URLhaus Database

You are currently viewing the URLhaus database entry for http://ntf.mohtash.ir/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606381
URL: http://ntf.mohtash.ir/hiddenbin/boatnet.sh4
URL Status:Offline
Host: ntf.mohtash.ir
Date added:2025-08-19 03:41:16 UTC
Last online:2025-08-31 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-19 03:42:11 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 16 hours, 19 minutes Bad (down since 2025-08-31 20:02:03 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28n/aelf 1ff919c6528e2e4531ffe74ac4cd35c9fbbd513cc38fb69bedf7ebb16f961b9bn/aMirai
2025-08-28n/aelf 110d19e9c27ec58f51fe9aa2f71d91eeb07eca50d51858d09a850ed210a5d2d0n/aMirai
2025-08-25n/aelf ace77db8aa98e2d72be06bdf7198156227ef9361b0eb503621119776b251805en/aMirai
2025-08-25n/aelf 6c28f4fbdaa7cce53393a8bd8d5f01055088a83395cd0e8798f1d816b145d8a6n/aMirai
2025-08-21n/aelf 36d3b3653880b431b00c1356d31efdd1201f7dd2754d00d0438da0dc95337b34Virustotal results 48.44%Mirai
2025-08-21n/aelf 2214f1235eed9aa823862ff8bf7e6f5882305551ef942df25d05c93e13d0f5d4Virustotal results 42.19%Mirai
2025-08-20n/aelf fccfb92f7f7237a09f4571f7ffe40e1e1fdbd2bcdec8c9b2bdc38ee386526f3eVirustotal results 43.75%Mirai
2025-08-19n/aelf 1033db20cce4931f1af808459ce614e926ed1f3e66ecf2505b79ab5de42d7f84Virustotal results 46.88%Mirai
2025-08-19n/aelf f02fe8c7cc3606fa06f9c148e486f218cdae02485f9a421587257e42e3634706Virustotal results 43.75%Mirai