URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665461
URL: http://178.16.54.217/hiddenbin/boatnet.ppc
URL Status:flame Online (spreading malware for 3 months, 3 days, 18 hours, 19 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:18 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-09boatnet.ppcelf 2313a270cebf5b69ccc34a66cb02b78cb5b04ec984fc3a7c63be1076b806c861n/aMirai
2026-01-05boatnet.ppcelf 33566d7aeaf5b758da5349c19cef619f96ecd6c3d1e16d9d1994e2d6e50a98c0n/aMirai
2025-10-09boatnet.ppcelf e551533ff22deee76413079d663eda01b07c459609ff20df0ef107d667454e13n/aMirai