URLhaus Database

You are currently viewing the URLhaus database entry for http://83.168.110.191/iran.armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812849
URL: http://83.168.110.191/iran.armv4l
URL Status:flame Online (spreading malware for 1 month, 1 days, 13 hours, 28 minutes)
Host: 83.168.110.191
Date added:2026-04-06 08:13:25 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-06 08:14:15 UTC to ripe{at}skypass[dot]tech)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-04-19n/aelf 3b2dd06d13f1730ae577296a749d26eba90afd572913552c0dcebb4db879d000n/aMirai
2026-04-15n/aelf e26180196a1b0993d10b6f36446eaee8f2e7c11153d42bdacca76128daf438ffn/aMirai
2026-04-15n/aelf e2aa11e81aab1a4b7c4dad49b36ac3b5d248c086781b2d59fbc7db50527748c5n/aMirai
2026-04-13n/aelf 3132a9b85061961036c69db8e0d6a0fa406d2fb23d8e6ec3882ba70f847e9b7bn/aMirai
2026-04-06n/aelf 2a878369fc31716e19c37b89a0dcbd2569c536672ab085624edc6f45aca20cc3n/aMirai