A.I CyberSecurity Scoring
Company Information
Website:https://fanavaidc.com
Employees number:5
Number of followers:240
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:fanavaidc.com
Risk Score (AI oriented)
Between 700 and 749
Technology, Information and Internet
Updated:
19/03/2026
19/03/2026
734/1000
Moderate
Ba
Global Score (TPRM)
xxxx
Technology, Information and Internet
Score locked

داده سامانه فن آواModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
736
JULY 2026
736
JUNE 2026
736
MAY 2026
735
APRIL 2026
735
MARCH 2026
734
FEBRUARY 2026
765
Cyber Attack
14 Feb 2026 • داده سامانه فن آوا
Hetzner and Dade Samane Fanava Company: Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network
Iranian Server Misconfiguration Exposes Censorship-Bypass Relay and SSH Botnet Operation
733
LOW-32
HETFAN1773908769
Iranian Server Misconfiguration Exposes Censorship-Bypass Relay and SSH Botnet Operation
Researchers at Hunt.io uncovered a misconfigured open directory on an Iranian server, revealing a live censorship-bypass relay and SSH-based botnet infrastructure operated by a single actor. The discovery highlights how low-sophistication threat actors can repurpose techniques associated with Iranian advanced persistent threat (APT) groups for financial or personal gain.
The exposed server, hosted by Iranian ISP Dade Samane Fanava Company (PJS) at 185.221.239[.]162, contained 449 files across 59 subdirectories, including a .bash_history file, MHDDOS installer, C-based flood tools, and botnet components. A shared Let’s Encrypt TLS certificate for *.server21[.]org linked the server to 14 additional IPs, split between Hetzner (Finland) and Iranian ISPs, forming a purpose-built relay network.
The operation combined censorship circumvention with DDoS capabilities. A config-client.yaml file revealed a KCP-based Paqet tunnel, commonly used in Persian-language communities to bypass Iranian filtering, forwarding traffic to a Hetzner node (65.109.187[.]102). While appearing as a VPN relay, the server also hosted MHDDOS and custom SYN/UDP flood tools, targeting a FiveM GTA server (5.42.223[.]60:30120) and a web host (194.147.222[.]151:80/443).
The bash history allowed researchers to reconstruct the operation’s phases:
- Initial deployment of Paqet, GRE forwarders, and 3x-ui for censorship bypass.
- DDoS tooling, including compilation of syn.c and flood.c.
- Botnet build-out, with scripts (ohhhh.py, yse.py) automating SSH-based infections.
The ohhhh.py script opened 500 concurrent SSH sessions, uploaded and compiled cnc.c on victims, and launched it in detached screen sessions for persistence. The yse.py script acted as a kill switch, terminating processes across infected hosts. While the cnc.c source was not recovered, strings in the binary revealed a flood-focused botnet ("BOT CLIENT v1.0") with reconnection logic and attack commands.
Attribution signals point to an Iran-based operator:
- Hosting on Iranian ISPs and ArvanCloud DNS for server21[.]org.
- Use of Paqet "kharej" configurations, tailored for Iranian censorship.
- Farsi inline comments in scripts.
However, the opportunistic targeting of a game server and generic web infrastructure, along with basic tooling, suggests a profit- or personally motivated actor rather than a state-aligned group.
Indicators of compromise include the 15 IPs tied to the server21[.]org certificate, with key nodes at 185.221.239[.]162 (open directory) and 65.109.187[.]102 (Hetzner relay). Defenders are advised to monitor for unusual gcc usage, anomalous screen sessions, and high-concurrency SSH activity from these IPs.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
765
DECEMBER 2025
765
NOVEMBER 2025
765
OCTOBER 2025
765
SEPTEMBER 2025
765
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for داده سامانه فن آوا ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in July 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in June 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in May 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in April 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in March 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in February 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in January 2026 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in December 2025 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in November 2025 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in October 2025 ??
What was داده سامانه فن آوا's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on داده سامانه فن آوا's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with داده سامانه فن آوا ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view داده سامانه فن آوا's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?