URLhaus Database

You are currently viewing the URLhaus database entry for http://87.248.130.35/hiddenbin/boatnet.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606342
URL: http://87.248.130.35/hiddenbin/boatnet.arm5
URL Status:Offline
Host: 87.248.130.35
Date added:2025-08-19 02:09:17 UTC
Last online:2025-08-31 15:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-08-19 02:10:12 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 13 hours, 4 minutes Bad (down since 2025-08-31 15:14:14 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28n/aelf 2944417cc687828437b385ab784070a6ed78be9ff0351f0bb76252afd82f2d05Virustotal results 24.62%Mirai
2025-08-25n/aelf 3a06ae14188f140a44260b60b7c87bfe3a22014d12c9155db53d42dcda13d0ean/aMirai
2025-08-21n/aelf 923211296d7fbab4786ff2742d920b3ddea1ed56f54f02c340033de74fc6d573n/aMirai
2025-08-21n/aelf 566c8f4882bc8264d8f104f4f951b1bbe2a9a4087d9cc4f8df6f629f0fafca51n/aMirai
2025-08-20n/aelf 97593cef05ef18ea9ebbe2d9295c027caa49ac06fe642c2943df908a705e8ac2n/aMirai
2025-08-19n/aelf c205edcbe7e7c3293521cadd03d00a1d612be1d34cd66a22c6a4734d7178b580Virustotal results 25.00%Mirai
2025-08-19n/aelf 6ac92ad16c15457f5cf066bf8793d97a5ec0762f519d330a001f60ffad4a1e48n/aMirai