URLhaus Database

You are currently viewing the URLhaus database entry for http://cbot.galaxias.cc/hiddenbin/vision.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3506589
URL: http://cbot.galaxias.cc/hiddenbin/vision.mpsl
URL Status:Offline
Host: cbot.galaxias.cc
Date added:2025-04-10 12:00:05 UTC
Last online:2025-04-21 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Malware domain
SURBL :Blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: DaveLikesMalwre
Abuse complaint sent (?): Yes (2025-04-10 12:01:05 UTC to abuse{at}dolphinhost[dot]net)
Takedown time:10 days, 23 hours, 17 minutes Bad (down since 2025-04-21 11:18:44 UTC)
Tags:botnetdomain elf mirai link opendir

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-21vision.mpslelf 43c386a583b38d4418ee3d577e71369449598996d9d8674d1a1025a8afb29082n/aMirai
2025-04-20vision.mpslelf 385f8464f73d523616317bbcd6d81cc5399a54e8eb89bdc4e66d54e84179d549n/aMirai
2025-04-19vision.mpslelf 8f05cac88bbed3f74b7b737ffad871ed311354bfbdac84e60106dd1d46175353n/aMirai
2025-04-19vision.mpslelf f33702f333a48119c51ccc85549b6c5ffaabeda4bafaeef8456fcdbfa6cc9d12Virustotal results 46.77%Mirai
2025-04-13vision.mpslelf 8de978143c502b64117876e24e59a335c9cd24163540b85e161e70e36ee05f8bn/aMirai
2025-04-12vision.mpslelf a69cc20b2f56fc7e41214705cad7bf9ad880e9119149289d1225967c16deed73n/aMirai
2025-04-11vision.mpslelf a2f23b19392f5e5082222ec1af419aa1c221b8a2026dfb0abd756c35bb6ba535Virustotal results 42.86%Mirai
2025-04-10vision.mpslelf 7eb704742275a2fbd50c2ee0959359b09e51088be98a776b5e99119fedcd47d3n/aMirai