In 2017, Recorded Future researchers found that most of the malicious VBScript they examined on paste sites belonged to Houdini, also known as H-Worm. Their count was 213 posts as of April 26, 2017. The findings describe a historical campaign and do not establish how prevalent the malware is today.
What researchers found on paste sites
SecurityWeek reported on May 27, 2017, that Recorded Future had investigated an increase in malicious VBScript posts earlier that year. Most of the scripts in its investigation were Houdini, a malware family that the report said had existed since 2013. Some posts were exact matches; others used the same domain but contained altered VBScript.
Recorded Future’s figures, as reported by SecurityWeek, were current through April 26, 2017:
| Measure | Recorded Future’s 2017 count |
|---|---|
| Paste-site posts | 213 |
| Unique subdomains | 105 |
| Domains | 1 |
| Hashes | 190 |
These counts describe different things: posts are entries on paste sites, while domains and subdomains are infrastructure references and hashes identify files. They are historical investigation totals, not a current prevalence measure. SecurityWeek’s 2017 report summarizes the findings.
#1 Best Overall
How the reported malware behaved
Behavior described in the 2017 paste-site report
SecurityWeek said analyzed variants connected to a command-and-control (C2) server specified in the script, copied themselves to a directory after connecting, and created a registry key in a startup location to persist across restarts. Some active samples also communicated with a paste site as well as the host named in the script.
Behavior in Menlo Security’s separate sample analysis
Menlo Security analyzed a Houdini/H-Worm WSF sample containing heavily obfuscated VBScript. In that particular sample, the script checked removable drives, copied its WSF file, marked the copy hidden and system, hid original files, and created shortcuts that launched the hidden script. Menlo also documented sample-specific C2 behavior and commands to execute, update, download, upload, or sleep; those details should not be assumed to apply identically to every Houdini variant.
Menlo reported nearly 794 callbacks from one infected machine in the construction and engineering sector. That is an observation about one machine in its report, not a measure of how often the behavior occurred across infections. Its technical write-up provides the sample-level context.
What the reporting says about attribution
SecurityWeek reported that registration information for the domain microsofit[.]net included the name “Mohammed Raad,” an email address, and Germany as the country. The report described that domain and related subdomain clues as linking the malware to the registrant information. It did not establish that the named person authored the malware or personally posted every sample.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesThe paste-site posts were made through guest accounts, which could not be tied to a single person. As Daniel Hatheway, a Recorded Future researcher, put it: “The individual(s) reusing this Houdini VBscript are continually updating with new command and control servers.” The statement is quoted in SecurityWeek’s coverage; it describes reported reuse and updates, not proof of who was behind each post.
How to interpret the later Houdini reference
A 2019 SecurityWeek search-result excerpt described a later Houdini variant named WSH Remote Access Tool in a phishing campaign involving an MHT attachment that linked to a ZIP archive. That is separate later reporting. It does not demonstrate that the 2017 paste-site activity continued or that Houdini is active today. The 2019 report concerns that later campaign.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What these findings establish—and what they do not
The reporting documents Houdini/H-Worm in malicious VBScript found on paste sites in 2017, describes behaviors observed in analyzed variants and a separate Menlo sample, and records a qualified infrastructure-to-registrant association. It does not establish current prevalence, whether historical C2 infrastructure remains active, or how well any present-day security product detects the family. Those questions require current threat intelligence and product-specific testing.
For organizations, the reported persistence, script execution, and C2 activity are reasons to treat script-based malware as a security concern. The sources do not test or recommend a particular endpoint tool or managed detection service, so no product-specific detection claim follows from these findings.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

