URLhaus Database

You are currently viewing the URLhaus database entry for http://83.168.110.191/iran.aarch64 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812835
URL: http://83.168.110.191/iran.aarch64
URL Status:flame Online (spreading malware for 1 month, 1 days, 11 hours, 20 minutes)
Host: 83.168.110.191
Date added:2026-04-06 08:13:21 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-06 08:14:15 UTC to ripe{at}skypass[dot]tech)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-19n/aelf 5a0bfe4a04c65370ab29d3d1dd461a32abbb6fd7e1a233da7fad503b44521c29n/aMirai
2026-04-15n/aelf a569b753c6a424e1051c67e4cf1b222b847d3c4930f89dabcb66f8fe971ba92dn/aMirai
2026-04-15n/aelf 228211a3d2d50f8b72360b37f92bc4bea715996fe205c51b9180511f7709a9a8n/aMirai
2026-04-13n/aelf 57a64d5c60be00d3adcc4275abb95bcd69316c6639b4d5e168d6be470176ba85n/aMirai
2026-04-06n/aelf 178bbc7e4181d89196b2208fa1ee10989d2c1364013e56bca163ca49e4f61206n/aMirai