URLhaus Database

You are currently viewing the URLhaus database entry for http://gotemburgoxm.duckdns.org/sostener.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3509106
URL: http://gotemburgoxm.duckdns.org/sostener.vbs
URL Status:Offline
Host: gotemburgoxm.duckdns.org
Date added:2025-04-12 18:48:44 UTC
Last online:2025-08-16 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-08-15 12:16:13 UTC to abuse{at}frootvpn[dot]com)
Takedown time:1 month, 28 days, 20 hours, 2 minutes Bad (down since 2025-08-16 12:55:41 UTC)
Tags:opendir ua-wget vbs xworm

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-14sostener.vbstxt 62e65ddf448f62409bf2b252a1dda1c300de21fb0fff06ab07903360f301c1b5Virustotal results 6.56%XWorm
2025-07-02sostener.vbstxt 21aa261a83bd6d2b435ff38d3411c82bc7fa91b82adac99eb5c2153ac34f30e3n/a XWorm
2025-06-18sostener.vbstxt df0fe5536a69848a22b1b22f424a9bd598adafb30e09101dc98b214e09a1aef2Virustotal results 45.90%