maciejbi.hosting24.pl: a hosting subdomain that served Remcos scripts and a stego picture, and what to do if your PC fetched them

maciejbi.hosting24.pl is a subdomain on a Polish hosting service that URLhaus listed on 1 October 2026 for three files tagged RemcosRAT:

  • a PowerShell script
  • a second text file
  • a PNG picture tagged stego

Remcos is a remote access trojan for Windows. These files are not something you catch by visiting a page; a script already running on a PC fetches them. If you only saw the name in a log, nothing is proven. If something on your PC may have fetched them, treat the PC as watched: change passwords from another device, then scan and clean or reset Windows.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a script or program that downloads files from maciejbi.hosting24.pl usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Table of three URLhaus entries for maciejbi.hosting24.pl added on 1 October 2026, tagged RemcosRAT, all offline
The three URLhaus entries for maciejbi.hosting24.pl that we read on 8 October 2026. There is no browser screenshot: our check was one plain request from our server, which got an HTTP 403 error page.

Maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files): summary

TypeA malware address: URLhaus tags its three files RemcosRAT; one is a PowerShell script, one a PNG picture tagged stego
RiskHigh if a script on your PC fetched its files: keystrokes, passwords, screen, camera and microphone may be seen. Low if you only saw the name
SymptomsOften none. Unknown startup entries or scheduled tasks, and MSBuild.exe running with no reason, are the signs in the reports
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove startup entries, and reset Windows if you are not sure
Our check (8 October 2026)One plain request from our server: HTTP 403, Apache error page. A closed page clears nothing; the rating comes from URLhaus
Running since / first seenFiles first reported 1 October 2026; the parent domain hosting24.pl dates from 2007
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 9 more facts
PlatformWindows. Nothing we read says Mac or phones are affected
Detection namesNo detection name is known for these files, because we did not open them. For the family Microsoft uses Backdoor:Win32/Remcos
NameMaciejbi.hosting24.pl
Domain registered11 November 2007
Evidence3 write-ups by security sites; details still limited
First seen1 October 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data for maciejbi.hosting24.pl held in our database, RDAP for hosting24.pl, one plain request from our server, and published pages by MITRE ATT&CK, Microsoft, SonicWall Capture Labs, Microsoft Learn and Microsoft Support. We did not download the files and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What maciejbi.hosting24.pl is, and what we know about it

maciejbi.hosting24.pl is not a program on your PC. It is a web address, a subdomain on the Polish hosting service hosting24.pl, that the abuse.ch project URLhaus listed on 1 October 2026 for three files tagged RemcosRAT, a remote access trojan for Windows. We found no public write-up of this one address, so this page sets out what URLhaus shows, what our own plain request returned, and what security vendors publish about Remcos and the delivery trick the tags point to.

  1. 1

    What URLhaus lists

    Three file addresses on maciejbi.hosting24.pl, all added by the reporter abuse_ch within two minutes on the afternoon of 1 October 2026. One is a picture called img_120657.png on the secure https address. The other two have short random names, e847Sl1P and 006sK41x, on plain http. All three carry the threat label malware_download, and all three were marked offline when we read the data on 8 October 2026.

  2. 2

    What the tags mean

    RemcosRAT and rat say the files belong to a chain that installs Remcos, a remote control program. stego on the picture means data was hidden inside it. ascii on the two short names means they are plain text files, and powershell and ps1 on one of them say that text is a PowerShell script, the command language built into Windows.

  3. 3

    Who runs the address

    hosting24.pl is the parent domain of a hosting company; RDAP shows it registered on 11 November 2007 through DOMENY.TV MSERWIS Sp. z o.o. A name like maciejbi in front of it is usually one customer's own space on that service. We do not know whether that account was set up by the criminals or broken into, and nothing we read says which.

  4. 4

    What this means for you

    If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a Windows PC where a script already ran and went to fetch one of these files. A person browsing the web has no reason to ask for a random file name like e847Sl1P.

Kind of threat
A web address that served three files tagged RemcosRAT: two text scripts (one PowerShell) and one PNG picture tagged stego
Where the files were
hxxps://maciejbi.hosting24[.]pl/img_120657.png, hxxp://maciejbi.hosting24[.]pl/e847Sl1P and hxxp://maciejbi.hosting24[.]pl/006sK41x
Parent domain
hosting24.pl, registered 11 November 2007, registrar DOMENY.TV MSERWIS Sp. z o.o. (RDAP, read 8 October 2026). The record describes the hosting company, not the person behind the subdomain
URLhaus entries
3 file addresses, all added 1 October 2026 between 16:10 and 16:12 UTC; all 3 offline on 8 October 2026
Our request
8 October 2026: the server answered HTTP 403 with an Apache page titled Błąd 403 / Error 403 (forbidden)
Platform
Windows. MITRE lists Remcos as Windows software. Nothing we read says these files affect Mac, iPhone or Android

What maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request to maciejbi.hosting24.pl from our server on 8 October 2026: no browser, no clicks, no file downloads. The server answered with HTTP 403, an Apache error page that says access is forbidden. That clears nothing. It only tells you that the front page of the subdomain is closed today.

Our check, 8 October 2026

  • The address answers, but refusesHTTP status 403 from an Apache server, page title Błąd 403 / Error 403 (Polish and English for error 403). A hosting company often shows this when an account is suspended, empty or locked. We cannot tell which of these it is.
  • Why that is not a clean resultA server that handed out malware a week ago can be switched back on, and the files can return under new names. A closed front page also says nothing about other paths on the same server.
  • Notification requests, pop ups, redirectsNone. There was nothing to see: the answer was an error page, and there was no redirect.
  • URLhaus listingThree files tagged RemcosRAT on 1 October 2026, one PowerShell script, one other text file and one picture tagged stego. All three marked offline on 8 October 2026.
  • The files themselvesWe did not download them. We cannot tell you what the scripts say, which Remcos build the picture carries or where it reports to.

Dangerous: treat it as a malware address The 403 answer proves nothing either way. The rating comes from the three URLhaus reports and their RemcosRAT tags. Do not request files from this address and do not run anything that does.

What happened to maciejbi.hosting24.pl, from the first report to our check

Everything we know happened within one week. The times come from the URLhaus data we hold and are UTC; the registration date is for the hosting company's own domain.

  1. 11 November 2007

    The parent domain is registered

    RDAP shows hosting24.pl registered on 11 November 2007 through DOMENY.TV MSERWIS Sp. z o.o. This is the hosting company's domain. We have no date for when the maciejbi subdomain was created.

  2. 1 October 2026, 16:10 UTC

    A picture and a PowerShell script are reported

    abuse_ch adds img_120657.png at 16:10:17 with the tags rat, RemcosRAT and stego, and three seconds later e847Sl1P with the tags ascii, powershell, ps1, rat and RemcosRAT.

  3. 1 October 2026, 16:12 UTC

    A third text file is reported

    006sK41x is added at 16:12:13 with the tags ascii, rat and RemcosRAT. Three files reported within two minutes look like parts of one chain, found together. That is our reading of the times, not something the report says.

  4. 8 October 2026

    All three offline, and our check

    All three entries are marked offline. Our own plain request the same day gets HTTP 403 from an Apache server.

    Table of the three URLhaus entries for maciejbi.hosting24.pl with times, file names, tags and offline status
    The three URLhaus entries for maciejbi.hosting24.pl, all added on 1 October 2026 and all offline when we read them on 8 October 2026.

What the pattern suggests, and what it does not: a picture, a PowerShell script and a second text file reported together match the chains vendors describe, where one script fetches the next and the last step pulls code out of an image. We did not open the files, so the order in which they were used is our reading, not a fact.

How a picture and two scripts can install Remcos

A picture that hides code cannot hurt you by being opened or looked at. It works only when a script that is already running reads the hidden part and starts it. We did not see the files on maciejbi.hosting24.pl; this is how SonicWall Capture Labs describes a chain that delivered Remcos the same way.

Five steps: a script from an email archive runs, PowerShell fetches a second script, a PNG with hidden base64 code is downloaded, the code is decoded and injected into a trusted .NET process, Remcos connects to its controller
The picture trick in five steps, as SonicWall describes it. The first step on a victim's PC is not something we saw for this address.
  1. 1

    A first script is opened

    SonicWall (16 June 2025) describes an email with an archive that holds a JavaScript, VBScript or HTA file. The script is lightly scrambled with string replacement and base64 so that it looks harmless. Opening it is the step a person takes.

  2. 2

    PowerShell fetches the next piece

    The first script downloads a scrambled PowerShell script from a web address. On maciejbi.hosting24.pl, URLhaus tagged e847Sl1P as exactly that kind of file: plain text, PowerShell, ps1.

  3. 3

    A picture with a hidden program

    The PowerShell script downloads an image. Between the text markers <<BASE64_START>> and <<BASE64_END>> inside it sits a program written as base64 text. The script cuts that part out and turns it back into a program. The picture itself still opens as a normal image.

  4. 4

    The program hides inside a real Windows tool

    In SonicWall's case the decoded loader starts MSBuild.exe, a genuine Microsoft program, and replaces its contents with the malware. This is called process hollowing. In Task Manager the process then carries a trusted name.

  5. 5

    Remcos connects to its controller

    In the case SonicWall analysed, the payload placed into that process was Remcos. From then on a person elsewhere can use the PC. The next sections list what the sources say Remcos does.

SonicWall also found options in the same loader to create a scheduled task and to add a VBScript entry to the startup part of the registry, so the chain starts again after a restart. Whether the files on maciejbi.hosting24.pl used the same loader is not known.

What Remcos is

Remcos is sold openly as remote control and surveillance software, and it has been used in malware campaigns for years. The sources agree on what it can do; what each campaign adds around it differs.

Sources: MITRE ATT&CK S0332 and Microsoft's Backdoor:Win32/Remcos entry, read 8 October 2026.
QuestionWhat the sources saySource
What is it?A closed source tool marketed as remote control and surveillance software by a company called Breaking Security, seen in malware campaignsMITRE ATT&CK S0332, modified 23 April 2026
Which system?WindowsMITRE
What can it record?Keystrokes, screenshots, sound from the microphone, pictures from the webcam and clipboard contentsMITRE; Microsoft
What else can it do?Search, upload, download and delete files, list running programs, restart or shut down the PC, act as a SOCKS5 proxy for other trafficMITRE; Microsoft
How does it stay?MITRE says it adds itself to a registry Run key. Microsoft's sample created a registry key under the current user's software settingsMITRE; Microsoft
How does it hide?A command to inject itself into another process, a command to bypass User Account Control, and traffic to its controller that can use TLSMITRE
Who uses it?MITRE names Gorgon Group, Gamaredon Group, LazyScripter and APT-C-36, plus the campaign Operation Spalax. It is also sold to anyone, so most victims meet ordinary criminalsMITRE
Which build is on this address?Not known. URLhaus gives only the tag RemcosRAT; we did not open the filesNot available

What maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files) can steal or download

What Remcos can take from a Windows PC

A remote access trojan gives a stranger a seat at your computer, so the list below is what such a person can do, not what one build does on its own. Each item is named by at least one of the sources.

Reported as possible

  • Every key you type
  • Screenshots of your screen
  • Sound from your microphone
  • Pictures from your webcam
  • Passwords
  • Whatever you copy to the clipboard
  • Files searched for and downloaded
  • Files deleted or uploaded
  • Your PC used as a proxy
  • More malware downloaded
Sources: MITRE ATT&CK S0332, Microsoft's Backdoor:Win32/Remcos entry and SonicWall Capture Labs, read 8 October 2026.
DataDetailSource
KeystrokesA keylogger that the controller can start and stopMITRE; Microsoft
Screen, camera and soundScreen captures, webcam pictures and audio recorded from the microphoneMITRE; Microsoft
LoginsMicrosoft lists passwords among what it collects; SonicWall describes credential theftMicrosoft; SonicWall
ClipboardClipboard data, which can include passwords and wallet addresses you copyMITRE; Microsoft
FilesSearch, transfer and delete filesMITRE; Microsoft
NetworkActs as a SOCKS5 proxy, so others can send traffic through your connectionMITRE

What this can cost you

Reading this page or seeing the name costs nothing. The risks below apply to a Windows PC where a script fetched one of these files and Remcos then ran.

  • High

    Passwords and accounts

    A keylogger records what you type into every site, including new passwords you set on the same PC. Changing passwords there does not help; the person watching sees the new ones too.

  • High

    Someone using your PC live

    Remcos is built for remote control. The controller can come back at any time, look at the screen and act while you are signed in.

  • High

    Bank and crypto

    A bank session opened on the PC can be watched, and a wallet address you copy can be read from the clipboard. Crypto sent from a stolen wallet cannot be brought back.

  • Medium

    Your camera, microphone and files

    MITRE lists webcam pictures and microphone recording. Private documents and photos on the PC are exposed.

  • Medium

    Your connection used by others

    As a proxy, the PC can carry other people's traffic, which may lead to abuse reports against your internet address.

  • Low

    Nothing, if you only saw the name

    A name in a block list, a log or a warning is not an infection.

What you may notice, and what you may not

Remcos is meant to be quiet. The signs below come from the sources and from what they imply; none is certain, and many victims notice nothing at all.

SignWhat the reports show
A startup entry you did not makeMITRE says Remcos adds itself to a registry Run key. SonicWall's loader could add a VBScript to startup and create a scheduled task
A registry key with Remcos in its nameMicrosoft's sample created HKEY_CURRENT_USER\SOFTWARE\Remcos-YTPKR1. Other builds use other names, so a missing key proves nothing
MSBuild.exe running with no reasonSonicWall describes Remcos hollowed into MSBuild.exe. It is a real Microsoft program, so its presence alone is not proof
A Defender detection with Remcos in the nameMicrosoft uses the name Backdoor:Win32/Remcos for this family
Webcam light on, mouse moving, odd soundsFollows from the listed features; this is our reading, not a quote
Accounts acting on their ownLogins from new places, password reset emails, messages you did not send. This follows from stolen logins
NothingStealth is the point of a trojan that hides inside a trusted process

How to check the PC for maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)

How a person ends up asking for these files

Nobody visits maciejbi.hosting24.pl on purpose. The request comes from a script, so the real question is how that script reached the PC. We cannot say for this address; the routes below are the ones the sources describe for Remcos.

  1. 1

    An archive in an email

    SonicWall's chain began with an emailed archive holding a JavaScript, VBScript or HTA file. Opening the file inside the archive is what starts it. Such mails often pose as invoices, orders or shipping notices.

  2. 2

    A file that is not what it says

    Microsoft's advice for Remcos is not to open files unless they come from a legitimate source. A script with a document style name is the usual disguise.

  3. 3

    A hosting account used as a drop point

    Criminals like to place files on ordinary hosting services because the address looks like a normal website. That fits this address, but we do not know how the files got there.

Check your PC before you delete anything

Start with the question that matters: did something on this PC contact maciejbi.hosting24.pl, or did you open an unexpected archive, script or attachment around 1 October 2026? If you saw the name in a firewall or DNS log from your own network, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.

While you check, stop using the PC for banking, email, work or crypto, and do your account changes from another device.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the network cable. Remcos needs the connection to be used by its controller.

  2. 2

    Find which device asked for the address

    If you came here from a log, a router page or an alert, note the device and the time. Only that device is in question, not every device on the network.

  3. 3

    Look at what starts with Windows

    Open Settings > Apps > Startup and look for names you did not install. MITRE says Remcos uses the registry Run key, which is the source of many of these entries. Write down what you find; do not delete yet.

  4. 4

    Open Task Scheduler

    Press Start, type Task Scheduler and open it. In Task Scheduler Library, look for tasks with random names or tasks that run a script or a program from a user folder or from C:\Users\Public. SonicWall's loader had an option to create such a task.

  5. 5

    Look for trusted programs that should not be running

    Open Task Manager and look for MSBuild.exe running when you are not building software, or any process with steady network use you cannot explain. Right click it and choose Open file location. Its presence is not proof, and its absence does not clear the PC.

  6. 6

    Open Protection history

    In Windows Security > Virus & threat protection > Protection history, look for Backdoor:Win32/Remcos or any detection around 1 October 2026. Microsoft says Defender removes what it finds automatically, but leftovers can stay.

  7. 7

    Check your accounts from another device

    Look at the sign in activity of your email, bank and exchange accounts. This is quicker than any file check and shows whether the damage has already spread.

  8. 8

    A scan helps, but it does not clear the PC

    A scan finds known files. Treat a clean result like our 403 answer: one data point. No vendor publishes a removal procedure for this address and we infected no PC, so the plan below follows Microsoft's pages and is our judgement, not a tested result.

How to remove maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)

How to remove maciejbi.hosting24.pl

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to maciejbi.hosting24.pl or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever maciejbi.hosting24.pl installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The tags and every source we read describe a Windows threat: PowerShell scripts, a .NET loader and a Windows trojan. We found nothing that says the files on maciejbi.hosting24.pl affect anything else.

Your deviceWhat we knowWhat to do
MacMITRE lists Remcos for Windows only. PowerShell scripts and MSBuild.exe are Windows toolsNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes Remcos on iOSNothing to remove. If you typed passwords into a page you did not trust, change them
AndroidNo source mentions itNothing to remove for this threat; change passwords if you entered any

After removal: passwords, accounts and prevention

After a clean PC: protect what was taken

The PC is one half. The other half is everything you typed, copied or stored on it while the trojan was there. The order matters: another device first, then the PC.

Five steps in order: disconnect the PC, change passwords from another device, run Microsoft Defender Offline, check startup entries and Task Scheduler, reset this PC if unsure
The order of actions if a script like this ran on a PC. The steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, because it resets everything else, then bank, work, cloud storage and crypto exchanges. Anything typed on the PC while it was watched is already known.

  2. 2

    Sign out other sessions and turn on two step sign in

    In each important account, sign out of all devices and turn on two step sign in, so a stolen password alone does not let anyone in. Check the recovery email and phone number too.

  3. 3

    Move crypto if a wallet was on the PC

    If a seed phrase or a wallet file was on the PC, assume it is known. Make a new wallet on a clean device and move the funds.

  4. 4

    Run Microsoft Defender Offline

    Microsoft Learn says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes outside normal Windows. If BitLocker is on, Microsoft says to suspend it first. Results appear under Protection history.

  5. 5

    Remove what the check found, with care

    If Startup apps, the Run key or Task Scheduler showed an entry that you can tie to the malware, switch it off or delete it after the scan. If you cannot tell, do not guess: the safe answer is the reset below.

  6. 6

    If you are not sure, reset Windows

    Microsoft Support calls Reset this PC the most disruptive recovery option. In Windows 11 it sits under Settings > System > Recovery. It reinstalls Windows from the device and removes apps and settings; you choose whether to keep personal files. Back up documents first, and have your BitLocker recovery key ready.

  7. 7

    Watch your money and accounts for weeks

    Turn on alerts at your bank and check statements. Tell contacts not to open links sent from your accounts if any were used.

If maciejbi.hosting24.pl is your hosting account

A subdomain on a hosting service usually belongs to one customer. If this is your account and you did not put these files there, someone else has access to it.

  1. 1

    Contact hosting24.pl support

    Ask them what they saw, whether they locked the account, and which files and logins were involved. The 403 answer we got may be their doing.

  2. 2

    Change every password of the account

    Change the hosting panel, FTP, database and email passwords from a clean device, and turn on two step sign in where the panel offers it.

  3. 3

    Look for files you did not upload

    Files with random names without an ending, PNG files in odd places and PowerShell text are the kind URLhaus listed. Remove them and keep copies for the support team.

  4. 4

    Check your own PC

    Hosting passwords are often stolen from the owner's own computer by a trojan of this kind. Do the checks on this page on the PC you use to manage the site.

  5. 5

    Ask for removal from the list

    Once the files are gone, URLhaus already marks them offline. Keep the account clean; new files would bring new reports.

Keep a PC out of this kind of chain

The picture is the late part of the chain. Every source we read starts earlier, with an archive or a script that a person opened.

Do

  • Treat an unexpected archive with a .js, .vbs or .hta file inside as an attack, and delete it.
  • Show file name endings in File Explorer so a script posing as a document is visible.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager and two step sign in, so one stolen password is not enough.
  • Keep a backup of documents on a disk that you unplug.

Don't

  • Do not open attachments from senders you do not expect, even when they look like an invoice or an order.
  • Do not run scripts or programs from download links sent in chats or mails.
  • Do not change passwords on the PC you suspect.
  • Do not take a quiet scan or an offline server as proof that you are safe.

Questions about maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)

What is maciejbi.hosting24.pl?

It is a subdomain on the Polish hosting service hosting24.pl that URLhaus, the malware tracking project of abuse.ch, listed on 1 October 2026 for three files tagged RemcosRAT. One is a PNG picture tagged stego, one a PowerShell script and one a second text file.

It is not a program on your PC and not a site anyone is meant to visit. We did not download the files, so their contents are not confirmed by us.

Is maciejbi.hosting24.pl safe to open?

No. Do not request files from it and do not run anything that does. All three reported files were offline on 8 October 2026, and our plain request got an HTTP 403 error page.

That proves nothing: files can come back under new names. The rating comes from the three URLhaus reports and their RemcosRAT tags.

Is hosting24.pl itself dangerous?

Nothing we read says so. hosting24.pl is a hosting company's domain registered in 2007, and maciejbi is one space on it. The reports name only that subdomain.

Other sites on the same service are separate accounts, and we found no reports about them in the data we hold. If your own site is on hosting24.pl, this report alone is not a reason to move it.

What is Remcos?

Remcos is software sold by a company called Breaking Security as remote control and surveillance software, and it is used widely in malware campaigns.

MITRE and Microsoft list keylogging, screenshots, webcam pictures, microphone recording, clipboard reading, file transfer and use of the PC as a proxy. It runs on Windows and needs a script or loader to get onto the PC first.

What does stego mean on a PNG file?

It is short for steganography, hiding data inside another file. SonicWall describes pictures with a base64 encoded program placed between the markers BASE64_START and BASE64_END. The file still opens as a normal picture.

A PowerShell script already running reads the hidden part, decodes it and starts it, so the picture is a carrier, not something that infects you when you look at it.

I saw maciejbi.hosting24.pl in my firewall or DNS log. Am I infected?

Not necessarily, and the name alone proves nothing. It does mean that a device on your network asked for it, and people do not usually do that by hand. Find which device it was, disconnect it and run the checks on this page:

  • Startup apps
  • Task Scheduler
  • Task Manager
  • Protection history
  • a Microsoft Defender Offline scan

Change passwords from another device.

How do I remove Remcos from Windows?

Change your passwords from another device first. Then run Microsoft Defender Offline from Windows Security, Virus and threat protection, Scan options, and check Startup apps and Task Scheduler for entries you did not make.

Microsoft detects the family as Backdoor:Win32/Remcos. If you cannot be sure the PC is clean, use Reset this PC under Settings, System, Recovery after backing up your documents.

Can Remcos see my webcam and hear me?

Yes, according to MITRE and Microsoft: Remcos can take webcam pictures and record sound from the microphone, along with screenshots and keystrokes. Whether the controller uses that on a given PC is not something any report can tell you. Covering the camera helps against pictures, but the real answer is removing the trojan.

Does this affect my Mac, iPhone or Android phone?

Nothing we read says so. MITRE lists Remcos for Windows, and the files on this address are PowerShell scripts and a picture for a Windows loader.

If you typed passwords on any device into a page you did not trust, change them anyway. On a Windows PC in the same home, do the checks on this page instead.

Will Fortect remove maciejbi.hosting24.pl?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For maciejbi.hosting24.pl, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: maciejbi.hosting24.pl (Remcos RAT, PowerShell and stego PNG files)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year