Advertisement
bontchev

Cowrie JSON log (Hajime)

Feb 4th, 2017
346
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
JSON 9.53 KB | None | 0 0
  1. {"eventid": "cowrie.session.connect", "timestamp": "2017-02-04T14:55:39.501787Z", "session": "df4eb841", "message": "New connection: 2.177.161.222:58379 (192.168.0.102:23) [session: TT1021]", "src_port": 58379, "system": "cowrie.telnet.transport.HoneyPotTelnetFactory", "isError": 0, "src_ip": "2.177.161.222", "dst_port": 23, "dst_ip": "192.168.0.102", "sensor": "vesselin-pc"}
  2. {"eventid": "cowrie.login.failed", "username": "Administrator", "timestamp": "2017-02-04T14:55:40.701137Z", "message": "login attempt [Administrator/admin] failed", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "password": "admin", "sensor": "vesselin-pc"}
  3. {"eventid": "cowrie.login.success", "username": "root", "timestamp": "2017-02-04T14:55:41.596937Z", "message": "login attempt [root/user] succeeded", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "password": "user", "sensor": "vesselin-pc"}
  4. {"eventid": "cowrie.log.open", "timestamp": "2017-02-04T14:55:42.177782Z", "message": "Opening TTY Log: log/tty/20170204-165542-None-1021i.log", "ttylog": "log/tty/20170204-165542-None-1021i.log", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "sensor": "vesselin-pc"}
  5. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:42.854702Z", "message": "CMD: enable", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "enable", "sensor": "vesselin-pc"}
  6. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:42.855941Z", "message": "Command found: enable ", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "enable ", "sensor": "vesselin-pc"}
  7. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:42.857661Z", "message": "CMD: shell", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "shell", "sensor": "vesselin-pc"}
  8. {"eventid": "cowrie.command.failed", "timestamp": "2017-02-04T14:55:42.858993Z", "message": "Command not found: shell", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "shell", "sensor": "vesselin-pc"}
  9. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:42.860285Z", "message": "CMD: sh", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "sh", "sensor": "vesselin-pc"}
  10. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:42.861435Z", "message": "Command found: sh ", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "sh ", "sensor": "vesselin-pc"}
  11. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:43.160565Z", "message": "CMD: cat /proc/mounts; /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cat /proc/mounts; /bin/busybox GTWRY", "sensor": "vesselin-pc"}
  12. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.162041Z", "message": "Command found: cat /proc/mounts", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cat /proc/mounts", "sensor": "vesselin-pc"}
  13. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.163585Z", "message": "Command found: /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "/bin/busybox GTWRY", "sensor": "vesselin-pc"}
  14. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:43.471431Z", "message": "CMD: cd /dev/shm; (cat .s || cp /bin/echo .s); /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cd /dev/shm; (cat .s || cp /bin/echo .s); /bin/busybox GTWRY", "sensor": "vesselin-pc"}
  15. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.472933Z", "message": "Command found: cd /dev/shm", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cd /dev/shm", "sensor": "vesselin-pc"}
  16. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.474667Z", "message": "Command found: cat .s", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cat .s", "sensor": "vesselin-pc"}
  17. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.476165Z", "message": "Command found: cp /bin/echo .s", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cp /bin/echo .s", "sensor": "vesselin-pc"}
  18. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.477563Z", "message": "Command found: /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "/bin/busybox GTWRY", "sensor": "vesselin-pc"}
  19. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:43.778834Z", "message": "CMD: nc; wget; /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "nc; wget; /bin/busybox GTWRY", "sensor": "vesselin-pc"}
  20. {"eventid": "cowrie.command.failed", "timestamp": "2017-02-04T14:55:43.780255Z", "message": "Command not found: nc", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "nc", "sensor": "vesselin-pc"}
  21. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.781303Z", "message": "Command found: wget ", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "wget ", "sensor": "vesselin-pc"}
  22. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:43.782616Z", "message": "Command found: /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "/bin/busybox GTWRY", "sensor": "vesselin-pc"}
  23. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:44.077425Z", "message": "CMD: (dd bs=52 count=1 if=.s || cat .s)", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "(dd bs=52 count=1 if=.s || cat .s)", "sensor": "vesselin-pc"}
  24. {"eventid": "cowrie.command.failed", "timestamp": "2017-02-04T14:55:44.078930Z", "message": "Command not found: dd bs=52 count=1 if=.s", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "dd bs=52 count=1 if=.s", "sensor": "vesselin-pc"}
  25. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:44.080057Z", "message": "Command found: cat /dev/shm/.s", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "cat /dev/shm/.s", "sensor": "vesselin-pc"}
  26. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:44.374819Z", "message": "CMD: /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "/bin/busybox GTWRY", "sensor": "vesselin-pc"}
  27. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:44.376101Z", "message": "Command found: /bin/busybox GTWRY", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "/bin/busybox GTWRY", "sensor": "vesselin-pc"}
  28. {"eventid": "cowrie.command.input", "timestamp": "2017-02-04T14:55:44.378578Z", "message": "CMD: rm .s; exit", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "rm .s; exit", "sensor": "vesselin-pc"}
  29. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:44.379764Z", "message": "Command found: rm /dev/shm/.s", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "rm /dev/shm/.s", "sensor": "vesselin-pc"}
  30. {"eventid": "cowrie.command.success", "timestamp": "2017-02-04T14:55:44.380803Z", "message": "Command found: exit ", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "session": "df4eb841", "input": "exit ", "sensor": "vesselin-pc"}
  31. {"eventid": "cowrie.log.closed", "timestamp": "2017-02-04T14:55:44.706633Z", "message": "Closing TTY Log: log/tty/20170204-165542-None-1021i.log after 2 seconds", "ttylog": "log/tty/20170204-165542-None-1021i.log", "system": "CowrieTelnetTransport,1021,2.177.161.222", "src_ip": "2.177.161.222", "session": "df4eb841", "duration": 2.529057025909424, "sensor": "vesselin-pc", "isError": 0, "size": 81068}
  32. {"eventid": "cowrie.session.closed", "timestamp": "2017-02-04T14:55:44.708136Z", "message": "Connection lost after 5 seconds", "system": "CowrieTelnetTransport,1021,2.177.161.222", "isError": 0, "src_ip": "2.177.161.222", "duration": 5.206450939178467, "session": "df4eb841", "sensor": "vesselin-pc"}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement