URLhaus Database

You are currently viewing the URLhaus database entry for http://6f841a9a-243d-4072-8e01-b07a63e328cd.random.tbtt.duckdns.org/CopilotDriver.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3561701
URL: http://6f841a9a-243d-4072-8e01-b07a63e328cd.random.tbtt.duckdns.org/CopilotDriver.vbs
URL Status:Offline
Host: 6f841a9a-243d-4072-8e01-b07a63e328cd.random.tbtt.duckdns.org
Date added:2025-06-13 01:18:38 UTC
Last online:2025-07-19 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Riordz
Abuse complaint sent (?): Yes (2025-06-16 16:54:09 UTC to abuse[dot]internet{at}tigo[dot]com[dot]co)
Takedown time:1 month, 2 days, 7 hours, 31 minutes Bad (down since 2025-07-19 00:25:28 UTC)
Tags:opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-07-18CopilotDriver.vbsvbs d7ebd5189406570fb7f202a1ab8095526b776d155e118fe207fd51e98c6f941cVirustotal results 11.29%RemcosRAT
2025-07-02CopilotDriver.vbstxt e9e6b5fc76e944d6b5bedcc3fc4ccd374082af41547d9444009e5b1923c0d808n/a RemcosRAT
2025-07-01CopilotDriver.vbstxt a2727b617e87d1c8070d69cf1c5fa58c757ae0e425c26c049dce311e1adb5745Virustotal results 22.58%
2025-06-28CopilotDriver.vbstxt 5da646edf1eed3abc74e49e1a9daf4e4e5bedb7a1652ca3311cd7f8bce650babn/a RemcosRAT
2025-06-26CopilotDriver.vbstxt 7cc4edef464d473ad938087c7ab1fade6c6915310bf406a42b89f11e8a4bebden/a 
2025-06-23CopilotDriver.vbstxt 1311aed7b08093746c808edea41d40fb2e8547a1bd86a2516cf7bf4f1f2075fdn/aRemcosRAT
2025-06-18CopilotDriver.vbstxt fd43d26f1db150f1ce6faa221521e0ac9d32ffc26fc835bdc564ce6d93a5ee84n/aRemcosRAT
2025-06-17CopilotDriver.vbstxt cfdc2ae6a13e3aec697ff5535644d20bad1bae878d39ba2f56af905a8ab039d4n/aRemcosRAT
2025-06-17CopilotDriver.vbstxt 3c456a7c35a2a9d3a4a69e51adda6eb1aa3e35369e11e1ec07988379c1ebb8c2n/aRemcosRAT
2025-06-16CopilotDriver.vbstxt 5289ae56de34e2a10a649deedbc33133911ae1c7d713e7d0451bd2780b7a9c66Virustotal results 20.97% RemcosRAT