URLhaus Database

You are currently viewing the URLhaus database entry for http://xanax.enzostress.st/arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3776891
URL: http://xanax.enzostress.st/arm7
URL Status:flame Online (spreading malware for 1 month, 10 days, 6 hours, 40 minutes)
Host: xanax.enzostress.st
Date added:2026-02-13 08:32:06 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-03-25 02:53:10 UTC to support{at}62yun[dot]com)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-25n/aelf 8f2ba1e2c1af27d3b3324bc609cd21a625d6b0c1f9bbd36cad21bfe449445467n/aMirai
2026-03-25n/aelf af80de855fcf969408463e4901fca5ea60b40c633e967e1b47346672d374cdf7n/aMirai
2026-03-24n/aelf aa706e29c04a68054fe8dad260fa432ff05612552ce4ff4a618ee7dbe4a892bdn/aMirai
2026-03-21n/aelf d80bd720ee3c2e7d9ebb188b6c8749df8276a18677b32627c93b5f2375bba439n/aMirai
2026-03-12n/aelf 098c779e2c36a3b50d94aa1d0167a6e301cb1ce258733127f13d880f9347e40dn/aMirai
2026-02-14n/aelf 9ecfa8723d042c9d4f60991e2b337cea5757fa5f39c729c5744123ea1da0c6c8n/aMirai
2026-02-13n/aelf 39826aaef71a256b7f220273335c9c36ca7382023f110045b718f98107987f91n/aMirai