URLhaus Database

You are currently viewing the URLhaus database entry for http://186.169.69.76/31agosto.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3692775
URL: http://186.169.69.76/31agosto.vbs
URL Status:Offline
Host: 186.169.69.76
Date added:2025-11-01 07:55:19 UTC
Last online:2025-11-13 05:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-11-01 08:00:16 UTC to admin[dot]internet{at}telecom[dot]com[dot]co)
Takedown time:11 days, 21 hours, 55 minutes Bad (down since 2025-11-13 05:55:49 UTC)
Tags:DEU geofenced opendir RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-1131agosto.vbstxt cb0ec11df5fb97d727bea30c9d207c70cb6508e3159b2a9d9dad062d39d78750Virustotal results 20.97% 
2025-11-0531agosto.vbstxt e2ae3121af3fd9874ba17612b0c012ca1962dfd918cc1d479384dad7bf469c64Virustotal results 20.97% RemcosRAT
2025-11-0531agosto.vbstxt cdf18dce59da13a347c6d2d60a0bf6190228b46e595863308769a1cb34ca5fd0Virustotal results 22.58% RemcosRAT
2025-11-0131agosto.vbstxt 71fc5b649c4ca8ada3d1b6cfdcc52337504238fcc4a705d967f6a4e54b49d4d5Virustotal results 20.97%