コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/11/13 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/11/13分です。

特徴
Location:JP

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:US

GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Struts2へのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

Location:UK

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Oracle WebLogic脆弱性(CVE-2020-14882,CVE-2020-14883,CVE-2020-14750)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Nmap Scripting Engineによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
WordPress Pluginへのスキャン行為
を確認しました。

Location:SG

GPONルータの脆弱性(CVE-2018-10561)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
UserAgentがHello, Worldであるアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:30 (前日比:-17)
US:総アクセス数:33 (前日比:+4)
UK:総アクセス数:89 (前日比:+40)
SG:総アクセス数:63 (前日比:+20)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.83.163.89 Germany
1 5.188.210.227 Russia
1 13.82.175.242 United States
1 20.186.105.7 United States
1 37.187.139.22 France
1 40.76.44.252 United States
1 41.199.195.84 Egypt
1 61.219.11.153 Taiwan
2 68.183.188.21 United States
9 91.241.19.84 Russia
1 101.51.75.70 Thailand
1 103.62.237.170 India
1 112.203.169.198 Philippines
1 172.105.77.209 United States
1 180.249.116.59 Indonesia
1 185.101.32.29 Norway
1 191.239.183.6 Brazil
1 192.241.219.22 United States
1 192.241.234.77 United States
2 209.141.33.215 United States

UserAgent一覧

件数 UserAgent
10 -
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0
2 Mozilla/5.0 zgrab/0.x
2 ZmEu
1 curl/7.55.1

リクエスト内容一覧

件数 Method Request Protocol
1 -
5 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /console/ HTTP/1.1
6 GET /currentsetting.htm HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /images.php HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.89.243.54 Italy
1 42.228.224.138 China
3 51.210.242.129 France
1 54.86.137.3 United States
1 61.219.11.153 Taiwan
9 91.241.19.84 Russia
1 104.244.168.11 United States
1 118.79.220.75 China
1 118.173.126.114 Thailand
1 167.71.175.10 United States
1 172.105.77.209 United States
1 172.105.89.161 United States
1 182.57.58.18 India
2 185.156.72.27 Russia
1 192.241.215.210 United States
1 192.241.216.214 United States
1 192.241.239.9 United States
1 219.157.56.59 China
1 221.15.20.75 China
3 222.222.233.5 China

UserAgent一覧

件数 UserAgent
12 -
3 Go-http-client/1.1
1 Hello, World
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
2 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
3 GET /currentsetting.htm HTTP/1.1
2 GET /hudson HTTP/1.1
1 GET /index.action HTTP/1.1
1 GET /index.do HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /struts2-rest-showcase/orders.xhtml HTTP/1.1
1 GET /v2/_catalog HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
3 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 27.79.251.114 Vietnam
1 27.147.203.211 Bangladesh
1 37.187.139.22 France
1 49.48.115.219 Thailand
1 61.219.11.153 Taiwan
1 65.122.183.157 United States
9 91.241.19.84 Russia
62 129.213.35.30 United States
4 164.52.24.163 China
1 172.105.77.209 United States
2 185.156.72.27 Russia
3 185.239.242.45 Netherlands
1 192.241.232.250 United States
1 192.241.238.241 United States

UserAgent一覧

件数 UserAgent
15 -
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
62 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
2 Mozilla/5.0 zgrab/0.x
1 curl/7.55.1

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
5 \x16\x03\x01
2 \x16\x03\x01\x01\"\x01
1 DYNS / HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /api/spec.json HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /console/css/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/css/%252e%252e%252fconsole.portal HTTP/1.1
1 GET /console/images/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/images/%252e%252e%252fconsole.portal HTTP/1.1
4 GET /currentsetting.htm HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /nmaplowercheck1605128303 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /spec/api.json HTTP/1.1
1 GET /ui HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 HEAD /actuator HTTP/1.1
1 HEAD /actuator/auditevents HTTP/1.1
1 HEAD /actuator/beans HTTP/1.1
1 HEAD /actuator/conditions HTTP/1.1
1 HEAD /actuator/configprops HTTP/1.1
1 HEAD /actuator/env HTTP/1.1
1 HEAD /actuator/health HTTP/1.1
1 HEAD /actuator/heapdump HTTP/1.1
1 HEAD /actuator/httptrace HTTP/1.1
1 HEAD /actuator/hystrix.stream HTTP/1.1
1 HEAD /actuator/info HTTP/1.1
1 HEAD /actuator/jolokia HTTP/1.1
1 HEAD /actuator/loggers HTTP/1.1
1 HEAD /actuator/mappings HTTP/1.1
1 HEAD /actuator/metrics HTTP/1.1
1 HEAD /actuator/scheduledtasks HTTP/1.1
1 HEAD /actuator/threaddump HTTP/1.1
1 HEAD /auditevents HTTP/1.1
1 HEAD /autoconfig HTTP/1.1
1 HEAD /beans HTTP/1.1
1 HEAD /cloudfoundryapplication HTTP/1.1
1 HEAD /configprops HTTP/1.1
1 HEAD /dump HTTP/1.1
1 HEAD /env HTTP/1.1
1 HEAD /health HTTP/1.1
1 HEAD /heapdump HTTP/1.1
1 HEAD /hystrix.stream HTTP/1.1
1 HEAD /info HTTP/1.1
1 HEAD /jolokia HTTP/1.1
1 HEAD /loggers HTTP/1.1
1 HEAD /mappings HTTP/1.1
1 HEAD /metrics HTTP/1.1
1 HEAD /threaddump HTTP/1.1
1 HEAD /trace HTTP/1.1
11 OPTIONS / HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /images.php HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PROPFIND / HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
1 45.118.113.253 Indonesia
1 49.37.6.124 India
1 49.37.183.110 India
1 61.219.11.153 Taiwan
9 91.241.19.84 Russia
29 94.102.56.130 Netherlands
1 104.208.222.221 United States
1 121.165.110.38 South Korea
1 124.122.230.229 Thailand
10 154.113.16.226 Nigeria
1 157.100.76.152 Ecuador
1 159.192.186.99 Thailand
1 162.243.128.57 United States
1 177.130.244.48 Brazil
1 178.62.55.19 United Kingdom
1 189.203.205.126 Mexico
1 192.241.210.65 United States

UserAgent一覧

件数 UserAgent
10 -
1 Go-http-client/1.1
1 Hello, World
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
1 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0
2 Mozilla/5.0 zgrab/0.x
29 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /MyAdmin/scripts/setup.php HTTP/1.1
1 GET /PHPMYADMIN/scripts/setup.php HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /console/ HTTP/1.1
9 GET /currentsetting.htm HTTP/1.1
1 GET /database/scripts/setup.php HTTP/1.1
1 GET /db/scripts/setup.php HTTP/1.1
1 GET /dbadmin/scripts/setup.php HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
1 GET /my/scripts/setup.php HTTP/1.1
1 GET /myadmin/scripts/setup.php HTTP/1.1
1 GET /mysql/scripts/setup.php HTTP/1.1
1 GET /mysqladmin/scripts/setup.php HTTP/1.1
1 GET /pHpMyAdMiN/scripts/setup.php HTTP/1.1
1 GET /phpAdmin/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2.10.0.0/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2.11.11.3/scripts/setup.ph HTTP/1.1
1 GET /phpMyAdmin-2.11.11/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-3.0.0.0-all-languages/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin/scripts/db.init.php HTTP/1.1
1 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /phpadmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin/scripts/db.init.php HTTP/1.1
1 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin1/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin2/scripts/setup.php HTTP/1.1
1 GET /pma/scripts/setup.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /scripts/setup.php HTTP/1.1
1 GET /setup.php HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sqladm/scripts/setup.php HTTP/1.1
1 GET /sqladmin/scripts/setup.php HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1