Zip password encryption is trivially broken and should not be trusted for anything more than basic obfuscation. I'd recommend:
- Using AES directly yourself with a strong password.
- Hosting behind authentication
- Using a different password per user.
This should a) make it effectively impossible to detect the malware, b) make it clear that the intention is for research and education only, and c) prevent bad actors from maliciously using your hosted repository of malware.
> when i try to add it to "Authorized redirect URIs" for Oauth getting this error: "The request has been classified as abusive and was not allowed to proceed"
Is this for Google OAuth? I don't know anything about this system, but I wouldn't be surprised if the data lags behind the up to date safe browsing database. Maybe try again tomorrow?