Skip to content

Instantly share code, notes, and snippets.

@gnh1201
Created August 25, 2022 03:35
Show Gist options
  • Save gnh1201/4e7c6e2c06e7b093dadcf7700b87bc4f to your computer and use it in GitHub Desktop.
Save gnh1201/4e7c6e2c06e7b093dadcf7700b87bc4f to your computer and use it in GitHub Desktop.
api.tistory.us honeypot
172.70.222.28 - - [25/Aug/2022:00:18:24 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.yega.co.kr/index.php" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
143.92.32.36 - - [25/Aug/2022:00:45:51 +0900] "GET /v82991.html HTTP/1.1" 404 199 "https://m.sm.cn/s?q=www.zkhyy.com&from=smor&safe=1&snum=0" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.81 YisouSpider/5.0 Safari/537.36"
172.70.233.44 - - [25/Aug/2022:00:56:21 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/board.php?bo_table=music&wr_id=2" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
172.68.118.130 - - [25/Aug/2022:01:36:48 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dongha.net/index.php" "Mozilla/5.0 (compatible; SEOkicks; +https://www.seokicks.de/robot.html)"
172.68.118.130 - - [25/Aug/2022:01:44:59 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://dicafamily.com/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
172.70.122.144 - - [25/Aug/2022:01:45:37 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dicafamily.com/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
172.70.122.194 - - [25/Aug/2022:01:47:24 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.caexport.co.kr/index.htm" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
172.70.222.28 - - [25/Aug/2022:02:00:03 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basic.mraon.com/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.222.194 - - [25/Aug/2022:02:16:17 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://seso.co.kr/index.html" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
162.158.118.36 - - [25/Aug/2022:02:27:59 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.seso.co.kr/index.html" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.233.168 - - [25/Aug/2022:02:34:52 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/board.php?bo_table=movie" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
172.70.49.166 - - [25/Aug/2022:02:43:12 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.basicbooks.co.kr/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.68.118.130 - - [25/Aug/2022:02:46:24 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dongha.net/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
172.70.233.60 - - [25/Aug/2022:03:13:33 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/bbs/board.php?bcode=movie&wr_id=3" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
172.70.233.142 - - [25/Aug/2022:03:35:21 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://smwc.mraon.com/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.233.60 - - [25/Aug/2022:03:38:49 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/write.php?w=r&bo_table=product_introduce&wr_id=9&page=2" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
172.70.122.194 - - [25/Aug/2022:03:48:47 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.yega.co.kr/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
27.150.190.96 - - [25/Aug/2022:03:58:20 +0900] "GET http://49.247.146.99:80/mysql/scripts/setup.php HTTP/1.0" 404 169 "-" "-"
27.150.190.96 - - [25/Aug/2022:03:58:20 +0900] "GET http://49.247.146.99:80/pma/scripts/setup.php HTTP/1.0" 404 169 "-" "-"
27.150.190.96 - - [25/Aug/2022:03:58:20 +0900] "GET http://49.247.146.99:80/phpMyAdmin/scripts/setup.php HTTP/1.0" 404 169 "-" "-"
172.70.49.204 - - [25/Aug/2022:04:53:10 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/board.php?bo_table=music&wr_id=4" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
162.158.118.70 - - [25/Aug/2022:05:00:17 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://www.smwc.or.kr/" "mozilla/5.0 (compatible; ahrefsbot/7.0; +http://ahrefs.com/robot/)"
172.70.233.142 - - [25/Aug/2022:05:11:15 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/bbs/kcaptcha_image.php?t=1658793600056" "googlebot-image/1.0"
45.61.185.39 - - [25/Aug/2022:05:21:35 +0900] "POST /boaform/admin/formLogin HTTP/1.1" 404 143 "http://49.247.146.99:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0"
172.68.118.130 - - [25/Aug/2022:05:24:57 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basicbooks.co.kr/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.233.168 - - [25/Aug/2022:05:32:59 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/bbs/board.php?bcode=google&page=1" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
162.158.118.36 - - [25/Aug/2022:05:58:32 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.seso.co.kr/index.html" "Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+https://webmaster.petalsearch.com/site/petalbot)"
172.70.233.168 - - [25/Aug/2022:06:05:42 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://www.smwc.or.kr/" "mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.68.118.130 - - [25/Aug/2022:06:20:14 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://e-planet.co.kr/index.htm" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
172.70.233.60 - - [25/Aug/2022:06:52:05 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://www.smwc.or.kr/" "mozilla/5.0 (compatible; yandexbot/3.0; +http://yandex.com/bots)"
162.158.118.30 - - [25/Aug/2022:06:54:04 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://www.smwc.or.kr/" "mozilla/5.0 (compatible; yandexbot/3.0; +http://yandex.com/bots)"
172.68.118.130 - - [25/Aug/2022:06:58:15 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://seso.co.kr/index.html" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.122.168 - - [25/Aug/2022:07:24:27 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://smwc.or.kr/" "mozilla/5.0 (compatible; ahrefsbot/7.0; +http://ahrefs.com/robot/)"
172.70.233.142 - - [25/Aug/2022:07:26:26 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/bbs/kcaptcha_image.php?t=1658102400052" "googlebot-image/1.0"
172.70.222.116 - - [25/Aug/2022:07:27:05 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://yega.co.kr/index.php" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.222.28 - - [25/Aug/2022:07:39:03 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://yega.co.kr/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
162.158.118.186 - - [25/Aug/2022:07:54:18 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.e-planet.co.kr/index.htm" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
172.70.233.60 - - [25/Aug/2022:07:55:52 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/board.php?bo_table=google&wr_id=2" "mozilla/5.0 (linux; android 7.0;) applewebkit/537.36 (khtml, like gecko) mobile safari/537.36 (compatible; petalbot;+https://webmaster.petalsearch.com/site/petalbot)"
172.68.118.106 - - [25/Aug/2022:08:05:35 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dongha.net/index.php" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.222.194 - - [25/Aug/2022:08:13:38 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.yega.co.kr/index.php" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.68.118.130 - - [25/Aug/2022:08:21:08 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://smwc.or.kr/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
162.158.118.44 - - [25/Aug/2022:08:47:46 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://caexport.co.kr/index.htm" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36"
172.70.222.28 - - [25/Aug/2022:08:49:05 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://landp.co.kr/index.html" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.223.7 - - [25/Aug/2022:08:51:03 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.yega.co.kr/index.php" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36"
172.70.233.142 - - [25/Aug/2022:09:02:46 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basicbooks.co.kr/" "mozilla/5.0 (linux; android 6.0.1; nexus 5x build/mmb29p) applewebkit/537.36 (khtml, like gecko) chrome/104.0.5112.79 mobile safari/537.36 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.70.233.44 - - [25/Aug/2022:09:22:52 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/m/bbs/board.php?bo_table=movie&wr_id=4&page=" "mozilla/5.0 (linux; android 6.0.1; nexus 5x build/mmb29p) applewebkit/537.36 (khtml, like gecko) chrome/104.0.5112.79 mobile safari/537.36 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.70.233.168 - - [25/Aug/2022:09:30:41 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://smwc.or.kr/" "mozilla/5.0 (compatible; yandexbot/3.0; +http://yandex.com/bots)"
172.70.222.116 - - [25/Aug/2022:09:31:05 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://dicafamily.com/index.php" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.222.194 - - [25/Aug/2022:09:34:42 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dicafamily.com/index.php" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.79 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.122.96 - - [25/Aug/2022:09:48:13 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basicbooks.co.kr/" "mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.68.118.44 - - [25/Aug/2022:09:48:13 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basicbooks.co.kr/" "mozilla/5.0 (linux; android 6.0.1; nexus 5x build/mmb29p) applewebkit/537.36 (khtml, like gecko) chrome/99.0.4844.84 mobile safari/537.36 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.68.118.130 - - [25/Aug/2022:10:21:06 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.landp.co.kr/index.html" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.79 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
172.70.122.168 - - [25/Aug/2022:11:09:01 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://dongha.net/index.php" "Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
172.70.122.96 - - [25/Aug/2022:11:10:30 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://dongha.net/index.php" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)"
172.70.222.28 - - [25/Aug/2022:11:29:24 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dongha.net/index.php" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.79 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
162.158.118.128 - - [25/Aug/2022:11:32:05 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dicafamily.com/index.php" "Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
172.70.233.142 - - [25/Aug/2022:11:35:07 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://basic.mraon.com/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.233.26 - - [25/Aug/2022:11:36:52 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://kdy.raonweb.com/bbs/board.php?bo_table=intra_human" "mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)"
172.70.223.7 - - [25/Aug/2022:11:43:27 +0900] "GET /entry.php HTTP/1.1" 200 9 "https://www.smwc.or.kr/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
162.158.118.44 - - [25/Aug/2022:11:51:08 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://seso.co.kr/index.html" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.222.194 - - [25/Aug/2022:11:51:52 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.dongha.net/index.php" "Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
172.68.118.106 - - [25/Aug/2022:12:02:29 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.seso.co.kr/index.html" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.223.7 - - [25/Aug/2022:12:17:46 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://www.basicbooks.co.kr/" "mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"
172.70.222.116 - - [25/Aug/2022:12:28:42 +0900] "GET /entry.php HTTP/1.1" 200 9 "http://dongha.net/index.php" "Sogou web spider/4.0(+http://www.sogou.com/docs/help/webmasters.htm#07)"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment