TF-1853585
high
📛 Threat Title
Mirai: URL that delivers a malware payload http://103.83.87.122/iran.armv4l
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-19 07:08:32 UTC. Reporter: anonymous.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://103.83.87.122/iran.armv4l
IOC database
- Type
- url
- Value
http://103.83.87.122/iran.armv4l- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://urlhaus.abuse.ch/downloads/text_recent/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-18 23:58:02 UTC. Reporter: anonymous.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:blog.qualys.com
The above-mentioned figure shows the complete details of identified command-and-control servers, with respective payload content to the final URL , which drops the Mirai malware . Murdoc Botnet Mirai malware , here dubbed as Murdoc Botnet, is a prominent malware family for *nix systems. It mainly targets vulnerable AVTECH and Huawei devices.
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware , launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:securityboulevard.com
The image shows an example of a bash script that , when executed, downloads a second-stage binary that installs the Mirai malware onto the infected host. This surge in malicious URL delivery coincides with attackers' increasing use of AI and machine learning to generate sophisticated DDoS attacks.
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:www.akamai.com
Akamai researchers identified an active exploitation of CVE-2023-26801, a critical command injection vulnerability discovered in March 2023 (CVSS 9.8). The Akamai Security Intelligence Response Team (SIRT) observed this exploit in the wild as early as June 13, 2023, and it continues to be active. The vulnerability is being exploited to spread the Mirai botnet malware in the following firmware ...
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.imperva.com
The image shows an example of a bash script that , when executed, downloads a second-stage binary that installs the Mirai malware onto the infected host. This surge in malicious URL delivery coincides with attackers' increasing use of AI and machine learning to generate sophisticated DDoS attacks.
-
web:www.radware.com
Mirai as an Evolving IoT Botnet Ecosystem As of 2026, Mirai is a reusable malware lineage and attack framework that continues to shape IoT-driven DDoS activity. Radware describes Mirai as one of the defining IoT botnets because its leaked source code enabled attackers to create customized variants and rapidly expand DDoS capabilities across poorly secured connected devices. The key risk is ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.