URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: efjgerws.galaxias.cc
Domain registrar:Cloudflare -
Domain registration date:2025-02-23 11:43:18 UTC
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2025-11-21 08:39:05 UTC
Total malware sites :14
Online malware sites :14 (100%)
Offline Malware sites :0 (0%)
Newest active malware site :2025-11-21 08:39:16 UTC
Oldest active malware site :2025-11-21 08:39:09 UTC (Age: 1 day, 5 hours, 39 minutes)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2025-11-21 08:39:09 213.209.143.33SBL675855AS214943 RAILNET- DEyes

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2025-11-21 08:39:16http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:16http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/run.shOnlinebotnetdomain mirai ext sh BlinkzSec
2025-11-21 08:39:14http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:11http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:11http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:09http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec
2025-11-21 08:39:09http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxn...Onlinebotnetdomain elf mirai ext BlinkzSec

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2025-11-22 05:47:162446b0241649dea2d9f6e002e8f16839c3f22ce33e81bb6c82041bb61fd3a049elfMirai
2025-11-22 05:33:18ae093903334c0a4e338ee2a1319df33a50061464d0fc9224e11495c79e56452eelfMirai
2025-11-22 05:13:099fe41548f51d3c8f0359562bd8230b3e5637f577ec0f3d314662e9985d0fcc6celfMirai
2025-11-22 05:11:23aae9860707ad578a69e391f7265eb07f3009d1a4f18f9359477555c908ddfd70elfMirai
2025-11-22 05:09:5635088515ba116a711346d0afe02cbf5f2b052e1b240bab08f2bc5218dc6fb4a2elfMirai
2025-11-22 04:57:160b52352c32334927fb7f040d63055d1dabba48ec55b7fe490fd5a94fe01a527eelfMirai
2025-11-22 04:55:4917f0330f89e0034caf2a3364212e3a4f76578e505e4f46ffdbebe252abcf9076elfMirai
2025-11-22 04:51:334e2a7d8ff0fd193a59efb1530c21b8280de20f2ae6580ccd9a376ee040b5e18belfMirai
2025-11-22 04:50:07d79f9d8be685be0f4ac96aed0909d00f09c4b7f07f559de447c974ef72cc4c9delfMirai
2025-11-22 04:41:5369762625d380fb3cb706cbdf559ff2a24077ba3cc2432d91c8ca665815f72883elfMirai
2025-11-22 04:23:137d1a64fce814f579fdeafa68a1f7b89412ee705456e2d2ed543e2ea2a51c49efelfMirai
2025-11-22 03:57:586dece824c88ec2ed11f8ac7c87938104e240a73e4231a95a0c5904f01303e307elfMirai
2025-11-22 03:57:02ff7b429989ec654e23096083a6a85ec5e6b6f44c5e293f3de2f96df1ada586b1elfMirai
2025-11-22 01:56:55bb11b15f115a5c833cc2c808fa74ef877707f23e3ecc42a23fd5917baf3590aaelfMirai
2025-11-21 08:39:164c83cc1dc10a3eb858d90b81a1ac0a196ec895c6c197709800e5f35884ec89e3elfMirai
2025-11-21 08:39:16f5a8ba6abd8eb44d12c1e262d6e4b9af14699b1be4cc3c2560ded39fb930e86celfMirai
2025-11-21 08:39:14cbe882628455e98b007d8c33ac513a3253ab876f1a2ae81403ce471fef0e0690elfMirai
2025-11-21 08:39:147e197774b6d07284f9ee3615da54c5932cd2e74cdd886684cdba6301c3f1f8eaelfMirai
2025-11-21 08:39:14fb1b595f89a787fe3a2ea67326e0a3f246f98edf659d65c44a1949aa7f69afb3elfMirai
2025-11-21 08:39:149f5fcd8c3657d152c37e6a591b61679e358bce2fa1243f1c76f345d1fe5f391felfMirai
2025-11-21 08:39:149bd176eb133076dea427fbc4ba6c2a856fc0e76b8d6ed8c021b15175232a89a8elfMirai
2025-11-21 08:39:1483b628a580c1fb473a0a55efb1dad03f6a81f1a5c1e0ae99f550a764fd9d9efeshMirai
2025-11-21 08:39:143940c974e3a4c6f4dc6ab3b152ee87a301cc44bf1091ccf6f942c05484031f84elfMirai
2025-11-21 08:39:135f0f39365f6409df14c648f42dca41142d9b296bbc5e6f8ef374636fdc1bd5edelfMirai
2025-11-21 08:39:11dda759e0254f8fe4943252fa5e73a66b729de0e018ff22a9e57e7f973fa9b967elfMirai
2025-11-21 08:39:1111b1b08e46d004bcd7d15ee07f0ec27e1c0712be5fa9e2c22a9148257b755740elfMirai
2025-11-21 08:39:09ebd0b6965def259a3ad014e5e04747ea861b7945f8dd0f49f679926fa419715delfMirai
2025-11-21 08:39:0927ca89f689d3c08c63c6dfb889629470edf2cbe1ab2f50762f6803da40b1fe41elfMirai