45.9.20.101 - - [08/May/2022:03:09:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.213.6 - - [08/May/2022:03:23:11 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 198.235.24.141 - - [08/May/2022:03:40:10 +0200] "GET / HTTP/1.1" 301 392 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 34.204.174.111 - - [08/May/2022:03:45:08 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 34.204.174.111 - - [08/May/2022:03:45:09 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 45.9.20.101 - - [08/May/2022:04:08:01 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.9.20.101 - - [08/May/2022:04:28:40 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.134.134 - - [08/May/2022:04:57:00 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.134.134 - - [08/May/2022:04:57:08 +0200] "GET /showLogin.cc HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 109.237.103.118 - - [08/May/2022:05:03:43 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.118 - - [08/May/2022:05:03:43 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 131.220.6.152 - - [08/May/2022:05:05:05 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 45.9.20.101 - - [08/May/2022:05:39:40 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.215.236 - - [08/May/2022:06:30:22 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 45.9.20.101 - - [08/May/2022:06:48:59 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 81.209.177.16 - - [08/May/2022:06:56:15 +0200] "GET /robots.txt HTTP/1.1" 301 395 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 81.209.177.16 - - [08/May/2022:06:56:15 +0200] "GET / HTTP/1.1" 301 385 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 34.140.248.32 - - [08/May/2022:07:04:33 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.27.1" 45.9.20.101 - - [08/May/2022:07:31:16 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 89.252.177.18 - - [08/May/2022:08:15:27 +0200] "GET /i.php HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.252.177.18 - - [08/May/2022:08:15:28 +0200] "POST /i.php HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 157.55.39.25 - - [08/May/2022:08:16:39 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 45.9.20.101 - - [08/May/2022:08:18:03 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.208.223 - - [08/May/2022:08:38:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 184.105.139.69 - - [08/May/2022:11:09:36 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.45 - - [08/May/2022:11:10:11 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.45 - - [08/May/2022:11:10:12 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.45 - - [08/May/2022:11:10:12 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 20.22.223.132 - - [08/May/2022:11:54:25 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 20.22.223.132 - - [08/May/2022:11:54:26 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 192.241.213.19 - - [08/May/2022:13:10:11 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.237 - - [08/May/2022:13:10:26 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.221.14 - - [08/May/2022:13:10:33 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 20.101.109.35 - - [08/May/2022:13:16:30 +0200] "GET /carbon/admin/login.jsp HTTP/1.1" 301 316 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/76.0.3809.81 Mobile/15E148 Safari/605.1" 198.235.24.146 - - [08/May/2022:13:31:43 +0200] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 185.162.235.175 - - [08/May/2022:14:08:42 +0200] "GET / HTTP/1.1" 400 379 "-" "-" 185.162.235.175 - - [08/May/2022:14:08:43 +0200] "GET / HTTP/1.1" 301 383 "-" "l9tcpid/v1.1.0" 185.162.235.175 - - [08/May/2022:14:08:43 +0200] "GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts HTTP/1.1" 400 293 "-" "Lkx-Apache2449TraversalPlugin/0.0.1 (+https://leakix.net/, +https://twitter.com/HaboubiAnis)" 185.162.235.175 - - [08/May/2022:14:08:43 +0200] "GET /.DS_Store HTTP/1.1" 301 307 "-" "Go-http-client/1.1" 185.162.235.175 - - [08/May/2022:14:08:43 +0200] "GET /.env HTTP/1.1" 301 304 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:43 +0200] "GET /.git/config HTTP/1.1" 301 310 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:44 +0200] "GET /telescope/requests HTTP/1.1" 301 311 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:44 +0200] "GET /login.action HTTP/1.1" 301 311 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:44 +0200] "GET /s/lkx/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1" 301 353 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:44 +0200] "GET /server-status HTTP/1.1" 301 308 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:44 +0200] "GET /config.json HTTP/1.1" 301 311 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:45 +0200] "GET /idx_config/ HTTP/1.1" 301 310 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:45 +0200] "GET /info.php HTTP/1.1" 301 307 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:45 +0200] "GET /.json HTTP/1.1" 301 305 "-" "l9explore/1.2.2" 185.162.235.175 - - [08/May/2022:14:08:46 +0200] "GET /api/geojson?url=file:///etc/hosts HTTP/1.1" 301 325 "-" "l9explore/1.2.2" 185.174.28.82 - - [08/May/2022:14:47:28 +0200] "GET /time.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.174.28.82 - - [08/May/2022:14:47:34 +0200] "POST /time.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 128.14.134.170 - - [08/May/2022:14:58:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.83.145.138 - - [08/May/2022:15:17:49 +0200] "GET /phpversion.php HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.145.138 - - [08/May/2022:15:17:50 +0200] "POST /phpversion.php HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.20 - - [08/May/2022:16:02:23 +0200] "GET /nuked-clan/index.php?file=News.aws/credentialsop=phpinfo HTTP/1.1" 301 334 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.20 - - [08/May/2022:16:02:24 +0200] "POST /nuked-clan/index.php?file=News.aws/credentialsop=phpinfo HTTP/1.1" 301 334 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 92.205.59.167 - - [08/May/2022:17:27:02 +0200] "GET / HTTP/1.1" 301 297 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.205.59.167 - - [08/May/2022:17:27:12 +0200] "GET /wp HTTP/1.1" 301 299 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.205.59.167 - - [08/May/2022:17:27:30 +0200] "GET /wordpress HTTP/1.1" 301 302 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.205.59.167 - - [08/May/2022:17:27:49 +0200] "GET /mobile HTTP/1.1" 301 300 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.205.59.167 - - [08/May/2022:17:28:08 +0200] "GET /WP HTTP/1.1" 301 299 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 92.205.59.167 - - [08/May/2022:17:28:21 +0200] "GET /shop HTTP/1.1" 301 300 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 104.131.44.76 - - [08/May/2022:17:32:10 +0200] "GET / HTTP/1.0" 301 380 "-" "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" 193.118.53.210 - - [08/May/2022:18:03:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 157.55.39.25 - - [08/May/2022:18:08:07 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 45.9.20.101 - - [08/May/2022:20:39:45 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 92.118.39.57 - - [08/May/2022:21:27:53 +0200] "GET / HTTP/1.1" 301 383 "-" "libwww-perl/6.64" 45.9.20.101 - - [08/May/2022:21:29:48 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.9.20.101 - - [08/May/2022:22:47:56 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 209.141.58.146 - - [08/May/2022:22:53:45 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 185.220.101.36 - - [08/May/2022:22:54:05 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 52.24.67.26 - - [08/May/2022:23:20:03 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.84.32.58 - - [08/May/2022:23:21:00 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.149.214.146 - - [08/May/2022:23:21:03 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 45.9.20.101 - - [08/May/2022:23:54:05 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.217.43.224 - - [08/May/2022:23:54:43 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.190.91.188 - - [09/May/2022:00:02:14 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 45.9.20.101 - - [09/May/2022:00:25:04 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.9.20.101 - - [09/May/2022:01:12:58 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"