URLhaus Database

You are currently viewing the URLhaus database entry for http://oficialrem.duckdns.org/SOSTENER.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3787546
URL: http://oficialrem.duckdns.org/SOSTENER.vbs
URL Status:flame Online (spreading malware for 1 month, 16 days, 22 hours, 57 minutes)
Host: oficialrem.duckdns.org
Date added:2026-02-28 14:45:13 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (phishing)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2026-04-10 14:56:12 UTC to admin[dot]internet{at}telecom[dot]com[dot]co)
Tags:opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-15SOSTENER.vbstxt b1090fc70e04a580641801a450e60e1280e3571b200f2301e86314cb571ec2c5n/a 
2026-04-15SOSTENER.vbstxt 1033bc1b8553e9b051f59a104ba9aea9d1a1322056decf4e696e1ab0dfc62fe4n/a 
2026-04-14SOSTENER.vbstxt c1bc4d0889a21ee2999e32f68ee95c1a54ecde6cbebce2c8f169aea32766bdf5n/a
2026-04-13SOSTENER.vbstxt 9b99747d1b73fbca15dbc14f2cd30f2d6fc12362ba78f271d30c2b5351945c2bn/a
2026-04-09SOSTENER.vbstxt 8b2423998a01a616fe73a8430f9b87b3e6a3a38d13000c248ccbdef1a55705c6n/a 
2026-04-09SOSTENER.vbstxt ba9303d913b9e097cb23c5dd92a6a8093f82b46c4ed8fc1e22e8d777e1a9c78en/a
2026-04-06SOSTENER.vbstxt 4e394265931b6602ca36766b3c62edc7a93dbebdde29b6ce04024f1e197a69d3n/a 
2026-03-25SOSTENER.vbstxt b9fdffceba4b093e709d48fe2505621b0f920491a371ad0fc072759ff410751en/a
2026-03-17SOSTENER.vbstxt e9cb1effe6f7d4a5e97a5de88ba65afdf0149420c6acec4d21db6210ca89fa81n/a
2026-03-16SOSTENER.vbstxt 5d7c62da6e8fd08d708db6904ae5a8e050b2c8df8ef16035a4c50eb631f7a1d0n/a