URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.217.111/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3616840
URL: http://5.42.217.111/hiddenbin/boatnet.arm
URL Status:Offline
Host: 5.42.217.111
Date added:2025-09-03 21:01:26 UTC
Last online:2025-09-06 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-03 21:02:14 UTC to amir[dot]ixi{at}gmail[dot]com,tehrangaming7{at}gmail[dot]com)
Takedown time:3 days, 0 hours, 12 minutes Bad (down since 2025-09-06 21:14:57 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-06boatnet.armelf 3507c48a7bbe1553222c9d5782376aa2db6aa2b35921106f989fb9b2bdd2476bn/aMirai
2025-09-06boatnet.armelf 90ca7d8622246fb4bb9c111864e108304dafa4d5d082042d1b4cb94398fc81c8n/aMirai
2025-09-05boatnet.armelf 2fa32907ca3ee9c951fd3bb48b639dceecd8bc7cf46874aad7d1239bad01bb9en/aMirai
2025-09-04boatnet.armelf cf1b4206239014c5b03201f5cd97c27a6b20baf267f8c12a8be7e97eb6514c69n/aMirai
2025-09-04boatnet.armelf 9a543c708a256db6c2cda1e1a4308b5697420c5d2ae64075e2b7cfb3e0d605d0n/aMirai
2025-09-03boatnet.armelf c602fbda629961b9fbd1d4ab121650d6d5ee837dd1fb0ce1d699c1c7cacc280cVirustotal results 26.15%Mirai