????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex241125.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 00:15:47 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 00:15:47 103.153.214.94 POST /directdata/direct/router - 8172 - 107.189.28.251 Mozilla/5.0+(ZZ;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/121.0.0.0+Safari/537.36 - 404 7 0 219 2024-11-25 00:15:47 103.153.214.94 GET /2pJi0zUWqjmi3v4c5GRwBr8T0HC.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.5+Safari/605.4.26 - 404 7 0 213 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 01:56:35 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 01:56:35 103.153.214.94 GET /wp-content/plugins/wp-all-import/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+14_4_1)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.3.1+Safari/605.1.15 - 404 7 0 725 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 03:00:31 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 03:00:31 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 - 58.186.133.199 - - 401 2 5 18 2024-11-25 03:00:31 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 40 2024-11-25 03:00:31 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 18 2024-11-25 03:00:31 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 VS17.0:PublishDialog:WTE17.11.231.19466;sid=f471ab9c-ad2f-4cbf-bc83-4a3cd076c4ad;op=Sync - 200 0 0 399 2024-11-25 03:00:31 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 512 2024-11-25 03:01:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 21 2024-11-25 03:01:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 22 2024-11-25 03:01:06 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 1328 2024-11-25 03:01:06 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 VS17.0:PublishDialog:WTE17.11.231.19466;sid=95d9ba1d-d9de-4f61-8f7a-1e8e2196ac00;op=Sync - 200 0 0 1237 2024-11-25 03:01:06 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 18 2024-11-25 03:01:08 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 - - 200 0 0 1370 2024-11-25 03:01:08 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 58.186.133.199 VS17.0:PublishDialog:WTE17.11.231.19466;sid=95d9ba1d-d9de-4f61-8f7a-1e8e2196ac00;op=Sync - 200 0 0 1271 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 03:23:06 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 03:23:06 103.153.214.94 GET /login redirect=%2F 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.5+Safari/605.9.17 - 404 7 0 219 2024-11-25 03:31:30 103.153.214.94 GET / - 8172 - 35.203.210.192 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 272 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 04:47:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 04:47:44 103.153.214.94 GET /servlet/com.sksoft.bill.ImageUpload filepath=/&filename=ac59075b964b0715.jsp 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:109.0)+Gecko/20100101+Firefox/114.0 - 404 7 0 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 06:32:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 06:32:50 103.153.214.94 POST /assets/php/upload.php - 8172 - 107.189.28.251 Mozilla/5.0+(X11;+Linux+i686;+rv:126.0)+Gecko/20100101+Firefox/126.0 http://bcvt.kontum.gov.vn:8172 404 7 0 220 2024-11-25 06:32:52 103.153.214.94 GET /assets/data/usrimg/2pkqutkd9o5ylkbqy1igbiaocsl.php - 8172 - 107.189.28.251 Mozilla/5.0+(X11;+Linux+i686;+rv:125.0)+Gecko/20100101+Firefox/125.0 - 404 7 0 215 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 07:07:38 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 07:07:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 - 116.96.77.209 - - 401 2 5 25 2024-11-25 07:07:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 36 2024-11-25 07:07:37 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 38 2024-11-25 07:07:38 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 617 2024-11-25 07:07:38 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=5e8fe0a8-c21a-4841-8fd5-c7d456215776;op=Sync - 200 0 0 381 2024-11-25 07:07:44 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 43 2024-11-25 07:07:44 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 26 2024-11-25 07:07:45 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=7bda6967-8ff3-43a5-abdc-cdcbfdc75203;op=Sync - 200 0 0 893 2024-11-25 07:07:45 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 1013 2024-11-25 07:07:45 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 25 2024-11-25 07:07:46 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=7bda6967-8ff3-43a5-abdc-cdcbfdc75203;op=Sync - 200 0 0 1130 2024-11-25 07:07:46 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 1243 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 07:52:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 07:52:43 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 36 2024-11-25 07:52:43 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 25 2024-11-25 07:52:43 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=02c498e1-c5bc-42a0-abeb-7ce9c40a62fc;op=Sync - 200 0 0 350 2024-11-25 07:52:43 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 454 2024-11-25 07:52:51 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 27 2024-11-25 07:52:51 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 26 2024-11-25 07:52:53 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 1146 2024-11-25 07:52:53 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=39f5005a-64bb-4d6b-a5e9-404413fc7535;op=Sync - 200 0 0 1032 2024-11-25 07:52:53 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 24 2024-11-25 07:52:55 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 VS17.0:PublishDialog:WTE17.11.231.19466;sid=39f5005a-64bb-4d6b-a5e9-404413fc7535;op=Sync - 200 0 0 2761 2024-11-25 07:52:55 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.209 - - 200 0 0 2878 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 08:24:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 08:24:50 103.153.214.94 GET /wp-content/themes/couponis-demo/style.css - 8172 - 107.189.28.251 Mozilla/5.0+(Fedora;+Linux+x86_64;+rv:121.0)+Gecko/20100101+Firefox/121.0 - 404 7 0 225 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 10:03:55 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 10:03:54 103.153.214.94 GET /wp-content/plugins/cooked-pro/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/64.0.3282.140+Safari/537.36+Edge/17.17134 - 404 7 0 237 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 11:44:58 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 11:44:58 103.153.214.94 GET /wp-content/themes/felici/style.css - 8172 - 107.189.28.251 Mozilla/5.0+(ZZ;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/127.0.0.0+Safari/537.36 - 404 7 0 232 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 13:26:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 13:26:43 103.153.214.94 GET /wp-content/plugins/shortcode-factory/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(SS;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/123.0.0.0+Safari/537.36 - 404 7 0 223 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 15:08:23 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 15:08:23 103.153.214.94 GET /cgi-bin/kerbynet Action=StartSessionSubmit&User='%0acat%20/etc/passwd%0a'&PW 8172 - 107.189.28.251 Mozilla/5.0+(Fedora;+Linux+x86_64;+rv:120.0)+Gecko/20100101+Firefox/120.0 - 404 7 0 224 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 15:40:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 15:40:38 103.153.214.94 GET / - 8172 - 162.216.150.174 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 282 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 16:46:58 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 16:46:57 103.153.214.94 GET /wp-content/plugins/wpSS/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/15.6.1+Safari/605.1.15 - 404 7 0 230 2024-11-25 16:59:32 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 22 2024-11-25 16:59:32 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 52 2024-11-25 16:59:32 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 50 2024-11-25 16:59:32 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=56bf0465-4819-407b-9ca5-fc5f87d69c80;op=Sync - 200 0 0 670 2024-11-25 16:59:32 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 851 2024-11-25 16:59:32 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 13 2024-11-25 17:00:39 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=56bf0465-4819-407b-9ca5-fc5f87d69c80;op=Sync - 200 0 0 65702 2024-11-25 17:00:39 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 65747 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 18:25:42 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 18:25:42 103.153.214.94 GET /wp-content/plugins/vaultpress/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.0+Safari/605.1.41 - 404 7 0 250 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 20:04:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 20:04:50 103.153.214.94 GET /cgi-bin/kerbynet Action=x509view&Section=NoAuthREQ&User&x509type=%27%0A%2Fetc%2Fsudo+tar+-cf+%2Fdev%2Fnull+%2Fdev%2Fnull+--checkpoint%3d1+--checkpoint-action%3dexec%3d%22id%22%0A%27 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.5+Safari/605.6.22 - 404 7 0 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 21:14:24 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 21:14:23 103.153.214.94 GET / - 8172 - 167.94.138.114 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 404 7 0 390 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 21:42:16 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 21:42:16 103.153.214.94 GET /wp-content/themes/activello/style.css - 8172 - 107.189.28.251 Mozilla/5.0+(Knoppix;+Linux+i686;+rv:123.0)+Gecko/20100101+Firefox/123.0 - 404 7 0 210 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-25 23:18:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-25 23:18:55 103.153.214.94 GET /cgi-bin/slogin/login.py - 8172 - 107.189.28.251 ()+{+:;+};+echo+;+echo+;+/bin/cat+/etc/passwd - 404 7 0 206 2024-11-25 23:19:22 103.153.214.94 GET / - 8172 - 87.236.176.168 Mozilla/5.0+(compatible;+InternetMeasurement/1.0;++https://internet-measurement.com/) - 404 7 0 326