Repository: cybersecurityops/cyber-ops-with-bash
Branch: master
Commit: 84ccf91092e1
Files: 71
Total size: 123.7 KB
Directory structure:
gitextract_c6os0si7/
├── LICENSE
├── ch03/
│ ├── echoparams.sh
│ └── osdetect.sh
├── ch04/
│ └── frost.txt
├── ch05/
│ ├── cmds.txt
│ ├── cutfile.txt
│ ├── getlocal.sh
│ ├── hashsearch.sh
│ ├── typesearch.sh
│ └── winlogs.sh
├── ch06/
│ ├── accesstime.txt
│ ├── awkusers.txt
│ ├── book.json
│ ├── book.xml
│ ├── csvex.txt
│ ├── ips.txt
│ ├── passwords.txt
│ ├── procowner.txt
│ ├── tasks.txt
│ ├── user.txt
│ └── usernames.txt
├── ch07/
│ ├── access.log
│ ├── countem.awk
│ ├── countem.sh
│ ├── histogram.sh
│ ├── histogram_plain.sh
│ ├── pagereq.awk
│ ├── pagereq.sh
│ ├── summer.sh
│ ├── useragents.sh
│ └── useragents.txt
├── ch08/
│ ├── livebar.sh
│ ├── looper.sh
│ ├── tailcount.sh
│ └── wintail.sh
├── ch09/
│ ├── autoscan.sh
│ ├── fd2.sh
│ └── scan.sh
├── ch10/
│ └── baseline.sh
├── ch11/
│ ├── Calc_VT.txt
│ ├── WannaCry_VT.txt
│ ├── helloworld.c
│ ├── vtjson.awk
│ └── vtjson.sh
├── ch12/
│ ├── tagit.sh
│ ├── webdash.sh
│ └── weblogfmt.sh
├── ch13/
│ ├── bannergrabber.sh
│ └── smtpconnect.sh
├── ch14/
│ ├── askey.sh
│ ├── innerscript.sh
│ ├── logfuscate.sh
│ ├── oneline.sh
│ ├── readable.sh
│ ├── streamcipher.sh
│ ├── synfuscate.sh
│ └── wrapper.sh
├── ch15/
│ ├── fuzzer.sh
│ └── fuzzme.c
├── ch16/
│ ├── LocalRat.sh
│ └── RemoteRat.sh
├── ch19/
│ └── pingmonitor.sh
├── ch20/
│ └── softinv.sh
├── ch21/
│ ├── test.input
│ └── validateconfig.sh
├── ch22/
│ ├── checkemail.1liner
│ ├── checkemail.sh
│ ├── checkemailAlt.sh
│ ├── checkpass.sh
│ └── emailbatch.sh
└── readme.txt
================================================
FILE CONTENTS
================================================
================================================
FILE: LICENSE
================================================
MIT License
Copyright (c) 2019 Cybersecurity Ops with bash
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
================================================
FILE: ch03/echoparams.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# echoparams.sh
#
# Description:
# Demonstrates accessing parameters in bash
#
# Usage:
# ./echoparms.sh
#
echo $#
echo $0
echo $1
echo $2
echo $3
================================================
FILE: ch03/osdetect.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# osdetect.sh
#
# Description:
# Distinguish between MS-Windows/Linux/MacOS
#
# Usage: bash osdetect.sh
# output will be one of: Linux MSWin macOS
#
if type -t wevtutil &> /dev/null # <1>
then
OS=MSWin
elif type -t scutil &> /dev/null # <2>
then
OS=macOS
else
OS=Linux
fi
echo $OS
================================================
FILE: ch04/frost.txt
================================================
1 Two roads diverged in a yellow wood,
2 And sorry I could not travel both
3 And be one traveler, long I stood
4 And looked down one as far as I could
5 To where it bent in the undergrowth;
6
7 Excerpt from The Road Not Taken by Robert Frost
================================================
FILE: ch05/cmds.txt
================================================
#Linux Command |MSWin Bash |XML tag |Purpose
#----------------+------------+-----------+------------------------------
uname -a |uname -a |uname |O.S. version etc
cat /proc/cpuinfo|systeminfo |sysinfo |system hardware and related info
ifconfig |ipconfig |nwinterface|Network interface information
ip route |route print |nwroute |routing table
arp -a |arp -a |nwarp |ARP table
netstat -a |netstat -a |netstat |network connections
mount |net share |diskinfo |mounted disks
ps -e |tasklist |processes |running processes
================================================
FILE: ch05/cutfile.txt
================================================
12/05/2017 192.168.10.14 test.html
12/30/2017 192.168.10.185 login.html
================================================
FILE: ch05/getlocal.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# getlocal.sh
#
# Description:
# Gathers general system information and dumps it to a file
#
# Usage:
# bash getlocal.sh < cmds.txt
# cmds.txt is a file with list of commands to run
#
# SepCmds - separate the commands from the line of input
function SepCmds()
{
LCMD=${ALINE%%|*} # <11>
REST=${ALINE#*|} # <12>
WCMD=${REST%%|*} # <13>
REST=${REST#*|}
TAG=${REST%%|*} # <14>
if [[ $OSTYPE == "MSWin" ]]
then
CMD="$WCMD"
else
CMD="$LCMD"
fi
}
function DumpInfo ()
{ # <5>
printf '\n' "$(date '+%F')" "$(date '+%T')"
readarray CMDS # <6>
for ALINE in "${CMDS[@]}" # <7>
do
# ignore comments
if [[ ${ALINE:0:1} == '#' ]] ; then continue ; fi # <8>
SepCmds
if [[ ${CMD:0:3} == N/A ]] # <9>
then
continue
else
printf "<%s>\n" $TAG # <10>
$CMD
printf "%s>\n" $TAG
fi
done
printf "\n"
}
OSTYPE=$(./osdetect.sh) # <1>
HOSTNM=$(hostname) # <2>
TMPFILE="${HOSTNM}.info" # <3>
# gather the info into the tmp file; errors, too
DumpInfo > $TMPFILE 2>&1 # <4>
================================================
FILE: ch05/hashsearch.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# hashsearch.sh
#
# Description:
# Recursively search a given directory for a file that
# matches a given SHA-1 hash
#
# Usage:
# hashsearch.sh
# hash - SHA-1 hash value to file to find
# directory - Top directory to start search
#
HASH=$1
DIR=${2:-.} # default is here, cwd
# convert pathname into an absolute path
function mkabspath () # <6>
{
if [[ $1 == /* ]] # <7>
then
ABS=$1
else
ABS="$PWD/$1" # <8>
fi
}
find $DIR -type f | # <1>
while read fn
do
THISONE=$(sha1sum "$fn") # <2>
THISONE=${THISONE%% *} # <3>
if [[ $THISONE == $HASH ]]
then
mkabspath "$fn" # <4>
echo $ABS # <5>
fi
done
================================================
FILE: ch05/typesearch.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# typesearch.sh
#
# Description:
# Search the file system for a given file type. It prints out the
# pathname when found.
#
# Usage:
# typesearch.sh [-c dir] [-i] [-R|r]
# -c Copy files found to dir
# -i Ignore case
# -R|r Recursively search subdirectories
# File type pattern to search for
# Path to start search
#
DEEPORNOT="-maxdepth 1" # just the current dir; default
# PARSE option arguments:
while getopts 'c:irR' opt; do # <1>
case "${opt}" in # <2>
c) # copy found files to specified directory
COPY=YES
DESTDIR="$OPTARG" # <3>
;;
i) # ignore u/l case differences in search
CASEMATCH='-i'
;;
[Rr]) # recursive # <4>
unset DEEPORNOT;; # <5>
*) # unknown/unsupported option # <6>
# error mesg will come from getopts, so just exit
exit 2 ;;
esac
done
shift $((OPTIND - 1)) # <7>
PATTERN=${1:-PDF document} # <8>
STARTDIR=${2:-.} # by default start here
find $STARTDIR $DEEPORNOT -type f | while read FN # <9>
do
file $FN | egrep -q $CASEMATCH "$PATTERN" # <10>
if (( $? == 0 )) # found one # <11>
then
echo $FN
if [[ $COPY ]] # <12>
then
cp -p $FN $DESTDIR # <13>
fi
fi
done
================================================
FILE: ch05/winlogs.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# winlogs.sh
#
# Description:
# Gather copies of Windows log files
#
# Usage:
# winlogs.sh [-z] [dir]
# -z Tar and zip the output
# dir Optional scratch directory for holding the log files
TGZ=0
if (( $# > 0 )) # <1>
then
if [[ ${1:0:2} == '-z' ]] # <2>
then
TGZ=1 # tgz flag to tar/zip the log files
shift
fi
fi
SYSNAM=$(hostname)
LOGDIR=${1:-/tmp/${SYSNAM}_logs} # <3>
mkdir -p $LOGDIR # <4>
cd ${LOGDIR} || exit -2
wevtutil el | while read ALOG # <5>
do
ALOG="${ALOG%$'\r'}" # <6>
echo "${ALOG}:" # <7>
SAFNAM="${ALOG// /_}" # <8>
SAFNAM="${SAFNAM//\//-}"
wevtutil epl "$ALOG" "${SYSNAM}_${SAFNAM}.evtx"
done
if (( TGZ == 1 )) # <9>
then
tar -czvf ${SYSNAM}_logs.tgz *.evtx # <10>
fi
================================================
FILE: ch06/accesstime.txt
================================================
0745,file1.txt,1
0830,file4.txt,2
0830,file5.txt,3
================================================
FILE: ch06/awkusers.txt
================================================
Mike Jones
John Smith
Kathy Jones
Jane Kennedy
Tim Scott
================================================
FILE: ch06/book.json
================================================
{ <1>
"title": "Cybersecurity Ops with bash", <2>
"edition": 1,
"authors": [ <3>
{
"firstName": "Paul",
"lastName": "Troncone"
},
{
"firstName": "Carl",
"lastName": "Albing"
}
]
}
================================================
FILE: ch06/book.xml
================================================
<1>
<2>
Paul <3>
Troncone
<4>
Carl
Albing
================================================
FILE: ch06/csvex.txt
================================================
"name","username","phone","password hash"
"John Smith","jsmith","555-555-1212",5f4dcc3b5aa765d61d8327deb882cf99
"Jane Smith","jnsmith","555-555-1234",e10adc3949ba59abbe56e057f20f883e
"Bill Jones","bjones","555-555-6789",d8578edf8458ce06fbc5bb76a58c5ca4
================================================
FILE: ch06/ips.txt
================================================
ip,OS
10.0.4.2,Windows 8
10.0.4.35,Ubuntu 16
10.0.4.107,macOS
10.0.4.145,macOS
================================================
FILE: ch06/passwords.txt
================================================
password,md5hash
123456,e10adc3949ba59abbe56e057f20f883e
password,5f4dcc3b5aa765d61d8327deb882cf99
welcome,40be4e59b9a2a2b5dffb918c0e86b3d7
ninja,3899dcbab79f92af727c2190bbd8abc5
abc123,e99a18c428cb38d5f260853678922e03
123456789,25f9e794323b453885f5181f1b624d0b
12345678,25d55ad283aa400af464c76d713c07ad
sunshine,0571749e2ac330a7455809c6b0e7af90
princess,8afa847f50a716e64932d995c8e7435a
qwerty,d8578edf8458ce06fbc5bb76a58c5c
================================================
FILE: ch06/procowner.txt
================================================
Process Owner;PID
jdoe;0
tjones;4
jsmith;340
msmith;528
================================================
FILE: ch06/tasks.txt
================================================
Image Name;PID;Session Name;Session#;Mem Usage
System Idle Process;0;Services;0;4 K
System;4;Services;0;2,140 K
smss.exe;340;Services;0;1,060 K
csrss.exe;528;Services;0;4,756 K
================================================
FILE: ch06/user.txt
================================================
user,ip
jdoe,10.0.4.2
jsmith,10.0.4.35
msmith,10.0.4.107
tjones,10.0.4.145
================================================
FILE: ch06/usernames.txt
================================================
1,jdoe
2,puser
3,jsmith
================================================
FILE: ch07/access.log
================================================
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /backblue.gif HTTP/1.1" 200 4529 "http://192.168.0.35/" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /fade.gif HTTP/1.1" 200 1112 "http://192.168.0.35/" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /favicon.ico HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /index.html HTTP/1.1" 200 6933 "-" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /favicon.ico HTTP/1.1" 404 504 "-" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:52:59 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:00 -0500] "GET /uploads/2/9/1/4/29147191/941880.png HTTP/1.1" 200 7835 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:00 -0500] "GET /uploads/2/9/1/4/29147191/31549414299.png?457 HTTP/1.1" 200 81377 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:00 -0500] "GET /uploads/2/9/1/4/29147191/2670902_orig.jpg HTTP/1.1" 200 19526 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:00 -0500] "GET /uploads/2/9/1/4/29147191/2267842_orig.jpg HTTP/1.1" 200 42818 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:00 -0500] "GET /uploads/2/9/1/4/29147191/2992005_orig.jpg HTTP/1.1" 200 47030 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /about.html HTTP/1.1" 200 7042 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /uploads/2/9/1/4/29147191/page-layouts-4078890_orig.jpg HTTP/1.1" 200 265418 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19445 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:53:11 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/GW-bridge.html HTTP/1.1" 200 5011 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /consulting.html HTTP/1.1" 200 7269 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /uploads/2/9/1/4/29147191/398980_orig.png HTTP/1.1" 200 120188 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:10 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19445 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:54:11 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5011 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /backblue.gif HTTP/1.1" 200 4529 "http://192.168.0.35/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /fade.gif HTTP/1.1" 200 1113 "http://192.168.0.35/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /favicon.ico HTTP/1.1" 404 503 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /index.html HTTP/1.1" 200 6932 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /uploads/2/9/1/4/29147191/941880.png HTTP/1.1" 200 7835 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /uploads/2/9/1/4/29147191/31549414299.png?457 HTTP/1.1" 200 81377 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /uploads/2/9/1/4/29147191/2670902_orig.jpg HTTP/1.1" 200 19525 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /uploads/2/9/1/4/29147191/2992005_orig.jpg HTTP/1.1" 200 47029 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:26 -0500] "GET /uploads/2/9/1/4/29147191/2267842_orig.jpg HTTP/1.1" 200 42819 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:30 -0500] "GET /support.html HTTP/1.1" 200 6207 "http://192.168.0.35/index.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:30 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/support.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:31 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/support.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:39 -0500] "GET /request-quote.html HTTP/1.1" 200 7326 "http://192.168.0.35/support.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:39 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:39 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5011 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:54:39 -0500] "GET /files/theme/images/select-arrowaf0e.png?1509483497 HTTP/1.1" 200 1386 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /products.html HTTP/1.1" 200 7158 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 200 16602 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 200 26428 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 200 38062 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:52 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19445 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:15:56:53 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /uploads/2/9/1/4/29147191/identity_orig.png HTTP/1.1" 200 47804 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /uploads/2/9/1/4/29147191/editor/078519-blue-jelly-icon-business-envelope5ca13.png?1492225862 HTTP/1.1" 200 7769 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /uploads/2/9/1/4/29147191/428026.png HTTP/1.1" 200 20174 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /uploads/2/9/1/4/29147191/principlesofcyber_orig.png HTTP/1.1" 200 43725 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /uploads/2/9/1/4/29147191/principlesofencryption-nb_orig.png HTTP/1.1" 200 45954 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:10 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5011 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:15:57:15 -0500] "GET /uploads/2/9/1/4/29147191/protecting_your_identity.pdf HTTP/1.1" 200 775340 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.26 - - [12/Nov/2017:16:16:01 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /backblue.gif HTTP/1.1" 200 4529 "http://192.168.0.35/" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /fade.gif HTTP/1.1" 200 1113 "http://192.168.0.35/" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /index.html HTTP/1.1" 200 6932 "http://192.168.0.35/" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /uploads/2/9/1/4/29147191/941880.png HTTP/1.1" 200 7835 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /uploads/2/9/1/4/29147191/31549414299.png?457 HTTP/1.1" 200 81378 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /uploads/2/9/1/4/29147191/2670902_orig.jpg HTTP/1.1" 200 19526 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /uploads/2/9/1/4/29147191/2267842_orig.jpg HTTP/1.1" 200 42818 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:02 -0500] "GET /uploads/2/9/1/4/29147191/2992005_orig.jpg HTTP/1.1" 200 47029 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:06 -0500] "GET /products.html HTTP/1.1" 200 7157 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:07 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 200 16602 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:07 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 200 26427 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:07 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 200 38061 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:07 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:16 -0500] "GET /bcp.html HTTP/1.1" 200 6651 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:16 -0500] "GET /uploads/2/9/1/4/29147191/601239_orig.png HTTP/1.1" 200 111181 "http://192.168.0.35/bcp.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:16 -0500] "GET /uploads/2/9/1/4/29147191/4304070_orig.png HTTP/1.1" 200 57269 "http://192.168.0.35/bcp.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:16:16 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Coffee.html HTTP/1.1" 200 5011 "http://192.168.0.35/bcp.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:05 -0500] "GET /consulting.html HTTP/1.1" 200 7269 "http://192.168.0.35/bcp.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:06 -0500] "GET /uploads/2/9/1/4/29147191/398980_orig.png HTTP/1.1" 200 120188 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:06 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5012 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:42 -0500] "GET /contact.html HTTP/1.1" 200 6976 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:42 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/contact.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.26 - - [12/Nov/2017:16:18:42 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/iPad.html HTTP/1.1" 200 5011 "http://192.168.0.35/contact.html" "Mozilla/5.0 (iPad; CPU OS 11_0 like Mac OS X) AppleWebKit/604.1.38 (KHTML, like Gecko) Version/11.0 Mobile/15A372 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:22 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:22 -0500] "GET /backblue.gif HTTP/1.1" 200 4529 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:22 -0500] "GET /fade.gif HTTP/1.1" 200 1113 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /index.html HTTP/1.1" 200 6932 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /uploads/2/9/1/4/29147191/941880.png HTTP/1.1" 200 7835 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /uploads/2/9/1/4/29147191/31549414299.png?457 HTTP/1.1" 200 81378 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /uploads/2/9/1/4/29147191/2670902_orig.jpg HTTP/1.1" 200 19526 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /uploads/2/9/1/4/29147191/2267842_orig.jpg HTTP/1.1" 200 42818 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:23 -0500] "GET /uploads/2/9/1/4/29147191/2992005_orig.jpg HTTP/1.1" 200 47029 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /uploads/2/9/1/4/29147191/identity_orig.png HTTP/1.1" 200 47804 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /uploads/2/9/1/4/29147191/editor/078519-blue-jelly-icon-business-envelope5ca13.png?1492225862 HTTP/1.1" 200 7769 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /uploads/2/9/1/4/29147191/428026.png HTTP/1.1" 200 20174 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /uploads/2/9/1/4/29147191/principlesofcyber_orig.png HTTP/1.1" 200 43725 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /uploads/2/9/1/4/29147191/principlesofencryption-nb_orig.png HTTP/1.1" 200 45953 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:28 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5011 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:16:42:34 -0500] "GET /uploads/2/9/1/4/29147191/principles_of_cyber.pdf HTTP/1.1" 200 765195 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:10 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:10 -0500] "GET /backblue.gif HTTP/1.1" 304 182 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:10 -0500] "GET /fade.gif HTTP/1.1" 304 181 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:10 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:10 -0500] "GET /index.html HTTP/1.1" 200 6932 "http://192.168.0.35/" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:12 -0500] "GET /products.html HTTP/1.1" 200 7157 "http://192.168.0.35/index.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:12 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 200 16602 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:12 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 200 38061 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:12 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 200 26427 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:12 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5012 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:17 -0500] "GET /risk.html HTTP/1.1" 200 6606 "http://192.168.0.35/products.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:17 -0500] "GET /uploads/2/9/1/4/29147191/43527096c52.png?356 HTTP/1.1" 200 55344 "http://192.168.0.35/risk.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:17 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Graph.html HTTP/1.1" 200 5012 "http://192.168.0.35/risk.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:17:29:17 -0500] "GET /uploads/2/9/1/4/29147191/4418930_orig.png HTTP/1.1" 200 174914 "http://192.168.0.35/risk.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:05 -0500] "GET /about.html HTTP/1.1" 200 7042 "http://192.168.0.35/risk.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:06 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/about.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:06 -0500] "GET /uploads/2/9/1/4/29147191/page-layouts-4078890_orig.jpg HTTP/1.1" 200 265419 "http://192.168.0.35/about.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:06 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/GW-bridge.html HTTP/1.1" 200 5011 "http://192.168.0.35/about.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:13 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/about.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:13 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5012 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.14 - - [12/Nov/2017:18:18:16 -0500] "GET /uploads/2/9/1/4/29147191/principles_of_encryption.pdf HTTP/1.1" 200 1045139 "http://192.168.0.35/resources.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_1 like Mac OS X) AppleWebKit/604.3.5 (KHTML, like Gecko) Version/11.0 Mobile/15B93 Safari/604.1"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /incident.html HTTP/1.1" 200 6621 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /uploads/2/9/1/4/29147191/4174185_orig.png HTTP/1.1" 200 99002 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /uploads/2/9/1/4/29147191/1888827_orig.png HTTP/1.1" 200 59026 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:25:48 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working.html HTTP/1.1" 200 5011 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.36 - - [12/Nov/2017:18:35:47 -0500] "GET /robots.txt HTTP/1.1" 404 503 "-" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:48 -0500] "GET / HTTP/1.1" 200 2377 "-" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:49 -0500] "GET /backblue.gif HTTP/1.1" 200 4529 "http://192.168.0.35/" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:50 -0500] "GET /fade.gif HTTP/1.1" 200 1112 "http://192.168.0.35/" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:51 -0500] "GET /index.html HTTP/1.1" 200 6932 "http://192.168.0.35/" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:52 -0500] "GET /uploads/2/9/1/4/29147191/31549414299.png?457 HTTP/1.1" 200 81377 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:53 -0500] "GET /uploads/2/9/1/4/29147191/2670902_orig.jpg HTTP/1.1" 200 19526 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:54 -0500] "GET /uploads/2/9/1/4/29147191/2267842_orig.jpg HTTP/1.1" 200 42819 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:55 -0500] "GET /uploads/2/9/1/4/29147191/2992005_orig.jpg HTTP/1.1" 200 47030 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:35:58 -0500] "GET /uploads/2/9/1/4/29147191/941880.png HTTP/1.1" 200 7836 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:01 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /products.html HTTP/1.1" 200 7158 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 200 16602 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 200 26428 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 200 38062 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:36:01 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.36 - - [12/Nov/2017:18:36:02 -0500] "GET /products.html HTTP/1.1" 200 7158 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:03 -0500] "GET /consulting.html HTTP/1.1" 200 7268 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:04 -0500] "GET /resources.html HTTP/1.1" 200 7568 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:05 -0500] "GET /about.html HTTP/1.1" 200 7041 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:06 -0500] "GET /support.html HTTP/1.1" 200 6207 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:07 -0500] "GET /contact.html HTTP/1.1" 200 6975 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /about.html HTTP/1.1" 200 7042 "http://192.168.0.35/incident.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.36 - - [12/Nov/2017:18:36:08 -0500] "GET /request-quote.html HTTP/1.1" 200 7325 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:36:08 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/GW-bridge.html HTTP/1.1" 200 5011 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.36 - - [12/Nov/2017:18:36:09 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:10 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:11 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/index.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:12 -0500] "GET /files/theme/images/default-bgaf0e.jpg?1509483497 HTTP/1.1" 200 239379 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:13 -0500] "GET /files/theme/images/select-arrowaf0e.png?1509483497 HTTP/1.1" 200 1385 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:14 -0500] "GET /files/theme/images/light-checkboxaf0e.png?1509483497 HTTP/1.1" 200 1456 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:15 -0500] "GET /files/theme/images/icon-bubbleaf0e.png?1509483497 HTTP/1.1" 200 1584 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:16 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 200 16602 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:17 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 200 26427 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:18 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 200 38062 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:19 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:20 -0500] "GET /risk.html HTTP/1.1" 200 6605 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:21 -0500] "GET /incident.html HTTP/1.1" 200 6620 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:23 -0500] "GET /bcp.html HTTP/1.1" 200 6650 "http://192.168.0.35/products.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:25 -0500] "GET /uploads/2/9/1/4/29147191/398980_orig.png HTTP/1.1" 200 120189 "http://192.168.0.35/consulting.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:27 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5011 "http://192.168.0.35/consulting.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:29 -0500] "GET /uploads/2/9/1/4/29147191/identity_orig.png HTTP/1.1" 200 47805 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:31 -0500] "GET /uploads/2/9/1/4/29147191/editor/078519-blue-jelly-icon-business-envelope5ca13.png?1492225862 HTTP/1.1" 200 7768 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:35 -0500] "GET /uploads/2/9/1/4/29147191/428026.png HTTP/1.1" 200 20173 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:40 -0500] "GET /uploads/2/9/1/4/29147191/principlesofcyber_orig.png HTTP/1.1" 200 43725 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:41 -0500] "GET /uploads/2/9/1/4/29147191/principlesofencryption-nb_orig.png HTTP/1.1" 200 45954 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:47 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5012 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:53 -0500] "GET /uploads/2/9/1/4/29147191/principles_of_encryption.pdf HTTP/1.1" 200 1045140 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:55 -0500] "GET /uploads/2/9/1/4/29147191/page-layouts-4078890_orig.jpg HTTP/1.1" 200 265419 "http://192.168.0.35/about.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.37 - - [12/Nov/2017:18:37:23 -0500] "GET /consulting.html HTTP/1.1" 200 7269 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:37:23 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:37:23 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:37:23 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:37:23 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:37:24 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5011 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /uploads/2/9/1/4/29147191/identity_orig.png HTTP/1.1" 200 47804 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /uploads/2/9/1/4/29147191/editor/078519-blue-jelly-icon-business-envelope5ca13.png?1492225862 HTTP/1.1" 200 7769 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /uploads/2/9/1/4/29147191/428026.png HTTP/1.1" 200 20174 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /uploads/2/9/1/4/29147191/principlesofcyber_orig.png HTTP/1.1" 200 43725 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /uploads/2/9/1/4/29147191/principlesofencryption-nb_orig.png HTTP/1.1" 200 45954 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:27 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5011 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:30 -0500] "GET /uploads/2/9/1/4/29147191/principles_of_cyber.pdf HTTP/1.1" 200 765194 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.36 - - [12/Nov/2017:18:36:49 -0500] "GET /uploads/2/9/1/4/29147191/protecting_your_identity.pdf HTTP/1.1" 200 775341 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:36:51 -0500] "GET /uploads/2/9/1/4/29147191/principles_of_cyber.pdf HTTP/1.1" 200 765194 "http://192.168.0.35/resources.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:37:44 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/GW-bridge.html HTTP/1.1" 200 5012 "http://192.168.0.35/about.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:37:45 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/iPad.html HTTP/1.1" 200 5011 "http://192.168.0.35/contact.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.11 - - [12/Nov/2017:18:37:46 -0500] "GET /risk.html HTTP/1.1" 200 6606 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:46 -0500] "GET /uploads/2/9/1/4/29147191/43527096c52.png?356 HTTP/1.1" 200 55344 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:46 -0500] "GET /uploads/2/9/1/4/29147191/4418930_orig.png HTTP/1.1" 200 174914 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:18:37:46 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Graph.html HTTP/1.1" 200 5011 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.36 - - [12/Nov/2017:18:37:47 -0500] "GET /uploads/2/9/1/4/29147191/43527096c52.png?356 HTTP/1.1" 200 55344 "http://192.168.0.35/risk.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:38:00 -0500] "GET /uploads/2/9/1/4/29147191/4418930_orig.png HTTP/1.1" 200 174914 "http://192.168.0.35/risk.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:38:31 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Graph.html HTTP/1.1" 200 5012 "http://192.168.0.35/risk.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:38:32 -0500] "GET /uploads/2/9/1/4/29147191/4174185_orig.png HTTP/1.1" 200 99001 "http://192.168.0.35/incident.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:38:49 -0500] "GET /uploads/2/9/1/4/29147191/1888827_orig.png HTTP/1.1" 200 59026 "http://192.168.0.35/incident.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:39:01 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working.html HTTP/1.1" 200 5012 "http://192.168.0.35/incident.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:39:03 -0500] "GET /uploads/2/9/1/4/29147191/601239_orig.png HTTP/1.1" 200 111182 "http://192.168.0.35/bcp.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:39:05 -0500] "GET /uploads/2/9/1/4/29147191/4304070_orig.png HTTP/1.1" 200 57268 "http://192.168.0.35/bcp.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.36 - - [12/Nov/2017:18:39:07 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Coffee.html HTTP/1.1" 200 5012 "http://192.168.0.35/bcp.html" "Mozilla/4.5 (compatible; HTTrack 3.0x; Windows 98)"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /uploads/2/9/1/4/29147191/identity_orig.png HTTP/1.1" 200 47804 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /uploads/2/9/1/4/29147191/editor/078519-blue-jelly-icon-business-envelope5ca13.png?1492225862 HTTP/1.1" 200 7769 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /uploads/2/9/1/4/29147191/428026.png HTTP/1.1" 200 20174 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /uploads/2/9/1/4/29147191/principlesofcyber_orig.png HTTP/1.1" 200 43724 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /uploads/2/9/1/4/29147191/principlesofencryption-nb_orig.png HTTP/1.1" 200 45953 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:41:56 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5011 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:18:42:01 -0500] "GET /uploads/2/9/1/4/29147191/protecting_your_identity.pdf HTTP/1.1" 200 775340 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /products.html HTTP/1.1" 200 7158 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /uploads/2/9/1/4/29147191/32981bd4c.png?161 HTTP/1.1" 304 182 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /uploads/2/9/1/4/29147191/99480889766.png?165 HTTP/1.1" 304 182 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /uploads/2/9/1/4/29147191/253922682aa.png?162 HTTP/1.1" 304 182 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:10 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Working2.html HTTP/1.1" 200 5011 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /risk.html HTTP/1.1" 200 6605 "http://192.168.0.35/products.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /uploads/2/9/1/4/29147191/43527096c52.png?356 HTTP/1.1" 200 55344 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:14 -0500] "GET /uploads/2/9/1/4/29147191/4418930_orig.png HTTP/1.1" 200 174913 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:15 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Graph.html HTTP/1.1" 200 5011 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /contact.html HTTP/1.1" 200 6975 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3413 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:18 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/iPad.html HTTP/1.1" 200 5011 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /request-quote.html HTTP/1.1" 200 7326 "http://192.168.0.35/contact.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1429 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Colaboration.html HTTP/1.1" 200 5011 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:31 -0500] "GET /files/theme/images/select-arrowaf0e.png?1509483497 HTTP/1.1" 200 1385 "http://192.168.0.35/files/main_styleaf0e.css?1509483497" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:45 -0500] "GET /about.html HTTP/1.1" 200 7042 "http://192.168.0.35/request-quote.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:45 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:45 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:45 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:45 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:25:46 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/GW-bridge.html HTTP/1.1" 200 5011 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:26:04 -0500] "GET /consulting.html HTTP/1.1" 200 7269 "http://192.168.0.35/about.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:26:04 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:26:04 -0500] "GET /files/theme/mobile49c2.js?1490908488 HTTP/1.1" 200 3414 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:26:04 -0500] "GET /files/theme/plugin49c2.js?1490908488 HTTP/1.1" 200 19444 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.37 - - [12/Nov/2017:19:26:04 -0500] "GET /files/theme/custom49c2.js?1490908488 HTTP/1.1" 200 1430 "http://192.168.0.35/consulting.html" "Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0"
192.168.0.11 - - [12/Nov/2017:19:26:09 -0500] "GET /resources.html HTTP/1.1" 200 7569 "http://192.168.0.35/risk.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:19:26:09 -0500] "GET /files/main_styleaf0e.css?1509483497 HTTP/1.1" 200 5022 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
192.168.0.11 - - [12/Nov/2017:19:26:09 -0500] "GET /_/cdn2.editmysite.com/images/editor/theme-background/stock/Work-Outside.html HTTP/1.1" 200 5011 "http://192.168.0.35/resources.html" "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:56.0) Gecko/20100101 Firefox/56.0"
================================================
FILE: ch07/countem.awk
================================================
# Cybersecurity Ops with bash
# countem.awk
#
# Description:
# Count the number of instances of an item using awk
#
# Usage:
# countem.awk < inputfile
#
awk '{ cnt[$1]++ }
END { for (id in cnt) {
printf "%d %s\n", cnt[id], id
}
}'
================================================
FILE: ch07/countem.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# countem.sh
#
# Description:
# Count the number of instances of an item using bash
#
# Usage:
# countem.sh < inputfile
#
declare -A cnt # assoc. array # <1>
while read id xtra # <2>
do
let cnt[$id]++ # <3>
done
# now display what we counted
# for each key in the (key, value) assoc. array
for id in "${!cnt[@]}" # <4>
do
printf '%s %d\n' "$id" "${cnt[$id]}" # <5>
done
================================================
FILE: ch07/histogram.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# histogram.sh
#
# Description:
# Generate a horizontal bar chart of specified data
#
# Usage: ./histogram.sh
# input format: label value
#
function pr_bar () # <1>
{
local -i i raw maxraw scaled # <2>
raw=$1
maxraw=$2
((scaled=(MAXBAR*raw)/maxraw)) # <3>
# min size guarantee
((raw > 0 && scaled == 0)) && scaled=1 # <4>
for((i=0; i
declare -i MAXBAR max
max=0
MAXBAR=50 # how large the largest bar should be
while read labl val
do
let RA[$labl]=$val # <6>
# keep the largest value; for scaling
(( val > max )) && max=$val
done
# scale and print it
for labl in "${!RA[@]}" # <7>
do
printf '%-20.20s ' "$labl"
pr_bar ${RA[$labl]} $max # <8>
done
================================================
FILE: ch07/histogram_plain.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# histogram_plain.sh
#
# Description:
# Generate a horizontal bar chart of specified data without
# using associative arrays, good for older versions of bash
#
# Usage: ./histogram_plain.sh
# input format: label value
#
declare -a RA_key RA_val # <1>
declare -i max ndx
max=0
maxbar=50 # how large the largest bar should be
ndx=0
while read labl val
do
RA_key[$ndx]=$labl # <2>
RA_value[$ndx]=$val
# keep the largest value; for scaling
(( val > max )) && max=$val
let ndx++
done
# scale and print it
for ((j=0; j
do
printf "%-20.20s " ${RA_key[$j]}
pr_bar ${RA_value[$j]} $max
done
================================================
FILE: ch07/pagereq.awk
================================================
# Cybersecurity Ops with bash
# pagereq.awk
#
# Description:
# Count the number of page requests for a given IP address using awk
#
# Usage:
# pagereq < inputfile
# IP address to search for
#
# count the number of page requests from an address ($1)
awk -v page="$1" '{ if ($1==page) {cnt[$7]+=1 } } # <1>
END { for (id in cnt) { # <2>
printf "%8d %s\n", cnt[id], id
}
}'
================================================
FILE: ch07/pagereq.sh
================================================
# Cybersecurity Ops with bash
# pagereq.sh
#
# Description:
# Count the number of page requests for a given IP address using bash
#
# Usage:
# pagereq < inputfile
# IP address to search for
#
declare -A cnt # <1>
while read addr d1 d2 datim gmtoff getr page therest
do
if [[ $1 == $addr ]] ; then let cnt[$page]+=1 ; fi
done
for id in ${!cnt[@]} # <2>
do
printf "%8d %s\n" ${cnt[$id]} $id
done
================================================
FILE: ch07/summer.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# summer.sh
#
# Description:
# Sum the total of field 2 values for each unique field 1
#
# Usage: ./summer.sh
# input format:
#
declare -A cnt # assoc. array
while read id count
do
let cnt[$id]+=$count
done
for id in "${!cnt[@]}"
do
printf "%-15s %8d\n" "${id}" "${cnt[${id}]}" #<1>
done
================================================
FILE: ch07/useragents.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# useragents.sh
#
# Description:
# Read through a log looking for unknown user agents
#
# Usage: ./useragents.sh <
# Apache access log
#
# mismatch - search through the array of known names
# returns 1 (false) if it finds a match
# returns 0 (true) if there is no match
function mismatch () # <1>
{
local -i i # <2>
for ((i=0; i<$KNSIZE; i++))
do
[[ "$1" =~ .*${KNOWN[$i]}.* ]] && return 1 # <3>
done
return 0
}
# read up the known ones
readarray -t KNOWN < "useragents.txt" # <4>
KNSIZE=${#KNOWN[@]} # <5>
# preprocess logfile (stdin) to pick out ipaddr and user agent
awk -F'"' '{print $1, $6}' | \
while read ipaddr dash1 dash2 dtstamp delta useragent # <6>
do
if mismatch "$useragent"
then
echo "anomaly: $ipaddr $useragent"
fi
done
================================================
FILE: ch07/useragents.txt
================================================
Firefox
Chrome
Safari
Edge
================================================
FILE: ch08/livebar.sh
================================================
#!/bin/bash -
#
# Cybersecurity Ops with bash
# livebar.sh
#
# Description:
# Creates a rolling horizontal bar chart of live data
#
# Usage:
#