URLhaus Database

You are currently viewing the URLhaus database entry for http://87.248.130.35/hiddenbin/boatnet.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606282
URL: http://87.248.130.35/hiddenbin/boatnet.arm7
URL Status:Offline
Host: 87.248.130.35
Date added:2025-08-18 21:02:08 UTC
Last online:2025-08-31 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-08-18 21:03:14 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 23 hours, 55 minutes Bad (down since 2025-08-31 20:59:11 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28n/aelf b50cb401830afeb0ababa44c7a4fd6ec8750e201390ab2552b1c94418d40af06Virustotal results 26.15%Mirai
2025-08-25n/aelf 4077839542b50c859f4b48e97d81a37e6115dbe6b4877c2cbd97c0ed45278357n/aMirai
2025-08-25n/aelf 60b5e41c5c6cf7a626e88c414ce1ff9e1f1d3ad25598cf17bb03d427491459d5n/aMirai
2025-08-21n/aelf 1ccc3f7af62ab2bb96aceaba602dadafd3d17f4804e1aefa1d741a3530e34dc3Virustotal results 37.50%Mirai
2025-08-21n/aelf 5108d78ffd2c1bcb6e74cfc12f77a0d87644195f5264d24956ad49be0ffdbcb5n/aMirai
2025-08-20n/aelf 06af5011038ac1d5a9211510a799fa9973bcd7f1204e6a89dbc9b98a0f9fc674Virustotal results 38.71%Mirai
2025-08-19n/aelf df3a9df59b2a6c34353370519fbbf88c5d2e018eabe415fdba323e3a87e48b5bVirustotal results 35.94%Mirai
2025-08-18n/aelf 084de1791f5be2b221c277d9f0260b897ffc550e98408f420dba5d388362db25n/aMirai