URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.sh4 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665468
URL: http://178.16.54.217/hiddenbin/boatnet.sh4
URL Status:flame Online (spreading malware for 3 months, 4 days, 22 hours, 28 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:19 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-09n/aelf b1f5e98e63e81978965cd386c8870f22687d1acf246dfb5153bce47d2e097c4fn/aMirai
2026-01-05n/aelf 5fcc98be5d091f08595c2c18e942e40d8d95be7d5c62c494fc94b91d452ed794n/aMirai
2025-10-09n/aelf f6c8f91a80e11dc658b1d0965d0d20d058983f7ad1a034def61a6b930a0eb9b1n/aMirai