ThreatFox IOC Database
You are viewing the ThreatFox database entry for ip:port 103.83.87.122:80.
Database Entry
| IOC ID: | 1853569 |
|---|---|
| IOC: | 103.83.87.122:80 |
| IOC Type : | ip:port |
| Threat Type : | botnet_cc |
| Malware: | Mirai |
| Malware alias: | Katana |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS44382 FIBA |
| Country: | US |
| First seen: | 2026-07-19 07:08:39 UTC |
| Last seen: | never |
| UUID: | a3d78c52-8303-11f1-8973-42010aa4000a |
| Reporter | Anonymous |
| Reward | 5 credits from ThreatFox |
Anonymous
Hi Threat Fox team,I'm a security researcher and I've been tracking an active non-Mirai-variant botnet Called Iranbot operated by an Egyptian threat actor (Telegram: @FuckIsra3l). I'm reaching out because I believe this is actionable enough for a takedown and I want to share everything I have.
I'm attaching a full threat intelligence report covering the complete C2 infrastructure, reverse-engineered binary protocol, propagation chains, file hashes, and all network/host IoCs. The report was produced with the assistance of Claude (Anthropic's AI) as an analytical tool, but all technical findings have been verified — binary analysis was done in Ghidra and Binary Ninja, and the C2 protocol was confirmed through live passive monitoring using a bot emulator I built.
Quick summary of what's in the report:
Http Server Spreading Malware At port 80 With The iran.archprefix etc: iran.x86_64
C2 at 103.83.87.122 port 2222 telnet/raw socket
Raw Elf Delivery At 103.83.87.122 port 4444 Which Delivers Arm7 BInary Which Potenitually Targets The "adb" Expoit Which Is Just socks5 Proxy Use To Get Behind Nat Deviices That Kimwolf Had Previously Used Since Then It Has Become Extremly Popular
14 target architectures, full binary hashes, telnet.sh dropper content
Operator's public Telegram channels: t.me/IranBoatnet and t.me/iranpowerproof
Binary strings including "Death to israel" confirming origin/ideology
Persistence mechanism (/etc/init.d/xs.main), full credential brute-force list, Realtek RCE chain
Botnet scale: Currently estimated at approximately 4,000 connected devices. The same operator previously ran a larger infrastructure that peaked at 10,000–13,000 devices before moving to the current setup.
I'm willing to help in any way I can — whether that's providing the raw binary samples, sharing the live monitoring script for your own observation, or answering questions about the protocol. I have active monitoring running and can capture commands if the operator becomes active during a takedown window.
Please let me know what else you need.
Best regards,
Niki
b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 iran.x86_64
bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317 iran.aarch64
f5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493 iran.m68k
e987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66 iran.mips
6e709fb9b09d9f8318724a8620812f55411a3ea49de6319c4832885547773ddd iran.mipsel
0d64cd75599dea5b8cf393b6e2b709f51b3971e64b96920e0707020e22ee7953 iran.powerpc
f38d748d9ea29424c28744c52bcd1d14328d49fcb604ca08fab3547ec500d6f0 iran.sparc
b4acd1ab65624b694946b1181bba0732bb63c88c51b8334914c26c1805b2e1aa iran.sh4
21c5f4a04173a5176d60b06095bf5d25e0022ffbe304601e368eccf718587dc8 iran.arc
ec442a132f27486d1dfa3faa92c03e10012afe2b8de39fa9b42b367f7971c989 iran.i486
9538c8a2edeaa8667134a469d03a7057ddc1e753ce1e5250f92f01c1097fcb1d iran.armv4l
d8cd1d9f8c092aa4a6c1b1b2b97c7de71d55c2af8332532d2956e4f5becac17e iran.armv5l
95f5bd70c4e40f9663b67d40d23a46ca21d97448f9a609be10b12837e6a59805 iran.armv6l
b1f2808e05cb42894790c12172ffacf8673a0a7e14c7af5ad43d5bedfa62a5e4 iran.armv7l
US