URLhaus Database

You are currently viewing the URLhaus database entry for http://xanax.enzostress.st/arm6 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3776895
URL: http://xanax.enzostress.st/arm6
URL Status:Offline
Host: xanax.enzostress.st
Date added:2026-02-13 08:32:18 UTC
Last online:2026-04-08 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2026-04-08 09:45:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 month, 28 days, 6 hours, 52 minutes Bad (down since 2026-04-12 15:25:50 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-12n/aelf d9cf616d3ee2e3876c290d87b32ee7ae84d0bdbaabaad7e2345e85a480e2004en/aMirai
2026-04-09n/aelf b6d839441c267eaf51204cbe1dd48d437e04730f73a22ab11c84a74bbbb8d22bn/aMirai
2026-04-05n/aelf 5f82cd6396f7b540336b955381981ffb04a5d4bb06b6a46b4f099ac5ff41ccccn/aMirai
2026-03-21n/aelf 545a59a819cabe72a1f8c1e72ff8969ee7f0f9b89032712fb3f610686452fcd4n/aMirai
2026-03-12n/aelf 2f7ab37cafd538adde724a335ea82da63a5a6b560714709e180ebf9d4a9911d4n/aMirai
2026-02-13n/aelf 0965d07e60fbd4832a86ea203bf972142b92c1bb61084272a8b8d870c3666d1bn/aMirai
2026-02-13n/aelf 505c7dad1f153d877d0eaf49c96fc5aea03000d3127fe927ffa4a1812f793186n/aMirai