#Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 00:03:11 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 00:03:11 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html) - - 404 2 1850 267 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 00:31:01 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 00:31:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /wp-login.php - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.2;+rv:28.0)+Gecko/20100101+Firefox/28.0 - https://google.com 404 2 1850 256 15 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 02:51:46 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 02:51:46 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_9_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/38.0.2125.111+Safari/537.36 - - 200 0 788 408 109 2018-01-12 02:51:51 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/42.0.2311.90+Safari/537.36 - - 200 0 792 393 109 2018-01-12 02:52:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots) - - 404 2 1850 225 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 04:05:38 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 04:05:37 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html) - - 200 0 792 334 109 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 07:32:10 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 07:32:09 W3SVC93 W2K3WEB1 192.168.25.10 HEAD /Default.htm - 80 - 192.168.25.52 HTTP/1.1 - - - 200 0 398 99 31 2018-01-12 07:34:03 W3SVC93 W2K3WEB1 192.168.25.10 HEAD /Default.htm - 80 - 192.168.25.52 HTTP/1.1 - - - 200 0 398 99 15 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 11:23:18 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 11:23:18 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=233933 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1362 325 359 2018-01-12 11:23:20 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+Trident/7.0;+rv:11.0)+like+Gecko - - 404 2 1850 268 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 11:49:37 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 11:49:37 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots) - - 404 2 1850 229 0 2018-01-12 11:49:41 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+YandexBot/3.0;++http://yandex.com/bots) - - 404 2 1850 274 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 12:32:20 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 12:32:20 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/50.0.2661.102+Safari/537.36;+360Spider - http://windsordistribution.com/ 200 0 788 360 109 2018-01-12 12:35:16 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/50.0.2661.102+Safari/537.36;+360Spider - http://www.windsordistribution.com/ 200 0 792 367 93 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 13:11:52 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 13:11:51 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=235936 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 6093 454 250 2018-01-12 13:13:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=235936 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 6093 447 234 2018-01-12 13:13:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Trident/7.0;+rv:11.0)+like+Gecko - - 404 2 1850 370 0 2018-01-12 13:15:33 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=235936 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1319 363 140 2018-01-12 13:15:33 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+Trident/7.0;+rv:11.0)+like+Gecko - - 404 2 1850 306 0 2018-01-12 13:27:16 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236307 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+11_2_2+like+Mac+OS+X)+AppleWebKit/604.4.7+(KHTML,+like+Gecko)+Version/11.0+Mobile/15C202+Safari/604.1 - - 200 0 443 497 250 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 13:49:30 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 13:49:30 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=354212 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - - 200 0 1323 456 156 2018-01-12 13:49:32 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 ASPSESSIONIDSQBATRDS=IAJJENCADLCDKCIPPALCLHEJ http://www.windsordistribution.com/vwrpacktrack.asp?pronum=354212 404 2 1850 492 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 14:17:05 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 14:17:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=355225 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.94+Safari/537.36+OPR/49.0.2725.64 - - 200 0 588 492 156 2018-01-12 14:17:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.94+Safari/537.36+OPR/49.0.2725.64 ASPSESSIONIDSQBATRDS=NAJJENCABJKNLNMOKDPHBGDI http://www.windsordistribution.com/vwrpacktrack.asp?pronum=355225 404 2 1850 528 0 2018-01-12 14:17:17 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=355225 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.94+Safari/537.36+OPR/49.0.2725.64 ASPSESSIONIDSQBATRDS=NAJJENCABJKNLNMOKDPHBGDI - 200 0 521 547 125 2018-01-12 14:17:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=355225 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.94+Safari/537.36+OPR/49.0.2725.64 ASPSESSIONIDSQBATRDS=NAJJENCABJKNLNMOKDPHBGDI - 200 0 521 547 156 2018-01-12 14:20:26 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236272 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 588 457 156 2018-01-12 14:20:26 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=OAJJENCAFLOAAEDHJALBHKMG http://www.windsordistribution.com/vwrpacktrack.asp?pronum=236272 404 2 1850 493 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 15:35:33 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 15:35:33 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=355156 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 1328 458 156 2018-01-12 15:35:33 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=BBJJENCABNHNAICEDGMIPKKB http://www.windsordistribution.com/vwrpacktrack.asp?pronum=355156 404 2 1850 494 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 16:17:37 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 16:17:37 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=123918 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=GAJJENCAKAKIOKHCLBBBAGEN - 200 0 1273 418 140 2018-01-12 16:17:37 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64;+Trident/7.0;+rv:11.0)+like+Gecko - - 404 2 1850 306 0 2018-01-12 16:18:14 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=123918 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=GAJJENCAKAKIOKHCLBBBAGEN - 200 0 1273 418 140 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 16:34:00 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 16:34:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=122612 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1340 363 156 2018-01-12 16:34:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=JBJJENCACOHNLNECOIDPJIEJ - 404 2 1850 341 0 2018-01-12 16:47:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=355098 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 1321 457 156 2018-01-12 16:47:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=KBJJENCALJHCNOMLHCBKBLEK http://www.windsordistribution.com/vwrpacktrack.asp?pronum=355098 404 2 1850 493 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 17:04:28 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 17:04:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236212 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 1323 447 156 2018-01-12 17:04:27 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=MBJJENCADABHJGLBFGPCGEPJ http://www.windsordistribution.com/vwrpacktrack.asp?pronum=236212 404 2 1850 483 0 2018-01-12 17:13:16 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236299 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 1321 465 156 2018-01-12 17:13:16 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_11_6)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=PBJJENCAFFGFCPGBFCMJPCAE http://www.windsordistribution.com/vwrpacktrack.asp?pronum=236299 404 2 1850 501 0 2018-01-12 17:18:16 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.2;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1847.116+Safari/537.36 - www.yahoo.com 200 0 788 410 125 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 18:09:24 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 18:09:24 W3SVC93 W2K3WEB1 192.168.25.10 POST /Default.htm %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 405 0 1822 1001 15 2018-01-12 18:09:24 W3SVC93 W2K3WEB1 192.168.25.10 POST /cgi-bin/php %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 404 2 1850 1012 0 2018-01-12 18:09:24 W3SVC93 W2K3WEB1 192.168.25.10 POST /cgi-bin/php5 %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 404 2 1850 1013 0 2018-01-12 18:09:25 W3SVC93 W2K3WEB1 192.168.25.10 POST /cgi-bin/php4 %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 404 2 1850 1013 0 2018-01-12 18:09:25 W3SVC93 W2K3WEB1 192.168.25.10 POST /cgi-bin/php-cgi %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 404 2 1850 1016 0 2018-01-12 18:09:25 W3SVC93 W2K3WEB1 192.168.25.10 POST /cgi-bin/php.cgi %2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - - 404 2 1850 1016 15 2018-01-12 18:09:40 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+SeznamBot/3.2;++http://napoveda.seznam.cz/en/seznambot-intro/) - - 404 2 1850 281 0 2018-01-12 18:09:41 W3SVC93 W2K3WEB1 192.168.25.10 GET /login.asp - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+SeznamBot/3.2;++http://napoveda.seznam.cz/en/seznambot-intro/) - - 200 0 1805 280 125 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 18:47:53 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 18:47:53 W3SVC93 W2K3WEB1 192.168.25.10 GET /Contact.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_8_0)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/34.0.1853.64+Safari/537.36 - - 200 0 1790 476 15 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 19:24:08 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 19:24:07 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+Googlebot/2.1;++http://www.google.com/bot.html) - - 404 2 1850 271 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 19:57:36 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 19:57:36 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=354874 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1334 363 156 2018-01-12 19:59:57 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - https://www.google.com/ 200 0 788 456 109 2018-01-12 19:59:57 W3SVC93 W2K3WEB1 192.168.25.10 GET /Homepage.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/ 200 0 1636 476 0 2018-01-12 19:59:57 W3SVC93 W2K3WEB1 192.168.25.10 GET /Menu.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/ 200 0 972 472 109 2018-01-12 19:59:57 W3SVC93 W2K3WEB1 192.168.25.10 GET /Homepage_files/image001.gif - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/Homepage.htm 200 0 11025 427 15 2018-01-12 19:59:57 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/ 404 2 1850 399 0 2018-01-12 20:00:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /Contact.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/Menu.htm 200 0 1790 483 0 2018-01-12 20:00:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /Contact_files/image001.gif - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 - http://windsordistribution.com/Contact.htm 200 0 10905 425 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 20:22:51 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 20:22:51 W3SVC93 W2K3WEB1 192.168.25.10 GET /menu.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+7_0+like+Mac+OS+X)+AppleWebKit/537.51.1+(KHTML,+like+Gecko)+Version/7.0+Mobile/11A465+Safari/9537.53+(compatible;+bingbot/2.0;++http://www.bing.com/bingbot.htm) - - 200 0 972 440 93 2018-01-12 20:24:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=351433 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 - - 200 0 1327 455 140 2018-01-12 20:24:05 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=GDJJENCAOOLOOGMPFJOMEMFI http://www.windsordistribution.com/vwrpacktrack.asp?pronum=351433 404 2 1850 491 0 2018-01-12 20:24:32 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=351433 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.132+Safari/537.36 ASPSESSIONIDSQBATRDS=GDJJENCAOOLOOGMPFJOMEMFI - 200 0 1258 510 171 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 21:36:34 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 21:36:34 W3SVC93 W2K3WEB1 192.168.25.10 HEAD /Default.htm - 80 - 192.168.25.52 HTTP/1.1 - - - 200 0 398 154 109 2018-01-12 21:36:34 W3SVC93 W2K3WEB1 192.168.25.10 HEAD /Default.htm - 80 - 192.168.25.52 HTTP/1.1 - - - 200 0 398 154 109 2018-01-12 21:36:36 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236085 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1340 363 171 2018-01-12 21:36:36 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=PDJJENCAPIDELPANMPKCAPAI - 404 2 1850 341 0 2018-01-12 21:36:37 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236085 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1340 363 140 2018-01-12 21:39:19 W3SVC93 W2K3WEB1 192.168.25.10 HEAD /Default.htm - 80 - 192.168.25.52 HTTP/1.1 - - - 200 0 398 154 109 2018-01-12 21:39:19 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=235946 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=AEJJENCAOHPFBOIFMCDPNKJM - 200 0 1293 418 140 2018-01-12 21:44:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=123829 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_13_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.84+Safari/537.36 - - 200 0 1333 470 156 2018-01-12 21:44:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_13_2)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/63.0.3239.84+Safari/537.36 ASPSESSIONIDSQBATRDS=BEJJENCABECEHNBANENHEGAO http://www.windsordistribution.com/vwrpacktrack.asp?pronum=123829 404 2 1850 506 0 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 22:28:49 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 22:28:49 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236046 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko - - 200 0 1348 363 250 2018-01-12 22:28:49 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=HEJJENCAOJNJCELEFKGAABIP - 404 2 1850 341 0 2018-01-12 22:29:15 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236049 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=HEJJENCAOJNJCELEFKGAABIP - 200 0 1298 418 140 2018-01-12 22:29:15 W3SVC93 W2K3WEB1 192.168.25.10 GET /favicon.ico - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=HEJJENCAOJNJCELEFKGAABIP - 404 2 1850 341 0 2018-01-12 22:29:49 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=354212 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/62.0.3202.75+Safari/537.36 ASPSESSIONIDSQBATRDS=IAJJENCADLCDKCIPPALCLHEJ - 200 0 1257 511 125 2018-01-12 22:31:00 W3SVC93 W2K3WEB1 192.168.25.10 GET /vwrpacktrack.asp pronum=236049 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+WOW64;+Trident/7.0;+rv:11.0)+like+Gecko ASPSESSIONIDSQBATRDS=HEJJENCAOJNJCELEFKGAABIP - 200 0 1298 418 156 #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2018-01-12 23:49:55 #Fields: date time s-sitename s-computername s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Cookie) cs(Referer) sc-status sc-win32-status sc-bytes cs-bytes time-taken 2018-01-12 23:49:55 W3SVC93 W2K3WEB1 192.168.25.10 GET /robots.txt - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+MJ12bot/v1.4.8;+http://mj12bot.com/) - - 404 2 1850 205 0 2018-01-12 23:49:56 W3SVC93 W2K3WEB1 192.168.25.10 GET /Default.htm - 80 - 192.168.25.52 HTTP/1.1 Mozilla/5.0+(compatible;+MJ12bot/v1.4.8;+http://mj12bot.com/) - - 200 0 990 382 109