????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex241018.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 02:32:14 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 02:32:14 103.153.214.94 HEAD /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 15 2024-10-18 02:32:14 103.153.214.94 HEAD /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 24 2024-10-18 02:32:14 103.153.214.94 HEAD /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 25 2024-10-18 02:32:14 103.153.214.94 POST /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=323afe3a-39d5-4061-9916-f98804ce12c1;op=Sync - 200 0 0 429 2024-10-18 02:32:14 103.153.214.94 POST /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 533 2024-10-18 02:32:14 103.153.214.94 HEAD /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 7 2024-10-18 02:33:06 103.153.214.94 POST /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 51348 2024-10-18 02:33:06 103.153.214.94 POST /msdeploy.axd Site=gdnn.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=323afe3a-39d5-4061-9916-f98804ce12c1;op=Sync - 200 0 0 51324 2024-10-18 02:40:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 10 2024-10-18 02:40:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 23 2024-10-18 02:40:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 18 2024-10-18 02:40:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 420 2024-10-18 02:40:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=fa88be12-8192-4335-9603-1771cd0cd292;op=Sync - 200 0 0 372 2024-10-18 02:40:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 9 2024-10-18 02:41:33 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=fa88be12-8192-4335-9603-1771cd0cd292;op=Sync - 200 0 0 77534 2024-10-18 02:41:33 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 77563 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 03:06:08 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 03:06:08 103.153.214.94 GET /Admin - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4.1+Safari/605.1.54 - 404 7 0 212 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 04:15:34 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 04:15:34 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 14 2024-10-18 04:15:34 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 26 2024-10-18 04:15:34 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 34 2024-10-18 04:15:34 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=63780d1d-8457-4a64-bc45-db3a41942332;op=Sync - 200 0 0 397 2024-10-18 04:15:34 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 493 2024-10-18 04:15:34 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 9 2024-10-18 04:16:52 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 77554 2024-10-18 04:16:52 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=63780d1d-8457-4a64-bc45-db3a41942332;op=Sync - 200 0 0 77543 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 04:38:15 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 04:38:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 21 2024-10-18 04:38:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 24 2024-10-18 04:38:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 20 2024-10-18 04:38:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 408 2024-10-18 04:38:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=1d4000ed-0d86-4fc1-adb9-3720873d1887;op=Sync - 200 0 0 348 2024-10-18 04:38:15 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 9 2024-10-18 04:39:33 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=1d4000ed-0d86-4fc1-adb9-3720873d1887;op=Sync - 200 0 0 77627 2024-10-18 04:39:33 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 77670 2024-10-18 04:45:27 103.153.214.94 GET /api/ping count=5&host=;cat%20/etc/passwd;&port=80&source=1.1.1.1&type=icmp 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/95.0.4638.54+Safari/537.36 - 404 7 0 210 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 06:22:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 06:22:44 103.153.214.94 POST /mifs/.;/services/LogService - 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/119.0 https://bcvt.kontum.gov.vn:8172 404 7 0 216 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 06:53:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 06:53:49 103.153.214.94 GET / - 8172 - 147.185.133.67 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 286 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 07:57:47 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 07:57:47 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 27 2024-10-18 07:57:47 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 35 2024-10-18 07:57:47 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 17 2024-10-18 07:57:47 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=bd79307d-b8cb-4aca-bd93-f6522ab5b26c;op=Sync - 200 0 0 354 2024-10-18 07:57:47 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 442 2024-10-18 07:57:47 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 11 2024-10-18 07:59:05 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=bd79307d-b8cb-4aca-bd93-f6522ab5b26c;op=Sync - 200 0 0 77371 2024-10-18 07:59:05 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 77413 2024-10-18 08:02:48 103.153.214.94 GET /wp-content/plugins/chatbot-chatgpt/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Kubuntu;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/123.0.0.0+Safari/537.36 - 404 7 0 210 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 08:41:25 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 08:41:25 103.153.214.94 HEAD /msdeploy.axd Site=yte.nextform.vn 8172 - 119.82.130.75 - - 401 2 5 14 2024-10-18 08:41:25 103.153.214.94 HEAD /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 - - 200 0 0 33 2024-10-18 08:41:25 103.153.214.94 HEAD /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 - - 200 0 0 23 2024-10-18 08:41:25 103.153.214.94 POST /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=7db6de6d-f965-4ef8-bf12-42c2d5af8218;op=Sync - 200 0 0 494 2024-10-18 08:41:25 103.153.214.94 POST /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 - - 200 0 0 596 2024-10-18 08:41:25 103.153.214.94 HEAD /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 - - 200 0 0 14 2024-10-18 08:42:28 103.153.214.94 POST /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=7db6de6d-f965-4ef8-bf12-42c2d5af8218;op=Sync - 200 0 0 62249 2024-10-18 08:42:28 103.153.214.94 POST /msdeploy.axd Site=yte.nextform.vn 8172 jenkins 119.82.130.75 - - 200 0 0 62299 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 09:43:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 09:43:09 103.153.214.94 GET /wp-content/plugins/cardoza-ajax-search/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4.1+Safari/605.7.24 - 404 7 0 225 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 11:21:58 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 11:21:58 103.153.214.94 GET /wp-content/plugins/UNKNOWN-CVE-2024-30226-1/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4+Safari/605.1.15 - 404 7 0 240 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 12:54:38 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 12:54:38 103.153.214.94 GET /about_state - 8172 - 107.189.28.251 Mozilla/5.0+(Ubuntu;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/125.0.0.0+Safari/537.36 - 404 7 0 225 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 15:02:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 15:02:56 103.153.214.94 GET /wp-content/plugins/nmedia-user-file-uploader/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Ubuntu;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/127.0.0.0+Safari/537.36 - 404 7 0 215 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 16:14:18 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 16:14:18 103.153.214.94 GET / - 8172 - 35.203.211.56 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 279 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 16:53:03 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 16:53:03 103.153.214.94 POST /user/login/checkPermit - 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0,+Win64,+x64,+rv:128.0)+Gecko/20100101+Firefox/128.0 - 404 7 0 223 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 18:36:18 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 18:36:18 103.153.214.94 GET /wp-content/plugins/cforms2/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.5+Safari/605.1.26 - 404 7 0 227 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 20:16:57 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 20:16:57 103.153.214.94 GET /wp-content/themes/appius/style.css - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4.1+Safari/605.6.27 - 404 7 0 211 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 21:11:54 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 21:11:54 103.153.214.94 GET / - 8172 - 167.94.138.38 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 404 7 0 299 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 21:50:43 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 21:50:43 103.153.214.94 GET / - 8172 - 157.230.244.205 Mozilla/5.0+(SS;+Linux+i686;+rv:120.0)+Gecko/20100101+Firefox/120.0 - 404 7 0 62 2024-10-18 21:58:21 103.153.214.94 GET /wp-content/plugins/mail-masta/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Knoppix;+Linux+x86_64;+rv:124.0)+Gecko/20100101+Firefox/124.0 - 404 7 0 226 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-10-18 23:36:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-10-18 23:36:51 103.153.214.94 GET /wp-content/plugins/metform/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Kubuntu;+Linux+x86_64;+rv:120.0)+Gecko/20100101+Firefox/120.0 - 404 7 0 227