URLhaus Database

You are currently viewing the URLhaus database entry for http://87.248.130.35/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606273
URL: http://87.248.130.35/hiddenbin/boatnet.arm
URL Status:Offline
Host: 87.248.130.35
Date added:2025-08-18 21:01:08 UTC
Last online:2025-08-31 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-08-18 21:02:13 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 23 hours, 12 minutes Bad (down since 2025-08-31 20:14:40 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28boatnet.armelf f5e000f5fbf47ca4af50578c9f7faa043cd26f387e265f76043a52e034a2648en/aMirai
2025-08-25boatnet.armelf 8301e36a9759efa36d81468e9e533def9b271c5a0a0371f87776d9006778f207n/aMirai
2025-08-25boatnet.armelf 2292bd3bb9dc1cae09c82552a0ec0f15359fb5c7ec1e21958070e3b78dac2a95Virustotal results 21.15%Mirai
2025-08-21boatnet.armelf ec419edc8a350e19c64ef17ab65b9d00d8262fa969e5dd1ab9fa915d6c8f6d26Virustotal results 28.12%Mirai
2025-08-21boatnet.armelf 78ef129e4dd9a7990ee896d23d696566322e70ea81ffb315bfffd0184ce176f6n/aMirai
2025-08-20boatnet.armelf 980a6e9e4b20ae09a971908057b12347b474600d1109b67ff3d283509e163e87n/aMirai
2025-08-19boatnet.armelf b34be18a3f0aa24ba85f0d596e8b0dc5591b54d284062f6c858a9691ef9ddfb1Virustotal results 19.61%Mirai
2025-08-18boatnet.armelf 77033f13820fb6da8c73e461c20b79e6c8fe9595ed495e7008f4a0a9962005c0n/aMirai