2月18号日志异常分析
20220218150200 223.71.97.99
www.01jh.net /01jh/zui/zixun/myhome/peiyao/hcjs/jhjs/yaopu.asp 350 22 1046 301 NULL 36 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 38414
20220218150200 223.71.97.99
www.01jh.net / 8551 22 1046 200 NULL 42 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 39286
20220218150200 223.71.97.99
www.01jh.net /01jh/zui/yamen/wabao/chat/wp.htm 336 22 1046 301 NULL 41 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 39042
20220218150200 223.71.97.99
www.01jh.net /01jh/zui/zixun/myhome/peiyao/top/ 350 22 1046 301 NULL 37 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 38416
20220218150208 223.71.97.99
www.01jh.net / 8552 22 1046 200 NULL 47 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 49454
20220218150239 223.71.97.99
www.01jh.net /01jh/zui/zixun/help/hcjs/card/ppp/guide.htm 335 22 1046 301 NULL 42 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 49458
20220218150239 223.71.97.99
www.01jh.net / 8549 22 1046 200 NULL 46 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 49458
20220218150239 223.71.97.99
www.01jh.net /01jh/zui/zixun/help/hcjs/card/biao/index.asp 350 22 1046 301 NULL 38 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 49456
20220218150240 223.71.97.99
www.01jh.net /01jh/zui/zixun/help/biao/shop/shop.asp 351 22 1046 301 NULL 39 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 47010
20220218150240 223.71.97.99
www.01jh.net / 8552 22 1046 200 NULL 43 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 49454
20220218150241 223.71.97.99
www.01jh.net /01jh/zui/yamen/shop/ppp/guide.htm 336 22 1046 301 NULL 42 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss 47010
20220218150241 223.71.97.99
www.01jh.net /01jh/zui/zixun/myhome/gg/jhmp/money.asp 351 22 1046 301 NULL 38 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "(null)" GET HTTP/1.1 miss
根据日志分析攻击者利用N个IP访问不存在的路径。或者是攻击者路径分析错误了,使用了其他江湖的路径来攻击本江湖,此次恶意操纵没影响到江湖没影响到江湖卡顿等问题,同样攻击者使用了Safari浏览器为内核的浏览器。