URLhaus Database

You are currently viewing the URLhaus database entry for http://31.25.11.228/hiddenbin/boatnet.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3611833
URL: http://31.25.11.228/hiddenbin/boatnet.ppc
URL Status:Offline
Host: 31.25.11.228
Date added:2025-08-26 09:34:14 UTC
Last online:2025-08-29 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-08-26 09:35:15 UTC to abuse{at}reiber[dot]eu)
Takedown time:3 days, 10 hours, 28 minutes Bad (down since 2025-08-29 20:03:16 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-29boatnet.ppcelf 03d3f7df8c9bc6a9e64f80eff7b61ab7a1866aa4db07d642f516c8391aa29897Virustotal results 35.38%Mirai
2025-08-29boatnet.ppcelf 6857291c92c0db61525974d7efec198d9702ba67512f44a5e7ac58364c42dcfan/aMirai
2025-08-27boatnet.ppcelf d1e83f90009db3d13ebd67d1c2781551d33b523bf861e8ed8a81f3f0d222bfa4Virustotal results 35.38%Mirai
2025-08-26boatnet.ppcelf cd0aa8777db246195df1debd93df60b1c4385021af16d75d1d3c2c7349d12d7en/aMirai
2025-08-26boatnet.ppcelf c4e520d63ab6c9c63de9998f176bee32018fa57634437074580d0a760acbe177n/aMirai