raw.githubusercontent.com
Checking live DNS resolution...
100/100
CRITICAL RISK
6772
Malware URLs
4
Resolved IPs
21185
Abuse Reports
5569
Active URLs

Threat Intelligence Summary: raw.githubusercontent.com

Risk Level: CRITICALThreat Score: 100/100

Assessment: raw.githubusercontent.com is a high-volume malware distribution domain with 5569 currently active malicious URLs. The scale of activity indicates a dedicated threat infrastructure rather than a compromised legitimate site. Immediate network-level blocking is strongly recommended. Malware families associated with this domain include config, stealer, DarkVisionRAT.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 6772 — Active: 5569 — Resolved IPs: 4 — Abuse Reports: 21185

First Seen: 2025-09-17T20:06:07 — Last Online: 2026-07-27T01:56:25

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

raw.githubusercontent.com has been associated with 6772 malware URLs , of which 5569 are currently active . The primary threat types are malware_download.

Active threat. This domain is currently serving malicious content. With over 6772 tracked malware URLs, this domain is a significant malware distribution point and should be blocked at the DNS or firewall level.

Associated malware families include: None.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2025-09-17T20:06:07
Last Seen Online
2026-07-27T01:56:25
Data Last Updated
2026-07-27T05:00:36.576322
Status Activity Timeline (50 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

ONLINE
https://raw.githubusercontent.com/sean100496/bnb/refs/heads/main/ScreenConnect.ClientSetup.exe
First detected as online
ONLINE OFFLINE
https://raw.githubusercontent.com/Paradoxouf/flycast-wasm/main/stubs/flycast-wasm-v1.3.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/sidiboy/Qidi_Q2_Mainline_Klipper/main/config_changes/Mainline-Klipper-Qidi-1.9.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/nigerbartus/Shai-Hulud-2.0-Detector/main/dist/Shai-Hulud-2.0-Detector_v3.5.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/AmyneDev/Ai-Gesture-Christmas-Tree/main/decarbonization/Christmas_Tree_Gesture_Ai_v2.1.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/iadnan21/yuv-ai-trends/main/.github/yuv-trends-ai-v1.1.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/kkshitij17/gidermetre/main/images/Software_3.0.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/HOAKKKK/botnet/refs/heads/main/johenlastgen.sh
Status changed from online to offline
OFFLINE ONLINE
https://raw.githubusercontent.com/ariefalabbasi/mcp-audit/main/src/mcp-audit-1.5.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/michae6543/OT-CRM/main/Backend/src/util/CRM_O_v2.4.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/zollaq/lifo/main/packages/core/src/utils/Software_2.3-alpha.1.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/IrishLaluz/DecisionTrace/main/tests/Decision-Trace-3.5.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/zvfas/dcl350-2026-jan-19/main/hexagonal-helper/src/com/example/hr/application/business/dcl_jan_v2.3.zip
Status changed from offline to online
ONLINE OFFLINE
https://raw.githubusercontent.com/nak-nak1308/verifiable-intent/main/spec/intent-verifiable-v1.7-alpha.4.zip
Status changed from online to offline
ONLINE OFFLINE
https://raw.githubusercontent.com/cezarhamza/tiktok-signature-api/main/mease/signature_api_tiktok_v2.2.zip
Status changed from online to offline
OFFLINE ONLINE
https://raw.githubusercontent.com/windowvalue821/codebase-to-course/main/references/course_to_codebase_v1.8.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/Hefty-cakchiquel295/QIE-Bbox-Studio/main/qwenimage/Bbox-Studio-QI-v1.1.zip
Status changed from offline to online
OFFLINE ONLINE
https://raw.githubusercontent.com/roottechinfosystemofficial/market-insight-claude-skill/main/.claude/skills/insight/assets/skill_claude_market_insight_1.1.zip
Status changed from offline to online
ONLINE OFFLINE
https://raw.githubusercontent.com/eracomtechnologies/LegacyCrossPlay/main/src/packets/Play-Cross-Legacy-v3.8-beta.1.zip
Status changed from online to offline
OFFLINE ONLINE
https://raw.githubusercontent.com/jennyloops/fakepay/main/Fakepay.jar
Status changed from offline to online
Showing 20 most recent changes of 50 total
Associated IP Addresses (4)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

185.199.108.133
5297 abuse reports Severity: medium
185.199.111.133
5297 abuse reports Severity: medium
185.199.110.133
5294 abuse reports Severity: medium
185.199.109.133
5297 abuse reports Severity: medium
Malware Classification
config
Malware family "config" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
stealer
Malware family "stealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
DarkVisionRAT
Malware family "DarkVisionRAT" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
ClearFake
Sophisticated social engineering campaign exploiting fake browser update prompts. Victims are tricked into manually executing malware by mimicking legitimate Chrome, Firefox, and Edge update interfaces. Primary delivery mechanism for information stealers and RATs.
infostealer
Malware family "infostealer" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Vidar
Forked from Arkei stealer in 2018, sold on Russian forums. Downloads legitimate DLLs at runtime to avoid detection. Targets browser data, crypto wallets, 2FA codes, and Discord tokens. Often distributed through cracked software and YouTube tutorial scams.
payload
Malware family "payload" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
base64
Malware family "base64" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
CryptoMiner
Malware family "CryptoMiner" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
powershell
Malware family "powershell" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
Malware URLs (6772)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://raw.githubusercontent.com/sean100496/bnb/refs/heads/main/ScreenConnect.ClientSetup.exe
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-24
None
https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/config.json
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
CoinMiner config json ua-wget
https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/w2.sh
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
CoinMiner sh ua-wget
https://raw.githubusercontent.com/jennyloops/gamblerig/main/Gamblerig.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/jennyloops/4e/main/4eclient.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/jennyloops/radium/main/Radiumclient.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/jennyloops/fakepay/main/Fakepay.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/jennyloops/krypton/main/kryptonclient.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/jennyloops/xenon/main/Xenonclient.jar
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-09
github jar jennyloops SilentNet
https://raw.githubusercontent.com/nulltrafficaway/labprojecttest/refs/heads/main/check2.sh
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-07-08
sh ua-wget
https://raw.githubusercontent.com/0xsdhzilqodizkahsqh/ozekqjsdhua/refs/heads/main/injection.js
Active Threat
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-06-29
payload PlagueStealer
https://raw.githubusercontent.com/seition2doc/dosta2/main/n3.bat
Taken Down
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-06-27
asc CoinMiner xworm
https://raw.githubusercontent.com/S4warm/CyberValorant-Valorant-Cheat-Aimbot-ESP/main/Eduty%20External/Valorant-External.vcxproj
Taken Down
IP: 185.199.108.133
Type: malware_download
First Seen: 2026-06-26
cmd trojan vcxproj
https://raw.githubusercontent.com/Besvigahw/VALORANT-EFI-DRIVER-Cheat-Hack/main/Driver/Driver/EFIClient.vcxproj
Taken Down
IP: 185.199.108.133
Type: malware_download
First Seen: 2026-06-26
cmd trojan vcxproj
https://raw.githubusercontent.com/HOAKKKK/botnet/refs/heads/main/johenlastgen.sh
Taken Down
IP: 185.199.109.133
Type: malware_download
First Seen: 2026-06-27
mirai sh ua-wget
https://raw.githubusercontent.com/therecruiter809876/Liquidbounce/master/NexusClient-1.21.1-v2.0.4.jar
Taken Down
IP: 185.199.110.133
Type: malware_download
First Seen: 2026-06-23
github jar SilentNet
https://raw.githubusercontent.com/ZORO-69-max/MyXpenseAPP/main/src/services/Xpense-APP-My-v2.8-alpha.3.zip
Active Threat
IP: 185.199.110.133
Type: malware_download
First Seen: 2026-06-22
LuaJIT-loader SmartLoader SmartLoader-MaaS
https://raw.githubusercontent.com/tailshaped-genusseriphus881/Weatherdetector/main/travis/Software-v3.0.zip
Active Threat
IP: 185.199.110.133
Type: malware_download
First Seen: 2026-06-22
LuaJIT-loader SmartLoader SmartLoader-MaaS
https://raw.githubusercontent.com/realizable-sucre824/idl-hp0/main/Hygeian/idl-hp0-v3.7.zip
Active Threat
IP: 185.199.110.133
Type: malware_download
First Seen: 2026-06-22
LuaJIT-loader SmartLoader SmartLoader-MaaS
https://raw.githubusercontent.com/hungnguyen1509asd/raydium-trading-bot/main/extrasystolic/raydium-trading-bot-1.0.zip
Active Threat
IP: 185.199.110.133
Type: malware_download
First Seen: 2026-06-22
LuaJIT-loader SmartLoader SmartLoader-MaaS
Showing 20 of 6772 URLs