maciejbi.hosting24.pl: a hosting subdomain that served Remcos scripts and a stego picture, and what to do if your PC fetched them
maciejbi.hosting24.pl is a subdomain on a Polish hosting service that URLhaus listed on 1 October 2026 for three files tagged RemcosRAT:
- a PowerShell script
- a second text file
- a PNG picture tagged stego
Remcos is a remote access trojan for Windows. These files are not something you catch by visiting a page; a script already running on a PC fetches them. If you only saw the name in a log, nothing is proven. If something on your PC may have fetched them, treat the PC as watched: change passwords from another device, then scan and clean or reset Windows.
Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a script or program that downloads files from maciejbi.hosting24.pl usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files): summary
| Type | A malware address: URLhaus tags its three files RemcosRAT; one is a PowerShell script, one a PNG picture tagged stego |
|---|---|
| Risk | High if a script on your PC fetched its files: keystrokes, passwords, screen, camera and microphone may be seen. Low if you only saw the name |
| Symptoms | Often none. Unknown startup entries or scheduled tasks, and MSBuild.exe running with no reason, are the signs in the reports |
| How to get rid of it | Change passwords from another device, run Microsoft Defender Offline, remove startup entries, and reset Windows if you are not sure |
| Our check (8 October 2026) | One plain request from our server: HTTP 403, Apache error page. A closed page clears nothing; the rating comes from URLhaus |
| Running since / first seen | Files first reported 1 October 2026; the parent domain hosting24.pl dates from 2007 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows. Nothing we read says Mac or phones are affected |
|---|---|
| Detection names | No detection name is known for these files, because we did not open them. For the family Microsoft uses Backdoor:Win32/Remcos |
| Name | Maciejbi.hosting24.pl |
| Domain registered | 11 November 2007 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 1 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 8 October 2026 |
Facts checked on 8 October 2026 against the URLhaus data for maciejbi.hosting24.pl held in our database, RDAP for hosting24.pl, one plain request from our server, and published pages by MITRE ATT&CK, Microsoft, SonicWall Capture Labs, Microsoft Learn and Microsoft Support. We did not download the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What maciejbi.hosting24.pl is, and what we know about it
maciejbi.hosting24.pl is not a program on your PC. It is a web address, a subdomain on the Polish hosting service hosting24.pl, that the abuse.ch project URLhaus listed on 1 October 2026 for three files tagged RemcosRAT, a remote access trojan for Windows. We found no public write-up of this one address, so this page sets out what URLhaus shows, what our own plain request returned, and what security vendors publish about Remcos and the delivery trick the tags point to.
- 1
What URLhaus lists
Three file addresses on maciejbi.hosting24.pl, all added by the reporter abuse_ch within two minutes on the afternoon of 1 October 2026. One is a picture called img_120657.png on the secure https address. The other two have short random names, e847Sl1P and 006sK41x, on plain http. All three carry the threat label malware_download, and all three were marked offline when we read the data on 8 October 2026.
- 2
What the tags mean
RemcosRAT and rat say the files belong to a chain that installs Remcos, a remote control program. stego on the picture means data was hidden inside it. ascii on the two short names means they are plain text files, and powershell and ps1 on one of them say that text is a PowerShell script, the command language built into Windows.
- 3
Who runs the address
hosting24.pl is the parent domain of a hosting company; RDAP shows it registered on 11 November 2007 through DOMENY.TV MSERWIS Sp. z o.o. A name like maciejbi in front of it is usually one customer's own space on that service. We do not know whether that account was set up by the criminals or broken into, and nothing we read says which.
- 4
What this means for you
If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a Windows PC where a script already ran and went to fetch one of these files. A person browsing the web has no reason to ask for a random file name like e847Sl1P.
- Kind of threat
- A web address that served three files tagged RemcosRAT: two text scripts (one PowerShell) and one PNG picture tagged stego
- Where the files were
- hxxps://maciejbi.hosting24[.]pl/img_120657.png, hxxp://maciejbi.hosting24[.]pl/e847Sl1P and hxxp://maciejbi.hosting24[.]pl/006sK41x
- Parent domain
- hosting24.pl, registered 11 November 2007, registrar DOMENY.TV MSERWIS Sp. z o.o. (RDAP, read 8 October 2026). The record describes the hosting company, not the person behind the subdomain
- URLhaus entries
- 3 file addresses, all added 1 October 2026 between 16:10 and 16:12 UTC; all 3 offline on 8 October 2026
- Our request
- 8 October 2026: the server answered HTTP 403 with an Apache page titled Błąd 403 / Error 403 (forbidden)
- Platform
- Windows. MITRE lists Remcos as Windows software. Nothing we read says these files affect Mac, iPhone or Android
What maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) does on an infected PC
What we checked on 8 October 2026, and what we could not
We sent one plain request to maciejbi.hosting24.pl from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered with HTTP 403, an Apache error page that says access is forbidden. That clears nothing. It only tells you that the front page of the subdomain is closed today.
Our check, 8 October 2026
- The address answers, but refusesHTTP status 403 from an Apache server, page title Błąd 403 / Error 403 (Polish and English for error 403). A hosting company often shows this when an account is suspended, empty or locked. We cannot tell which of these it is.
- Why that is not a clean resultA server that handed out malware a week ago can be switched back on, and the files can return under new names. A closed front page also says nothing about other paths on the same server.
- Notification requests, pop ups, redirectsNone. There was nothing to see: the answer was an error page, and there was no redirect.
- URLhaus listingThree files tagged RemcosRAT on 1 October 2026, one PowerShell script, one other text file and one picture tagged stego. All three marked offline on 8 October 2026.
- The files themselvesWe did not download them. We cannot tell you what the scripts say, which Remcos build the picture carries or where it reports to.
Dangerous: treat it as a malware address The 403 answer proves nothing either way. The rating comes from the three URLhaus reports and their RemcosRAT tags. Do not request files from this address and do not run anything that does.
What happened to maciejbi.hosting24.pl, from the first report to our check
Everything we know happened within one week. The times come from the URLhaus data we hold and are UTC; the registration date is for the hosting company's own domain.
11 November 2007
The parent domain is registered
RDAP shows hosting24.pl registered on 11 November 2007 through DOMENY.TV MSERWIS Sp. z o.o. This is the hosting company's domain. We have no date for when the maciejbi subdomain was created.
1 October 2026, 16:10 UTC
A picture and a PowerShell script are reported
abuse_ch adds img_120657.png at 16:10:17 with the tags rat, RemcosRAT and stego, and three seconds later e847Sl1P with the tags ascii, powershell, ps1, rat and RemcosRAT.
1 October 2026, 16:12 UTC
A third text file is reported
006sK41x is added at 16:12:13 with the tags ascii, rat and RemcosRAT. Three files reported within two minutes look like parts of one chain, found together. That is our reading of the times, not something the report says.
8 October 2026
All three offline, and our check
All three entries are marked offline. Our own plain request the same day gets HTTP 403 from an Apache server.

The three URLhaus entries for maciejbi.hosting24.pl, all added on 1 October 2026 and all offline when we read them on 8 October 2026.
What the pattern suggests, and what it does not: a picture, a PowerShell script and a second text file reported together match the chains vendors describe, where one script fetches the next and the last step pulls code out of an image. We did not open the files, so the order in which they were used is our reading, not a fact.
How a picture and two scripts can install Remcos
A picture that hides code cannot hurt you by being opened or looked at. It works only when a script that is already running reads the hidden part and starts it. We did not see the files on maciejbi.hosting24.pl; this is how SonicWall Capture Labs describes a chain that delivered Remcos the same way.

- 1
A first script is opened
SonicWall (16 June 2025) describes an email with an archive that holds a JavaScript, VBScript or HTA file. The script is lightly scrambled with string replacement and base64 so that it looks harmless. Opening it is the step a person takes.
- 2
PowerShell fetches the next piece
The first script downloads a scrambled PowerShell script from a web address. On maciejbi.hosting24.pl, URLhaus tagged e847Sl1P as exactly that kind of file: plain text, PowerShell, ps1.
- 3
A picture with a hidden program
The PowerShell script downloads an image. Between the text markers <<BASE64_START>> and <<BASE64_END>> inside it sits a program written as base64 text. The script cuts that part out and turns it back into a program. The picture itself still opens as a normal image.
- 4
The program hides inside a real Windows tool
In SonicWall's case the decoded loader starts MSBuild.exe, a genuine Microsoft program, and replaces its contents with the malware. This is called process hollowing. In Task Manager the process then carries a trusted name.
- 5
Remcos connects to its controller
In the case SonicWall analysed, the payload placed into that process was Remcos. From then on a person elsewhere can use the PC. The next sections list what the sources say Remcos does.
SonicWall also found options in the same loader to create a scheduled task and to add a VBScript entry to the startup part of the registry, so the chain starts again after a restart. Whether the files on maciejbi.hosting24.pl used the same loader is not known.
What Remcos is
Remcos is sold openly as remote control and surveillance software, and it has been used in malware campaigns for years. The sources agree on what it can do; what each campaign adds around it differs.
| Question | What the sources say | Source |
|---|---|---|
| What is it? | A closed source tool marketed as remote control and surveillance software by a company called Breaking Security, seen in malware campaigns | MITRE ATT&CK S0332, modified 23 April 2026 |
| Which system? | Windows | MITRE |
| What can it record? | Keystrokes, screenshots, sound from the microphone, pictures from the webcam and clipboard contents | MITRE; Microsoft |
| What else can it do? | Search, upload, download and delete files, list running programs, restart or shut down the PC, act as a SOCKS5 proxy for other traffic | MITRE; Microsoft |
| How does it stay? | MITRE says it adds itself to a registry Run key. Microsoft's sample created a registry key under the current user's software settings | MITRE; Microsoft |
| How does it hide? | A command to inject itself into another process, a command to bypass User Account Control, and traffic to its controller that can use TLS | MITRE |
| Who uses it? | MITRE names Gorgon Group, Gamaredon Group, LazyScripter and APT-C-36, plus the campaign Operation Spalax. It is also sold to anyone, so most victims meet ordinary criminals | MITRE |
| Which build is on this address? | Not known. URLhaus gives only the tag RemcosRAT; we did not open the files | Not available |
What maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) can steal or download
What Remcos can take from a Windows PC
A remote access trojan gives a stranger a seat at your computer, so the list below is what such a person can do, not what one build does on its own. Each item is named by at least one of the sources.
Reported as possible
- Every key you type
- Screenshots of your screen
- Sound from your microphone
- Pictures from your webcam
- Passwords
- Whatever you copy to the clipboard
- Files searched for and downloaded
- Files deleted or uploaded
- Your PC used as a proxy
- More malware downloaded
| Data | Detail | Source |
|---|---|---|
| Keystrokes | A keylogger that the controller can start and stop | MITRE; Microsoft |
| Screen, camera and sound | Screen captures, webcam pictures and audio recorded from the microphone | MITRE; Microsoft |
| Logins | Microsoft lists passwords among what it collects; SonicWall describes credential theft | Microsoft; SonicWall |
| Clipboard | Clipboard data, which can include passwords and wallet addresses you copy | MITRE; Microsoft |
| Files | Search, transfer and delete files | MITRE; Microsoft |
| Network | Acts as a SOCKS5 proxy, so others can send traffic through your connection | MITRE |
What this can cost you
Reading this page or seeing the name costs nothing. The risks below apply to a Windows PC where a script fetched one of these files and Remcos then ran.
- High
Passwords and accounts
A keylogger records what you type into every site, including new passwords you set on the same PC. Changing passwords there does not help; the person watching sees the new ones too.
- High
Someone using your PC live
Remcos is built for remote control. The controller can come back at any time, look at the screen and act while you are signed in.
- High
Bank and crypto
A bank session opened on the PC can be watched, and a wallet address you copy can be read from the clipboard. Crypto sent from a stolen wallet cannot be brought back.
- Medium
Your camera, microphone and files
MITRE lists webcam pictures and microphone recording. Private documents and photos on the PC are exposed.
- Medium
Your connection used by others
As a proxy, the PC can carry other people's traffic, which may lead to abuse reports against your internet address.
- Low
Nothing, if you only saw the name
A name in a block list, a log or a warning is not an infection.
What you may notice, and what you may not
Remcos is meant to be quiet. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing at all.
| Sign | What the reports show |
|---|---|
| A startup entry you did not make | MITRE says Remcos adds itself to a registry Run key. SonicWall's loader could add a VBScript to startup and create a scheduled task |
| A registry key with Remcos in its name | Microsoft's sample created HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1. Other builds use other names, so a missing key proves nothing |
| MSBuild.exe running with no reason | SonicWall describes Remcos hollowed into MSBuild.exe. It is a real Microsoft program, so its presence alone is not proof |
| A Defender detection with Remcos in the name | Microsoft uses the name Backdoor:Win32/Remcos for this family |
| Webcam light on, mouse moving, odd sounds | Follows from the listed features; this is our reading, not a quote |
| Accounts acting on their own | Logins from new places, password reset emails, messages you did not send. This follows from stolen logins |
| Nothing | Stealth is the point of a trojan that hides inside a trusted process |
How to check the PC for maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)
How a person ends up asking for these files
Nobody visits maciejbi.hosting24.pl on purpose. The request comes from a script, so the real question is how that script reached the PC. We cannot say for this address; the routes below are the ones the sources describe for Remcos.
- 1
An archive in an email
SonicWall's chain began with an emailed archive holding a JavaScript, VBScript or HTA file. Opening the file inside the archive is what starts it. Such mails often pose as invoices, orders or shipping notices.
- 2
A file that is not what it says
Microsoft's advice for Remcos is not to open files unless they come from a legitimate source. A script with a document style name is the usual disguise.
- 3
A hosting account used as a drop point
Criminals like to place files on ordinary hosting services because the address looks like a normal website. That fits this address, but we do not know how the files got there.
Check your PC before you delete anything
Start with the question that matters: did something on this PC contact maciejbi.hosting24.pl, or did you open an unexpected archive, script or attachment around 1 October 2026? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto, and do your account changes from another device.
- 1
Disconnect first
Turn off Wi-Fi or unplug the network cable. Remcos needs the connection to be used by its controller.
- 2
Find which device asked for the address
If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question, not every device on the network.
- 3
Look at what starts with Windows
Open Settings > Apps > Startup and look for names you did not install. MITRE says Remcos uses the registry Run key, which is the source of many of these entries. Write down what you find; do not delete yet.
- 4
Open Task Scheduler
Press Start, type Task Scheduler and open it. In Task Scheduler Library, look for tasks with random names or tasks that run a script or a program from a user folder or from C:\Users\Public. SonicWall's loader had an option to create such a task.
- 5
Look for trusted programs that should not be running
Open Task Manager and look for MSBuild.exe running when you are not building software, or any process with steady network use you cannot explain. Right click it and choose Open file location. Its presence is not proof, and its absence does not clear the PC.
- 6
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for Backdoor:Win32/Remcos or any detection around 1 October 2026. Microsoft says Defender removes what it finds automatically, but leftovers can stay.
- 7
Check your accounts from another device
Look at the sign in activity of your email, bank and exchange accounts. This is quicker than any file check and shows whether the damage has already spread.
- 8
A scan helps, but it does not clear the PC
A scan finds known files. Treat a clean result like our 403 answer: one data point. No vendor publishes a removal procedure for this address and we infected no PC, so the plan below follows Microsoft's pages and is our judgement, not a tested result.
How to remove maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)
How to remove maciejbi.hosting24.pl
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:
- a task that starts a file in
%AppData%or%Temp% - runs
powershellwith a long encoded line - opens a web address belongs to maciejbi.hosting24.pl or a similar program
Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
- a task that starts a file in
Step 2: Remove it from startup
Whatever maciejbi.hosting24.pl installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.
Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.
Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through
%LocalAppData%,%AppData%, %ProgramData% and the two Program Files folders.Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold
.exe,.dll, .js or .ps1 files are the strongest sign.Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.
Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.
Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The tags and every source we read describe a Windows threat: PowerShell scripts, a .NET loader and a Windows trojan. We found nothing that says the files on maciejbi.hosting24.pl affect anything else.
| Your device | What we know | What to do |
|---|---|---|
| Mac | MITRE lists Remcos for Windows only. PowerShell scripts and MSBuild.exe are Windows tools | Nothing to remove for this threat. Do not follow the Windows steps on a Mac |
| iPhone or iPad | No source describes Remcos on iOS | Nothing to remove. If you typed passwords into a page you did not trust, change them |
| Android | No source mentions it | Nothing to remove for this threat; change passwords if you entered any |
After removal: passwords, accounts and prevention
After a clean PC: protect what was taken
The PC is one half. The other half is everything you typed, copied or stored on it while the trojan was there. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Start with email, because it resets everything else, then bank, work, cloud storage and crypto exchanges. Anything typed on the PC while it was watched is already known.
- 2
Sign out other sessions and turn on two step sign in
In each important account, sign out of all devices and turn on two step sign in, so a stolen password alone does not let anyone in. Check the recovery email and phone number too.
- 3
Move crypto if a wallet was on the PC
If a seed phrase or a wallet file was on the PC, assume it is known. Make a new wallet on a clean device and move the funds.
- 4
Run Microsoft Defender Offline
Microsoft Learn says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes outside normal Windows. If BitLocker is on, Microsoft says to suspend it first. Results appear under Protection history.
- 5
Remove what the check found, with care
If Startup apps, the Run key or Task Scheduler showed an entry that you can tie to the malware, switch it off or delete it after the scan. If you cannot tell, do not guess: the safe answer is the reset below.
- 6
If you are not sure, reset Windows
Microsoft Support calls Reset this PC the most disruptive recovery option. In Windows 11 it sits under Settings > System > Recovery. It reinstalls Windows from the device and removes apps and settings; you choose whether to keep personal files. Back up documents first, and have your BitLocker recovery key ready.
- 7
Watch your money and accounts for weeks
Turn on alerts at your bank and check statements. Tell contacts not to open links sent from your accounts if any were used.
If maciejbi.hosting24.pl is your hosting account
A subdomain on a hosting service usually belongs to one customer. If this is your account and you did not put these files there, someone else has access to it.
- 1
Contact hosting24.pl support
Ask them what they saw, whether they locked the account, and which files and logins were involved. The 403 answer we got may be their doing.
- 2
Change every password of the account
Change the hosting panel, FTP, database and email passwords from a clean device, and turn on two step sign in where the panel offers it.
- 3
Look for files you did not upload
Files with random names without an ending, PNG files in odd places and PowerShell text are the kind URLhaus listed. Remove them and keep copies for the support team.
- 4
Check your own PC
Hosting passwords are often stolen from the owner's own computer by a trojan of this kind. Do the checks on this page on the PC you use to manage the site.
- 5
Ask for removal from the list
Once the files are gone, URLhaus already marks them offline. Keep the account clean; new files would bring new reports.
Keep a PC out of this kind of chain
The picture is the late part of the chain. Every source we read starts earlier, with an archive or a script that a person opened.
Do
- Treat an unexpected archive with a .js, .vbs or .hta file inside as an attack, and delete it.
- Show file name endings in File Explorer so a script posing as a document is visible.
- Keep Windows and Microsoft Defender updated.
- Use a password manager and two step sign in, so one stolen password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not open attachments from senders you do not expect, even when they look like an invoice or an order.
- Do not run scripts or programs from download links sent in chats or mails.
- Do not change passwords on the PC you suspect.
- Do not take a quiet scan or an offline server as proof that you are safe.
Questions about maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)
What is maciejbi.hosting24.pl?
It is a subdomain on the Polish hosting service hosting24.pl that URLhaus, the malware tracking project of abuse.ch, listed on 1 October 2026 for three files tagged RemcosRAT. One is a PNG picture tagged stego, one a PowerShell script and one a second text file.
It is not a program on your PC and not a site anyone is meant to visit. We did not download the files, so their contents are not confirmed by us.
Is maciejbi.hosting24.pl safe to open?
No. Do not request files from it and do not run anything that does. All three reported files were offline on 8 October 2026, and our plain request got an HTTP 403 error page.
That proves nothing: files can come back under new names. The rating comes from the three URLhaus reports and their RemcosRAT tags.
Is hosting24.pl itself dangerous?
Nothing we read says so. hosting24.pl is a hosting company's domain registered in 2007, and maciejbi is one space on it. The reports name only that subdomain.
Other sites on the same service are separate accounts, and we found no reports about them in the data we hold. If your own site is on hosting24.pl, this report alone is not a reason to move it.
What is Remcos?
Remcos is software sold by a company called Breaking Security as remote control and surveillance software, and it is used widely in malware campaigns.
MITRE and Microsoft list keylogging, screenshots, webcam pictures, microphone recording, clipboard reading, file transfer and use of the PC as a proxy. It runs on Windows and needs a script or loader to get onto the PC first.
What does stego mean on a PNG file?
It is short for steganography, hiding data inside another file. SonicWall describes pictures with a base64 encoded program placed between the markers BASE64_START and BASE64_END. The file still opens as a normal picture.
A PowerShell script already running reads the hidden part, decodes it and starts it, so the picture is a carrier, not something that infects you when you look at it.
I saw maciejbi.hosting24.pl in my firewall or DNS log. Am I infected?
Not necessarily, and the name alone proves nothing. It does mean that a device on your network asked for it, and people do not usually do that by hand. Find which device it was, disconnect it and run the checks on this page:
- Startup apps
- Task Scheduler
- Task Manager
- Protection history
- a Microsoft Defender Offline scan
Change passwords from another device.
How do I remove Remcos from Windows?
Change your passwords from another device first. Then run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options, and check Startup apps and Task Scheduler for entries you did not make.
Microsoft detects the family as Backdoor:Win32/Remcos. If you cannot be sure the PC is clean, use Reset this PC under Settings, System, Recovery after backing up your documents.
Can Remcos see my webcam and hear me?
Yes, according to MITRE and Microsoft: Remcos can take webcam pictures and record sound from the microphone, along with screenshots and keystrokes. Whether the controller uses that on a given PC is not something any report can tell you. Covering the camera helps against pictures, but the real answer is removing the trojan.
Does this affect my Mac, iPhone or Android phone?
Nothing we read says so. MITRE lists Remcos for Windows, and the files on this address are PowerShell scripts and a picture for a Windows loader.
If you typed passwords on any device into a page you did not trust, change them anyway. On a Windows PC in the same home, do the checks on this page instead.
Will Fortect remove maciejbi.hosting24.pl?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For maciejbi.hosting24.pl, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- MITRE ATT&CK: Remcos, S0332 (modified 23 April 2026) (read October 8, 2026)
- Microsoft Security Intelligence: Backdoor:Win32/Remcos (updated 25 September 2023) (read October 8, 2026)
- SonicWall Capture Labs: VMDetector Based Loader Abuses Steganography to Deliver Infostealers (16 June 2025) (read October 8, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 8, 2026)
- Microsoft Support: Recovery options in Windows (Reset this PC) (read October 8, 2026)