URLhaus Database

You are currently viewing the URLhaus database entry for http://myguyapp.com/bo.js which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3353523
URL: http://myguyapp.com/bo.js
URL Status:Offline
Host: myguyapp.com
Date added:2024-12-17 08:26:34 UTC
Last online:2025-09-25 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2025-09-24 12:44:09 UTC to abuse-network{at}squarespace[dot]com)
Takedown time:21 days, 7 hours, 17 minutes Bad (down since 2025-10-15 20:01:17 UTC)
Tags:c2 RemcosRAT link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-13bo.jsjs d44fa558b202e1f6f37fdcfc61ef1b85b0cdf1ba61a8cd88f0b9ce05092c8f52n/a 
2025-10-10bo.jsjs cc491853359d17fc2610898bd36edbe461374a291b32c59c7e41f71912a2ed0bn/a 
2025-10-10bo.jsjs d83736db415cef3f5c045285e8c856e9b9edf56af49e96070244ff400eaaa932Virustotal results 0.00%
2025-10-07bo.jsjs 0ec3b305f13bf1559f77eca501afceebe6b9713fec33cb3720d813a29151107fn/a 
2025-10-06bo.jsjs fccab89da4daa9007da4da79330e4c4b0b1a1223b4f0cff35229073f37404ecan/a 
2025-10-05bo.jsjs 9e6800e000d6e4cfadd0ee4a184b17173a46c992733f9be13cfe5493c59c19bbVirustotal results 0.00%RemcosRAT
2025-10-02bo.jsjs acfcbe23a50d1668ce1a528e6a7e0d41fff77d5e048345924bd1edb64363bb14Virustotal results 0.00%RemcosRAT
2025-09-29bo.jsjs 53d80d66ac0c4b75fc120dae7d801a1f204604cd6b0430f2beada542cbd21191n/aRemcosRAT
2025-09-26bo.jsjs c8638846eefddbcbd97d5cf879734e46abb6c12d6faffc411a0c061ed3a0eaffn/a
2025-09-24bo.jsjs 4bf088b63b28dc316e6b2e5a65a40eb6814ff25284e60e6bb9bce020fa22981dn/a