URLhaus Database

You are currently viewing the URLhaus database entry for http://87.248.130.35/hiddenbin/boatnet.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606339
URL: http://87.248.130.35/hiddenbin/boatnet.ppc
URL Status:Offline
Host: 87.248.130.35
Date added:2025-08-19 02:09:17 UTC
Last online:2025-08-31 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-08-19 02:10:11 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 18 hours, 11 minutes Bad (down since 2025-08-31 20:21:44 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28boatnet.ppcelf fff1297728f6e5c4d08c640cabff2461d7af035b9e7d17c955fcba6582aff8c2n/aMirai
2025-08-25boatnet.ppcelf 465607d175b9a5e205a257ae0f299696ce1cc96eed23fcf3f4cfa9dace736420n/aMirai
2025-08-25boatnet.ppcelf 9f3035c746ff5b7935ce860b49bf3ca4b55cf60c8611358b4ec0a456050e6df8n/aMirai
2025-08-21boatnet.ppcelf 9b867a4abc9e793ae31e22d7197e3bc22cf214fa0a778e664426f569a0feed93Virustotal results 28.12%Mirai
2025-08-21boatnet.ppcelf 720283dfa07ff4677887279605925b07ebcd582aa0493bfd3703084a26eaf7ffVirustotal results 27.42%Mirai
2025-08-21boatnet.ppcelf 4bed985d7c134155021b382daf690c2b0074fe03d99598f4c591a066da1a6003n/aMirai
2025-08-20boatnet.ppcelf 59ef0b8da2099b4226704903122cf6382d4e43e1e4c24e83aa084ae5e3240a84Virustotal results 31.25%Mirai
2025-08-19boatnet.ppcelf 185e09db22e6d66720392f9aca3423d35ea7bfd1398d43d03d4bf05ca4e48a4cVirustotal results 28.57%Mirai
2025-08-19boatnet.ppcelf 3010425e55ee9070246208ac2351632a68a456d51f2f34b57af1b2b4be867c26n/aMirai