URLhaus Database

You are currently viewing the URLhaus database entry for http://89.213.174.225/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3623313
URL: http://89.213.174.225/hiddenbin/boatnet.arm
URL Status:Offline
Host: 89.213.174.225
Date added:2025-09-13 16:27:18 UTC
Last online:2025-09-27 22:XX:XX UTC
Threat:Malware download Malware download
Reporter: ClearlyNotB
Abuse complaint sent (?): Yes (2025-09-13 16:28:10 UTC to report{at}abuseradar[dot]com)
Takedown time:14 days, 6 hours, 3 minutes Bad (down since 2025-09-27 22:32:09 UTC)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-27boatnet.armelf 3d1c06ab7a63ea3ab6fe5f226e3e0c7faa7c6926000fb048fcd041fb1d5b14a7Virustotal results 45.90%Mirai
2025-09-17boatnet.armelf 6d4cfb7ad25f84ed67173858ddbbb9c7bd6b8c67adbb30a6e0a7240d10a5bb12Virustotal results 26.15%Mirai
2025-09-13boatnet.armelf 6c614f0fb137fafaa9284eaca4be2566d5acf71df8f7ab87046801da4ca97ebdn/aMirai