Yesterday I deliberately exposed an HTTP server in my home computer to see how much botnets around the world wouldn't care. Here are the results so far.
Code:
191.103.217.125 - - [13/Sep/2021:15:13:27 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7
37.0.10.12 - - [13/Sep/2021:16:43:31 -0300] "GET / HTTP/1.1" 200 674 - Linux Gnu (cow)
183.136.225.56 - - [13/Sep/2021:19:00:56 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0
49.156.32.184 - - [13/Sep/2021:19:35:01 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
185.142.236.40 - - [13/Sep/2021:19:51:18 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
185.142.236.40 - - [13/Sep/2021:19:51:20 -0300] "GET /robots.txt HTTP/1.1" 200 362 - -
185.142.236.40 - - [13/Sep/2021:19:51:21 -0300] "GET /sitemap.xml HTTP/1.1" 404 313 - -
185.142.236.40 - - [13/Sep/2021:19:51:22 -0300] "GET /.well-known/security.txt HTTP/1.1" 404 313 - -
185.142.236.40 - - [13/Sep/2021:19:51:23 -0300] "GET /favicon.ico HTTP/1.1" 404 313 - Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
34.79.68.246 - - [13/Sep/2021:19:51:28 -0300] "GET / HTTP/1.1" 200 679 - python-requests/2.26.0
183.136.225.14 - - [13/Sep/2021:22:56:52 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0
183.136.225.14 - - [13/Sep/2021:22:58:05 -0300] "GET /favicon.ico HTTP/1.1" 404 313 - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
183.136.225.14 - - [13/Sep/2021:22:58:05 -0300] "GET /robots.txt HTTP/1.1" 200 357 - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
163.158.170.241 - - [13/Sep/2021:23:24:00 -0300] "GET / HTTP/1.0" 200 674 - -
121.159.237.113 - - [14/Sep/2021:00:48:03 -0300] "GET / HTTP/1.0" 200 679 - Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)
107.189.14.98 - - [14/Sep/2021:01:52:55 -0300] "GET / HTTP/1.1" 200 674 - Linux Gnu (cow)
103.227.118.97 - - [14/Sep/2021:02:36:36 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
125.26.158.214 - - [14/Sep/2021:03:05:59 -0300] "GET / HTTP/1.1" 200 679 - -
178.73.215.171 - - [14/Sep/2021:03:26:15 -0300] "GET / HTTP/1.0" 200 674 - -
54.151.23.84 - - [14/Sep/2021:03:59:33 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 zgrab/0.x
222.77.181.28 - - [14/Sep/2021:04:10:46 -0300] "GET / HTTP/1.1" 200 674 - Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
192.241.215.140 - - [14/Sep/2021:04:26:59 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 zgrab/0.x
123.205.106.96 - - [14/Sep/2021:04:28:56 -0300] "GET / HTTP/1.1" 200 679 - -
14.102.19.150 - - [14/Sep/2021:05:52:24 -0300] "GET / HTTP/1.1" 200 679 - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
34.79.68.246 - - [14/Sep/2021:05:56:55 -0300] "GET / HTTP/1.1" 200 679 - python-requests/2.26.0
107.189.14.98 - - [14/Sep/2021:06:10:38 -0300] "GET / HTTP/1.1" 200 674 - Linux Gnu (cow)
79.148.249.2 - - [14/Sep/2021:07:06:36 -0300] "GET / HTTP/1.0" 200 674 - -
I'm sure an SSH honeypot would be even more fun!
Bookmarks