URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.217.111/hiddenbin/boatnet.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3616666
URL: http://5.42.217.111/hiddenbin/boatnet.ppc
URL Status:Offline
Host: 5.42.217.111
Date added:2025-09-03 15:57:18 UTC
Last online:2025-09-07 02:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-09-03 15:58:10 UTC to amir[dot]ixi{at}gmail[dot]com,tehrangaming7{at}gmail[dot]com)
Takedown time:3 days, 10 hours, 26 minutes Bad (down since 2025-09-07 02:25:04 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-06boatnet.ppcelf e026c9cf3c1e3c70acf43a6c85946dc3ecbdf4aeb10c74fe3aa2812da54b0fb8n/aMirai
2025-09-05boatnet.ppcelf 2191f41a7620787b7252f935ded6ac1ecfc5e544e9fbcbab34f5a1e929b65083n/aMirai
2025-09-04boatnet.ppcelf 08312eabdc7feb0609d1de774f8d77274361d48d782c75220cd8e5df4c8ca5a7Virustotal results 29.69%Mirai
2025-09-04boatnet.ppcelf 62e8a9a14a203fc2eb2e01f536d13ce82e7c044c593a95520a3424b143cd2d47n/aMirai
2025-09-03boatnet.ppcelf c286e3eb01f981b60e15131c9b7f94d59d2435ab3096a3f669f3f7ec0a52058dn/aMirai