URLhaus Database

You are currently viewing the URLhaus database entry for http://31.25.11.228/hiddenbin/boatnet.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3611834
URL: http://31.25.11.228/hiddenbin/boatnet.arm5
URL Status:Offline
Host: 31.25.11.228
Date added:2025-08-26 09:34:16 UTC
Last online:2025-08-30 03:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-08-26 09:35:15 UTC to abuse{at}reiber[dot]eu)
Takedown time:3 days, 17 hours, 29 minutes Bad (down since 2025-08-30 03:04:37 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-29n/aelf afe44854a17bfbd33bd893f062a7b6720953824e29f6c5e51b75747cf972385fn/aMirai
2025-08-29n/aelf d8c5a08c27f3bc8912ef94456f00e6f259b2b314ab860b450519c7073fb0365cn/aMirai
2025-08-27n/aelf 7a6dfd4c286a5f48637b69315e70c9c5e6de51a4026fb4a2b1a7e7668c0e6213n/aMirai
2025-08-26n/aelf badc68b88808025c2877f1832ae6974af7172348c4b86666afc316117e1a9f3dn/aMirai
2025-08-26n/aelf 04f4fce7683829fa86455cae24f9f61cd87ab2019ee48dcaa57de5c2fdc318b5n/aMirai