URLhaus Database

You are currently viewing the URLhaus database entry for http://186.169.40.245/2septiembre.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3618147
URL: http://186.169.40.245/2septiembre.vbs
URL Status:Offline
Host: 186.169.40.245
Date added:2025-09-06 05:03:09 UTC
Last online:2025-09-08 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-06 05:04:10 UTC to admin[dot]internet{at}telecom[dot]com[dot]co)
Takedown time:2 days, 15 hours, 44 minutes Poor (down since 2025-09-08 20:48:26 UTC)
Tags:RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-082septiembre.vbstxt 67df45ee00c4d79267f06d0838515dfa3c1d4f0b04900cfe9d37fd0eb7c51d38Virustotal results 25.81% 
2025-09-062septiembre.vbstxt 932791f59371b7a69c112bedde0a369f77b03ce6ab3f4cb1c08be7ff49846137Virustotal results 24.19%RemcosRAT