URLhaus Database

You are currently viewing the URLhaus database entry for http://ntf.mohtash.ir/hiddenbin/boatnet.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3606385
URL: http://ntf.mohtash.ir/hiddenbin/boatnet.m68k
URL Status:Offline
Host: ntf.mohtash.ir
Date added:2025-08-19 03:41:19 UTC
Last online:2025-08-31 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-19 03:42:11 UTC to abuse-208161{at}tana[dot]ir)
Takedown time:12 days, 17 hours, 8 minutes Bad (down since 2025-08-31 20:50:50 UTC)
Tags:botnetdomain elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-28n/aelf 614da65bb9290e16302332692a6f7a0e722f1081ef2f8379d438addab8587fe5n/aMirai
2025-08-25n/aelf db2181117644d92b9d38c775456fde7143075c579a033e02bf1dd1c934d1db3an/aMirai
2025-08-25n/aelf 6cfde4500c1a9b2fd25bbcd6779f89a8628f1be957bdb72a863ecded61e2d335n/aMirai
2025-08-21n/aelf 06c0060883623dd6e497c3edbca1ac364fd800f1a4c9a57172656c1cc95b518dn/aMirai
2025-08-21n/aelf eb636d80a44f3cfeb38dbeb51d6848c8c96b4b1a9296be5b6b275084bf1c3a76Virustotal results 37.50%Mirai
2025-08-20n/aelf d7249d19695d2d26a5eb135043e3c72aab9d742fe8de07cf8bf1369632606944n/aMirai
2025-08-19n/aelf c35011dbc832680e1dc0283467c27339124d9e7a53938216ee6e72551cb087bbVirustotal results 40.62%Mirai
2025-08-19n/aelf 3839908590e99449b36f645bff46f45409a5bf87785d1f79a016ff71fb1352cbVirustotal results 42.19%Mirai