URLhaus Database

You are currently viewing the URLhaus database entry for https://mymsa-eg.com/us/?1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2639072
URL: https://mymsa-eg.com/us/?1
URL Status:Offline
Host: mymsa-eg.com
Date added:2023-05-22 19:54:11 UTC
Last online:2023-05-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-05-22 21:46:08 UTC to abuse{at}hostgator[dot]com)
Takedown time:15 hours, 56 minutes Good (down since 2023-05-23 13:42:51 UTC)
Tags:geofenced js Pikabot Qakbot link USA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-23Bzgnl.jsjs 70c1a3a956540d3b23b2ed818c92f957cc2d308f484a0f467251fe26cd7523afn/a 
2023-05-23Lteezvl.jsjs e79b73ca12c49b3a42df0fe10c595b0757028b2a3b921af14de55b38ac40490an/a 
2023-05-23Douyjs.jsjs 3919ba038096a7dd7d266d21ff8ab6ff44225560c9668918b5b025a7bdfa6ea4n/a 
2023-05-23Xnik.jsjs 5731e3ab09413fd00582c8174ea93b993c6ac701349235ae7beee50c2ffec49cn/a 
2023-05-23Iwbua.jsjs 24f19a6d375064e1c90aa07af0324c341d17adffcddad5ea5fb2d2c142413490n/a 
2023-05-23Yhkduefc.jsjs f0a43f0845847abdd434a82b3f18eebcbb1afcb3a68c56ba980e81437cda890cn/a 
2023-05-23Xinnq.jsjs 5efafcaa77b4a2c278b5dc7e1514226e0ec1b017f64654439a38d107be65f5ffn/a 
2023-05-22Gcfu.jsjs 030f72cafbaf336b8c6d798efdb9c58bceda7b4c0d638ef0e16341702e5c89c9n/a 
2023-05-22Woxnbv.jsjs c3901dc743de300de6054577a47d823c5d17537db3c5d42d563614be6858e1dcn/a