????
Current Path : C:/inetpub/logs/wmsvc/W3SVC1/ |
Current File : C:/inetpub/logs/wmsvc/W3SVC1/ex241127.log |
#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 00:31:55 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 00:31:55 103.153.214.94 GET /wp-content/themes/adifier-system/style.css - 8172 - 107.189.28.251 Mozilla/5.0+(SS;+Linux+i686;+rv:121.0)+Gecko/20100101+Firefox/121.0 - 404 7 0 207 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 01:31:05 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 01:31:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 - 116.96.77.201 - - 401 2 5 32 2024-11-27 01:31:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 54 2024-11-27 01:31:05 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 27 2024-11-27 01:31:05 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 476 2024-11-27 01:31:05 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 VS17.0:PublishDialog:WTE17.11.231.19466;sid=a0330ae8-008c-4fef-8151-42a8d51c10d1;op=Sync - 200 0 0 355 2024-11-27 01:33:30 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 34 2024-11-27 01:33:30 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 38 2024-11-27 01:33:31 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 VS17.0:PublishDialog:WTE17.11.231.19466;sid=ba3d4749-5fdc-4458-a4b8-f7c82b74df13;op=Sync - 200 0 0 1333 2024-11-27 01:33:31 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 1496 2024-11-27 01:33:31 103.153.214.94 HEAD /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 28 2024-11-27 01:33:34 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 - - 200 0 0 1936 2024-11-27 01:33:34 103.153.214.94 POST /msdeploy.axd site=kiemkegpmb.gdtsolutions.vn 8172 kiemke 116.96.77.201 VS17.0:PublishDialog:WTE17.11.231.19466;sid=ba3d4749-5fdc-4458-a4b8-f7c82b74df13;op=Sync - 200 0 0 1773 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 01:50:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 01:50:13 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 23 2024-11-27 01:50:13 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 22 2024-11-27 01:50:13 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 20 2024-11-27 01:50:13 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 526 2024-11-27 01:50:13 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=fd91ab95-9e66-49be-be32-edab6e4cda00;op=Sync - 200 0 0 437 2024-11-27 01:50:13 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 8 2024-11-27 01:51:21 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=fd91ab95-9e66-49be-be32-edab6e4cda00;op=Sync - 200 0 0 68537 2024-11-27 01:51:21 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 68562 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 03:40:53 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 03:40:52 103.153.214.94 GET / - 8172 - 35.203.210.32 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 264 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 05:28:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 05:28:38 103.153.214.94 GET /wp-content/plugins/quiz-master-next/README.md - 8172 - 107.189.28.251 Mozilla/5.0+(Kubuntu;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/120.0.0.0+Safari/537.36 - 404 7 0 222 2024-11-27 05:28:40 103.153.214.94 GET /wp-content/plugins/quiz-master-next/tests/_support/AcceptanceTester.php - 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4.1+Safari/605.1.35 - 404 7 0 219 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 07:20:07 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 07:20:07 103.153.214.94 GET /wp-content/plugins/easy-career-openings/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Debian;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/120.0.0.0+Safari/537.36 - 404 7 0 220 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 08:59:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 08:59:39 103.153.214.94 GET /wp-content/plugins/bookit/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Knoppix;+Linux+x86_64;+rv:123.0)+Gecko/20100101+Firefox/123.0 - 404 7 0 220 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 10:07:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 10:07:04 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 - 119.82.130.75 - - 401 2 5 12 2024-11-27 10:07:04 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 19 2024-11-27 10:07:04 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 91 2024-11-27 10:07:04 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=4485725e-2b20-4b82-9193-5b6298e11ef9;op=Sync - 200 0 0 383 2024-11-27 10:07:04 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 797 2024-11-27 10:07:04 103.153.214.94 HEAD /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 20 2024-11-27 10:08:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 - - 200 0 0 70435 2024-11-27 10:08:15 103.153.214.94 POST /msdeploy.axd Site=kiemkegpmb.gdtsolutions.vn 8172 jenkins 119.82.130.75 MSDeployExe;sid=4485725e-2b20-4b82-9193-5b6298e11ef9;op=Sync - 200 0 0 70428 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 10:38:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 10:38:39 103.153.214.94 GET /wp-content/plugins/cip4-folder-download-widget/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(SS;+Linux+x86_64;+rv:127.0)+Gecko/20100101+Firefox/127.0 - 404 7 0 223 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 12:30:47 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 12:30:47 103.153.214.94 GET /debug/list_logfile.php action=restartservice&bash=;echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(Fedora;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36 - 404 7 0 221 2024-11-27 12:30:47 103.153.214.94 GET /protocol/devicestatus/setdevicetime.php procotalarray[messagecontent]=a|echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.4.1+Safari/605.1.24 - 404 7 0 217 2024-11-27 12:30:47 103.153.214.94 GET /admin/device_status.php action=getethinfoðx=a|%20echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(ZZ;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/123.0.0.0+Safari/537.36 - 404 7 0 226 2024-11-27 12:30:47 103.153.214.94 GET /debug/rproxy_diag.php action=tarfile&search&logfile[0]=../../etc/passwd|%20echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(X11;+Linux+x86_64;+rv:120.0)+Gecko/20100101+Firefox/120.0 - 404 7 0 230 2024-11-27 12:30:47 103.153.214.94 GET /debug/list_logfile.php logfile%5B%5D=%2FIsc%2FLog%2Fsshd.log;echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(Fedora;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 404 7 0 216 2024-11-27 12:30:48 103.153.214.94 GET /admin/detail_tunel.php type=ikev1&tunnelname=a%20|%20echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(Ubuntu;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36 - 404 7 0 216 2024-11-27 12:30:53 103.153.214.94 GET /debug/show_logfile.php filename=a|echo+'E4t06uQzoB2jtZyaOzGlPv9yREJjVGzZ' 8172 - 107.189.28.251 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/103.0.0.0+Safari/537.36 - 404 7 0 216 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 14:21:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 14:21:51 103.153.214.94 POST / - 8172 - 107.189.28.251 Mozilla/5.0+(Ubuntu;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/121.0.0.0+Safari/537.36 https://bcvt.kontum.gov.vn:8172 404 7 0 221 2024-11-27 14:24:13 103.153.214.94 GET / - 8172 - 35.203.210.109 Expanse,+a+Palo+Alto+Networks+company,+searches+across+the+global+IPv4+space+multiple+times+per+day+to+identify+customers'+presences+on+the+Internet.+If+you+would+like+to+be+excluded+from+our+scans,+please+send+IP+addresses/domains+to:+scaninfo@paloaltonetworks.com - 404 7 0 263 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 14:40:36 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 14:40:36 103.153.214.94 GET / - 8172 - 206.168.34.207 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 404 7 0 242 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 14:56:10 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 14:56:10 103.153.214.94 GET / - 8172 - 206.168.34.203 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 404 7 0 235 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 16:01:14 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 16:01:14 103.153.214.94 POST /run - 8172 - 107.189.28.251 Mozilla/5.0+(Windows+NT+10.0;+rv:68.0)+Gecko/20100101+Firefox/68.0 - 404 7 0 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 17:40:51 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 17:40:51 103.153.214.94 GET /wp-content/plugins/miniorange-login-openid/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Debian;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 404 7 0 221 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 19:20:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 19:20:44 103.153.214.94 GET /wp-content/plugins/memphis-documents-library/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Knoppix;+Linux+i686)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/128.0.0.0+Safari/537.36 - 404 7 0 222 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 21:01:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 21:01:50 103.153.214.94 GET /wp-content/plugins/content_timeline/readme.txt - 8172 - 107.189.28.251 Mozilla/5.0+(Fedora;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/120.0.0.0+Safari/537.36 - 404 7 0 221 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2024-11-27 22:34:30 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2024-11-27 22:34:30 103.153.214.94 GET /admin/ajax/pages.php id=(sleep(6)) 8172 - 107.189.28.251 Mozilla/5.0+(CentOS;+Linux+i686;+rv:128.0)+Gecko/20100101+Firefox/128.0 - 404 7 0 220