URLhaus Database

You are currently viewing the URLhaus database entry for http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxnxni386xnxn which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3713410
URL: http://efjgerws.galaxias.cc/bins/xnxnxnxnxnxnxnxni386xnxn
URL Status:flame Online (spreading malware for 1 month, 3 days, 18 hours, 21 minutes)
Host: efjgerws.galaxias.cc
Date added:2025-11-21 08:39:14 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-12-22 05:23:17 UTC to abuse{at}virtualine[dot]org)
Tags:botnetdomain elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-12-24n/aelf 7a24c9415c56dcfce560e4e1d5f12dbba79da2478bd6c8e9ae2ddaa8782a65bdn/aMirai
2025-12-23n/aelf fa3aca53a9ce6132422aea7163f99c1df8afbe576d1cd4391f0350a983686064n/aMirai
2025-12-22n/aelf ccdbacff8e06c494edb527baa8f68a1b8d35fc4d60654b975470274b9d0e4356n/aMirai
2025-12-07n/aelf 3f3a91a529ef479b954273a9f12e2e3414340661d744fb84ab644c1c9233a941n/a
2025-12-07n/aelf fe27efe3d15f5fff6be2c631f122f4af95416e093ffec1fae5e81f1a7dc72b6fn/aMirai
2025-12-02n/aelf c46a7e01e2c40e63ad9e2ed2bccfd00f3035b1c1cb435b00a06db3502c27d456n/aMirai
2025-12-01n/aelf 3e758d8e3e456fb3cd439f89a180923eb69fb0b5bd470cbf4ba789ad318d2455Virustotal results 10.77%Mirai
2025-11-25n/aelf 93bc5a79c16adf7e784608f36172912df2b29712c2b0da58fcd062d7a3395a7cVirustotal results 6.15%Mirai
2025-11-23n/aelf 378e534d26dc62c14a99f04b01961ad0f1499ca594fd6d5208e0281b52e638b6Virustotal results 7.94%Mirai
2025-11-22n/aelf c4a45457e8ea3fec65cd81aa08cec971db088d86f0c5e0e3ab444894096cc51dn/aMirai
2025-11-22n/aelf 69762625d380fb3cb706cbdf559ff2a24077ba3cc2432d91c8ca665815f72883n/aMirai
2025-11-21n/aelf cbe882628455e98b007d8c33ac513a3253ab876f1a2ae81403ce471fef0e0690n/aMirai