URLhaus Database

You are currently viewing the URLhaus database entry for http://89.32.41.64/hiddenbin/boatnet.mpsl which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3632984
URL: http://89.32.41.64/hiddenbin/boatnet.mpsl
URL Status:Offline
Host: 89.32.41.64
Date added:2025-09-27 09:01:12 UTC
Last online:2025-10-01 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-27 09:02:12 UTC to abuse{at}hostmaze[dot]com)
Takedown time:4 days, 8 hours, 3 minutes Bad (down since 2025-10-01 17:05:40 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-30boatnet.mpslelf 966645cdcb838f93a637269ce794aa5375b3bc75c54c0068590ffd7ba8552b62Virustotal results 43.75%Mirai
2025-09-30boatnet.mpslelf a93cb4fd1229e48fb1873d1e3a4fa0f38a402600d547912065e0621bdcf5be7aVirustotal results 50.00%Mirai
2025-09-29boatnet.mpslelf feed21c51cca5d060007e9832d83b1ba78717e286b54fd21b6ee84894891bc38n/aMirai
2025-09-29boatnet.mpslelf 4de73433a4c367f5a50d8b0b0fc3e4bd89d36da18ef67b1d03d9aeba651bf49dn/aMirai
2025-09-28boatnet.mpslelf c1d252015cf9ccc262ec8e7c8acfacd109d7988f16eb84736ab2133e34669618n/aMirai
2025-09-28boatnet.mpslelf e5c3b7d5e00c7ec6897c535ecac273aaf6fd85b7df42954a43618a84f31ac4f2n/aMirai
2025-09-27boatnet.mpslelf dc5a4e709f84de9ac97812bc1a57a5ee7d9c95b144c0261259281727a7e3677bn/aMirai
2025-09-27boatnet.mpslelf 1ee239dc736dbec123c70a8109777103b7cec9304676a837840ee77eb3a6948cn/aMirai