URLhaus Database

You are currently viewing the URLhaus database entry for http://83.168.110.191/iran.armv4l which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3812849
URL: http://83.168.110.191/iran.armv4l
URL Status:flame Online (spreading malware for 2 months, 14 days, 15 hours, 23 minutes)
Host: 83.168.110.191
Date added:2026-04-06 08:13:25 UTC
Threat:Malware download Malware download
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2026-04-06 08:14:15 UTC to ripe{at}skypass[dot]tech)
Tags:elf mirai link ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-06-09n/aelf a09d4c56ed1f5539952a74fe8e28b505e7100feda7b0f23de77b3718befc50fan/aMirai
2026-05-31n/aelf 279a71b9186b6902ab9ebfc662859c2745e5063c24c1abee7c7b68e125484d42n/aMirai
2026-05-30n/aelf 5e559dcca4130ed69d6436be4fd77ca7404cb41a6f82edd94b7dfb131ba9a9d7n/aMirai
2026-05-29n/aelf 121448bb3eb771de731d4d5ca51d0fdd1b1282369db7ced0e6126992f009d114n/aMirai
2026-05-28n/aelf e28886142e669aec9ad91b076d088bde7161fc7ddb57e89b561d01eafa70f28bn/aMirai
2026-05-27n/aelf dc9be3263ee07ab296ed8bac65eddd14eabd556697e5fab17280d2e8160ed4f9n/aMirai
2026-05-08n/aelf 2ef71ffa6b038ba342552a0b21e741b6894a29f1205542cfaa384e4efcdd1ec6n/aMirai
2026-04-19n/aelf 3b2dd06d13f1730ae577296a749d26eba90afd572913552c0dcebb4db879d000n/aMirai
2026-04-15n/aelf e26180196a1b0993d10b6f36446eaee8f2e7c11153d42bdacca76128daf438ffn/aMirai
2026-04-15n/aelf e2aa11e81aab1a4b7c4dad49b36ac3b5d248c086781b2d59fbc7db50527748c5n/aMirai
2026-04-13n/aelf 3132a9b85061961036c69db8e0d6a0fa406d2fb23d8e6ec3882ba70f847e9b7bn/aMirai
2026-04-06n/aelf 2a878369fc31716e19c37b89a0dcbd2569c536672ab085624edc6f45aca20cc3n/aMirai