URLhaus Database

You are currently viewing the URLhaus database entry for http://181.206.158.190/CopilotDriver.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3597687
URL: http://181.206.158.190/CopilotDriver.js
URL Status:Offline
Host: 181.206.158.190
Date added:2025-08-06 18:27:15 UTC
Last online:2026-03-12 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_WT
Abuse complaint sent (?): Yes (2025-08-06 18:28:24 UTC to abuse[dot]internet{at}tigo[dot]com[dot]co)
Takedown time:7 months, 8 days, 1 hours, 57 minutes Bad (down since 2026-03-12 20:25:33 UTC)
Tags:PureLogsStealer RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-12CopilotDriver.jsjs 9a9cd60f80414c625cf3294b98481957db92f8b2a78e612d1284ac0c91870cb3n/aRemcosRAT
2026-03-11CopilotDriver.jsjs bc1c7bdb7589ef7870bbd4857c5916aab284305661aaa99a0354c9d6ad581033n/aRemcosRAT
2026-03-11CopilotDriver.jsjs 1dd20400a7bb38e2bc807c8bbe15fb719b3466be957bbd9b71f620f876916287n/aRemcosRAT
2026-03-10CopilotDriver.jsjs 61c61e5c4d5caa801b3d6ee7ba915ce19793274d659fc6e2bb14076fc5fdcb59n/aRemcosRAT
2026-03-09CopilotDriver.jsjs b545bb595b332d6d8e13a57d2f968fb35e4b5c39eaef92d57f0881ddd8380dd7n/a 
2026-03-09CopilotDriver.jsjs 1d0ea54f75d592d7fe26d4fa350f66569e2deb31e98cb2be9be8ad25c3f12b9dn/a RemcosRAT
2026-03-07CopilotDriver.jsjs ae43c84b6303b2e60cdbd681ac8cf6eb4acf9b9a0155a37299d49bdabd7d0a52n/aRemcosRAT
2026-03-03CopilotDriver.jsjs 8262a999b922f4db69bbae6222cd1ba9862081306539cd1061e17085010cf89fn/aRemcosRAT
2026-02-27CopilotDriver.jsjs 731ae18f35cdcefa9d8ad03ceb602a3655085cc343a6e5bc3ad0ba8108d00837n/aRemcosRAT
2026-02-26CopilotDriver.jsjs eae6a4c5d87b8cf77b73626857ce4ace839e9edfb20ce72c46d162156be140cfn/aRemcosRAT
2026-02-26CopilotDriver.jsunknown 8af664ca4ef048c7fd92c2df1dd077ff2a2c9296d3bbe9b43c518656e43a76e6n/a 
2026-02-26CopilotDriver.jsjs 2908ea1bc70b89147dda141fabffc6fa2e8f7c703b7e090a556d1d55d7909acfn/a 
2026-02-24CopilotDriver.jsjs f7c0fa71262a275d264399318021997cf7bf68593cb71e487ab40739db5dee45n/a 
2026-02-23CopilotDriver.jsjs 04a33e6ac3ce8f8e832d51a452ef935f19cb3e16e8f41375945e7092b211c335n/a
2026-02-22CopilotDriver.jsjs bb069ae21ea35f433754f782cc0b4d2e8334e2e2ea435c2a5de49b6efe7a371en/aRemcosRAT
2026-02-21CopilotDriver.jsjs df29673a520423aa0af9535754aafdbe4a154d63827d10dbc1d87d733abf173en/a 
2026-02-19CopilotDriver.jsjs 40418a5c0b271e9119d21af4be73d4bef5fdf3276b2d6490ebc321fdce56101en/a RemcosRAT
2026-02-18CopilotDriver.jsjs 8b830f87be92486468561ab3f41a08bbafb24e2602f77a431ca42c15384fcc06n/a RemcosRAT
2026-02-16CopilotDriver.jsjs 3ed1a8c4ec7d25272e0640c39c924848ffbc57856cde779a9a6af6e6058b57afn/aRemcosRAT
2026-02-13CopilotDriver.jsjs 91baa6693a7101a106695f9eac9ecbbf6d6da66fd9a64f619ef3b18b268140a6n/a RemcosRAT
2026-02-12CopilotDriver.jsjs 62510b5dddaf01d04d3cff4920203d1c61b745ababc403aa2635fdc595d89b8an/a 
2026-02-12CopilotDriver.jsjs 4a68c6d4b5fb83e9241e81ec9decd050dd3f4a4f430ef517a72910c5c383087fn/a
2026-02-09CopilotDriver.jsjs ad63d5dba41c2c198bc7a23e2ff60b51e54a19082082a1297be85bbbcc787f61n/a 
2026-02-07CopilotDriver.jsjs dbde6a18d579383c8394a7525ca60c136d827f38a84d0639ef35897d6567c38bn/a 
2026-02-06CopilotDriver.jsjs ec9f57d5efb7103142b0713e7ff0ab6fbf217f50dd69c2640928c557a4a36cbcn/a RemcosRAT
2026-02-04CopilotDriver.jsjs c86ebb0e9a245fbe86a024641eb2a7dc236351c98ef98392ea366539b509827dn/aRemcosRAT
2026-02-03CopilotDriver.jsjs b2c0471f0b98d016db3f73ff001b097cbefe3b8e41eecd027fa40aa96a2cf3a2n/aPureLogsStealer
2026-02-03CopilotDriver.jsjs 4a8dab65abcfd71f3a62a956a8d8bde06a7a9aaa694ebffe42958675ff3b14f9n/a 
2025-08-09CopilotDriver.jsjs c59cf133700b2304326538d8ed9a3a6cde6b30579d627e87483517dbeeb3399en/aRemcosRAT
2025-08-06CopilotDriver.jsjs 4c2ad56ca838044373118a64685e3a460eee36851c20a740b30bfb139c25ff51n/a