ハニーポットの観測(T-Pot:2025/10)Observation of Honeypot

PC
ブログ

今月のアクセス数上位ポート

今月は1000万件越えです。1144万件。先月の2倍程度です。

アクセス数上位ポート ①19(chargen) ②5060(SIP) ③445(SMB) ④25(SMTP) ⑤22(SSH)

その大半は見て通り19番ポート宛のchargenによるDDoS(これだけで約800万件)でした。

今月は見ての通り19番ポートへのアクセスはトルコがその大半を占めました。これは先月と同様です。

5060番ポートのみ

5060番ポートへのアクセスのみは左図の通りです。ルーマニアが圧倒的ですが、先月の定期便とはかなり変化しました。

10月13日未明(JST)には、チェコからの25番ポートSMTPのアクセスが集中しました。

25番ポートのみ
19,5060,25番ポート以外
5038番ポートのみ

5038番ポート(Asterisk)へのアクセスがありました。オーストラリアとオランダからが多かったです。

5900番ポート(VNC)へのアクセスがありました。ウクライナからのアクセスが大半です。

5900番ポートのみ

今月のアクセス数上位国

アクセス数上位国 ①トルコ(19) ②アラブ首長国連邦(19) ③ルーマニア(5060) ④チェコ(25) ⑤アメリカ(5060)

DDoSotとHoneyTrap以外

今月の攻撃IDパスワード

ユーザ名(top500)試行数パスワード(top500)試行数
root
admin
ubuntu
user
345gs5662d34
ftp
test
Admin
postgres
oracle
123
git
mysql
ftpuser
dell
hadoop
alex
guest
sa
deploy
lenovo
debian
dev
support
administrator
minecraft
es
testuser
www
user01
steam
odoo
pi
dspace
developer
backup
sysadmin
user1
elasticsearch
admin1
jenkins
anonymous
docker
demo
vpn
test1
ec2-user
nginx
www-data
ftptest
server
centos
tomcat
newuser
daemon

user2
elastic
adminuser
appuser
app
dmdba
es2
teamspeak
ubnt
nagios
sol
kafka
a
username
grid
deployer
devops
frappe
github
bot
nexus
sftpuser
ali
ts3
manager
ansible
crypto_app
cryptotest
john
redis
sammy
dolphinscheduler
odoo17
tempuser
web
super
master
arkserver
runner
monitor
botuser
student
myuser
gitlab-runner
devuser
weblogic
apache
abc
cloud
superadmin
teste
esuser
zabbix
bitwarden
amir
data
operator
Administrator
bitrix
ahmed
proxyuser
seekcy
david
dockeruser
vagrant
roman
foundry
it
huawei
mostafa
db
user123
luis
tester
system
rocky
azureuser
temp
wwwroot
daniel
lab
me
scanner
soporte
Accept: /
erpnext
webmaster
teamspeak3
vncuser
User-Agent:(略)/2.27.1
scan
felix
pivpn
reza
stack
solana
mcserver
tom
odoo15
remote
fivem
vyos
test2
samba
0
bin
gitlab
oscar
rustserver
agent
ftp_user
uftp
GET / HTTP/1.1
default
richard
nextcloud
ts3server
mc
sshuser
nobody
vnc
jla
gpadmin
svn
remoto
mongodb
sonar
staging
client
post
odin
plex
config
factorio
ftpguest
jack
palworld
terraria
user3
gerrit
public
lrendon
node
surya
User-Agent: (略)/1.1
cisco
sftp
test01
vps
kim
novinhost
ts
squid
luna
minima
test3
dbadmin
jito
nvidia
hduser
nodeuser
opc
secret
user4
userbot
hp
informix
joy
mahesh
ps
bash
django
g
netweb
service
User-Agent: (略) 537.36
asterisk
router
wang
wordpress
Accept-Encoding: gzip
dummy
root1
vpn1
1234
pp
systemd
work
airflow
odoo16
helpdesk
info
itadmin
odoo18
Test
aaa
bigdata
btf
caddy
nsroot
puppet
usuario
dns
dolphin
sshd
angel
aryan
kingbase
nick
omsagent
pawel
rancher
admin2
esearch
fedora
lighthouse
payment
radio
titu
weewx
amp
miriam
vhserver
contabilidade
satisfactory
uucp
ds
prod
telecomadmin
victor
aman
console
grafana
api
drupal
thomas
ydy
mary
root2
sonarUser
debianuser
hadi
old
redhat
sync
tech
backend
elsearch
fa
gm
holu
testftp
testing
toni
zt
astra
bonus
cqrong
kubernetes
prueba
sakurai
1
123456
adrian
alireza
amit
auto
bitnami
loginuser
mega
mike
niaoyun
odoo12
packer
peter
qclinux
ranger
supervisor
admin1234
alin
clouduser
josue
mapr
orangepi
sean
administrador
albert
basit
builduser
hugo
nil
bbs
charles
desarrollo
esther
ftpadmin
joe
julian
latitude
raymond
sys
t
amine
ftp1
init
kali
linux
mark
vbox
anderson
hello
jonathan
oper
qw
rebecca
solr
ssm
vijay
vishal
dennis
edit
morteza
nikita
ryan
smart
sqlite
tl
xyh
abbas
abcd
abe
ajay
anton
bob
finance
installer
jerry
office
search
silas
student4
tv
worker
zookeeper
aria
ark
azure
csgo
geoserver
maria
roo
sc
telnet
anu
aovalle
bill
crafty
csgoserver
db2inst1
exam
ftp2
george
guest1
kodi
library
matrix
paul
pedro
splunk
sunil
amandabackup
clay
craft
ddd
el
elk
erp
hacluster
jim
kelly
lucas
mohamed
mongo
open
pablo
qwe
rose
sftp_user
ssh
test123
wanghao
webapp
zs
alan
ay
chris
cristi
denis
fabio
harry
hu
ivan
ldap
newadmin
pratik
rafael
rahul
sh
suporte
t128
test4
wujiawei
Cisco
aa
array
artem
asdf
carlos
comp
debug
federica
gmodserver
intern
log
maryam
min
ping
ricardo
webuser
yogi
zoom
ADMIN
adsl
arthur
belkinstyle
cacti
cassandra
castle
cf1c22
cs
fox
fs
ict
joggler
46400
9701
7095
6757
5825
3629
3570
2251
2230
2220
1805
1506
1328
1181
1121
1084
1076
849
824
807
771
728
676
579
548
486
481
474
473
469
453
451
431
422
411
408
407
401
392
390
378
375
356
353
350
344
325
318
318
311
308
307
296
295
287
285
275
272
268
267
266
261
261
261
254
249
249
247
244
242
237
229
229
227
227
224
222
216
213
213
207
201
201
201
199
198
189
188
188
187
187
185
182
180
176
170
169
168
166
164
162
161
157
156
156
154
154
152
151
149
147
146
146
145
144
143
142
142
141
140
140
139
134
133
132
132
129
129
128
128
127
126
124
122
122
121
121
121
121
121
120
119
118
117
117
116
115
114
114
114
114
113
112
111
106
106
105
100
97
96
95
95
95
95
95
92
92
92
90
90
90
89
89
88
86
85
85
84
83
83
82
81
81
81
80
80
79
78
77
77
77
77
76
76
76
75
75
74
73
73
72
72
70
70
69
68
68
68
67
66
65
63
61
60
60
59
59
59
59
59
59
58
58
58
58
58
57
57
57
56
56
55
55
55
55
55
54
54
54
54
53
53
53
53
52
52
51
50
50
50
49
49
49
49
49
49
48
48
47
47
47
46
46
46
46
46
46
46
45
45
45
45
45
45
45
45
44
44
44
43
43
43
42
42
42
42
41
41
41
40
40
40
40
39
39
39
38
38
38
38
38
38
37
37
37
37
37
37
37
37
37
36
36
36
36
36
36
35
35
35
35
35
35
35
35
35
35
35
35
35
35
35
35
35
34
34
34
34
34
34
34
33
33
33
33
33
33
32
32
32
32
32
32
32
32
32
32
32
31
31
31
31
31
31
31
30
30
30
30
30
30
30
30
30
30
29
29
29
29
29
29
29
29
29
28
28
28
28
28
28
28
28
28
28
28
28
28
28
28
28
27
27
27
27
27
27
27
27
27
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
25
24
24
24
24
24
24
24
24
24
24
24
24
24
24
24
24
24
24
24
23
23
23
23
23
23
23
23
23
23
23
23
23
23
23
23
23
23
23
22
22
22
22
22
22
22
22
22
22
22
22
22
123456
123
345gs5662d34
3245gs5662d34
password
admin

1234
12345678
P@ssw0rd
123123
ubuntu
12345
123456789
root
1
admin123
Password
passw0rd
alex
1234567
qwerty
test
1234567890
password1
abc123
P@ssw0rd123
111111
1q2w3e4r
p@ssw0rd
user
oracle
p@ssword
dell
123qwe
root123
Huawei@123
root@123
password123
123321
Qaz123qaz
Passw0rd
nPSpP4PBW0
Password123
ftppassword
postgres
welcome
abcd1234
Password123!
123@@@
Password1
Aa123456
Host:【IPアドレス】:23
P@ssw0rd1
P@ssw0rd@123
Password@123
1qaz2wsx
qwerty123
es2
letmein
adminHW
mysql
Password01
git
LeitboGi0ro
654321
pass
zhbjETuyMffoL8F
admin@123
guest
P@ssw0rd@2025
test123
dell@123
lenovo
lenovo@123
hadoop
Admin@123
pass123
12
password@123
1qaz@WSX
000000
123abc
1111
ubuntu@123
Password@2025
2glehe5t24th1issZs
abc123456
admin1234
Ahgf3487@rtjhskl854hd47893@#a4nC
Passw0rd@123
dell123
54321
123.com
root123456
changeme
qwe123
oracle123
sysadmin@1
abcd123
Huawei
Huawei123456
123qwerty
4321
huawei123
postgres123
wasd
a
0
123@Robert
huawei123!@#
admin1
root1
1234qwer
a123456
ftp
git123
ubnt
Accept-Encoding: gzip, deflate
Admin123
Huawei12#$
grid
321
111
centos
1q2w3e
debian
toor
foundry
qwer1234
Connection: keep-alive
test1234
PASSWORD
support
huawei
secret
abc1234
user123
1qazxsw2
ubuntu123
test@123
Diesel1982
root1234
server
default
mysql123
q1w2e3r4
!QAZ2wsx
raspberry
www
qwertyui
QWE123!@#qwe
hadoop123
root12
passwd
user123456
Admin@9000
ftpuser
adminadmin
ubuntu123456
——fuck——
test123456
123123123
666666
aa123456
cloud
operator
testuser
Accept: /
nginx
root12345
ubuntu123123
zabbix
Connection: close
dev
user1
anonymous
linux
root1234567
tomcat
1234.com
P@ssw0rd!
master
root123123
root123456789
test123123
oracle123456
password1!
root12345678
Lenovo@123
git123123
user123123
112233
1qazXSW@
Dell@123
demo
git123456
postgres123123
1q2!@#$%
mysql123456
redhat
xurros22$
P@ssword
hadoop123123
hadoop123456
mysql123123
oracle123123
postgres123456
deploy
Admin123456
Password1!
0000
123qwe!@#
ABCabc123
guest123
rootroot
ts
Aa123456@
Abc123
config
minecraft
test1
odin
a1234567
devops
odoo17
supportAtlanta
system
Aa112211.
administrator
dspace
ftp123
ftpguest
nagios
Abc1234
Password1234
pass1234
!Q2w3e4r
1!deshine
21
novinhost.org
1qaz!QAZ
docker
02041992Ionela%^&
Admin@1234
plex
tizi@123
09N1RCa1Hs31
11111111
987654321
Drag1823hcacatcuciocolataABC111
elastic
pulamea123
qwerty123456
qwerty@123
123qwe123
1qaz2wsx3edc
Admin1234
Qq123456
cisco123
nexus
testpass
555555
Dev@2025Dev@2025
Welcome@123
es
ftp_user@2025
Sugipula123$
bin
cisco
elasticsearch
ftpuser123
odoo
12341234
1Q2w3e4r
321start
dolphinscheduler
esuser
pwlamea123
jenkins
terraria
123qweasd
1qaz@wsx
7ujMko0admin123
Aa@123456
aA123456
nobody
nsroot
qq123456
vagrant
!Q@W3e4r
—fuck_you—-
159357
Zc123456
app
bot
es123456
gitlab
huawei@123
nvidia
odoo16
odoo18
q1w2e3
r00t
solana
sonar
steam123
teamspeak
vyos
123456a
A123456
Password123@
developer
m0n1t0r
steam
000
1234abcd
bigdata
hello
p@55w0rd
redis
squid
student
12qwaszx
1qaz2WSX
Admin2020!
abc12345
alpine
azerty
deploy123
idbteam
oscar
samba
888888
A123456a
Ab123456
Apple@123
angel
appuser
factorio
welcome1
1314520
admin01
luna
manager
tomcat@123
windows
123456qw
5201314
P@55w0rd
centreon
data
service
!1qaz2wsx
A@123456
a1234567!
click1
dev123456
dmdba
g
pgj-heu05HQM=bMvz
qazxswedc
qwe12#$
test2
1234!@#$
123456Qwe
1qaz@WSX3edc
8888888
Qw123456!
nginx123
pa55w0rd
password!
runner
user3
weblogic
123qwe!@
7777777
abc
adminuser
ansible
aryan123
fuckyou
gitlab-runner
guest1
helpdesk
jack
joy
miriam123
orangepi
password@321
pp
rancher
sakurai
tom
Test123
admintelecom
holu
p@ssw0rd!
palworld
pi
post123
qwe123@@
rocky
woaini
P@ssw0rd@1
asdf1234
changeme123
jito
oscar123
qwerty12
test321
M3gaP33!
P@ssw0rd!!
esearch
hope
kubernetes
qwertyuiop
sol
workwork
11111
agent
asterisk
devry
email@email.com
mike
qazxswedc`123
qwa123
vpnpass
0l0ctyQh243O63uD
123qweASD
Qwerty1
derok010101
11223344
Abcd1234
Voidsetdownload.so
abc@123
kafka
password@2025
sor123in
super
user2
username
159753
Passw0rd!
Password12345
frappe
testtest
6666
999999
@
Aa12345678
Bscs@2024
Ubuntu123
a123456A
abcdefg
basit
deployer
geoserver
kingbase
packer
qQ123456
qazwsx
qwe
web
00000
12344321
aB123456
adminpass
anonymous@
myuser
solana123
wang123
123456b
Welcome@1234
aa@123456
asd
david
latitude
qwe123!@#
toni
vpn123
zxcvbnm
!@#$%^
11
1234rewq!
128tRoutes
Aa123456~
aaa
hola1234
init
office
pa55word
pawel
q
88888888
Admin
Joysuch@Locate2023
P@$$w0rd
bitrix
dolphin
14402
7344
5825
5799
5031
3917
3118
1942
1690
1673
1597
1574
1535
1351
1203
1159
1055
1031
880
865
759
751
675
666
652
599
567
553
505
499
495
486
448
441
420
404
401
390
383
379
361
359
351
346
345
344
342
339
310
309
294
287
283
270
270
268
266
258
257
255
252
246
244
242
240
227
222
222
221
221
220
220
219
219
217
211
208
206
201
201
194
189
189
184
184
179
177
176
172
171
167
152
149
148
148
147
145
143
142
141
138
138
136
134
133
133
131
129
128
128
128
126
124
123
123
123
120
120
119
119
119
118
116
115
115
114
114
114
112
111
110
109
106
105
104
104
103
102
100
96
95
94
94
93
90
90
90
88
88
87
86
85
83
83
82
82
80
80
79
79
78
78
75
75
75
75
75
75
74
74
74
74
74
73
73
73
72
72
72
72
71
71
71
71
71
71
70
70
70
69
69
69
68
68
68
68
68
68
67
67
67
67
66
66
66
66
66
66
64
62
62
61
61
61
61
61
61
60
60
60
60
60
59
58
58
58
58
58
57
57
57
57
57
57
56
56
56
55
55
55
55
54
54
53
53
53
53
52
52
52
51
51
51
51
51
50
50
50
50
50
50
50
49
49
49
49
49
48
48
48
48
48
48
47
47
47
47
47
47
46
46
45
45
45
45
44
44
44
44
44
43
43
43
43
43
43
43
43
43
43
43
43
43
43
43
43
43
43
43
42
42
42
42
42
42
41
41
41
41
41
41
41
41
40
40
40
40
40
40
40
40
40
40
39
39
39
39
39
39
39
39
38
38
38
38
38
38
37
37
37
37
37
37
36
36
36
36
36
36
36
36
36
36
36
35
35
35
35
35
35
35
35
35
35
35
34
34
34
34
34
34
34
34
34
34
34
34
34
34
34
34
34
34
34
33
33
33
33
33
33
33
33
33
33
32
32
32
32
32
32
32
31
31
31
31
31
31
31
31
30
30
30
30
30
30
30
30
30
29
29
29
29
28
28
28
28
28
28
28
28
28
28
27
27
27
27
27
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
26
25
25
25
25
25
25
25
25
24
24
24
24
24
24
24
24
24
24
23
23
23
23
23
23
23
23
23
23
23
23
22
22
22
22
22
22

コメント