DANGER
malware detected
github.com / N0rz3
N0rz3/ Zehef
Python·37 files·commit 5b0c120·scanned 2h ago·cached ✓
70/100
DANGEROUS
Sensitive capability combinations reachable from entry points. Do not run without review.
This repository contains patterns associated with malware. Do NOT run this code.
verdict accurate?
Research / educational context
threat-state: dangerouslive
FINDINGS ░▒▓
criticalKnown malicious / C2 domainKnown domains used by Lazarus Group and other malware for hosting payloads or exfiltrating data.modules/breaches/pastedumper.py+5
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.modules/breaches/pastedumper.py+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
31 files scanned @ 5b0c120 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration5
file system access0
obfuscation3
supply chain0
owasp / injection0
telemetry
files 31/37rules hit 3engine v6commit 5b0c120
github
N0rz3/Zehef
Zehef is an osint tool to track emails
1078
118
1200d
37 files
31 scanned(84%)
5b0c120
architecture░▒▓
entry (1) flagged (1) pkg (37)
67 nodes · 89 edgesscroll to zoom · click node to jump to finding