193.106.191.48 - - [06/Jun/2022:03:14:24 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.221.207 - - [06/Jun/2022:03:43:00 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 193.106.191.48 - - [06/Jun/2022:03:56:17 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 80.94.93.250 - - [06/Jun/2022:04:02:35 +0200] "GET /admin/config.php HTTP/1.1" 301 313 "-" "python-requests/2.27.1" 192.241.221.234 - - [06/Jun/2022:04:13:31 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 193.106.191.48 - - [06/Jun/2022:04:46:48 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 131.220.6.152 - - [06/Jun/2022:04:53:28 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:05:35:45 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.118.53.202 - - [06/Jun/2022:05:37:17 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 81.71.60.111 - - [06/Jun/2022:06:08:02 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36" 209.126.136.3 - - [06/Jun/2022:06:22:19 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" 35.233.62.116 - - [06/Jun/2022:06:29:43 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.27.1" 193.106.191.48 - - [06/Jun/2022:06:38:30 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 81.209.177.16 - - [06/Jun/2022:06:51:31 +0200] "GET /robots.txt HTTP/1.1" 301 395 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 81.209.177.16 - - [06/Jun/2022:06:51:31 +0200] "GET / HTTP/1.1" 301 385 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 193.106.191.48 - - [06/Jun/2022:07:18:11 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 184.105.247.194 - - [06/Jun/2022:07:26:12 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 193.106.191.48 - - [06/Jun/2022:07:52:58 +0200] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.134.134 - - [06/Jun/2022:08:03:49 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:09:25:20 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:09:57:37 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:11:11:05 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 47.243.233.244 - - [06/Jun/2022:11:29:46 +0200] "GET /dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 343 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:29:48 +0200] "GET /dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 343 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:29:52 +0200] "POST /dns-query HTTP/1.1" 301 308 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:29:54 +0200] "POST /dns-query HTTP/1.1" 301 308 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:29:57 +0200] "GET /query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 340 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:29:59 +0200] "GET /query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 340 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:02 +0200] "POST /query HTTP/1.1" 301 305 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:05 +0200] "POST /query HTTP/1.1" 301 305 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:08 +0200] "GET /resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 342 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:10 +0200] "GET /resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 342 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:13 +0200] "POST /resolve HTTP/1.1" 301 305 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:15 +0200] "POST /resolve HTTP/1.1" 301 305 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:18 +0200] "GET /?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 337 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:20 +0200] "GET /?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 301 337 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:23 +0200] "POST / HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 47.243.233.244 - - [06/Jun/2022:11:30:25 +0200] "POST / HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 157.55.39.125 - - [06/Jun/2022:11:51:11 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 109.237.103.118 - - [06/Jun/2022:11:53:08 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.118 - - [06/Jun/2022:11:53:09 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 159.223.214.78 - - [06/Jun/2022:12:00:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 128.14.134.170 - - [06/Jun/2022:12:52:01 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.222.24 - - [06/Jun/2022:13:17:46 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.221.14 - - [06/Jun/2022:13:18:25 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.221.43 - - [06/Jun/2022:13:19:08 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.206.202 - - [06/Jun/2022:13:39:08 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 111.13.63.67 - - [06/Jun/2022:13:44:06 +0200] "GET / HTTP/1.1" 301 301 "-" "iTunes/9.0.2 (Windows; N)" 111.13.63.67 - - [06/Jun/2022:13:44:14 +0200] "GET //sitemap.xml HTTP/1.1" 301 309 "-" "iTunes/9.0.2 (Windows; N)" 111.13.63.67 - - [06/Jun/2022:13:44:14 +0200] "GET //robots.txt HTTP/1.1" 301 308 "-" "iTunes/9.0.2 (Windows; N)" 111.13.63.67 - - [06/Jun/2022:13:44:15 +0200] "GET //.well-known/security.txt HTTP/1.1" 301 319 "-" "iTunes/9.0.2 (Windows; N)" 20.232.197.111 - - [06/Jun/2022:14:42:11 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.82 Safari/537.36" 161.35.14.135 - - [06/Jun/2022:14:44:19 +0200] "GET / HTTP/1.1" 301 383 "-" "libwww-perl/6.66" 94.102.56.151 - - [06/Jun/2022:15:39:36 +0200] "GET / HTTP/1.1" 301 383 "-" "libwww-perl/6.61" 202.102.144.122 - - [06/Jun/2022:16:14:52 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 Chrome" 172.105.189.111 - - [06/Jun/2022:18:49:27 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 92.118.161.57 - - [06/Jun/2022:19:59:19 +0200] "GET / HTTP/1.1" 301 383 "-" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 161.156.29.33 - - [06/Jun/2022:20:00:13 +0200] "GET /robots.txt HTTP/1.1" 301 397 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 161.156.29.33 - - [06/Jun/2022:20:00:13 +0200] "GET / HTTP/1.1" 301 387 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 119.90.42.89 - - [06/Jun/2022:20:21:12 +0200] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 119.90.42.89 - - [06/Jun/2022:20:21:13 +0200] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 119.90.42.89 - - [06/Jun/2022:20:21:17 +0200] "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 400 379 "-" "-" 119.90.42.89 - - [06/Jun/2022:20:21:19 +0200] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 400 379 "-" "-" 119.90.42.89 - - [06/Jun/2022:20:21:22 +0200] "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 400 379 "-" "-" 119.90.42.89 - - [06/Jun/2022:20:21:24 +0200] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 400 379 "-" "-" 167.94.138.120 - - [06/Jun/2022:21:21:11 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.120 - - [06/Jun/2022:21:21:11 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.120 - - [06/Jun/2022:21:21:12 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 193.118.53.194 - - [06/Jun/2022:22:15:53 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 54.200.137.15 - - [06/Jun/2022:23:16:05 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:23:17:42 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.106.191.48 - - [06/Jun/2022:23:48:43 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 161.35.14.135 - - [07/Jun/2022:00:21:46 +0200] "GET / HTTP/1.1" 301 383 "-" "libwww-perl/6.66" 180.149.125.170 - - [07/Jun/2022:00:24:38 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 157.55.39.125 - - [07/Jun/2022:00:41:15 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 193.106.191.48 - - [07/Jun/2022:00:51:17 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.106.191.48 - - [07/Jun/2022:01:34:37 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"