URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.52.103/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3615410
URL: http://178.16.52.103/hiddenbin/boatnet.arm
URL Status:Offline
Host: 178.16.52.103
Date added:2025-09-02 02:45:26 UTC
Last online:2025-10-03 09:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-09-02 02:46:11 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Takedown time:1 month, 1 days, 6 hours, 29 minutes Bad (down since 2025-10-03 09:15:18 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-09boatnet.armelf a546b013a6bca7bbefcc52a37825a4b36184597b3d9d926b14a0c0bb21af17a7n/aMirai
2025-09-06boatnet.armelf 8da72671a84cda3829ca004ea561de6e2e9eb15a4e6bf4dee4d1e67222c57925n/aMirai
2025-09-05boatnet.armelf 8236c9d9b2b45b7a3fd669bb6316d9f91d1e06acb51c1755467025f13f0bc60dVirustotal results 27.69%Mirai
2025-09-02boatnet.armelf f51aa690bd8a55db984f70993895b22a02e64bc220f41901528224a8bb35ebb3Virustotal results 28.12%Mirai