HEX
Server: Apache
System:
User: ()
PHP: 7.4.33
Disabled: system,passthru,shell_exec,exec,proc_close,proc_open,proc_get_status,proc_nice,proc_terminate,highlight_file,escapeshellcmd,pclose,debugger_off,debugger_on,leak,listen,define_syslog_variables,ftp_exec,posix_uname,posix_getpwuid,get_current_user,getmyuid,getmygid,apache_child_terminate,posix_kill,posix_mkfifo,posix_setpgid,posix_setsid,posix_setuid,escapeshellarg,myshellexec,escapeshellarg,disk_free_space,disk_total_space,show_source,dl,symlink,listen,syslog,php_ini_scanned_files,inurl,apache_setenv,closelog,rar_open,bzopen,bzread,bzwrite,shellcode,show_source,apache_get_modules,apache_get_version,apache_note,openlog,crack_check,crack_closedict,pcntl_exec,ini_alter,backtick,cmd,virtual,getservbyport,myshellexec,hypot,pg_host,phpini,link,readlink,syslog,id,ftok,posix_access,error_log,sym,php_u,psockopen,apache_child_k_closedict,crack_getlastmessage,crack_opendict,php_ini,ini_restore,popen,curl_multi_exec,php_uname
Upload Files
File: /home/homework/tmp/awstats/ssl/awstats112021.homework.mycpanel.ba.txt
AWSTATS DATA FILE 7.8 (build 20200416)
# If you remove this file, all statistics for date 202111 will be lost/reset.
# Last config file used to build this data file was /home/homework/tmp/awstats/ssl/awstats.homework.mycpanel.ba.conf.

# Position (offset in bytes) in this file for beginning of each section for
# direct I/O access. If you made changes somewhere in this file, you should
# also remove completely the MAP section (AWStats will rewrite it at next
# update).
BEGIN_MAP 28
POS_GENERAL 2021                
POS_TIME 2689                
POS_VISITOR 8331                
POS_DAY 8796                
POS_DOMAIN 3285                
POS_LOGIN 3552                
POS_ROBOT 3707                
POS_WORMS 3979                
POS_EMAILSENDER 4110                
POS_EMAILRECEIVER 4253                
POS_SESSION 9050                
POS_SIDER 9207                
POS_FILETYPES 4388                
POS_DOWNLOADS 4507                
POS_OS 4555                
POS_BROWSER 4690                
POS_SCREENSIZE 4836                
POS_UNKNOWNREFERER 4910                
POS_UNKNOWNREFERERBROWSER 5152                
POS_ORIGIN 5303                
POS_SEREFERRALS 5437                
POS_PAGEREFS 5581                
POS_SEARCHWORDS 6115                
POS_KEYWORDS 6267                
POS_MISC 2353                
POS_ERRORS 6326                
POS_CLUSTER 3408                
POS_SIDER_404 6428                
END_MAP

# LastLine    = Date of last record processed - Last record line number in last log - Last record offset in last log - Last record signature value
# FirstTime   = Date of first visit for history file
# LastTime    = Date of last visit for history file
# LastUpdate  = Date of last update - Nb of parsed records - Nb of parsed old records - Nb of parsed new records - Nb of parsed corrupted - Nb of parsed dropped
# TotalVisits = Number of visits
# TotalUnique = Number of unique visitors
# MonthHostsKnown   = Number of hosts known
# MonthHostsUnKnown = Number of hosts unknown
BEGIN_GENERAL 8
LastLine 20211201030739 8373 1965607 15598587520460
FirstTime 0
LastTime 20211129150539
LastUpdate 20211201062412 1 0 0 0 0
TotalVisits 13                  
TotalUnique 10                  
MonthHostsKnown 0                   
MonthHostsUnknown 10                  
END_GENERAL

# Misc ID - Pages - Hits - Bandwidth
BEGIN_MISC 10
JavascriptDisabled 0 0 0
RealPlayerSupport 0 0 0
TotalMisc 0 0 0
AddToFavourites 0 0 0
WindowsMediaPlayerSupport 0 0 0
FlashSupport 0 0 0
QuickTimeSupport 0 0 0
JavaEnabled 0 0 0
DirectorSupport 0 0 0
PDFSupport 0 0 0
END_MISC

# Hour - Pages - Hits - Bandwidth - Not viewed Pages - Not viewed Hits - Not viewed Bandwidth
BEGIN_TIME 24
0 0 0 0 15 16 712
1 12 12 173230 121 121 2322
2 0 0 0 3 3 70
3 0 0 0 2 2 0
4 3 3 62652 7 9 50609
5 0 0 0 3 3 35
6 0 0 0 10 11 452
7 0 0 0 6 6 122
8 0 0 0 4 4 35
9 26 26 319444 5 7 165
10 0 0 0 1 2 70
11 3 3 114333 4 5 122
12 1 1 12279 8 9 76371
13 2 2 76197 40 40 1684
14 2 2 24546 4 5 217
15 1 1 12273 8 11 49255
16 0 0 0 29 31 1439
17 0 0 0 0 2 61
18 0 0 0 0 0 0
19 0 0 0 5 5 190
20 0 0 0 6 7 140
21 0 0 0 28 28 1439
22 11 11 135094 5 7 209
23 26 26 319490 16 17 633
END_TIME

# Domain - Pages - Hits - Bandwidth
# The 25 first Pages must be first (order not required for others)
BEGIN_DOMAIN 4
us 83 83 1174621
ru 2 2 24546
de 1 1 12279
gr 1 1 38092
END_DOMAIN

# Cluster ID - Pages - Hits - Bandwidth
BEGIN_CLUSTER 0
END_CLUSTER

# Login - Pages - Hits - Bandwidth - Last visit
# The 10 first Pages must be first (order not required for others)
BEGIN_LOGIN 0
END_LOGIN

# Robot ID - Hits - Bandwidth - Last visit - Hits on robots.txt
# The 25 first Hits must be first (order not required for others)
BEGIN_ROBOT 4
unknown 8 208 20211126160842 8
Baiduspider/ 5 61359 20211114150744 0
survey 2 76196 20211104125643 0
no_user_agent 1 38104 20211112043405 0
END_ROBOT

# Worm ID - Hits - Bandwidth - Last visit
# The 5 first Hits must be first (order not required for others)
BEGIN_WORMS 0
END_WORMS

# EMail - Hits - Bandwidth - Last visit
# The 20 first Hits must be first (order not required for others)
BEGIN_EMAILSENDER 0
END_EMAILSENDER

# EMail - Hits - Bandwidth - Last visit
# The 20 first hits must be first (order not required for others)
BEGIN_EMAILRECEIVER 0
END_EMAILRECEIVER

# Files type - Hits - Bandwidth - Bandwidth without compression - Bandwidth after compression
BEGIN_FILETYPES 3
env 22 270207 0 0
html 14 197749 0 0
php 51 781582 0 0
END_FILETYPES

# Downloads - Hits - Bandwidth
BEGIN_DOWNLOADS 0
END_DOWNLOADS

# OS ID - Hits
BEGIN_OS ID - Hits - Pages 5
androidnougat 22 22
winxp 2 2
Unknown 56 56
linuxubuntu 1 1
win10 6 6
END_OS

# Browser ID - Hits - Pages
BEGIN_BROWSER 6
msie6.0 2 2
firefox94.0 6 6
firefox62.0 1 1
Unknown 54 54
mozilla 2 2
chrome60.0.3112.107 22 22
END_BROWSER

# Screen size - Hits
BEGIN_SCREENSIZE 0
END_SCREENSIZE

# Unknown referer OS - Last visit date
BEGIN_UNKNOWNREFERER 3
Go_http_package 20211101132942
Mozilla/5.0_(compatible;_CensysInspect/1.1;__https://about.censys.io/) 20211112043415
python-requests/2.26.0 20211129150539
END_UNKNOWNREFERER

# Unknown referer Browser - Last visit date
BEGIN_UNKNOWNREFERERBROWSER 2
python-requests/2.26.0 20211129150539
Go_http_package 20211101132942
END_UNKNOWNREFERERBROWSER

# Origin - Pages - Hits 
BEGIN_ORIGIN 6
From0 77 77
From1 0 0
From2 0 0
From3 10 10
From4 0 0
From5 0 0
END_ORIGIN

# Search engine referers ID - Pages - Hits
BEGIN_SEREFERRALS 0
END_SEREFERRALS

# External page referers - Pages - Hits
# The 25 first Pages must be first (order not required for others)
BEGIN_PAGEREFS 8
http://cpanel.homework.mycpanel.ba/wp-login.php 2 2
http://webmail.homework.mycpanel.ba/wp-login.php 2 2
https://cpanel.homework.mycpanel.ba 1 1
https://webmail.homework.mycpanel.ba 1 1
http://cpanel.homework.mycpanel.ba/blog/wp-login.php 1 1
http://cpanel.homework.mycpanel.ba/wp/wp-login.php 1 1
http://cpanel.homework.mycpanel.ba/wordpress/wp-login.php 1 1
http://77.77.207.4:80 1 1
END_PAGEREFS

# Search keyphrases - Number of search
# The 10 first number of search must be first (order not required for others)
BEGIN_SEARCHWORDS 0
END_SEARCHWORDS

# Search keywords - Number of search
# The 25 first number of search must be first (order not required for others)
BEGIN_KEYWORDS 0
END_KEYWORDS

# Errors - Hits - Bandwidth
BEGIN_ERRORS 2
401 188 8789
404 146 1696
END_ERRORS

# URL with 404 errors - Hits - Last URL referrer
BEGIN_SIDER_404 102
/2index.php 1 -
/shx.php 1 -
/send.php 1 -
/shellalfa.php 1 -
/silahoy.php 1 -
/shellx.php 1 -
/sindex.php 1 -
/dr.php 1 -
/ups.php 1 -
/nee.php 1 -
/403.php 1 -
/XxX.php 1 -
/Gel.php 1 -
/ohayo.php 1 -
/wp-login.php 2 https://www.homework.mycpanel.ba/wp-login.php
/404.php 1 -
/wp-configr.php 1 -
/chitoge.php 1 -
/z.php 1 -
/wsoshell.php 1 -
/sh3ll.php 1 -
/Indox.php 1 -
/config.inc.php 1 -
/new.php 1 -
/wso.php 2 -
/wp-configer.php 2 -
/wi.php 1 -
/alex.php 1 -
/wp-content/wp-admin.php 1 -
/vuln.php 1 -
/owl.php 1 -
/wikindex.php 1 -
/bypass.php 1 -
/wp-uploads.php 1 -
/defau1t.php 1 -
/cms.php 1 -
/FoxWSO.php 1 -
/3index.php 1 -
/data.php 1 -
/shell.php 2 -
/1.php 1 -
/baindex.php 1 -
/xox.php 1 -
/access.php 1 -
/MARIJUANA.php 1 -
/mar.php 1 -
/f.php 1 -
/100.php 1 -
/41.php 1 -
/upload.php 1 -
/alfa.php 2 -
/wp-blog.php 1 -
/.env 2 -
/11index.php 1 -
/of.php 1 -
/w.php 1 -
/a.php 2 -
/leafmailer.php 1 -
/ws.php 1 -
/stindex.php 1 -
/3.php 1 -
/nzul.php 1 -
/o.php 1 -
/1index.php 1 -
/sym.php 1 -
/wp-content/wp-logins.php 1 -
/media-admin.php 1 -
/leaf.php 2 -
/x.php 2 -
/f3l.php 1 -
/exploit.php 1 -
/xxx.php 1 -
/images/vuln.php 1 -
/new-index.php 1 -
/kirisaki.php 1 -
/4price.php 1 -
/anone.php 1 -
/v.php 1 -
/cpanel.php 1 -
/mini.php 1 -
/default.php 1 -
/mailer.php 2 -
/ 35 -
/c.php 1 -
/autoload_classmap.php 1 -
/doc.php 1 -
/wp-wso.php 1 -
/symlink.php 1 -
/old-index.php 1 -
/0byte.php 1 -
/wci.php 1 -
/c99.php 1 -
/xx.php 1 -
/wp-confirm.php 1 -
/haxor.php 1 -
/wp.php 1 -
/777.php 1 -
/0x.php 1 -
/root.php 1 -
/ngery.php 1 -
/.fk.php 1 -
/wp-admin.php 1 -
END_SIDER_404

# Host - Pages - Hits - Bandwidth - Last visit date - [Start date of last visit] - [Last page of last visit]
# [Start date of last visit] and [Last page of last visit] are saved only if session is not finished
# The 25 first Hits must be first (order not required for others)
BEGIN_VISITOR 10
161.35.122.17 74 74 909141 20211118233753
3.131.90.12 3 3 114333 20211112110743
167.94.138.59 2 2 24547 20211112043415
185.158.115.77 2 2 24546 20211121140306
92.118.160.17 1 1 38092 20211101132942
18.119.167.55 1 1 38117 20211112013236
20.124.113.110 1 1 12273 20211129150539
3.142.120.46 1 1 38105 20211111132542
3.80.33.166 1 1 38105 20211110042133
194.163.159.35 1 1 12279 20211127120548
END_VISITOR

# Date - Pages - Hits - Bandwidth - Visits
BEGIN_DAY 9
20211101 1 1 38092 1
20211110 1 1 38105 1
20211111 1 1 38105 1
20211112 17 17 312091 4
20211113 11 11 135113 1
20211118 52 52 638934 2
20211121 2 2 24546 1
20211127 1 1 12279 1
20211129 1 1 12273 1
END_DAY

# Session range - Number of visits
BEGIN_SESSION 2
30s-2mn 2
0s-30s 11
END_SESSION

# URL - Pages - Bandwidth - Entry - Exit
# The 25 first Pages must be first (order not required for others)
BEGIN_SIDER 41
/ 8 124004 4 4
/wp-login.php 4 126606 4 4
/wp-content/plugins/xichang/x.php 2 24593 0 0
/wp-content/plugins/widget-logic/mini.php 2 24595 0 2
/.env 2 24557 2 0
/new_license.php 2 24571 0 0
/wso.php 2 24560 0 0
/public/.env 2 24563 0 0
/test/.env 2 24568 0 0
/shop/.env 2 24566 0 2
/indoxploit.php 2 24563 0 0
/system/.env 2 24564 0 0
/wp-content/uploads/2021/11/ 2 24577 0 0
/098.php 2 24555 0 0
/upload.php 2 24554 0 0
/wp-content/plugins/theme-configurator/mini.php 2 24612 0 0
/wp-includes/css/modules.php 2 24574 2 0
/wp-content/vuln.php 2 24573 0 0
/wp-admin/shapes.php 2 24570 0 0
/vendor/.env 2 24559 0 0
/V5.php 2 24560 0 0
/wp-content/plugins/ppus/up.php 2 24597 0 0
/wp-content/plugins/html404/ 2 24592 0 0
/shell.php 2 24562 0 0
/wp-admin/network/wp-footer.php 2 24584 0 0
/wordpress/wp-login.php 1 38115 0 0
/wp/wp-login.php 1 38108 1 0
/blog/wp-login.php 1 38110 0 1
/admin/.env 2 24560 0 0
/wp-content/uploads/ 2 24576 0 0
/wp-content/plugins/vwcleanerplugin/bump.php 2 24615 0 0
/laravel/.env 2 24570 0 0
/upel.php 2 24554 0 0
/olux.php 2 24556 0 0
/api/.env 2 24565 0 0
/wp-content/plugins/ubh/index.php 2 24589 0 0
/wp-info.php 2 24561 0 0
/sites/.env 2 24570 0 0
/blog/.env 2 24565 0 0
/wp-content/plugins/upspy/index.php 2 24591 0 0
/up.php 2 24554 0 0
END_SIDER