URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665468
URL: http://178.16.54.217/hiddenbin/boatnet.sh4
URL Status:Offline
Host: 178.16.54.217
Date added:2025-10-09 03:05:19 UTC
Last online:2026-03-03 19:XX:XX UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Takedown time:4 months, 25 days, 16 hours, 40 minutes Bad (down since 2026-03-03 19:46:20 UTC)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-02-11n/aelf 6087de4c25529b98f2839803654d6a259e8118eb1d3db0f2d94dbb584110a655n/aMirai
2026-01-29n/aelf a558be3a0df83912d5dd1141e0ce04c4bc6a3ab6c2c1b80b302fab0316ddd811n/aMirai
2026-01-29n/aelf dd898f1cc12fc80dcdd5a91e10023a4b67be38cb1824016a65f534ced8e1ae45n/aMirai
2026-01-28n/aelf e6c447a89a4f91a32aadc22adbb8f4c21d2efe196165071eab5b9f9c7ec75e23n/aMirai
2026-01-25n/aelf 40a6b12ec3aa4583c2f18735fcd6b70bcda02124fcd435c92784c58e62c416f1n/aMirai
2026-01-16n/aelf 0a5c891a9dbf9bcbb7bd83ca0c3baa39fe01f2e90e7c305a8e4f4b9b45fde01bn/aMirai
2026-01-09n/aelf b1f5e98e63e81978965cd386c8870f22687d1acf246dfb5153bce47d2e097c4fn/aMirai
2026-01-05n/aelf 5fcc98be5d091f08595c2c18e942e40d8d95be7d5c62c494fc94b91d452ed794n/aMirai
2025-10-09n/aelf f6c8f91a80e11dc658b1d0965d0d20d058983f7ad1a034def61a6b930a0eb9b1n/aMirai