192.241.217.91 - - [13/Jan/2022:01:33:04 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 198.199.107.58 - - [13/Jan/2022:01:34:32 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.31 - - [13/Jan/2022:01:35:08 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 207.46.13.56 - - [13/Jan/2022:02:30:28 +0100] "GET / HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 156.96.156.9 - - [13/Jan/2022:04:03:49 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 156.96.156.9 - - [13/Jan/2022:04:03:50 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 192.241.205.59 - - [13/Jan/2022:04:07:50 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 40.77.167.42 - - [13/Jan/2022:04:20:59 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 162.142.125.58 - - [13/Jan/2022:04:37:23 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.58 - - [13/Jan/2022:04:37:24 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 64.62.197.182 - - [13/Jan/2022:04:45:28 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 131.220.6.152 - - [13/Jan/2022:04:48:03 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 208.100.26.248 - - [13/Jan/2022:07:02:29 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 7.1.2; LG-SP200) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.93 Mobile Safari/537.36" 208.100.26.247 - - [13/Jan/2022:07:02:30 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:69.0) Gecko/20100101 Firefox/69.0" 192.241.217.26 - - [13/Jan/2022:07:35:31 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 212.243.9.107 - - [13/Jan/2022:07:52:46 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.10" 130.211.54.158 - - [13/Jan/2022:08:08:59 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.27.1" 167.94.138.116 - - [13/Jan/2022:09:24:34 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.116 - - [13/Jan/2022:09:24:35 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 2.56.56.140 - - [13/Jan/2022:09:45:52 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 2.56.56.140 - - [13/Jan/2022:09:45:53 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:10:33:41 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 3.145.135.127 - - [13/Jan/2022:11:12:54 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" 192.241.219.52 - - [13/Jan/2022:11:16:47 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.214.242 - - [13/Jan/2022:11:27:32 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 193.118.53.210 - - [13/Jan/2022:11:43:20 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:11:55:35 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 207.46.13.56 - - [13/Jan/2022:12:01:22 +0100] "GET / HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 45.146.165.37 - - [13/Jan/2022:12:49:24 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:13:28:25 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 66.240.236.109 - - [13/Jan/2022:13:42:25 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 207.46.13.233 - - [13/Jan/2022:13:52:04 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.233 - - [13/Jan/2022:13:52:06 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.42 - - [13/Jan/2022:13:52:13 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 109.248.6.50 - - [13/Jan/2022:14:48:17 +0100] "GET /favicon.ico HTTP/1.0" 301 399 "-" "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" 45.146.165.37 - - [13/Jan/2022:14:59:46 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:15:17:37 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:16:10:33 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:16:54:48 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [13/Jan/2022:18:19:27 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 139.162.145.250 - - [13/Jan/2022:18:45:51 +0100] "GET /bag2 HTTP/1.1" 301 304 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" 45.146.165.37 - - [13/Jan/2022:19:34:06 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.220.100.242 - - [13/Jan/2022:19:39:16 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 185.220.101.37 - - [13/Jan/2022:19:39:47 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 80.82.65.18 - - [13/Jan/2022:20:20:13 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:95.0) Gecko/20100101 Firefox/95.0" 45.146.165.37 - - [13/Jan/2022:20:45:31 +0100] "-" 408 - "-" "-" 204.12.198.244 - - [13/Jan/2022:20:47:36 +0100] "GET / HTTP/1.1" 301 295 "http://www.google.com.hk" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" 39.96.140.103 - - [13/Jan/2022:23:00:04 +0100] "GET /dns-query?dns=CjgBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE HTTP/1.1" 301 340 "-" "python-requests/2.26.0" 39.96.140.103 - - [13/Jan/2022:23:00:07 +0100] "GET /dns-query?dns=VpsBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE HTTP/1.1" 301 340 "-" "python-httpx/0.19.0" 34.96.130.9 - - [13/Jan/2022:23:12:27 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 128.1.248.42 - - [13/Jan/2022:23:36:31 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 89.248.165.95 - - [14/Jan/2022:00:37:43 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 89.248.165.95 - - [14/Jan/2022:00:37:55 +0100] "PROPFIND / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:55 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:55 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:55 +0100] "SSTP_DUPLEX_POST /sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/ HTTP/1.1" 400 925 "-" "-" 89.248.165.95 - - [14/Jan/2022:00:37:57 +0100] "POST /IPHTTPS HTTP/1.1" 400 500 "-" "-" 89.248.165.95 - - [14/Jan/2022:00:37:57 +0100] "GET /favicon.ico HTTP/1.1" 301 394 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:58 +0100] "FXBC / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:58 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:59 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:59 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:59 +0100] "GET /HNAP1 HTTP/1.1" 301 388 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:37:59 +0100] "HEAD / HTTP/1.1" 301 - "-" "AnyConnect Darwin_i386 3.1.05160" 89.248.165.95 - - [14/Jan/2022:00:38:00 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:00 +0100] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:01 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:01 +0100] "POST / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:02 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:02 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:02 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:03 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 89.248.165.95 - - [14/Jan/2022:00:38:03 +0100] "OPTIONS / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 156.146.50.162 - - [14/Jan/2022:00:42:52 +0100] "OPTIONS / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; MSIE 7.0; Windows NT 5.0; Trident/4.0; FBSMTWB; .NET CLR 2.0.34861; .NET CLR 3.0.3746.3218; .NET CLR 3.5.33652; msn OptimizedIE8;ENUS)"