id: dionaea-http-honeypot-detect info: name: Dionaea HTTP Honeypot - Detect author: UnaPibaGeek severity: info description: | Dionaea HTTP honeypot has been identified. The response to an incorrect HTTP method reveals a possible setup of the Dioanea web application honeypot. metadata: max-request: 1 vendor: dionaea product: http tags: dionaea,honeypot,ir,cti http: - raw: - | AAAA / HTTP/1.1 Host: {{Hostname}} unsafe: true matchers-condition: and matchers: - type: status status: - 501 - type: word part: header words: - "nginx" - type: word part: body words: - '' # digest: 4a0a00473045022100882cfcbeb68848cd81c48a8170dc7d171efe8a06229a294f1a29f37ffa786b0002205a67f53fbd5246db953b5753bda9896c9b4ca9d7dd2c52ad8647de3781195d53:922c64590222798bb761d5b6d8e72950