URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.ppc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665461
URL: http://178.16.54.217/hiddenbin/boatnet.ppc
URL Status:flame Online (spreading malware for 3 months, 26 days, 6 hours, 47 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:18 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-29boatnet.ppcelf 5ebdff2c8e8f34bd81dcc1ba4592a34c8c0291de8841169ab337b9c14c9b3229n/aMirai
2026-01-28boatnet.ppcelf 291725b2b9e8f68adafd42f2065106657c370e690c4cd9129856973c072a9d5an/aMirai
2026-01-28boatnet.ppcelf c4fe739308f310665bdefd49ffe713a48637476678c227ae52e3876366901aebn/aMirai
2026-01-25boatnet.ppcelf c881ba300eca39dc43ef7989e76871519e67848b6a6ef01ae3d5824b5a3af345n/aMirai
2026-01-16boatnet.ppcelf 3a998b5ab4bd90684002298bc52db65ffbc42d79f163b511f05728c1e0d2de80n/aMirai
2026-01-09boatnet.ppcelf 2313a270cebf5b69ccc34a66cb02b78cb5b04ec984fc3a7c63be1076b806c861n/aMirai
2026-01-05boatnet.ppcelf 33566d7aeaf5b758da5349c19cef619f96ecd6c3d1e16d9d1994e2d6e50a98c0n/aMirai
2025-10-09boatnet.ppcelf e551533ff22deee76413079d663eda01b07c459609ff20df0ef107d667454e13n/aMirai