gsgd.co.uk - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned gsgd.co.uk and returned a suspicious verdict (score 20), categorised as credential-harvest. The page resolved to 54.228.187.79 on Amazon.com, Inc. in IE. The domain was registered 8245 days ago through Fasthosts Internet Ltd. 14 domains and 1 IP were contacted, over 9 HTTP requests. 4 malware samples communicate with this URL (Gootloader). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
http://gsgd.co.uk/sandbox/jquery/easing/ - Domain: gsgd.co.uk · IP: 54.228.187.79 · AS16509 · IE
- Server: nginx/1.18.0
- Page title: jQuery Easing Plugin
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Fasthosts Internet Ltd · domain age 8245 days · created 2004-01-21
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 9 23: · subject CN=gsgd.co.uk
- HTTP requests captured: 9
- Scan tier: fast · observed 2026-08-19 18:17:00 UTC
Redirect chain
http://gsgd.co.uk/sandbox/jquery/easing/https://gsgd.co.uk/sandbox/jquery/easing/
Malware communicating with this URL (4)
These samples were observed contacting or being served from gsgd.co.uk. Each links to its full analysis.
- e10f2a1e2dd8f9b6de2dba4dc6834c0b89fe52f1fe3918f71cd29529edb5244e - referenced ·
e10f2a1e2dd8f9b6de2dba4dc6834c0b· first seen 2026-08-19 - Gootloader - referenced ·
a219dfaf4b5acc45855fdd5fc1e5278f· first seen 2026-08-19 - Gootloader - referenced ·
f1cbe5f24bb5373e39fa3abb363f16cf· first seen 2026-08-19 - 80e0acd51c4750b4d3338c71d96154fc40ecf2d382b4656a30180be48e37409f - referenced ·
80e0acd51c4750b4d3338c71d96154fc· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- PHP
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 54.228.187.79 - AS16509 Amazon.com, Inc. (Ireland)
Observed indicators
- gsgd.co.uk
- maxcdn.bootstrapcdn.com
- www.google-analytics.com
- code.jquery.com
- gist.github.com
- pagead2.googlesyndication.com
- github.com
- cdnjs.com
- virginmoneygiving.com
- media72.net
- www.magenet.com
- www.robertpenner.com
- www.paypal.com
- www.webhostingsearch.com
- 54.228.187.79
- https://gsgd.co.uk/sandbox/jquery/easing/
- https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css
- https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap-theme.min.css
- https://www.google-analytics.com/urchin.js
- https://code.jquery.com/jquery-1.12.4.min.js
Other scans of gsgd.co.uk (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - unknown ·
https://gsgd.co.uk/sandbox/jquery.easIng.php - 19 Aug 2026 - unknown ·
https://rstacruz.github.io/jquery.transit/ - 19 Aug 2026 - suspicious
- 13 Aug 2026 - unknown ·
https://rstacruz.github.io/jquery.transit/
Questions about gsgd.co.uk
- Is gsgd.co.uk safe?
- No. MalwareAnalyzer scanned gsgd.co.uk on 19 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with gsgd.co.uk?
- 4 analysed samples communicate with this URL, including Gootloader.
- How was gsgd.co.uk checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of gsgd.co.uk
Scanned on MalwareAnalyzer by Cyble · Open interactive scan