URLhaus Database

You are currently viewing the URLhaus database entry for http://5.42.217.111/hiddenbin/boatnet.arc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3616889
URL: http://5.42.217.111/hiddenbin/boatnet.arc
URL Status:Offline
Host: 5.42.217.111
Date added:2025-09-04 00:57:16 UTC
Last online:2025-09-06 21:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-09-04 00:58:16 UTC to amir[dot]ixi{at}gmail[dot]com,tehrangaming7{at}gmail[dot]com)
Takedown time:2 days, 20 hours, 41 minutes Poor (down since 2025-09-06 21:39:32 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-06boatnet.arcelf 7d9378136afc95055aa5b8a42dc9e4e2f0578f6545202b4e9a6529ef8956b01fn/aMirai
2025-09-06boatnet.arcelf 51cc1a3de34bf00c345607ca6e699d629efe5e996fbb4856a0fd10fc59a9e3f6n/aMirai
2025-09-05boatnet.arcelf e86ac18f7e339a2ef607a3123c4db2e4a4a8259990ba27e14210a8b0834ddcebn/aMirai
2025-09-04boatnet.arcelf 9f09a1fac7a028af8255a299ce103dfa0c4b94fc4458f0587bf14736baa65134n/aMirai
2025-09-04boatnet.arcelf bc664992a2cb27fe49620206516834a8d570f71e17a08ce80fb3eaa6c52acb65n/aMirai
2025-09-04boatnet.arcelf dd9e67fc4090b7af2ae256e4190546246f4c5c417a31ce05191e0813f141a68en/aMirai