> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Malicious ZIP File Delivered via GitHub Release
- URL: https://darkwebinformer.com/ioc-alert-malicious-zip-file-delivered-via-github-release/
- Published: 2025-10-07T17:48:27.000Z
- Updated: 2025-10-07T17:48:27.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A suspicious GitHub-hosted ZIP file has been identified as part of a **payload delivery campaign**. The file is associated with **SmartLoader** activity and was submitted to URLHaus. Hosting on GitHub increases trust abuse, allowing malicious actors to distribute malware under the guise of legitimate repositories. Confidence is assessed at 80%.

---

## 📌 Key Details

| Field           | Information                                                                  |
| --------------- | ---------------------------------------------------------------------------- |
| **Type**        | URL                                                                          |
| **Indicator**   | <https://github.com/dungtaplaptrinh/IVMS/releases/download/v1.0/Release.zip> |
| **Threat Type** | Payload Delivery                                                             |
| **Malware**     | Unknown                                                                      |
| **Confidence**  | 80%                                                                          |
| **Date**        | 07 Oct 2025 – 17:20:02 UTC                                                   |
| **Tags**        | SmartLoader, urlhaus, zip                                                    |
| **Reporter**    | Pikachu                                                                      |
| **Reference**   | None                                                                         |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** landing page | nonk’s website
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/0199bfb5-325f-73aa-a4da-71497cea0b6a.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/0199bfb5-325f-73aa-a4da-71497cea0b6a/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/10/79823596782359867239873-2.jpg)

---

## 📡 Related Intelligence

- **VirusTotal Report:** [VirusTotal URL Report](https://www.virustotal.com/gui/url/fee7319352f43c88481d03084cd18903b981329ae3aded3ed3f3785203e00ded)

---

## 🛡️ Defensive Guidance

- Alert on attempts to download executables or compressed files from GitHub release pages outside of trusted repositories.
- Monitor for SmartLoader infection indicators such as secondary payload downloads and persistence attempts.
- Educate users on the risks of downloading executables from unknown GitHub repositories.

---

⚠️ This IOC highlights the **growing abuse of developer platforms like GitHub** to host and deliver malicious payloads, leveraging user trust in popular services to bypass traditional detection.