URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.m68k which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665466
URL: http://178.16.54.217/hiddenbin/boatnet.m68k
URL Status:flame Online (spreading malware for 4 months, 5 days, 16 hours, 48 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:19 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-11n/aelf 5547e4f1a0d15e432b8e2e3c021956cc84b771a1ca97a4961d2c4f45111ea1c8n/aMirai
2026-01-29n/aelf d16177f483bec8cb7f85f47291fc29d3d8670dd836049ef19d4bdc202d7ef5c6n/aMirai
2026-01-28n/aelf 685c3e9b12662ff9d10a581a40a9c8d4b2d8d4e7b5d88efea6873518599dd0b6n/aMirai
2026-01-28n/aelf 45e8f91daa2633c959445a8c2f54d0b11ab738917ec782720c7369cb1241e54cn/aMirai
2026-01-26n/aelf def6275287fa4d9e8c9ad6c1a7e41c8de4c1b4693628fb27a90fc532a3cd2087n/aMirai
2026-01-16n/aelf 4634c836afdef0eee3750b684cece9a5e8c0bab8aa05795bdd163210c28f8aa4n/aMirai
2026-01-09n/aelf 0b2ad1055b4e7805b44fef67931a2b3b61bb906bb743ae3a7278ef9a9111c993n/aMirai
2026-01-05n/aelf ea676e5a3227511581b89f3b8c406ff6a210451ae221fa3aad1f4ad5961c6a9an/aMirai
2025-10-09n/aelf 6e6def17c343d05e2b8975d44202c5811cb653830b524c2af9271fe80de80021n/aMirai