s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1853578 high

📛 Threat Title

Mirai: URL that delivers a malware payload http://103.83.87.122/iran.mips

Category: Mirai Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-19 07:08:36 UTC. Reporter: anonymous.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://103.83.87.122/iran.mips

IOC database

Type
url
Value
http://103.83.87.122/iran.mips
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://urlhaus.abuse.ch/downloads/text_recent/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-18 23:58:02 UTC. Reporter: anonymous.

Remediations (10)

  • web:github.com

    This repository contains a comprehensive malware analysis report focusing on the Mirai IoT botnet. The project details the setup of a secure malware analysis laboratory and presents a research-based analysis of the Mirai malware . It covers the critical aspects of establishing an isolated analysis environment, the selection of appropriate tools, and a thorough investigation of Mirai's ...

  • web:github.com

    This repository contains a static malware analysis of the IoT Mirai malware (loader component) obtained from theZoo malware repository. The objective of this project is to understand Mirai's infection mechanism, network behavior, architecture-specific payload delivery, and execution flow using reverse engineering techniques.

  • web:securityboulevard.com

    The image shows an example of a bash script that , when executed, downloads a second-stage binary that installs the Mirai malware onto the infected host. This surge in malicious URL delivery coincides with attackers' increasing use of AI and machine learning to generate sophisticated DDoS attacks.

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL .

  • web:www.akamai.com

    The SIRT honeypots caught samples of Mirai using this vulnerability to infect devices as early as June 13, 2023 (Figures 1 and 2). The payload attempts to inject a wget command by downloading a 32-bit Mips compiled Mirai binary, setting it to be world executable, and then executing it (Figures 3 and 4).

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.cloudsek.com

    CloudSEK uncovered a large-scale Loader- as -a-Service botnet distributing RondoDoX, Mirai , and Morte payloads through SOHO routers, IoT devices, and enterprise apps. Exploiting weak credentials, unsanitized inputs, and old CVEs, the campaign surged 230% in mid-2025, weaponizing compromised devices for cryptomining, DDoS, and enterprise intrusions. With rapid infrastructure rotation and multi ...

  • web:www.imperva.com

    The image shows an example of a bash script that , when executed, downloads a second-stage binary that installs the Mirai malware onto the infected host. This surge in malicious URL delivery coincides with attackers' increasing use of AI and machine learning to generate sophisticated DDoS attacks.

  • web:www.radware.com

    Mirai as an Evolving IoT Botnet Ecosystem As of 2026, Mirai is a reusable malware lineage and attack framework that continues to shape IoT-driven DDoS activity. Radware describes Mirai as one of the defining IoT botnets because its leaked source code enabled attackers to create customized variants and rapidly expand DDoS capabilities across poorly secured connected devices. The key risk is ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.