65.49.20.68 - - [19/Jul/2022:03:15:53 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 183.136.225.35 - - [19/Jul/2022:03:20:31 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 65.49.20.124 - - [19/Jul/2022:03:26:45 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 zgrab/0.x" 65.49.20.88 - - [19/Jul/2022:03:29:07 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 192.241.216.46 - - [19/Jul/2022:04:09:15 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 209.141.57.178 - - [19/Jul/2022:04:41:22 +0200] "-" 408 - "-" "-" 192.241.206.37 - - [19/Jul/2022:04:50:35 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 23.251.102.74 - - [19/Jul/2022:05:16:51 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 66.240.236.116 - - [19/Jul/2022:05:28:41 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 34.140.248.32 - - [19/Jul/2022:05:51:35 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 205.210.31.161 - - [19/Jul/2022:07:12:44 +0200] "GET / HTTP/1.1" 301 377 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 43.134.234.251 - - [19/Jul/2022:07:28:27 +0200] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 207.46.13.120 - - [19/Jul/2022:07:42:33 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 97.89.144.44 - - [19/Jul/2022:08:46:53 +0200] "GET / HTTP/1.1" 301 307 "-" "SEC-SGHX210/1.0 UP.Link/6.3.1.13.0" 109.237.103.118 - - [19/Jul/2022:10:18:00 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.118 - - [19/Jul/2022:10:18:01 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:14 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:15 +0200] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:15 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:16 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:17 +0200] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:18 +0200] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:18 +0200] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:19 +0200] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:19 +0200] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:19 +0200] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:20 +0200] "GET /.aws HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:20 +0200] "POST /.aws HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:21 +0200] "GET /public/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:21 +0200] "POST /public/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:22 +0200] "GET /public/.aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:22 +0200] "POST /public/.aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:23 +0200] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:23 +0200] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:24 +0200] "GET /public/aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:24 +0200] "POST /public/aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:25 +0200] "GET /public/.aws HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.103.38 - - [19/Jul/2022:12:19:25 +0200] "POST /public/.aws HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 23.251.102.74 - - [19/Jul/2022:12:44:13 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 23.251.102.74 - - [19/Jul/2022:12:44:22 +0200] "GET /showLogin.cc HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 104.206.128.66 - - [19/Jul/2022:13:09:01 +0200] "GET / HTTP/1.1" 301 383 "-" "https://gdnplus.com:Gather Analyze Provide." 198.235.24.138 - - [19/Jul/2022:13:18:03 +0200] "GET / HTTP/1.1" 301 391 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 192.241.219.87 - - [19/Jul/2022:13:27:06 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.222.24 - - [19/Jul/2022:13:27:51 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.221.14 - - [19/Jul/2022:13:28:53 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 185.7.214.104 - - [19/Jul/2022:16:12:30 +0200] "-" 408 - "-" "-" 92.255.85.38 - - [19/Jul/2022:16:12:43 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 205.210.31.153 - - [19/Jul/2022:16:35:24 +0200] "GET / HTTP/1.1" 301 392 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 179.43.155.171 - - [19/Jul/2022:16:57:00 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Linux; Android 11; GM1910) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Mobile Safari/537.36" 94.102.61.8 - - [19/Jul/2022:17:17:10 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 198.235.24.26 - - [19/Jul/2022:18:51:17 +0200] "GET / HTTP/1.1" 301 379 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.244.213.30 - - [19/Jul/2022:18:59:59 +0200] "GET /invoker/readonly HTTP/1.1" 301 313 "-" "Mozilla/5.0 (Linux; Android 11; RMX1921) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.58 Mobile Safari/537.36" 180.149.125.163 - - [19/Jul/2022:19:42:06 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 185.7.214.104 - - [19/Jul/2022:20:08:52 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.142.236.41 - - [19/Jul/2022:20:09:37 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" 185.142.236.41 - - [19/Jul/2022:20:09:49 +0200] "" 400 379 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:09:50 +0200] "" 400 379 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:09:54 +0200] "" 400 379 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:09:57 +0200] "quit" 400 379 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:10:02 +0200] "GET /robots.txt HTTP/1.1" 301 393 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:10:03 +0200] "GET /sitemap.xml HTTP/1.1" 301 394 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:10:05 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 407 "-" "-" 185.142.236.41 - - [19/Jul/2022:20:10:20 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0" 185.142.236.41 - - [19/Jul/2022:20:10:23 +0200] "" 400 379 "-" "-" 207.46.13.120 - - [19/Jul/2022:20:15:26 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 162.221.192.26 - - [19/Jul/2022:20:44:16 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 139.162.207.84 - - [19/Jul/2022:20:57:23 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.130.97.118 - - [19/Jul/2022:21:31:40 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-requests/2.28.0" 83.136.32.58 - - [19/Jul/2022:21:38:39 +0200] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 91.198.115.10 - - [19/Jul/2022:21:39:44 +0200] "GET / HTTP/1.1" 301 383 "-" "Java/1.8.0_312" 185.7.214.104 - - [19/Jul/2022:22:16:11 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.7 - - [19/Jul/2022:23:05:38 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.95.147.28 - - [19/Jul/2022:23:59:07 +0200] "-" 408 - "-" "-" 45.95.147.29 - - [20/Jul/2022:00:00:31 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.106 Safari/537.36" 45.95.147.29 - - [20/Jul/2022:00:00:31 +0200] "GET /sssss HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.106 Safari/537.36" 185.83.144.103 - - [20/Jul/2022:00:07:59 +0200] "GET /credentials/.env HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.144.103 - - [20/Jul/2022:00:07:59 +0200] "POST /credentials/.env HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.220.101.184 - - [20/Jul/2022:01:06:29 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 103.203.57.10 - - [20/Jul/2022:01:08:10 +0200] "GET / HTTP/1.1" 301 383 "-" "HTTP Banner Detection (https://security.ipip.net)" 191.232.38.25 - - [20/Jul/2022:01:38:55 +0200] "POST /mgmt/tm/util/bash HTTP/1.1" 301 400 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.84 Safari/537.36" 185.83.146.154 - - [20/Jul/2022:01:39:24 +0200] "GET /xampp/phpinfo.php HTTP/1.1" 301 319 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [20/Jul/2022:01:39:25 +0200] "POST /xampp/phpinfo.php HTTP/1.1" 301 319 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 35.167.27.234 - - [20/Jul/2022:01:54:46 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.200.14.157 - - [20/Jul/2022:01:55:10 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 18.237.206.31 - - [20/Jul/2022:01:59:12 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.165.140.239 - - [20/Jul/2022:01:59:30 +0200] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.165.140.239 - - [20/Jul/2022:01:59:33 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36"