HoneyLabs

Payloads observatory

Malware our honeypots were told to download.

When an exploit payload carries a wget/curl one-liner, we fetch the file in a sandboxed collector, hash it, and check it against VirusTotal (uploading samples VT has not seen). 35 files so far, 25 flagged malicious. URLs are shown in Safe-IOC form; hashes link to the VT report, hosts pivot into the per-IP report.

File / SHA-256 VT verdict Fetched via Delivery URL First seen
sex.sh31/75tftp[http]://143[.]20[.]185[.]220/sex.sh2026-06-12 18:12
Ciabins.sh37/75wget[http]://94[.]183[.]232[.]247/Ciabins.sh2026-06-12 15:16
unnamed35/75wget[http]://176[.]65[.]139[.]195/bins/zoryn.mips2026-06-11 15:29
7b15e02eb1012a75718bdbb7e4eb296337f7ddab26/75wget[http]://217[.]60[.]195[.]70:8080/x862026-06-09 13:14
bin.sh51/75wget[http]://115[.]55[.]85[.]7:55027/Mozi.m2026-06-07 07:19
unnamed4/75curl[http]://45[.]13[.]186[.]32/run.sh2026-06-06 19:11
4878210/75curl[http]://vitacocoyougoloco[.]potassium[.]st/r2026-06-06 18:31
unnamed23/75wget[http]://176[.]65[.]149[.]168/adb.sh2026-06-06 15:13
cat.sh19/75curl[http]://176[.]65[.]139[.]126/cat.sh2026-06-06 03:28
boatnet.mips35/75wget[http]://176[.]65[.]149[.]124/hiddenbin/mips2026-06-05 09:24
3oxzm.exe26/75busybox-wget[http]://176[.]65[.]139[.]27/x86_642026-05-30 12:37
8dkf5gpv.exe16/75b64[https]://14[.]46[.]136[.]77/sh2026-05-18 21:14
8dceaa82_sh.sh15/75curl[https]://121[.]176[.]14[.]102/sh2026-05-17 02:30
unnamed0/75curl[http]://d83vf6ijchmkg68t4cug4jds7x74gxnen[.]oast[.]site2026-05-16 14:15
unnamed0/75curl[http]://d83vf6ijchmkg68t4cug5jsq37tzghngc[.]oast[.]site2026-05-16 14:15
unnamed0/75wget[http]://101[.]36[.]125[.]58:10598/i/969a34/a14n/op0w/2026-05-15 15:12
unnamed0/75curl[http]://d83ilri1dk0477fthfq0ggt3rbqhkemox[.]oast[.]live2026-05-15 14:25
unnamed0/75wget[http]://d83ilri1dk0477fthfq0po7uie93fhth3[.]oast[.]live2026-05-15 14:25
unnamedpendingcurl[http]://d83ilri1dk0477fthfq07jr7cfmkb4c47[.]oast[.]live2026-05-15 14:21
unnamedpendingcurl[http]://d83ilri1dk0477fthfq0rudrqc8gxud1d[.]oast[.]live2026-05-15 14:21
bin.sh51/75wget[http]://27[.]37[.]111[.]24:48041/Mozi.m2026-05-15 14:05
unnamed10/75wget[http]://45[.]153[.]34[.]93/mips2026-05-15 01:12
linux.sh12/75tftp[http]://156[.]238[.]242[.]196/linux.sh2026-05-14 20:08
9294532/75tftp[http]://142[.]248[.]80[.]144/lol.sh2026-05-12 09:38
run.sh3/75curl[http]://176[.]65[.]139[.]166/run.sh2026-05-09 14:24
phantom.mips31/75wget[http]://45[.]157[.]233[.]103/bins/phantom.mips2026-05-08 15:57
eec5c6c219535fba3a0492ea8118b397_bin.sh54/75wget[http]://110[.]37[.]13[.]96:37828/Mozi.m2026-05-08 04:19
unnamed3/75wget[http]://168[.]220[.]248[.]106:9087/payload/a6i3khk75wgf/su9wyp.sh2026-05-07 23:21
unnamedpendingcurl[https]://updates[.]officehub[.]works2026-05-07 16:59
9zmn8.exe32/74wget[http]://176[.]65[.]139[.]131/bins/mips2026-05-07 16:58
ef3d2de82b34_stager-amd643/75curl[https]://cdn[.]boyzee[.]xyz/086ad118cef06dd1ebe63c7b/stager-amd642026-05-07 16:58
akido.mips41/74wget[http]://45[.]157[.]233[.]103/d/akido.mips2026-05-07 16:58
rondo.aqg.sh0/74busybox-wget[http]://204[.]10[.]194[.]134/rondo.2026-05-07 16:57
mips23/74wget[http]://31[.]56[.]209[.]125/bins/mips2026-05-07 16:57
file0/75curl[http]://151[.]243[.]11[.]232026-05-07 16:56
refreshed every collector cycle · cached 10 min · newest 200 shown