192.241.204.240 - - [06/Oct/2021:02:07:13 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 3.101.39.205 - - [06/Oct/2021:02:44:38 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 402 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 103.203.59.1 - - [06/Oct/2021:03:09:45 +0200] "GET / HTTP/1.1" 301 383 "-" "HTTP Banner Detection (https://security.ipip.net)" 193.118.53.210 - - [06/Oct/2021:03:12:42 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 109.237.103.118 - - [06/Oct/2021:04:04:56 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.118 - - [06/Oct/2021:04:04:57 +0200] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 161.156.29.33 - - [06/Oct/2021:04:46:06 +0200] "GET /robots.txt HTTP/1.1" 301 397 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 161.156.29.33 - - [06/Oct/2021:04:46:06 +0200] "GET / HTTP/1.1" 301 387 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 131.220.6.152 - - [06/Oct/2021:04:51:52 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 185.180.143.75 - - [06/Oct/2021:05:01:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 165.227.125.18 - - [06/Oct/2021:05:15:58 +0200] "GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd HTTP/1.1" 400 293 "-" "Mozilla/5.0 zgrab/0.x" 34.77.162.10 - - [06/Oct/2021:05:38:00 +0200] "GET / HTTP/1.1" 301 377 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 45.146.164.110 - - [06/Oct/2021:05:39:32 +0200] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:33 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.72 - - [06/Oct/2021:05:39:34 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:35 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:36 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:40 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:41 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:41 +0200] "POST /api/jsonws/invoke HTTP/1.1" 301 314 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:42 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:44 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:45 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.164.110 - - [06/Oct/2021:05:39:45 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.135.14.201 - - [06/Oct/2021:06:31:57 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 34.135.14.201 - - [06/Oct/2021:06:31:59 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 64.62.197.92 - - [06/Oct/2021:07:22:08 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 193.106.29.210 - - [06/Oct/2021:08:19:35 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" 192.241.197.106 - - [06/Oct/2021:08:25:14 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.208.235 - - [06/Oct/2021:08:41:47 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 198.199.104.235 - - [06/Oct/2021:08:44:30 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.208.5 - - [06/Oct/2021:08:45:50 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 60.217.75.69 - - [06/Oct/2021:10:00:00 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 185.189.182.234 - - [06/Oct/2021:10:11:38 +0200] "GET /v0Dr HTTP/1.1" 400 379 "-" "-" 128.14.134.170 - - [06/Oct/2021:11:45:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.200.157 - - [06/Oct/2021:11:55:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 45.146.164.110 - - [06/Oct/2021:12:06:01 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 40.77.167.57 - - [06/Oct/2021:12:10:49 +0200] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.57 - - [06/Oct/2021:12:10:50 +0200] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.73 - - [06/Oct/2021:12:10:55 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 192.241.209.99 - - [06/Oct/2021:14:48:14 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 45.155.126.3 - - [06/Oct/2021:15:05:56 +0200] "-" 408 - "-" "-" 212.102.35.152 - - [06/Oct/2021:16:09:35 +0200] "-" 408 - "-" "-" 23.129.64.135 - - [06/Oct/2021:16:20:08 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 185.220.100.241 - - [06/Oct/2021:16:20:10 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 128.14.141.34 - - [06/Oct/2021:17:18:07 +0200] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 92.118.161.17 - - [06/Oct/2021:17:57:31 +0200] "GET / HTTP/1.1" 400 374 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 37.49.225.132 - - [06/Oct/2021:19:26:07 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 37.49.225.132 - - [06/Oct/2021:19:26:08 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 162.221.192.26 - - [06/Oct/2021:19:46:49 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 106.125.148.120 - - [06/Oct/2021:20:15:47 +0200] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.2459.87 Safari/537.36" 223.167.32.118 - - [06/Oct/2021:20:54:26 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 223.167.32.118 - - [06/Oct/2021:20:54:27 +0200] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 223.167.32.118 - - [06/Oct/2021:20:54:28 +0200] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 223.167.32.118 - - [06/Oct/2021:20:54:30 +0200] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 223.167.32.118 - - [06/Oct/2021:20:54:31 +0200] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 223.167.32.118 - - [06/Oct/2021:20:54:32 +0200] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 167.94.138.57 - - [06/Oct/2021:21:57:10 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.57 - - [06/Oct/2021:21:57:10 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 128.14.134.170 - - [06/Oct/2021:23:10:35 +0200] "GET /solr/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 34.79.107.251 - - [06/Oct/2021:23:22:07 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 34.221.199.152 - - [06/Oct/2021:23:33:11 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.218.240.159 - - [06/Oct/2021:23:33:22 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 18.237.166.79 - - [06/Oct/2021:23:33:42 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.88.146.97 - - [06/Oct/2021:23:33:46 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 40.77.167.73 - - [06/Oct/2021:23:55:43 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 23.148.145.236 - - [07/Oct/2021:00:20:21 +0200] "GET / HTTP/1.1" 301 383 "-" "libwww-perl/6.57" 52.89.168.180 - - [07/Oct/2021:01:20:28 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.221.208.188 - - [07/Oct/2021:01:20:55 +0200] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36"