URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665469
URL: http://178.16.54.217/hiddenbin/boatnet.x86
URL Status:flame Online (spreading malware for 3 months, 5 days, 19 hours, 26 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:21 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-09n/aelf ee464b46f46ba9a46a7c761e4a8d9bd598b1e941a09e942205496a98413c708fn/aMirai
2026-01-05n/aelf 02450f777d3863514d5071346144297728426c794a085d9c6e1f603f83985848n/aMirai
2025-10-09n/aelf 575f49ab7f9a1c63f78edbdb1275737cff37d5d03488a8b825627206c7e2a04bn/aMirai