summary: github.com

Risk Level: CRITICALThreat Score: 100/100

Assessment: github.com is a high-volume malware distribution domain with 667 currently active malicious URLs. The scale of activity indicates a dedicated threat infrastructure rather than a compromised legitimate site. Immediate network-level blocking is strongly recommended. Malware families associated with this domain include pw-4475, FakeCheat, stealer.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 2266 — Active: 667 — Resolved IPs: 3 — Abuse Reports: 728

First Seen: 2025-09-18T01:42:05 — Last Online: 2026-07-27T02:02:03

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

github.com has been associated with 2266 malware URLs , of which 667 are currently active . The primary threat types are malware_download.

Active threat. This domain is currently serving malicious content. With over 2266 tracked malware URLs, this domain is a significant malware distribution point and should be blocked at the DNS or firewall level.

Associated malware families include: None.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2025-09-18T01:42:05
Last Seen Online
2026-07-27T02:02:03
Data Last Updated
2026-07-27T05:00:36.228211
Status Activity Timeline (50 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

ONLINE OFFLINE
https://github.com/officedesknote-star/bodakuwa/raw/refs/heads/main/ScreenConnect.ClientSetup%20(18)%20(1).msi
Status changed from online to offline
ONLINE OFFLINE
https://github.com/officedesknote-star/bzeet/raw/refs/heads/main/ScreenConnect.ClientSetup%20(25).msi
Status changed from online to offline
ONLINE OFFLINE
https://github.com/officedesknote-star/DESKFRO/raw/refs/heads/main/ScreenConnect.ClientSetup%20(17)%20(1).msi
Status changed from online to offline
ONLINE OFFLINE
https://github.com/officedesknote-star/bzeett/raw/refs/heads/main/ScreenConnect.ClientSetup%20(20)%20(1).msi
Status changed from online to offline
ONLINE OFFLINE
https://github.com/officedesknote-star/sww/raw/refs/heads/main/ScreenConnect.ClientSetup%20(19)%20(2).msi
Status changed from online to offline
ONLINE OFFLINE
https://github.com/gcoyerk/quickbooks-windows-master/releases/download/V1.32/quickbooks-windows-master.zip
Status changed from online to offline
ONLINE OFFLINE
https://github.com/dm-7926/dz-nvd/raw/main/m1n.zip
Status changed from online to offline
ONLINE OFFLINE
https://github.com/dm-7926/dz-nvd/raw/refs/heads/main/m1n.zip
Status changed from online to offline
OFFLINE
https://github.com/dm-7926/dz-nvd/raw/main/udm-m.bat
First detected as offline
ONLINE
https://github.com/dm-7926/dz-nvd/raw/main/m1n.zip
First detected as online
ONLINE
https://github.com/dm-7926/dz-nvd/raw/refs/heads/main/m1n.zip
First detected as online
OFFLINE
https://github.com/dm-7926/dz-nvd/raw/refs/heads/main/udm-m.bat
First detected as offline
OFFLINE ONLINE
https://github.com/smailikskywarsp4s/ArcRaiders-FPS-Booster-2025-2026/raw/refs/heads/main/BOOSTER.rar
Status changed from offline to online
ONLINE OFFLINE
https://github.com/smailikskywarsp4s/ArcRaiders-FPS-Booster-2025-2026/raw/refs/heads/main/BOOSTER.rar
Status changed from online to offline
OFFLINE ONLINE
https://github.com/officedesknote-star/DESKFRO/raw/refs/heads/main/ScreenConnect.ClientSetup%20(17)%20(1).msi
Status changed from offline to online
ONLINE OFFLINE
https://github.com/officedesknote-star/DESKFRO/raw/refs/heads/main/ScreenConnect.ClientSetup%20(17)%20(1).msi
Status changed from online to offline
OFFLINE ONLINE
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t3.zip
Status changed from offline to online
ONLINE
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t2.zip
First detected as online
OFFLINE
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t3.zip
First detected as offline
ONLINE
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t1.zip
First detected as online
Showing 20 most recent changes of 50 total
Associated IP Addresses (3)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

140.82.112.4
122 abuse reports Severity: high
140.82.121.4
303 abuse reports Severity: high
140.82.121.3
303 abuse reports Severity: high
Malware Classification
pw-4475
Malware family "pw-4475" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
FakeCheat
Malware family "FakeCheat" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
stealer
Malware family "stealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
EvelynStealer
Malware family "EvelynStealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
ClearFake
Sophisticated social engineering campaign exploiting fake browser update prompts. Victims are tricked into manually executing malware by mimicking legitimate Chrome, Firefox, and Edge update interfaces. Primary delivery mechanism for information stealers and RATs.
adeladel32951
Malware family "adeladel32951" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
infostealer
Malware family "infostealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Vidar
Forked from Arkei stealer in 2018, sold on Russian forums. Downloads legitimate DLLs at runtime to avoid detection. Targets browser data, crypto wallets, 2FA codes, and Discord tokens. Often distributed through cracked software and YouTube tutorial scams.
pw-azuro
Malware family "pw-azuro" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
pw-7701
Malware family "pw-7701" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Malware URLs (2266)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://github.com/dm-7926/dz-nvd/raw/main/udm-m.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-18
None
https://github.com/dm-7926/dz-nvd/raw/main/m1n.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-18
None
https://github.com/dm-7926/dz-nvd/raw/refs/heads/main/m1n.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-18
None
https://github.com/dm-7926/dz-nvd/raw/refs/heads/main/udm-m.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-18
None
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t3.zip
Active Threat
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/dcm1-6626/T-1million/blob/main/t1.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/dcm1-6626/T-1million/blob/main/t2.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/up-6626/udt/blob/main/udt.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t2.zip
Active Threat
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/up-6626/udt/raw/refs/heads/main/udt.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/up-6626/udm/blob/main/udm.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/up-6626/udm/raw/refs/heads/main/udm.bat
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/dcm1-6626/T-1million/raw/refs/heads/main/t1.zip
Active Threat
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/dcm1-6626/T-1million/blob/main/t3.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
None
https://github.com/officedesknote-star/DESKFRO/raw/refs/heads/main/ScreenConnect.ClientSetup%20(17)%20(1).msi
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
connectwise
https://github.com/officedesknote-star/bzeet/raw/refs/heads/main/ScreenConnect.ClientSetup%20(25).msi
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
connectwise
https://github.com/officedesknote-star/bodakuwa/raw/refs/heads/main/ScreenConnect.ClientSetup%20(18)%20(1).msi
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
connectwise
https://github.com/officedesknote-star/bzeett/raw/refs/heads/main/ScreenConnect.ClientSetup%20(20)%20(1).msi
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
connectwise
https://github.com/officedesknote-star/sww/raw/refs/heads/main/ScreenConnect.ClientSetup%20(19)%20(2).msi
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-04
connectwise
https://github.com/VideoPad-Free-for-PC/.github/archive/refs/heads/main.zip
Taken Down
IP: 140.82.121.4
Type: malware_download
First Seen: 2026-07-01
None
Showing 20 of 2266 URLs