URLhaus Database

You are currently viewing the URLhaus database entry for http://89.32.41.64/hiddenbin/boatnet.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3632990
URL: http://89.32.41.64/hiddenbin/boatnet.arm5
URL Status:Offline
Host: 89.32.41.64
Date added:2025-09-27 09:02:11 UTC
Last online:2025-10-01 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: threatquery
Abuse complaint sent (?): Yes (2025-09-27 09:03:11 UTC to abuse{at}hostmaze[dot]com)
Takedown time:4 days, 8 hours, 7 minutes Bad (down since 2025-10-01 17:10:27 UTC)
Tags:32-bit elf mirai link Mozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-09-30n/aelf 904ebd2ac0980029659bb582fb5757a111af3f9f9cf4a8b3cd63a1ce45b261f3Virustotal results 26.56%Mirai
2025-09-30n/aelf 048123f575bf2f11430a775f26f9f804ad3c2dddb4cc0231d0a00670dacbcef5n/aMirai
2025-09-29n/aelf 271fd9b275194e0891a0250165e1f10f810291018ac023797b5de5297d18f4acn/aMirai
2025-09-28n/aelf e787962008315da3acef405f3ac379213567c762bbffabf019b784f53ae56bc5n/aMirai
2025-09-27n/aelf 24276cf4710a12c290d17a779e083794549b6c2983c7b533a27904d9725b2531n/aMirai
2025-09-27n/aelf edfe5fd38781cdbf4814936e0ef17b46de270f5f3c4528af8664203b0121818en/aMirai