URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665466
URL: http://178.16.54.217/hiddenbin/boatnet.m68k
URL Status:flame Online (spreading malware for 3 months, 4 days, 22 hours, 28 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:19 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-09n/aelf 0b2ad1055b4e7805b44fef67931a2b3b61bb906bb743ae3a7278ef9a9111c993n/aMirai
2026-01-05n/aelf ea676e5a3227511581b89f3b8c406ff6a210451ae221fa3aad1f4ad5961c6a9an/aMirai
2025-10-09n/aelf 6e6def17c343d05e2b8975d44202c5811cb653830b524c2af9271fe80de80021n/aMirai