URLhaus Database

You are currently viewing the URLhaus database entry for http://83.168.110.191/iran.sparc which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812841
URL: http://83.168.110.191/iran.sparc
URL Status:flame Online (spreading malware for 1 month, 1 days, 17 hours, 28 minutes)
Host: 83.168.110.191
Date added:2026-04-06 08:13:21 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-06 08:14:15 UTC to ripe{at}skypass[dot]tech)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-19n/aelf 12beb3771da4789f865c242118545b0e6e3493022eeb600c481ec203715f6084n/aMirai
2026-04-15n/aelf 7ae60105127245b497ac611187bae5f0c4ca6a9f8de8bfe509ee97ca65c18d0fn/aMirai
2026-04-15n/aelf 9d76b150e46633898f491ca374e06ccc0030d41a939a3ada7e19348eec0a4a00n/aMirai
2026-04-13n/aelf 2b4d8e7bcaf850ead0283268ea0c5500c95e33c16283bba502506025e071928dn/aMirai
2026-04-06n/aelf 4a38b31b4ab29b7e5da48d77ddec5aae6f8795ca2455fbdf2d1659120b0404ccn/aMirai