id: dionaea-http-honeypot-detect info: name: Dionaea HTTP Honeypot - Detect author: UnaPibaGeek severity: info description: | Dionaea HTTP honeypot has been identified. The response to an incorrect HTTP method reveals a possible setup of the Dioanea web application honeypot. metadata: max-request: 1 vendor: dionaea product: http tags: dionaea,honeypot,ir,cti http: - raw: - | AAAA / HTTP/1.1 Host: {{Hostname}} unsafe: true matchers-condition: and matchers: - type: status status: - 501 - type: word part: header words: - "nginx" - type: word part: body words: - '' # digest: 4a0a0047304502204845c6f76cf7d6627f48ac9616242b173361e5fdcd62f859968af7f28ee6a71e022100cfc357166073926ec2e6d6fa94129f82915a8a708f11d5b0e9559ffcb20dc58f:922c64590222798bb761d5b6d8e72950