154.89.5.73 - - [12/Feb/2022:01:12:09 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 52.33.34.15 - - [12/Feb/2022:01:20:43 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.65.68 - - [12/Feb/2022:01:23:15 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 106.75.251.234 - - [12/Feb/2022:01:30:56 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 157.55.39.210 - - [12/Feb/2022:02:34:56 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 157.55.39.210 - - [12/Feb/2022:02:34:57 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.6 - - [12/Feb/2022:02:35:00 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 178.239.21.165 - - [12/Feb/2022:03:05:44 +0100] "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 301 325 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.53.1.el7.x86_64" 34.96.130.18 - - [12/Feb/2022:04:00:06 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" 45.146.165.37 - - [12/Feb/2022:04:02:46 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 131.220.6.152 - - [12/Feb/2022:04:53:36 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:05:15:54 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.118.53.202 - - [12/Feb/2022:05:27:12 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:05:28:06 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 3.145.65.71 - - [12/Feb/2022:05:30:11 +0100] "GET /.env HTTP/1.1" 301 304 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:12 +0100] "GET /admin/.env HTTP/1.1" 301 308 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:12 +0100] "GET /admin-app/.env HTTP/1.1" 301 311 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:13 +0100] "GET /api/.env HTTP/1.1" 301 307 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:14 +0100] "GET /back/.env HTTP/1.1" 301 308 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:15 +0100] "GET /backend/.env HTTP/1.1" 301 310 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:16 +0100] "GET /cp/.env HTTP/1.1" 301 306 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:16 +0100] "GET /development/.env HTTP/1.1" 301 311 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:17 +0100] "GET /docker/.env HTTP/1.1" 301 308 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:18 +0100] "GET /local/.env HTTP/1.1" 301 308 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:19 +0100] "GET /private/.env HTTP/1.1" 301 309 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:20 +0100] "GET /rest/.env HTTP/1.1" 301 307 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:20 +0100] "GET /shared/.env HTTP/1.1" 301 308 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:21 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:22 +0100] "GET /system/.env HTTP/1.1" 301 309 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:23 +0100] "GET /sources/.env HTTP/1.1" 301 309 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:24 +0100] "GET /public/.env HTTP/1.1" 301 309 "-" "python-requests/2.22.0" 3.145.65.71 - - [12/Feb/2022:05:30:24 +0100] "GET /v1/.env HTTP/1.1" 301 306 "-" "python-requests/2.22.0" 35.233.62.116 - - [12/Feb/2022:06:18:38 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.27.1" 208.100.26.249 - - [12/Feb/2022:06:46:04 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 7.0; G3416) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36" 208.100.26.236 - - [12/Feb/2022:06:46:04 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" 45.146.165.37 - - [12/Feb/2022:06:51:58 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.141.34 - - [12/Feb/2022:06:57:48 +0100] "GET /cgi-bin/config.exp HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:07:48:05 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:08:05:52 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:08:56:56 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 74.82.47.4 - - [12/Feb/2022:08:58:05 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.60 - - [12/Feb/2022:09:27:46 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.60 - - [12/Feb/2022:09:27:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.60 - - [12/Feb/2022:09:27:47 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 208.100.26.233 - - [12/Feb/2022:09:41:45 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 Edg/84.0.522.52" 109.237.103.9 - - [12/Feb/2022:10:17:44 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.9 - - [12/Feb/2022:10:17:44 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:10:19:00 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 109.237.103.123 - - [12/Feb/2022:10:55:51 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.123 - - [12/Feb/2022:10:55:52 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 193.118.53.210 - - [12/Feb/2022:11:30:55 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:11:38:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.146.165.37 - - [12/Feb/2022:12:13:12 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 157.55.39.210 - - [12/Feb/2022:12:14:50 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 157.55.39.210 - - [12/Feb/2022:12:14:52 +0100] "GET /robots.txt HTTP/1.1" 301 311 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.6 - - [12/Feb/2022:12:14:55 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 92.118.160.17 - - [12/Feb/2022:12:50:34 +0100] "GET / HTTP/1.1" 301 391 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 45.146.165.37 - - [12/Feb/2022:12:58:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 23.251.102.74 - - [12/Feb/2022:13:38:19 +0100] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 301 330 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 178.73.215.171 - - [12/Feb/2022:13:41:07 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 83.145.36.70 - - [12/Feb/2022:14:28:35 +0100] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_2_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" 83.145.36.70 - - [12/Feb/2022:14:28:46 +0100] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_2_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" 192.241.209.112 - - [12/Feb/2022:17:03:48 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 128.14.141.34 - - [12/Feb/2022:18:18:35 +0100] "GET /remote/login HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.211.186 - - [12/Feb/2022:21:08:26 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.211.22 - - [12/Feb/2022:21:08:28 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.209.153 - - [12/Feb/2022:21:10:33 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 103.203.59.1 - - [12/Feb/2022:21:47:57 +0100] "GET / HTTP/1.1" 301 383 "-" "HTTP Banner Detection (https://security.ipip.net)" 185.180.143.71 - - [12/Feb/2022:22:25:51 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 193.118.53.210 - - [12/Feb/2022:23:06:43 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 92.118.160.1 - - [12/Feb/2022:23:37:12 +0100] "GET / HTTP/1.1" 301 394 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 45.146.165.37 - - [12/Feb/2022:23:48:41 +0100] "-" 408 - "-" "-" 192.241.212.241 - - [13/Feb/2022:00:23:23 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.210.54 - - [13/Feb/2022:00:30:29 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x"