157.245.176.143 - - [06/Sep/2022:02:50:53 +0200] "SSTP_DUPLEX_POST /sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/ HTTP/1.1" 400 925 "-" "-" 152.89.196.23 - - [06/Sep/2022:04:00:56 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 103.149.192.163 - - [06/Sep/2022:04:51:31 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 192.241.197.147 - - [06/Sep/2022:05:16:41 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 179.43.175.140 - - [06/Sep/2022:07:17:33 +0200] "GET /static../.git/config HTTP/1.1" 301 314 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36" 198.235.24.26 - - [06/Sep/2022:07:53:58 +0200] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.199.93.232 - - [06/Sep/2022:08:45:07 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 205.210.31.176 - - [06/Sep/2022:10:15:28 +0200] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 193.118.53.194 - - [06/Sep/2022:11:22:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.210.182 - - [06/Sep/2022:11:55:46 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.208.155 - - [06/Sep/2022:11:58:08 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.220.206 - - [06/Sep/2022:11:58:24 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 205.210.31.38 - - [06/Sep/2022:13:06:51 +0200] "GET / HTTP/1.1" 301 383 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 152.89.196.62 - - [06/Sep/2022:13:25:34 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.1.248.42 - - [06/Sep/2022:14:49:05 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 154.89.5.203 - - [06/Sep/2022:14:58:30 +0200] "GET / HTTP/1.0" 301 383 "-" "-" 152.89.196.23 - - [06/Sep/2022:16:55:16 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 54.91.114.252 - - [06/Sep/2022:17:12:09 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3111.57 Safari/537.32" 66.249.70.35 - - [06/Sep/2022:17:25:04 +0200] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.70.39 - - [06/Sep/2022:17:25:05 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 139.162.200.4 - - [06/Sep/2022:17:37:58 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 128.14.134.134 - - [06/Sep/2022:18:40:41 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:47:56 +0200] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:47:58 +0200] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:00 +0200] "GET /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:01 +0200] "POST /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:03 +0200] "GET /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:06 +0200] "POST /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:07 +0200] "GET /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:09 +0200] "POST /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:11 +0200] "GET /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:13 +0200] "POST /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:14 +0200] "GET /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:16 +0200] "POST /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:17 +0200] "GET /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:18 +0200] "POST /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:20 +0200] "GET /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:21 +0200] "POST /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:23 +0200] "GET /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Sep/2022:18:48:25 +0200] "POST /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 64.62.197.152 - - [06/Sep/2022:18:48:58 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 64.62.197.152 - - [06/Sep/2022:18:57:09 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15" 180.149.125.168 - - [06/Sep/2022:19:00:04 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 64.62.197.162 - - [06/Sep/2022:19:01:02 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:104.0) Gecko/20100101 Firefox/104.0" 198.235.24.40 - - [06/Sep/2022:21:24:14 +0200] "GET / HTTP/1.1" 301 386 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.235.24.139 - - [06/Sep/2022:22:40:30 +0200] "GET / HTTP/1.1" 301 385 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 23.251.102.74 - - [06/Sep/2022:23:03:27 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 83.136.32.58 - - [06/Sep/2022:23:19:27 +0200] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 192.241.213.189 - - [06/Sep/2022:23:31:28 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 34.76.96.55 - - [07/Sep/2022:00:56:51 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 35.89.135.52 - - [07/Sep/2022:00:58:12 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 94.102.61.8 - - [07/Sep/2022:01:01:17 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 128.14.134.134 - - [07/Sep/2022:01:56:14 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.83.144.103 - - [07/Sep/2022:01:59:04 +0200] "GET /.aws/.credentials.php HTTP/1.1" 301 321 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.144.103 - - [07/Sep/2022:01:59:04 +0200] "POST /.aws/.credentials.php HTTP/1.1" 301 321 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"