Skip to content

Instantly share code, notes, and snippets.

@zam89
Forked from hwdsl2/README.md
Created June 26, 2014 07:30
Show Gist options
  • Save zam89/50329a91456081c9a3f1 to your computer and use it in GitHub Desktop.
Save zam89/50329a91456081c9a3f1 to your computer and use it in GitHub Desktop.
# This list summarizes recent malware caught in my Kippo SSH Honeypot (http://code.google.com/p/kippo/)
#
# For detailed instructions, please see:
# https://blog.ls20.com/check-your-server-for-malware-from-ssh-brute-force-attacks/
#
# Last Updated: March 24, 2014
#
# Copyright (C) 2014 Lin Song
#
# This program is free software: you can redistribute it and/or modify it under
# the terms of the GNU General Public License as published by the Free Software
# Foundation, either version 3 of the License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful, but WITHOUT ANY
# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
# PARTICULAR PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License along with
# this program. If not, see http://www.gnu.org/licenses/.
# MD5SUM Possible File Names
80a99cd271f130e0f64f183f12095265 /etc/diretc.l
9c4e4ef7e79d5f260a9b13e77abcc259 /etc/diretc.l
83326c5ae5376d63498e42618cb1d9b3 /etc/diretc.l
80a99cd271f130e0f64f183f12095265 /etc/java.13.2.8_16
9c4e4ef7e79d5f260a9b13e77abcc259 /etc/java.13.2.8_18
83326c5ae5376d63498e42618cb1d9b3 /etc/java.13.2.8_18
9c4e4ef7e79d5f260a9b13e77abcc259 /etc/java_2014
83326c5ae5376d63498e42618cb1d9b3 /etc/java_2014
9c2f44edee83c31b142610faa7ffe3b3 /etc/cy64
f955a36f848c36e38d0dff581399e3b6 /etc/ncs
caa260800a3f735ad514270fbbe78fcd /etc/reSuSEfire.w
caa260800a3f735ad514270fbbe78fcd /root/xsyer
6ab42db3476ad4e6ad35157067a426bc /etc/profile.d/SoftwareDistribution
0cbd9086d8d8c45f41ea4538b43e3616 /bin/cupsdd
bf03acf2720352918f1f9dfda611bc45 /bin/xmit64
82d292121dd53f110567b889f8358657 /bin/ssh64
c550f6184723b683b57a55505d0cb4ec /bin/yatewa
b7e97f6e749dd91f64d5972475677d69 /sbin/kthread
ec400e0db4bcfedccecea5d1ce4a1825 /root/bash_long
5928a53a3421beee73a5a445c7bf2ebb /root/bash_long
ec400e0db4bcfedccecea5d1ce4a1825 /root/bash_logom
2e0dea7b7db639d11187feb0f4f6b000 /root/bash_logom
31e8fdfdb756e095998ae21f45fda4ca /root/dos32
5f676c379c85be2c6bc03c916450b4dd /root/txma
a8cce4ce5fbe908588ceb7c733f7b2bd /root/txma11
a54320f8047a40fbb766866af7a25770 /root/txma11
7afbb039033efd372d5653569ccce3b8 /root/txma3
9e3133b0614048836b2044f6f9a061cb /root/ma
90bd2296b15d802600e18daefb1e2e62 /root/c32
dcc4a3125a99c184afaab3b2430a8d7e /root/c64
dcc4a3125a99c184afaab3b2430a8d7e /root/liunxc64
fb52be7d86ba3e8fcbf909f456eeccfd /root/liunxc32
6b2f58187d17f0a5fa8f1d324d50e710 /root/userxne
e0d2366de8a758badf0cad95900fb6fd /root/.24m
63f0f4d5cdf109e87836c90a58361d4b /root/.UST
1e86a23bb73eed9640c8d19a684b886e /root/gouw
1e86a23bb73eed9640c8d19a684b886e /root/ifconfig
7e76c870b457b668391be92aa1d7c008 /root/ifconfig
50118d1a877688eab328e2112f034a60 /root/linux
ab505fb84f39b69c0aff14d1929086a4 /root/cscs
ab505fb84f39b69c0aff14d1929086a4 /root/linux
ab505fb84f39b69c0aff14d1929086a4 /root/linuxx
6f51f7bc4fe4a945049a437459394adf /root/.Modemcheck
6f51f7bc4fe4a945049a437459394adf /root/.updatecheck
1f9bd18ff9a90b61d72f872eae15d499 /root/zxc123
1f9bd18ff9a90b61d72f872eae15d499 /root/zxc321
3506a74c513cdc385807ebc9b1a216af /root/ios
dd4d6029fe00ec0ae08271b28f7a5a6d /root/cshrcc
b700521970ec169975c590d18a286171 /root/getsetup.hb
9966d5db77f247070fcac9590a3fde80 /root/getsetup.hb
86329cbe9b47e6c90d89c68fbf796f79 /root/getsetup.hb
401a3fd9e8daa2373dae61245ae97e0e /root/getsetup.hb
18d41a48a53bc3bcaecc07a803c2a2db /root/getsetup.hb
8e65e8b5f2d00f71ee8de2bcee407ad2 /root/dd32
733b31f3dfe46e57bfb293289b5ed593 /root/dd64
84c4f5e2c81068236f1401d303e52085 /root/nodeJR
5466f341d65312a66641ad6421ca63bd /root/nodeJR
528bbc87130098e55e3faa0157b8936f /root/nodeJR
3fed0aa9120aa058fc1e7f301f1fb7e0 /root/kkk
3fed0aa9120aa058fc1e7f301f1fb7e0 /root/nodes
3fed0aa9120aa058fc1e7f301f1fb7e0 /root/123
690c8a14f1aa05f144c3ff7cc4c7ea8d /root/mm32
b71e0090dd8e0f5ca4f7210c5ecfce1a /root/mm64
ab715baef276c969d7d21cf27b0e0aef /root/.TSmm
c68554b546e7de3f212a6c26c9d96bb6 /root/64
19ad88d19418234819a4a0f46aaf0f34 /root/cxks
4b1e9e8ccf91998393509290d436ede3 /root/cxkss
eed6522ed012ad495ee9eaea3f066ef2 /root/httpd.hb
30007cda4c431ef9fe37716fbfdadab0 /root/user
30007cda4c431ef9fe37716fbfdadab0 /root/users
8c4bce27cd44f28dba22fadcfa3f3a06 /root/users
f6276abfeaa57ada50ef0b56d5275cd3 /root/wkyd
fa20d6bd91be980d863aa94efa39a590 /root/wgsh
b187d19a63679cfb91e3f1aebe7a23e0 /root/wgsh
aa5d780034d9ca32edb012d1ca187e00 /root/wgsh
994700f5c93d1f4e7fb7fbbaca6bb79c /root/wgsh
233a03d85db3eee89d67597490afc3a7 /root/wgsh
093ffd1388415d2f5c99ec4ead73b91f /root/wgsh
13669c37be8849448fc92bb2c75add51 /etc/svchosts
13669c37be8849448fc92bb2c75add51 /root/svchosts
8f8505d7e3e25574882e70a158551e66 /root/svchost
0e64a366ccec9fd5677dfd31a0aba973 /root/svchost
512993a73fb0ae207696c4b7fef330cb /root/lt
9a79058309a87e16c6a7470489d8226a /root/abu
310f4a5a0791d69c88ebbb8689400312 /root/toor
cf9b45438275c0943f108636558559bf /root/meiun
89dd649e0b4f7935b2786b22e8ae720b /root/11
67c531c3319bfc841408a18fa3f6fcac /root/servers
9b65f910fb30aff2e736fd260fa2c1d3 /root/conrd
726b4fd90df2b0159717a1bfa7f4efe3 /root/jap
d7f6974c1843c3ff62a2cda85ea77ffb /root/jap
b650d34d47ba9ff62a71942fba4f5368 /root/338
7916b6b7d6e10c51c0b88985bfb1d49c /root/cao
a1e57333583f1091def576113d56cd29 /root/ss
2681b3cef29a9223c326123900398e6a /root/xp.png
3be2648af1f4b9a9798debc851de6476 /root/lssos
bd8c590af56458ebe63332bdeb910c4c /root/2
260533ebd353c3075c9dddf7784e86f9 /root/disknop
c92129fc230bacd113530fee254fc2b6 /root/disknop
8d5421762c535be5d80ce96b36df1c27 /root/disknop
6cba81e9e4528453d93b0896d1a78efd /root/disknop
260533ebd353c3075c9dddf7784e86f9 /root/disknyp
c92129fc230bacd113530fee254fc2b6 /root/disknyp
8d5421762c535be5d80ce96b36df1c27 /root/disknyp
6cba81e9e4528453d93b0896d1a78efd /root/disknyp
719bfa0b4606b7c73cbd1ae4f50e87cd /root/n26
3364fed8c955072f81487c3320ee8151 /root/csrss
fb9cfa23f939c41628b9a7684be9c562 /root/kacpid
4349d64d5e28059b56006429194ee496 /root/nohup
c72ab1b1931817fcd7181cdce481aedd /root/tomcat32
466fd855aa5a261cb0a68cdc7da8f2ae /root/liushi
04a4ceee1337d919d1c580a49122f1ad /root/blo.txt
7c62f6cd9d0121c11f1d4e8a305f9dd9 /root/fatfix.tar.gz
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment