URLhaus Database

You are currently viewing the URLhaus database entry for http://213.209.150.107/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3547865
URL: http://213.209.150.107/hiddenbin/boatnet.sh4
URL Status:Offline
Host: 213.209.150.107
Date added:2025-05-20 07:25:15 UTC
Last online:2025-09-02 01:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-05-20 07:26:08 UTC to abuse{at}virtualine[dot]org)
Takedown time:3 months, 14 days, 18 hours, 31 minutes Bad (down since 2025-09-02 01:58:02 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-21n/aelf 461fe3e1aced4836db038714958761d7dddd91b72aae4cf07c3519620b8e5337n/aMirai
2025-08-20n/aelf 0d7cec7cf889cf4a38f437c481f43d64e76125833f32d1ef454c013716499b36n/aMirai
2025-08-13n/aelf 703d408bd31e7671b2e4d59ea320def4e4d35d3f0acaaa95ff7ad91c66b4dacfVirustotal results 43.75%Mirai
2025-08-10n/aelf 455bf4364a0f3826a0ea637e241d379e3bf780db495cda8764a67a61cbe0ea06n/aMirai
2025-06-02n/aelf 504c2ff801b817abd8e6aba1ea9c00ef9fc796bd6dd6778035813a45cd584e94n/aMirai
2025-05-22n/aelf 2ec4c76f12651a31a9a9016c1a9bbf962cdeeb2ad06913c15e38d4990a789f0bVirustotal results 62.50%Mirai
2025-05-21n/aelf 091e8b298e19c1e019bdaa82d9ce9e85e7c041e4e8c715926312f0fd686ba79fn/aMirai
2025-05-21n/aelf 59e26630de8e1151ce737113adbd8d419f0f174da3163f169ff634afce0116d8n/aMirai
2025-05-20n/aelf 18f6d1982b74f277a9b3888ae98526e0636f2e7ca044599a9263a9e726e73ef8n/aMirai