LittleDemon WebShell


Linux hosting5.siteguarding.com 3.10.0-962.3.2.lve1.5.88.el7.x86_64 #1 SMP Fri Sep 26 14:06:42 UTC 2025 x86_64
Path : /home/devsafetybis/tmp/awstats/
File Upload :
Command :
Current File : /home/devsafetybis/tmp/awstats/awstats012024.jm3916.dev.safetybis.com.txt

AWSTATS DATA FILE 7.8 (build 20200416)
# If you remove this file, all statistics for date 202401 will be lost/reset.
# Last config file used to build this data file was /home/devsafetybis/tmp/awstats/awstats.jm3916.dev.safetybis.com.conf.

# Position (offset in bytes) in this file for beginning of each section for
# direct I/O access. If you made changes somewhere in this file, you should
# also remove completely the MAP section (AWStats will rewrite it at next
# update).
BEGIN_MAP 28
POS_GENERAL 2025                
POS_TIME 2698                
POS_VISITOR 11443               
POS_DAY 12889               
POS_DOMAIN 3309                
POS_LOGIN 3638                
POS_ROBOT 3793                
POS_WORMS 4154                
POS_EMAILSENDER 4285                
POS_EMAILRECEIVER 4428                
POS_SESSION 13328               
POS_SIDER 13496               
POS_FILETYPES 4563                
POS_DOWNLOADS 4716                
POS_OS 4764                
POS_BROWSER 5033                
POS_SCREENSIZE 5610                
POS_UNKNOWNREFERER 5684                
POS_UNKNOWNREFERERBROWSER 6380                
POS_ORIGIN 6882                
POS_SEREFERRALS 7015                
POS_PAGEREFS 7159                
POS_SEARCHWORDS 7307                
POS_KEYWORDS 7459                
POS_MISC 2362                
POS_ERRORS 7518                
POS_CLUSTER 3494                
POS_SIDER_404 7607                
END_MAP

# LastLine    = Date of last record processed - Last record line number in last log - Last record offset in last log - Last record signature value
# FirstTime   = Date of first visit for history file
# LastTime    = Date of last visit for history file
# LastUpdate  = Date of last update - Nb of parsed records - Nb of parsed old records - Nb of parsed new records - Nb of parsed corrupted - Nb of parsed dropped
# TotalVisits = Number of visits
# TotalUnique = Number of unique visitors
# MonthHostsKnown   = Number of hosts known
# MonthHostsUnKnown = Number of hosts unknown
BEGIN_GENERAL 8
LastLine 20240201014522 3 451 9446527064062
FirstTime 20240102003313
LastTime 20240131173155
LastUpdate 20240201131552 3 0 2 0 0
TotalVisits 39                  
TotalUnique 35                  
MonthHostsKnown 0                   
MonthHostsUnknown 36                  
END_GENERAL

# Misc ID - Pages - Hits - Bandwidth
BEGIN_MISC 10
DirectorSupport 0 0 0
FlashSupport 0 0 0
JavascriptDisabled 0 0 0
TotalMisc 0 0 0
WindowsMediaPlayerSupport 0 0 0
RealPlayerSupport 0 0 0
AddToFavourites 0 7 0
PDFSupport 0 0 0
JavaEnabled 0 0 0
QuickTimeSupport 0 0 0
END_MISC

# Hour - Pages - Hits - Bandwidth - Not viewed Pages - Not viewed Hits - Not viewed Bandwidth
BEGIN_TIME 24
0 3 3 19428 1 2 16
1 1 1 6476 14 16 2243
2 0 4 42403 5 10 8187
3 0 0 0 2 2 16
4 2 2 12944 23 26 9396
5 0 0 0 2 2 32
6 2 2 12936 2 3 16
7 1 1 0 13 13 0
8 0 0 0 2 3 6484
9 1 1 6476 2 3 8503
10 1 1 6468 3 6 0
11 1 1 6476 0 1 0
12 3 3 19420 5 5 80
13 4 20 321162 7 8 16
14 1 1 6468 4 4 64
15 17 52 1210826 29 39 333226
16 2 2 12944 26 29 2227
17 3 3 19420 5 5 6532
18 2 10 160585 7 9 8575
19 1 1 6476 6 7 13829
20 1 1 6468 5 5 6516
21 2 9 50040 0 1 0
22 0 0 0 7 7 64
23 1 1 6476 4 5 8543
END_TIME

# Domain - Pages - Hits - Bandwidth
# The 25 first Pages must be first (order not required for others)
BEGIN_DOMAIN 9
us 23 85 1637168
ca 9 9 58236
in 5 5 32364
nl 3 3 6604
cn 3 3 19428
gb 2 2 12944
ru 2 10 160585
zz 1 1 87
at 1 1 6476
END_DOMAIN

# Cluster ID - Pages - Hits - Bandwidth
BEGIN_CLUSTER 0
END_CLUSTER

# Login - Pages - Hits - Bandwidth - Last visit
# The 10 first Pages must be first (order not required for others)
BEGIN_LOGIN 0
END_LOGIN

# Robot ID - Hits - Bandwidth - Last visit - Hits on robots.txt
# The 25 first Hits must be first (order not required for others)
BEGIN_ROBOT 6
archive\.org_bot 11 318097 20240103151843 0
no_user_agent 8 51776 20240129092512 0
bot[\s_+:,\.\;\/\\-] 6 16260 20240129024722 4
link 1 21 20240111024758 0
survey 1 6476 20240101181746 0
Go\-http\-client/ 1 6570 20240103151644 0
END_ROBOT

# Worm ID - Hits - Bandwidth - Last visit
# The 5 first Hits must be first (order not required for others)
BEGIN_WORMS 0
END_WORMS

# EMail - Hits - Bandwidth - Last visit
# The 20 first Hits must be first (order not required for others)
BEGIN_EMAILSENDER 0
END_EMAILSENDER

# EMail - Hits - Bandwidth - Last visit
# The 20 first hits must be first (order not required for others)
BEGIN_EMAILRECEIVER 0
END_EMAILRECEIVER

# Files type - Hits - Bandwidth - Bandwidth without compression - Bandwidth after compression
BEGIN_FILETYPES 5
Unknown 5 389 0 0
js 67 1112922 0 0
woff 3 76272 0 0
css 3 491787 0 0
html 41 252522 0 0
END_FILETYPES

# Downloads - Hits - Bandwidth
BEGIN_DOWNLOADS 0
END_DOWNLOADS

# OS ID - Hits
BEGIN_OS ID - Hits - Pages 15
macosx15 5 4
android10 1 0
win10 37 9
macosx6 1 0
macosx5 1 0
macosx 9 1
macosx14 1 0
macosx11 1 0
androidpie 1 0
Unknown 40 24
android 2 1
androidmarshmallow 4 3
androidjellybean 1 1
linux 6 5
win7 9 1
END_OS

# Browser ID - Hits - Pages
BEGIN_BROWSER 25
chrome118.0.5993.80 1 1
chrome117.0.5938.132 22 4
chrome72.0.3626.121 1 0
chrome74.0.3729.169 1 1
Unknown 35 19
mozilla 5 5
chrome52.0.3558.98 1 1
chrome101.0.4951.61 1 0
chrome87.0.4280.88 9 1
chrome4.0.302.2 1 0
chrome114.0.0.0 2 2
safari10.1 1 0
chrome96.0.4664.110 4 4
android 1 1
chrome103.0.0.0 1 0
chrome83.0.4103.61 9 1
opera86.0.4363.50 1 0
chrome108.0.0.0 5 5
chrome75.0.3770.100 1 0
chrome81.0.4044.138 2 2
chrome76.0.3809.111 1 0
chrome76.0.3809.100 1 0
opera12.16 1 0
chrome79.0.3945.79 11 2
chrome9.0.597.15 1 0
END_BROWSER

# Screen size - Hits
BEGIN_SCREENSIZE 0
END_SCREENSIZE

# Unknown referer OS - Last visit date
BEGIN_UNKNOWNREFERER 7
Cpanel-HTTP-Client/1.0 20240103151223
Mozilla/5.0_(compatible;_CensysInspect/1.1;__https://about.censys.io/) 20240130161730
python-httpx/0.25.2 20240107135719
python-requests/2.27.1 20240131173155
fasthttp 20240126121043
Expanse,_a_Palo_Alto_Networks_company,_searches_across_the_global_IPv4_space_multiple_times_per_day_to_identify_customers'_presences_on_the_Internet._If_you_would_like_to_be_excluded_from_our_scans,_please_send_IP_addresses/domains_to:_scaninfo@paloaltonetworks.com 20240131151009
Mozilla/5.0_(compatible;_Let's_Encrypt_validation_server;__https://www.letsencrypt.org) 20240103151612
END_UNKNOWNREFERER

# Unknown referer Browser - Last visit date
BEGIN_UNKNOWNREFERERBROWSER 5
python-httpx/0.25.2 20240107135719
python-requests/2.27.1 20240131173155
Cpanel-HTTP-Client/1.0 20240103151223
fasthttp 20240126121043
Expanse,_a_Palo_Alto_Networks_company,_searches_across_the_global_IPv4_space_multiple_times_per_day_to_identify_customers'_presences_on_the_Internet._If_you_would_like_to_be_excluded_from_our_scans,_please_send_IP_addresses/domains_to:_scaninfo@paloaltonetworks.com 20240131151009
END_UNKNOWNREFERERBROWSER

# Origin - Pages - Hits 
BEGIN_ORIGIN 6
From0 46 73
From1 0 0
From2 0 0
From3 0 0
From4 3 46
From5 0 0
END_ORIGIN

# Search engine referers ID - Pages - Hits
BEGIN_SEREFERRALS 0
END_SEREFERRALS

# External page referers - Pages - Hits
# The 25 first Pages must be first (order not required for others)
BEGIN_PAGEREFS 0
END_PAGEREFS

# Search keyphrases - Number of search
# The 10 first number of search must be first (order not required for others)
BEGIN_SEARCHWORDS 0
END_SEARCHWORDS

# Search keywords - Number of search
# The 25 first number of search must be first (order not required for others)
BEGIN_KEYWORDS 0
END_KEYWORDS

# Errors - Hits - Bandwidth
BEGIN_ERRORS 1
404 174 1232
END_ERRORS

# URL with 404 errors - Hits - Last URL referrer
BEGIN_SIDER_404 125
/inputs.php 1 www.google.com
/sftp-config.json 1 -
/backup/wp-admin/setup-config.php 1 www.google.com
/about.php 1 -
/wp-admin/css/colors/xmrlpc.php 1 -
/main 1 -
/images/xmrlpc.php 1 -
/ws.php 1 -
/MARIJUANA.php 1 -
/c.php 1 -
/cong.php 1 -
/wp-admin/cong.php 1 -
/cgi-bin/xmrlpc.php 1 -
/wp-content/plugins/ai-engine/app/chatbot.js 1 www.google.com
/wp-content/plugins/backup-backup/includes/restore-batching.php 1 -
/login.action 1 -
/s/437313e2235323e22333e2231323/_/ 1 -
/gawean.php 1 -
/.vscode/sftp.json 2 -
/tmp/cmd.php 1 -
/.aws/credentials 2 -
/alfanew.php 1 -
/wp-content/pm.php 1 -
/wp-content/plugins/backup-backup/admin/css/bmi-plugin.min.css 1 -
/.env 1 -
/home 1 -
/alfanew.PhP7 1 -
/wp-content/plugins/backup-backup/readme.txt 1 -
/wp-content/plugins/ai-engine/app/index.js 2 -
/wp-content/plugins/woocommerce-payments/dist/blocks-checkout.css 1 -
/wp.php 1 -
/v2/_catalog 1 -
/wp-admin/js/widgets/xmrlpc.php 1 -
/wp-includes/js/jquery/jquery.js 1 www.google.com
/jquery.php 1 -
/.well-known/about.php 1 -
/_all_dbs 1 -
/about 1 -
//wp-admin/setup-config.php 1 www.google.com
/.DS_Store 1 -
/backup 1 -
/wp-admin/network/xmrlpc.php 1 -
/wp-admin/images/admin.php 1 -
/wp-admin/xmrlpc.php 1 -
/.well-known/admin.php 1 -
/plugin.php 1 -
/.well-known/pki-validation/xmrlpc.php 1 -
/atomlib.php 1 -
/wp-admin/setup-config.php 1 www.google.com
/wp-admin/install.php 1 -
/wordpress/wp-admin/setup-config.php 1 www.google.com
/.git/config 1 -
/README.md 1 -
/debug/default/view 1 -
/simple.php 6 -
/404.php 1 -
/shell.php 3 -
/wp-includes/SimplePie/plugins.php 1 -
/wzy.php 4 www.google.com
/batm.php 1 -
/lol.php 1 www.google.com
/xmrlpc.php 1 -
/wp-admin/css/colors/blue/xmrlpc.php 1 -
/general.php 3 www.google.com
/exec.php 1 -
/.well-known/acme-challenge/xmrlpc.php 1 -
/wp-content/plugins/index.php 1 -
/wp-admin/css/colors/coffee/xmrlpc.php 1 -
/wp-admin/includes/wp-login.php 1 -
/input.php 3 www.google.com
/classwithtostring.php 1 -
/wp/wp-admin/setup-config.php 1 www.google.com
/ioxi01.php 1 -
/wp-admin/admin-ajax.php 1 -
//old/wp-admin/setup-config.php 1 www.google.com
/wp 1 -
/p.php 1 -
/wp-config-sample.php 1 -
/gawean.PhP7 1 -
/cmd.php 1 -
/server-status 1 -
/powny.php 1 -
/wp-content/plugins/pwnd/pwnd.php 1 www.google.com
/new 1 -
/bc 1 -
/wp-admin/includes/xmrlpc.php 1 -
/p0wny.php 1 -
/wp-includes/style.php 1 -
/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application 1 -
/ninjawebshell.php 1 -
/wp-admin/images/xmrlpc.php 1 -
/wp-atom.php 1 -
/wp-admin/style.php 1 -
/wp-content/plugins/core/include.php 1 -
/wp-content/plugins/iloveyou/ilovejoana.php 1 www.google.com
/config.json 1 -
/OLD/wp-admin/setup-config.php 1 www.google.com
/marijuana.php 1 -
/old/wp-admin/setup-config.php 1 www.google.com
/wp-content/style.php 1 -
//OLD/wp-admin/setup-config.php 1 www.google.com
/worm0.PhP7 1 -
/wp-login.php 22 -
/style.php 8 -
/wp-content/plugins/better-search-replace/assets/js/better-search-replace.js 1 -
/wp-admin/network/index.php 1 -
/wordpress 1 -
/uploads/cmd.php 1 -
/wp-content/plugins/post-smtp/style/testEmail.html 1 -
/cgi-bin/cgi-bin/about.php7 1 -
/old 1 -
/wp-admin/user/xmrlpc.php 1 -
/tmp/shell.php 1 -
/telescope/requests 1 -
/wp-pano 2 -
/mar.php 1 -
/bk 1 -
/ninja.php 1 -
/wp-content/plugins/mw-wp-form/css/admin-common.css 2 -
/img/xmrlpc.php 1 -
//wordpress/wp-admin/setup-config.php 1 www.google.com
/wp-includes/js/jquery/jquery.min.js 3 www.google.com
/css/xmrlpc.php 1 -
/wp-content/themes/buddyboss-theme/style.css 1 -
/nf_tracking.php 1 -
END_SIDER_404

# Host - Pages - Hits - Bandwidth - Last visit date - [Start date of last visit] - [Last page of last visit]
# [Start date of last visit] and [Last page of last visit] are saved only if session is not finished
# The 25 first Hits must be first (order not required for others)
BEGIN_VISITOR 36
103.139.17.127 5 5 32364 20240126121043
65.154.226.170 4 22 686924 20240124150623
205.169.39.192 3 20 497571 20240103151852
212.32.252.174 2 2 128 20240103151223
199.241.138.241 2 2 6530 20240107155642
52.90.67.56 2 18 308218 20240107135718
185.141.119.49 2 10 160585 20240126011217
124.220.171.34 2 2 12952 20240102004148
62.197.150.19 1 1 6476 20240120180510
164.90.222.93 1 1 6476 20240103151643
107.191.63.155 1 8 43564 20240103214937
64.23.131.34 1 1 6468 20240124062629
146.190.250.87 1 1 6476 20240113195102
35.88.64.53 1 1 87 20240103151612
198.235.24.176 1 1 6468 20240123042207
138.197.135.171 1 1 6468 20240110060709
23.178.112.108 1 1 87 20240103151612
162.142.125.223 1 1 6468 20240130161730
198.235.24.252 1 1 6476 20240123111740
88.99.26.177 1 1 6468 20240103151755
198.235.24.240 1 1 6468 20240120101349
92.223.86.13 1 1 6476 20240131173155
36.99.136.129 1 1 6476 20240109235051
146.70.178.94 1 1 6476 20240104092305
162.142.125.215 1 1 6476 20240125040956
198.235.24.86 1 1 6476 20240127004822
198.235.24.124 1 1 6468 20240125204646
198.235.24.204 1 1 6468 20240106170835
3.141.28.134 1 1 87 20240103151612
198.199.68.94 1 1 6476 20240127163437
198.235.24.10 1 1 6476 20240130175209
198.235.24.177 1 1 6468 20240131151009
157.245.74.3 1 1 6476 20240104215338
18.222.13.15 0 4 42403 
198.235.24.13 1 1 6468 20240102142234
45.80.158.200 1 1 0 20240126073538
END_VISITOR

# Date - Pages - Hits - Bandwidth - Visits
BEGIN_DAY 18
20240102 3 3 19420 2
20240103 13 46 897930 9
20240104 2 2 12952 2
20240106 1 1 6468 1
20240107 6 22 327692 3
20240109 1 1 6476 1
20240110 1 1 6468 1
20240111 0 4 42403 0
20240113 1 1 6476 1
20240120 3 11 167053 3
20240121 1 1 6476 1
20240123 2 2 12944 2
20240124 3 12 349930 2
20240125 2 2 12944 2
20240126 4 4 19420 3
20240127 2 2 12952 2
20240130 2 2 12944 2
20240131 2 2 12944 2
END_DAY

# Session range - Number of visits
BEGIN_SESSION 3
0s-30s 36
5mn-15mn 1
30s-2mn 2
END_SESSION

# URL - Pages - Bandwidth - Entry - Exit
# The 25 first Pages must be first (order not required for others)
BEGIN_SIDER 5
/ 41 252522 35 32
/.well-known/acme-challenge/jG5zk--xe0XfNpphTKqIYn4OZZSQAaRhTE1nMybBm4E 3 261 3 3
/media/jui/fonts/IcoMoon.woff 3 76272 0 3
/.well-known/acme-challenge/KU2XORSV72V37WR9BLFHPTTF1KGC94RP 1 64 0 1
/.well-known/acme-challenge/BWPA-CH3OH5IX9BO_1TY31E6SGJW67ST 1 64 1 0
END_SIDER

LittleDemon - FACEBOOK
[ KELUAR ]