URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.217.111/hiddenbin/boatnet.arm7 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3616667
URL: http://5.42.217.111/hiddenbin/boatnet.arm7
URL Status:Offline
Host: 5.42.217.111
Date added:2025-09-03 15:57:18 UTC
Last online:2025-09-06 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: tolisec
Abuse complaint sent (?): Yes (2025-09-03 15:58:10 UTC to amir[dot]ixi{at}gmail[dot]com,tehrangaming7{at}gmail[dot]com)
Takedown time:3 days, 5 hours, 24 minutes Bad (down since 2025-09-06 21:22:59 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-06n/aelf b6e921e75a98000c695ef1b27afde44eca93ee222c64dca3190cf482382352f2n/aMirai
2025-09-06n/aelf 3a5a54f5964dc7dfce6fef6a92ecb30f7c52815ffb24f10885690bce7b939f87Virustotal results 37.50%Mirai
2025-09-05n/aelf 9b455af80d461d60260753e94cf943b0937cf44e6f34c28c9bbf87915f0c74d9Virustotal results 38.46%Mirai
2025-09-05n/aelf 78389e6f6571b5e06dbfdf82b14190ae7a37e62e61981f5cb0e4234c7c9829e1Virustotal results 39.06%Mirai
2025-09-04n/aelf 45a0e5de3cc2134b7cef97b74cb96fad7f045dbe364d5041b85531acec5f4279n/aMirai
2025-09-03n/aelf 855ac14545d65a55f7340d2d69342f6d34798ce124961932215af9698c763eaen/aMirai