URLhaus Database

You are currently viewing the URLhaus database entry for http://83.168.110.191/iran.mipsel which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812827
URL: http://83.168.110.191/iran.mipsel
URL Status:flame Online (spreading malware for 1 month, 1 days, 13 hours, 25 minutes)
Host: 83.168.110.191
Date added:2026-04-06 08:13:21 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-06 08:14:14 UTC to ripe{at}skypass[dot]tech)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-19n/aelf d1bcfaea2f0b268ac6ba7ad0ef2de8f48f4984ffa99d4f5104330d01649e8005n/aMirai
2026-04-19n/aelf 0a826860bdd3c551c7b5318dbf3b5bb1da80570a6de044cb1d6814e063591791n/aMirai
2026-04-15n/aelf fd8c86b3ee999a51467c36b753cc65fe1c5dea314c04ff5669cc04600682277dn/aMirai
2026-04-13n/aelf bff36ed4acdbafe5dde46d2159839efcb33ab941cd568463c0c03d53db2490bcn/aMirai
2026-04-06n/aelf 3d605b4e113d87780f36a26cc04f647e04f65744c8c2055d1dc194d0c39652can/aMirai