URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.arm5 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665460
URL: http://178.16.54.217/hiddenbin/boatnet.arm5
URL Status:flame Online (spreading malware for 3 months, 28 days, 22 hours, 21 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:18 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-29n/aelf 8fdcb319f873ec694db9b2f0572e6757e0c89c16927e9911cffa82e7ea5e1098n/aMirai
2026-01-28n/aelf f3616b5ccb6459270ba9e7cfaec30c78b6d44e491d0f40bcc2f532ed7eb8036cn/aMirai
2026-01-28n/aelf 81cfe7a09c71db0776f0baba68bc38e9ad9bc079e3805f15a57ee4a8faaea77an/aMirai
2026-01-25n/aelf f47d6817b277324bc258b4172a7ccdf3e6b1bfa96f1e3d12a21f24236d3a6317n/aMirai
2026-01-16n/aelf 0f9155007cf7b474fe78b97f52ec345e6a905317c790160600e166322abcb837n/aMirai
2026-01-09n/aelf 9b6dca6a5be10dd548440b7191edcb9a74b68da57906a7a7e0275fefdc4afa51n/aMirai
2026-01-05n/aelf e46b8e6a993dd1f43ba02df79de7b9d73432135013e8d3d1d193fb80f382eeadn/aMirai
2025-10-09n/aelf a0d9306874a59f4be636ee579b3151191d753ce330b474808c31869b6315f47cn/aMirai