URLhaus Database

You are currently viewing the URLhaus database entry for http://158.94.209.243/svchost.vbs which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3660314
URL: http://158.94.209.243/svchost.vbs
URL Status:Offline
Host: 158.94.209.243
Date added:2025-10-06 12:25:10 UTC
Last online:2025-11-20 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-06 12:26:13 UTC to abuse{at}metaspinner[dot]net)
Takedown time:1 month, 15 days, 10 hours, 50 minutes Bad (down since 2025-11-20 23:16:26 UTC)
Tags:AsyncRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-11-20svchost.vbstxt 89d74e1cc49c526f2b8cb961132e8bea0d5cb79605154f1baec82611e4d78073Virustotal results 22.58% 
2025-11-01svchost.vbstxt b4644f9aee58b5d8a2dd347c7b424e384944df1f0874422cfde9031f8ace7cd5Virustotal results 19.67% 
2025-10-23svchost.vbstxt dd70d4106356e00a77d16b7703480738b04ce834e025dbbcc9e2ea189978d27eVirustotal results 17.74% AsyncRAT
2025-10-07svchost.vbstxt 2e993a9fcd092234c91b87774180866d23718a396a5867b3b355b7214c429a54Virustotal results 24.19%AsyncRAT
2025-10-06svchost.vbstxt 3030605201850595dc0cec5af841299b5bac0af2140bf8ed116154937200f537Virustotal results 20.97% AsyncRAT