URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.217.111/hiddenbin/boatnet.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3616664
URL: http://5.42.217.111/hiddenbin/boatnet.arm5
URL Status:Offline
Host: 5.42.217.111
Date added:2025-09-03 15:56:19 UTC
Last online:2025-09-06 20:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-09-03 15:57:10 UTC to amir[dot]ixi{at}gmail[dot]com,tehrangaming7{at}gmail[dot]com)
Takedown time:3 days, 4 hours, 25 minutes Bad (down since 2025-09-06 20:22:18 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-06n/aelf 9a12f0a82b0412f6ee904b1d7c791e2e198b8ec004cd1886da5f0e6a67611e9fn/aMirai
2025-09-06n/aelf 3933dbb5a7728d8470cd875b61c4f51235a26da27017fa0827ce6eb3c425ed89n/aMirai
2025-09-05n/aelf 0a05cc80e7da08d370a65354970bf1f340c910b34acc0384ebecb13bedfbc1ccn/aMirai
2025-09-04n/aelf 3cc805564cd852625e773fdaab709a2c428de37142e547d142ed7f65b638b3f1n/aMirai
2025-09-04n/aelf 8327602eee31dca3687a299991a09d2ca2080e0ac99fb17b18c3c437ccb84280n/aMirai
2025-09-03n/aelf 0ac2df2704e5127accd26d293c1a0cd85a7c7a47028c60a48bdc352b46fdc338n/aMirai