← Back to Cyber Tours

About This Collection

This collection maps the digital infrastructure of the Iranian government and Hezbollah across multiple domains. Through DNS enumeration, certificate transparency analysis, JavaScript source inspection, and HTTP header review, ODINT identified critical misconfigurations including private IP leaks, exposed admin portals, VPN endpoints, and the regime's complete reliance on ArvanCloud (AS205585) as a CDN single point of failure. Hezbollah's deliberate use of Russian and Czech hosting for resilience against Western takedowns is documented alongside EXIF metadata that attributes content creation to specific workstations in Beirut.

23
Key Findings Files
182
Embassy Subdomains
120+
Captured HTML Pages
100+
Hezbollah Media Files
28+
Tracking Tokens
12
ASNs Mapped
14
Intel Reports
50+
IRNA Subdomains

Interactive Reports

Explore the Iran collection through interactive dashboards

Critical Findings

Key security exposures discovered across Iranian government infrastructure

FindingTargetImpact
Private IP Leakkateb.irna.ir → 10.30.41.85Internal network topology exposed
VPN Endpointr1.vpn.minister.local.mfa.gov.irMinisterial VPN, internal naming leaked
Admin Portaladmin.english.khamenei.irAdmin interface found via cert transparency
Hidden APIformx.khamenei.linkSeparate TLD to hide API infrastructure
Mobile APKdl.farsnews.ir/app.apkIRGC news app available for reverse engineering
Embassy Network*.mfa.gov.ir (182 subdomains)Complete diplomatic web presence mapped
Dev Tools Exposedjira.farsnews.irJIRA, Confluence, Telegram API integration
Monitoring Infraprtg.mehrnews.comPRTG network monitor, HR system exposed
EXIF AttributionHezbollah media filesPhotoshop 7.0 (pirated), Beirut working hours
WhatsApp OPSECalahednews.com.lbOriginal WhatsApp filenames preserved

Targets

Government entities and FTO media operations analyzed

TargetDomainTypeKey Finding
IRNAirna.irState News AgencyPrivate IP leaked, internal subnets mapped
MFAmfa.gov.irForeign MinistryVPN endpoint, 182 embassy subdomains
Supreme Leaderkhamenei.irRegime LeadershipAdmin portal, hidden API on separate TLD
President.irpresident.irPresidential OfficeAS34592 direct attribution
FarsNewsfarsnews.irIRGC NewsJIRA, Confluence, Telegram API, APK
MehrNewsmehrnews.comState MediaPRTG monitoring, HR system
Hezbollahmoqawama.org.lbFTO PropagandaRussian/Czech hosting strategy
Al-Manar TValmanar.com.lbFTO MediaSelectel Moscow + Alibaba Malaysia

Government ASN Map

Autonomous System ownership linking infrastructure to state entities

ASNOwnerUsage
AS34592Iranian Presidential Adminpresident.ir
AS29079IRNAirna.ir network
AS24631Tose'h Fanavarimfa.gov.ir
AS48434Tebyan-e-Noor Institutekhamenei.ir mail
AS205585ArvanCloudALL gov sites CDN — single point of failure

Raw Downloads

Browse the full Iran intelligence archive

📂
Full Iran Archive
Browse all data — key findings, intel reports, Hezbollah media, captured pages
Browse
TXT
Key Findings Summary
10 critical findings — IP leaks, VPN endpoints, admin portals, EXIF attribution
Download
TXT
Hash & Token Database
28+ tracking tokens — GA IDs, GTM containers, session hashes, Clarity IDs
Download
TXT
OSINT Session Log
Timestamped research log documenting discovery methodology
Download

Published Articles

Investigation coverage and analysis

📰
Iran: Government & Hezbollah Infrastructure Analysis
Full investigation on Substack — 23 key findings, embassy subdomains, tracking tokens, Hezbollah hosting
Read
📰
Inside Iran's Cuba-Turkey-China Trade Strategy
Global Recon Report — Iran's international trade and sanctions evasion networks
Read
📰
Opinion: The U.S.-Iran Conflict Is Not a “New War”
Global Recon Report — analysis of the 2026 U.S. and Israeli strikes on Iran
Read
Donate