URLhaus Database

You are currently viewing the URLhaus database entry for http://176.65.139.59/hiddenbin/boatnet.arm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3825880
URL: http://176.65.139.59/hiddenbin/boatnet.arm
URL Status:flame Online (spreading malware for 16 days, 18 hours, 13 minutes)
Host: 176.65.139.59
Date added:2026-04-19 11:29:12 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-19 11:30:24 UTC to abuse{at}stormindustries[dot]llc)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-02boatnet.armelf 712121d29b06d5583856e5de4d6f5f164e0c0b21372fc0d1815354fe3ad979d0n/a
2026-05-02boatnet.armelf 9ed2ac431e1bc62f21499327c21f75155191aa6c0cc71eec0e48e54662a13dd6n/a
2026-05-01boatnet.armelf a6f771fcd479e5430a76853790e420fbd81b3786de306f5e78ba4ca613811b40n/aMirai
2026-04-29boatnet.armelf 6fbd27ed6f09e1c7531f9a8669807e854bf52d56e06da72c152a442045eab9bdn/aMirai
2026-04-28boatnet.armelf df9ef49e14e8811abd2da85c212d3470b4894f6f588513cbc07d74d47e2e166dn/aMirai
2026-04-27boatnet.armelf 9e10f2aace0584c5001e81848a513e0fdb7f94b629873f2de405fadce29ac50cn/aMirai
2026-04-24boatnet.armelf 0630ab17e5835270c5df6efd53b30b975f493ddcae716ca63eba76e037baf547n/aMirai
2026-04-23boatnet.armelf b8639d9c6b1c903cc3daee2be163c1c925db0a9bee46158e9730f4627b2e6ed1n/aMirai
2026-04-19boatnet.armelf 743722b02dc5adc93f53a49dea1280ce7a0d2da4befaed81d90877dbadca96acn/aMirai