Remix.run Logo
▲ klaushardt 2 hours ago

Edit4: Sorry, False Alarm: https://any.run/malware-trends/amadey/

    IP addresses
    185.199.108.133
    Hostname: cdn-185-199-111-133.github.com.
https://dnschecker.org/reverse-dns.php?query=185.199.111.133

---

Virus Total: Activity related to AMADEY - according to source Cluster25 - 6 months ago This DOMAIN is used by AMADEY. Amadey is a botnet agent that appeared around October 2018 sold on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server. It can also load other payloads to the victims' devices.

macOS download url after downloading with librewolf and rightclicking "copy downoload url": https://www.virustotal.com/gui/url/f1e08a34d17fd85cd8896ba86...

Edit: i dont get this when copying direct links from the readme.md. Its just when i click them and copy the url it used to download.

Edit2: i get this too when i download the x64 exe and copy the download link from the librewolf (firefox fork) download manager https://www.virustotal.com/gui/url-analysis/u-6a55e124c22f9b...

Edit3: maybe false alarm and the botnet used the github url https://release-assets.githubusercontent.com/ to spread malware?

▲ 2 hours ago | parent | next [-]
[deleted]
▲poly2it 2 hours ago | parent | prev | next [-]

I'm not sure you submitted the actual artefact? Would be interested in knowing, though.

▲klaushardt 2 hours ago | parent [-]

If you copy the url at the top and resolve it, it downloads the bin. But i think this may be a false alarm and the botnet just spread his malware over github.

▲mickelsen an hour ago | parent [-]

I love trying out new software, but with Github getting blasted all the time, supply chain compromise, and now in the vibe coding era with people not even checking, we have to be careful. It sucks that this is the status quo now.

▲thesnarkitecht 18 minutes ago | parent | prev [-]

[flagged]