Automated .env file harvester with UA crusader-worker/1.0. Probed for .env, .env.bak, .env.dev, .env ...
show moreAutomated .env file harvester with UA crusader-worker/1.0. Probed for .env, .env.bak, .env.dev, .env.prod, .env.production, .env.local, actuator/env, and wp-config.php.swp. Google Cloud origin. Captured by an ESP32 HTTP honeypot.
show less
AI/LLM credential harvester. Sent 50+ GET requests targeting .claude/settings.json, openai.json, ant ...
show moreAI/LLM credential harvester. Sent 50+ GET requests targeting .claude/settings.json, openai.json, anthropic.json, litellm_config.yaml, .aider.conf.yml, .cursor/config.json, mcp.json, gcp.json, credentials.json, secrets.json, shell histories, and DB dumps. UA spoofed as Chrome/124 Linux. Captured by an ESP32 HTTP honeypot.
show less
Aggressive multi-port scanner. Made 10+ SSH connection attempts with client SSH-2.0-Go, then injecte ...
show moreAggressive multi-port scanner. Made 10+ SSH connection attempts with client SSH-2.0-Go, then injected raw HTTP GET requests into SSH, ADB, and Telnet service ports. Appeared as a Telnet login attempt with username GET / HTTP/1.1. Captured by an ESP32 multi-service honeypot.
show less
ADB (Android Debug Bridge) scanner. Sent CNXN handshake followed by a raw HTTP GET on the ADB port. ...
show moreADB (Android Debug Bridge) scanner. Sent CNXN handshake followed by a raw HTTP GET on the ADB port. DigitalOcean origin. Captured by an ESP32 ADB honeypot.
show less
Persistent Go-http-client/1.1 scanner. Made repeated GET /login requests across multiple hours. Capt ...
show morePersistent Go-http-client/1.1 scanner. Made repeated GET /login requests across multiple hours. Captured by an ESP32 HTTP honeypot.
show less
Persistent scanner. Attempted OpenWRT LUCI authentication bypass via /cgi-bin/luci/;stok=/locale. Al ...
show morePersistent scanner. Attempted OpenWRT LUCI authentication bypass via /cgi-bin/luci/;stok=/locale. Also probed /login.asp and / using python-requests and browser UAs across multiple sessions. Captured by an ESP32 HTTP honeypot.
show less
ADB (Android Debug Bridge) scanner. Sent CNXN handshake across two separate connection attempts. Cap ...
show moreADB (Android Debug Bridge) scanner. Sent CNXN handshake across two separate connection attempts. Captured by an ESP32 ADB honeypot.
show less
Three rapid SSH connection attempts using client SSH-2.0-Go. Linode/Akamai origin. Captured by an ES ...
show moreThree rapid SSH connection attempts using client SSH-2.0-Go. Linode/Akamai origin. Captured by an ESP32 SSH honeypot.
show less
Probed /boaform/admin/formLogin with no user-agent. Targets the Boa web server login form found on T ...
show moreProbed /boaform/admin/formLogin with no user-agent. Targets the Boa web server login form found on TOTOLINK, D-Link, and TP-Link routers. Captured by an ESP32 HTTP honeypot.
show less
SSH intrusion and credential-harvester deployment. Authenticated via SSH and used SFTP to upload a G ...
show moreSSH intrusion and credential-harvester deployment. Authenticated via SSH and used SFTP to upload a Go-compiled PAM credential-harvesting binary disguised as sshd (SHA-256 f9dd99970ad2a4ce3ed0f3c37a2cdac97260b0427dd77ae2eeafb148e1189f49, 35/63 VT detections). Binary implements a full PAM conversation handler to intercept and exfiltrate credentials. Same campaign as prior sshd-replacement uploads from 116.148.226.140, 150.136.227.229, and 218.98.97.7. Captured by a Cowrie honeypot.
show less
Telnet-based attack. Connected to a Cowrie honeypot and downloaded the hDvrHelper multi-architecture ...
show moreTelnet-based attack. Connected to a Cowrie honeypot and downloaded the hDvrHelper multi-architecture Mirai dropper (SHA-256 a6296a79f44e21b76604d2d2bbf795d2cf380f70e39d45fbf166707ff3b4a6a4) over HTTP from 65.183.189.172 path /wget. Dropper fetches architecture-specific Mirai payloads; 10/60 detections on VirusTotal.
show less
Malware distribution server. Served a Mozi botnet ARM ELF payload (SHA-256 12013662c71da69de977c04cd ...
show moreMalware distribution server. Served a Mozi botnet ARM ELF payload (SHA-256 12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef) on port 482159 to bots attacking IoT devices via Telnet. Mozi is a P2P DHT botnet targeting routers via TR-069/CWMP; 51/62 detections on VirusTotal. Observed by a Cowrie honeypot.
show less
Malware distribution server. Served the hDvrHelper multi-architecture Mirai dropper (SHA-256 a6296a7 ...
show moreMalware distribution server. Served the hDvrHelper multi-architecture Mirai dropper (SHA-256 a6296a79f44e21b76604d2d2bbf795d2cf380f70e39d45fbf166707ff3b4a6a4) at path /wget to bots exploiting IoT devices via Telnet. Dropper fetches architecture-specific Mirai payloads; 10/60 detections on VirusTotal. Observed by a Cowrie honeypot.
show less
Telnet credential attack against an IoT-style service. Authenticated with e8ehomeasb/e8ehomeasb, obt ...
show moreTelnet credential attack against an IoT-style service. Authenticated with e8ehomeasb/e8ehomeasb, obtained a shell, set the hostname to slur, and probed /tmp /var /var/run /var/tmp /dev /dev/shm /etc /mnt /usr /boot and /home for writable execution locations. No executable payload completed transfer. Captured by a Cowrie honeypot.
show less
Telnet-based attack. Connected to a Cowrie honeypot and downloaded an obfuscated MIPS LSB ELF botnet ...
show moreTelnet-based attack. Connected to a Cowrie honeypot and downloaded an obfuscated MIPS LSB ELF botnet payload (SHA-256 f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8) over HTTP from 119.179.115.63 port 42441 path /bin.sh. Payload is a known Mirai-family bot with 39/75 detections on VirusTotal.
show less
Malware distribution server. Served an obfuscated MIPS LSB ELF botnet payload (SHA-256 f6c97b1e2ed02 ...
show moreMalware distribution server. Served an obfuscated MIPS LSB ELF botnet payload (SHA-256 f6c97b1e2ed02578ca1066c8235ba4f991e645f89012406c639dbccc6582eec8) on port 42441 path /bin.sh to bots attacking IoT devices via Telnet. Payload is a Mirai-family DDoS bot observed by a Cowrie honeypot.
show less
Telnet-based attack. Connected to a Cowrie honeypot and downloaded a Mozi botnet ARM ELF payload (SH ...
show moreTelnet-based attack. Connected to a Cowrie honeypot and downloaded a Mozi botnet ARM ELF payload (SHA-256 12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef) over HTTP from 42.228.130.73 port 482159. Mozi is a P2P botnet targeting routers and IoT devices via TR-069/CWMP; 51/62 detections on VirusTotal.
show less
Telnet credential attack and malware-delivery attempt. Authenticated with admin/admin, probed the en ...
show moreTelnet credential attack and malware-delivery attempt. Authenticated with admin/admin, probed the environment and writable directories, then downloaded the hDvrHelper Mirai dropper SHA-256 a6296a79f44e21b76604d2d2bbf795d2cf380f70e39d45fbf166707ff3b4a6a4 over HTTP from 185.93.89.72/wget. TFTP and FTP fallback delivery attempts followed. Captured by a Cowrie honeypot.
show less
Telnet-based attack. Connected to a Cowrie honeypot and downloaded the RyMGang DDoS botnet multi-arc ...
show moreTelnet-based attack. Connected to a Cowrie honeypot and downloaded the RyMGang DDoS botnet multi-arch dropper bins.sh (SHA-256 8e06754e5e64bdf5f61dd604a5f12e9bc10f5502316b5379fb258f84a5d84702) plus MIPS LSB (SHA-256 7cc0b40e8819ec9139ffae5942add2db1c26e168edaeda57302c9047f23dfb6c, 39/75 VT) and MIPS MSB (SHA-256 30c7d351e70323915566d2bb648b4313c9722b34252929a8c7050f6495ae14fc, 40/62 VT) DDoS bots from 131.123.40.104. Bots report to C2 at 131.123.40.104:4444 and conduct UDP/TCP floods, Source Engine amplification, and SSH lateral movement.
show less
Malware payload server and DDoS botnet C2. Served RyMGang multi-architecture DDoS bots (MIPS LSB SHA ...
show moreMalware payload server and DDoS botnet C2. Served RyMGang multi-architecture DDoS bots (MIPS LSB SHA-256 7cc0b40e..., MIPS MSB SHA-256 30c7d351...) and the multi-arch dropper bins.sh via randomized paths. C2 port 4444; bots conduct UDP/TCP floods, Valve Source Engine amplification attacks, and SSH lateral movement using sshpass. Gang tag RyMGang embedded in DDoS payloads; associated domain dayzddos.co. Observed by a Cowrie honeypot.
show less
Malware payload server observed at TCP port 36219 path /i. It served ARM Mirai-family binary SHA-256 ...
show moreMalware payload server observed at TCP port 36219 path /i. It served ARM Mirai-family binary SHA-256 24b8db23032375dfb68668d6354b9524564207bb56a4e03174b940dc78d3a42c to multiple attacking bot nodes during authenticated honeypot sessions. Captured by a Cowrie honeypot.
show less
IoT-targeted honeypot intrusion associated with the LUHZQK router-exploitation campaign. After acces ...
show moreIoT-targeted honeypot intrusion associated with the LUHZQK router-exploitation campaign. After access this source retrieved MIPS Mirai-family payload SHA-256 4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7 from TCP port 55889 path /i and attempted a second payload endpoint. Captured by a Cowrie honeypot.
show less
Malware payload server observed at TCP port 55889 path /i. It served MIPS MSB Mirai-family DDoS bina ...
show moreMalware payload server observed at TCP port 55889 path /i. It served MIPS MSB Mirai-family DDoS binary SHA-256 4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7 to multiple attacking bot nodes. The payload contains HTTP flood functionality. Captured through Cowrie honeypot sessions.
show less
IoT-targeted honeypot intrusion followed by malware retrieval. After access this source downloaded M ...
show moreIoT-targeted honeypot intrusion followed by malware retrieval. After access this source downloaded MIPS MSB Mirai-family DDoS payload SHA-256 4293c1d8574dc87c58360d6bac3daa182f64f7785c9d41da5e0741d2b1817fc7 from 126.76.103.220 TCP port 37207 path /i. Captured by a Cowrie honeypot.
show less
IoT-targeted Telnet honeypot intrusion and malware-delivery attempt. After access this bot attempted ...
show moreIoT-targeted Telnet honeypot intrusion and malware-delivery attempt. After access this bot attempted to retrieve a payload from its own address on TCP port 57670 path /i. The payload endpoint was unavailable during capture. Observed in a completed Cowrie session.
show less
HackingBrute-ForceExploited HostIoT Targeted
By clicking βAccept allβ, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.