URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665463
URL: http://178.16.54.217/hiddenbin/boatnet.arm
URL Status:flame Online (spreading malware for 4 months, 5 days, 15 hours, 9 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:19 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-11boatnet.armelf f908e53503421a884e965983ab056ea40557ad21039d0f8a3c64a73db19cd2d7n/aMirai
2026-01-29boatnet.armelf f782bb03e6f02f16ac28fa996bc39cbbc0f3ca03b7fc9d744b3393775fe92115n/aMirai
2026-01-28boatnet.armelf e368bd223868997613b2ba853fe28aab85eaf1033e42e689c3ce506ccd044293n/aMirai
2026-01-28boatnet.armelf 588344923e23bb4b0e4f7ae929eb29e7cbd01b4a03a50dfa0c23fc416569c8d4n/aMirai
2026-01-26boatnet.armelf 8afc3dffd596e3278b15d948087112539b31cbf846e985f4cf82a72b24cde0fen/aMirai
2026-01-16boatnet.armelf 912902fca7a5202b31e6899162a7231faa58eca49f15510bc1a7676c0d99fdb2n/aMirai
2026-01-09boatnet.armelf e139e43d30c84b84378965d71227d0618e551b3be40dc2264101d44bb3d7579bn/aMirai
2026-01-05boatnet.armelf 0fd803aeed16e2e4c752da443e9a69aa56664b21f8e4c95a16dd55bd9b5b0757n/aMirai
2025-10-09boatnet.armelf 050b4490f5b8523238acb52120dca20c1d7bd8260e5ac856671c6e7fbd6c88f5n/aMirai