URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.54.217/hiddenbin/boatnet.x86 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3665469
URL: http://178.16.54.217/hiddenbin/boatnet.x86
URL Status:flame Online (spreading malware for 4 months, 4 days, 4 hours, 53 minutes)
Host: 178.16.54.217
Date added:2025-10-09 03:05:21 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-10-09 03:06:15 UTC to abuse{at}metaspinner[dot]net)
Tags:elf mirai link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-01-29n/aelf a4f75bf922b35e3bdf8c9bd3841db40b493e8ccbb3e1d3591fd482b28145702fn/aMirai
2026-01-28n/aelf 98ed64e307b12f20fb49a22a06c7b08a672fdf1a47aba67817368cfc56dc60e8n/aMirai
2026-01-28n/aelf 2ef60a12f05e64ec3828a788f9d27075e31a74781d404a4d653725964045061en/aMirai
2026-01-26n/aelf 6fd7d5914dda628b5c5357ea9d507e6b03708d96a16afa85e7d7d5f2dba96177n/aMirai
2026-01-16n/aelf 06ac813a890fd2b295a9a11e16b7459158329f004d743ac2810e5ac6d125cd34n/aMirai
2026-01-09n/aelf ee464b46f46ba9a46a7c761e4a8d9bd598b1e941a09e942205496a98413c708fn/aMirai
2026-01-05n/aelf 02450f777d3863514d5071346144297728426c794a085d9c6e1f603f83985848n/aMirai
2025-10-09n/aelf 575f49ab7f9a1c63f78edbdb1275737cff37d5d03488a8b825627206c7e2a04bn/aMirai