ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://103.83.87.122/iran.x86_64.
Database Entry
| IOC ID: | 1853575 |
|---|---|
| IOC: | http://103.83.87.122/iran.x86_64 |
| IOC Type : | url |
| Threat Type : | payload_delivery |
| Malware: | Mirai |
| Malware alias: | Katana |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS44382 FIBA |
| Country: | US |
| First seen: | 2026-07-19 07:08:37 UTC |
| Last seen: | never |
| UUID: | 82a16661-8304-11f1-8973-42010aa4000a |
| Reporter | Anonymous |
| Reward | 5 credits from ThreatFox |
Anonymous
Http Payload Delivery On Port 80 At 103.83.87.122Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
US