URLhaus Database

You are currently viewing the URLhaus database entry for http://89.32.41.64/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3632975
URL: http://89.32.41.64/hiddenbin/boatnet.sh4
URL Status:Offline
Host: 89.32.41.64
Date added:2025-09-27 09:01:12 UTC
Last online:2025-10-01 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-27 09:02:12 UTC to abuse{at}hostmaze[dot]com)
Takedown time:4 days, 7 hours, 33 minutes Bad (down since 2025-10-01 16:35:14 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-30n/aelf 3ff5ab76461f67f90d3aeddc7463757740b737ce4f2f94299468639335106a7fn/aMirai
2025-09-30n/aelf 59e03a16c762b1dbaba33cf0fb62b7ee00e94e84937e857849e315909b7477f8Virustotal results 60.94%Mirai
2025-09-29n/aelf a94de8c80ad4c38a2a2565b7482177b920c3b40c7cf11bc2b620f66da39b7df2n/aMirai
2025-09-28n/aelf 1365ae4579f67e462833501f51695b50a5f2de923513ca72bf13dcc9dbaf900cn/aMirai
2025-09-27n/aelf d0904c3426a1176ad40e6dbb106fcc81950b88d90d487f7ad8aca9b4999577e0n/aMirai
2025-09-27n/aelf 12e371fe45f80b85650734bcc7142422991c7c657b43cf3ccb571d2cfcbe6cf8n/aMirai
2025-09-27n/aelf 5062c0ff35ac6cef5e32fabc18f97cdc165e28d24a719706e066ab5464c0a517n/aMirai