[root@biologicalamount:/data/cowrie/log]# cat cowrie.json | egrep "(153\.231\.215\.1[1-4]|153\.231\.216\.179|153\.231\.216\.18[0-2]|153\.231\.216\.18[7-9]|153\.231\.216\.190|153\.231\.216\.219|153\.231\.216\.22[0-2])"
{"eventid": "cowrie.session.connect", "src_ip": "153.231.215.13", "src_port": 47286, "timestamp": "2019-03-13T09:09:22.590887Z", "message": "New connection: 153.231.215.13:47286 (172.29.0.2:22) [session: a020e68d6fe7]", "dst_ip": "172.29.0.2", "system": "cowrie.ssh.factory.CowrieSSHFactory", "protocol": "ssh", "isError": 0, "session": "a020e68d6fe7", "dst_port": 22, "sensor": "4ee2d0f61953"}
{"macCS": ["hmac-sha1", "hmac-sha1-96", "hmac-md5", "hmac-md5-96", "hmac-ripemd160", "hmac-ripemd160@openssh.com"], "session": "a020e68d6fe7", "kexAlgs": ["diffie-hellman-group14-sha1", "diffie-hellman-group-exchange-sha1", "diffie-hellman-group1-sha1"], "message": "Remote SSH version: SSH-2.0-libssh2_1.4.3", "system": "HoneyPotSSHTransport,1469,153.231.215.13", "src_ip": "153.231.215.13", "version": "SSH-2.0-libssh2_1.4.3", "sensor": "4ee2d0f61953", "eventid": "cowrie.client.version", "timestamp": "2019-03-13T09:09:22.628323Z", "keyAlgs": ["ssh-rsa", "ssh-dss"], "isError": 0, "compCS": ["none"], "encCS": ["aes128-ctr", "aes192-ctr", "aes256-ctr", "aes256-cbc", "rijndael-cbc@lysator.liu.se", "aes192-cbc", "aes128-cbc", "blowfish-cbc", "arcfour128", "arcfour", "cast128-cbc", "3des-cbc"]}
{"eventid": "cowrie.login.failed", "username": "root", "timestamp": "2019-03-13T09:09:22.948849Z", "message": "login attempt [root/xc3511] failed", "system": "SSHService 'ssh-userauth' on HoneyPotSSHTransport,1469,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "session": "a020e68d6fe7", "password": "xc3511", "sensor": "4ee2d0f61953"}
{"eventid": "cowrie.session.closed", "timestamp": "2019-03-13T09:09:23.995059Z", "message": "Connection lost after 1 seconds", "system": "HoneyPotSSHTransport,1469,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "duration": 1.4031720161437988, "session": "a020e68d6fe7", "sensor": "4ee2d0f61953"}
{"eventid": "cowrie.session.connect", "src_ip": "153.231.215.13", "src_port": 47510, "timestamp": "2019-03-13T09:10:24.133492Z", "message": "New connection: 153.231.215.13:47510 (172.29.0.2:22) [session: 3ae14ca22d67]", "dst_ip": "172.29.0.2", "system": "cowrie.ssh.factory.CowrieSSHFactory", "protocol": "ssh", "isError": 0, "session": "3ae14ca22d67", "dst_port": 22, "sensor": "4ee2d0f61953"}
{"macCS": ["hmac-sha1", "hmac-sha1-96", "hmac-md5", "hmac-md5-96", "hmac-ripemd160", "hmac-ripemd160@openssh.com"], "session": "3ae14ca22d67", "kexAlgs": ["diffie-hellman-group14-sha1", "diffie-hellman-group-exchange-sha1", "diffie-hellman-group1-sha1"], "message": "Remote SSH version: SSH-2.0-libssh2_1.4.3", "system": "HoneyPotSSHTransport,1473,153.231.215.13", "src_ip": "153.231.215.13", "version": "SSH-2.0-libssh2_1.4.3", "sensor": "4ee2d0f61953", "eventid": "cowrie.client.version", "timestamp": "2019-03-13T09:10:24.183258Z", "keyAlgs": ["ssh-rsa", "ssh-dss"], "isError": 0, "compCS": ["none"], "encCS": ["aes128-ctr", "aes192-ctr", "aes256-ctr", "aes256-cbc", "rijndael-cbc@lysator.liu.se", "aes192-cbc", "aes128-cbc", "blowfish-cbc", "arcfour128", "arcfour", "cast128-cbc", "3des-cbc"]}
{"eventid": "cowrie.login.success", "username": "root", "timestamp": "2019-03-13T09:10:24.485131Z", "message": "login attempt [root/vizxv] succeeded", "system": "SSHService 'ssh-userauth' on HoneyPotSSHTransport,1473,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "session": "3ae14ca22d67", "password": "vizxv", "sensor": "4ee2d0f61953"}
{"eventid": "cowrie.log.open", "ttylog": "log/tty/20190313-091024-3ae14ca22d67-0i.log", "timestamp": "2019-03-13T09:10:24.905866Z", "message": "Opening TTY Log: log/tty/20190313-091024-3ae14ca22d67-0i.log", "system": "SSHChannel session (0) on SSHService 'ssh-connection' on HoneyPotSSHTransport,1473,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "session": "3ae14ca22d67", "sensor": "4ee2d0f61953"}
{"eventid": "cowrie.session.params", "timestamp": "2019-03-13T09:10:24.913387Z", "sensor": "4ee2d0f61953", "system": "SSHChannel session (0) on SSHService 'ssh-connection' on HoneyPotSSHTransport,1473,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "session": "3ae14ca22d67", "arch": "linux-x64-lsb", "message": []}
{"eventid": "cowrie.command.input", "timestamp": "2019-03-13T09:10:24.967074Z", "message": "CMD: echo foo", "system": "SSHChannel session (0) on SSHService 'ssh-connection' on HoneyPotSSHTransport,1473,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "session": "3ae14ca22d67", "input": "echo foo", "sensor": "4ee2d0f61953"}
{"eventid": "cowrie.log.closed", "timestamp": "2019-03-13T09:10:25.014073Z", "message": "Closing TTY Log: log/tty/20190313-091024-3ae14ca22d67-0i.log after 0 seconds", "ttylog": "log/tty/20190313-091024-3ae14ca22d67-0i.log", "system": "SSHChannel session (0) on SSHService 'ssh-connection' on HoneyPotSSHTransport,1473,153.231.215.13", "src_ip": "153.231.215.13", "session": "3ae14ca22d67", "duration": 0.10831880569458008, "sensor": "4ee2d0f61953", "isError": 0, "size": 342}
{"eventid": "cowrie.session.closed", "timestamp": "2019-03-13T09:10:25.113628Z", "message": "Connection lost after 0 seconds", "system": "HoneyPotSSHTransport,1473,153.231.215.13", "isError": 0, "src_ip": "153.231.215.13", "duration": 0.9793009757995605, "session": "3ae14ca22d67", "sensor": "4ee2d0f61953"}
~以下略~