🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://github.com/Siphodhl1980/nbew/releases/download/new/clip.exe.

Database Entry


IOC ID:1921398
IOC: https://github.com/Siphodhl1980/nbew/releases/download/new/clip.exe
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS36459 GITHUB
Country:- US
First seen:2026-09-17 05:41:53 UTC
Last seen:never
UUID:5021eb4b-b225-11f1-8450-42010aa4000a
Reporter nevermorelove
Reward 5 credits from ThreatFox
Tags:kehrlast shinomiya_relay
Reference: https://www.virustotal.com/gui/url/33cd18861db00d77ac804b98fef72de5d1f5dfaa78868d066493933828075bf6

Avatar
nevermorelove
sha256 1a3ba01a13f108345d81439858adcea3247a2e51dd98ac7ba265a762629fdfb4 - MS Defender Trojan:Win32/Kepavll!rfn, 2928 downloads | Part of trojanized electron NSIS dropper campaign (build kehrlast). Dropper sha256 64bf8990b84d3480b0f5585ec932d96d719e6e8e7285a0705cc8054cdbc46663, C2 relay 85.137.252.40:3000 (secret 6679bdc6c31fde390b507fd94c8f7e8b). Account: github.com/Siphodhl1980 (id 260470363, created 2026-02-09).