URLhaus Database

You are currently viewing the URLhaus database entry for http://ggg.galaxias.cc/xnxnxnxnxnxnxnxnm68kxnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3633636
URL: http://ggg.galaxias.cc/xnxnxnxnxnxnxnxnm68kxnxn
URL Status:Offline
Host: ggg.galaxias.cc
Date added:2025-09-28 08:25:19 UTC
Last online:2025-10-02 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-09-28 08:26:09 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:4 days, 1 hours, 9 minutes Bad (down since 2025-10-02 09:35:45 UTC)
Tags:botnetdomain elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-02n/aelf c90b8fe9afffc64e13cbbda5a32b6136589b82f63636a89d014c7e3dd3aa000fn/aMirai
2025-10-02n/aelf ae6ded977d976475a5916dfef659a57fc8561ff1ba730e2394780e1dd0120ff4n/aMirai
2025-10-01n/aelf b8f896d58daa6692ab0d5f30d65cbf97417fe85cd15325a043da27f41d36cb38n/aMirai
2025-10-01n/aelf d77e0b05811445847387dfe3e1da2ea663cdb51c7f8f0dd87cc2849042d6cdf0n/aMirai
2025-09-28n/aelf f52289b7430d335d6d29693d3c683ab887fc4a1f827c8fd640e9041603e17ea6n/aMirai
2025-09-28n/aelf 1241b8623fd0f956f861271908fcada71ee02450c73fff913edc55efa51a7badVirustotal results 35.94%Mirai