URLhaus Database

You are currently viewing the URLhaus database entry for http://181.206.158.190/CopilotDriver.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3597687
URL: http://181.206.158.190/CopilotDriver.js
URL Status:flame Online (spreading malware for 6 months, 20 days, 16 hours, 50 minutes)
Host: 181.206.158.190
Date added:2025-08-06 18:27:15 UTC
Threat:Malware download Malware download
Reporter: JAMESWT_WT
Abuse complaint sent (?): Yes (2025-08-06 18:28:24 UTC to abuse[dot]internet{at}tigo[dot]com[dot]co)
Tags:PureLogsStealer RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-22CopilotDriver.jsjs bb069ae21ea35f433754f782cc0b4d2e8334e2e2ea435c2a5de49b6efe7a371en/aRemcosRAT
2026-02-21CopilotDriver.jsjs df29673a520423aa0af9535754aafdbe4a154d63827d10dbc1d87d733abf173en/a 
2026-02-19CopilotDriver.jsjs 40418a5c0b271e9119d21af4be73d4bef5fdf3276b2d6490ebc321fdce56101en/a RemcosRAT
2026-02-18CopilotDriver.jsjs 8b830f87be92486468561ab3f41a08bbafb24e2602f77a431ca42c15384fcc06n/a RemcosRAT
2026-02-16CopilotDriver.jsjs 3ed1a8c4ec7d25272e0640c39c924848ffbc57856cde779a9a6af6e6058b57afn/aRemcosRAT
2026-02-13CopilotDriver.jsjs 91baa6693a7101a106695f9eac9ecbbf6d6da66fd9a64f619ef3b18b268140a6n/a RemcosRAT
2026-02-12CopilotDriver.jsjs 62510b5dddaf01d04d3cff4920203d1c61b745ababc403aa2635fdc595d89b8an/a 
2026-02-12CopilotDriver.jsjs 4a68c6d4b5fb83e9241e81ec9decd050dd3f4a4f430ef517a72910c5c383087fn/a
2026-02-09CopilotDriver.jsjs ad63d5dba41c2c198bc7a23e2ff60b51e54a19082082a1297be85bbbcc787f61n/a 
2026-02-07CopilotDriver.jsjs dbde6a18d579383c8394a7525ca60c136d827f38a84d0639ef35897d6567c38bn/a 
2026-02-06CopilotDriver.jsjs ec9f57d5efb7103142b0713e7ff0ab6fbf217f50dd69c2640928c557a4a36cbcn/a RemcosRAT
2026-02-04CopilotDriver.jsjs c86ebb0e9a245fbe86a024641eb2a7dc236351c98ef98392ea366539b509827dn/aRemcosRAT
2026-02-03CopilotDriver.jsjs b2c0471f0b98d016db3f73ff001b097cbefe3b8e41eecd027fa40aa96a2cf3a2n/aPureLogsStealer
2026-02-03CopilotDriver.jsjs 4a8dab65abcfd71f3a62a956a8d8bde06a7a9aaa694ebffe42958675ff3b14f9n/a 
2025-08-09CopilotDriver.jsjs c59cf133700b2304326538d8ed9a3a6cde6b30579d627e87483517dbeeb3399en/aRemcosRAT
2025-08-06CopilotDriver.jsjs 4c2ad56ca838044373118a64685e3a460eee36851c20a740b30bfb139c25ff51n/a