151.236.33.190 - - [03/Oct/2022:02:25:31 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 192.53.170.163 - - [03/Oct/2022:02:27:11 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 34.208.253.219 - - [03/Oct/2022:02:29:20 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.215.242.244 - - [03/Oct/2022:02:29:30 +0200] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.215.242.244 - - [03/Oct/2022:02:29:35 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.210.30.206 - - [03/Oct/2022:02:56:11 +0200] "GET /style.php?sig=rename HTTP/1.1" 301 399 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.104 Safari/537.36" 54.89.141.175 - - [03/Oct/2022:02:56:35 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3009.106 Safari/537.32" 159.65.179.51 - - [03/Oct/2022:03:08:57 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 159.65.179.51 - - [03/Oct/2022:03:09:03 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 87.236.176.216 - - [03/Oct/2022:03:35:42 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 88.214.43.118 - - [03/Oct/2022:04:36:29 +0200] "GET /phpinfi.php HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.118 - - [03/Oct/2022:04:36:29 +0200] "POST /phpinfi.php HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.220.236 - - [03/Oct/2022:04:39:36 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 192.241.215.172 - - [03/Oct/2022:04:48:08 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 213.32.122.82 - - [03/Oct/2022:05:41:49 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 154.89.5.208 - - [03/Oct/2022:06:37:10 +0200] "GET / HTTP/1.0" 301 383 "-" "-" 64.62.197.137 - - [03/Oct/2022:06:51:18 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 64.62.197.137 - - [03/Oct/2022:06:57:52 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; rv:104.0) Gecko/20100101 Firefox/104.0" 64.62.197.146 - - [03/Oct/2022:07:01:43 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0" 88.214.43.215 - - [03/Oct/2022:07:29:30 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:32 +0200] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:33 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:35 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:36 +0200] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:37 +0200] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:39 +0200] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:39 +0200] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:41 +0200] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:42 +0200] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:43 +0200] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.215 - - [03/Oct/2022:07:29:45 +0200] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 193.106.29.122 - - [03/Oct/2022:08:00:34 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 35.84.199.62 - - [03/Oct/2022:08:01:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 71.6.232.2 - - [03/Oct/2022:08:27:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" 194.110.203.44 - - [03/Oct/2022:09:15:23 +0200] "GET /harm.at.bak.sql HTTP/1.1" 301 392 "-" "Firefox" 192.241.207.158 - - [03/Oct/2022:09:52:53 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.38 - - [03/Oct/2022:10:08:02 +0200] "GET /harm.at.bck.sql HTTP/1.1" 301 392 "-" "Firefox" 192.241.213.57 - - [03/Oct/2022:11:26:50 +0200] "GET /version HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 194.5.73.5 - - [03/Oct/2022:11:36:00 +0200] "GET /rest/api/latest/repos HTTP/1.1" 301 313 "-" "Mozilla/5.0 - divd scan for case 2022-00053 - see csirt.divd.nl" 194.5.73.5 - - [03/Oct/2022:11:36:00 +0200] "GET /rest/api/latest/projects/%7B%7Bkey%7D%7D/repos/%7B%7Bslug%7D%7D/archive?filename=cTVtS&at=cTVtS&path=cTVtS&prefix=ax%00--exec=%60divd_fake_command%60%00--remote=origin HTTP/1.1" 301 415 "-" "Mozilla/5.0 - divd scan for case 2022-00053 - see csirt.divd.nl" 194.110.203.39 - - [03/Oct/2022:11:48:08 +0200] "GET /klub.kornland.at.bck.sql HTTP/1.1" 301 410 "-" "Firefox" 192.241.205.22 - - [03/Oct/2022:12:15:27 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.120 - - [03/Oct/2022:12:18:04 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.213.175 - - [03/Oct/2022:12:20:23 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.23 - - [03/Oct/2022:12:21:14 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 205.210.31.55 - - [03/Oct/2022:13:38:45 +0200] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 194.110.203.44 - - [03/Oct/2022:14:32:18 +0200] "GET /harm.bak.sql HTTP/1.1" 301 389 "-" "Firefox" 43.131.66.209 - - [03/Oct/2022:15:44:28 +0200] "GET / HTTP/1.1" 400 500 "-" "curl/7.64.1" 162.19.196.234 - - [03/Oct/2022:15:45:28 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 162.19.196.234 - - [03/Oct/2022:15:45:29 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 162.142.125.210 - - [03/Oct/2022:18:19:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.210 - - [03/Oct/2022:18:19:34 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 165.227.211.51 - - [03/Oct/2022:19:31:24 +0200] "GET / HTTP/1.0" 301 387 "-" "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" 104.248.196.61 - - [03/Oct/2022:19:33:06 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 152.89.196.211 - - [03/Oct/2022:20:36:20 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.16 - - [03/Oct/2022:20:58:43 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 154.209.125.71 - - [03/Oct/2022:21:05:08 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 20.101.57.24 - - [03/Oct/2022:21:09:50 +0200] "POST /wp-plain.php HTTP/1.1" 301 389 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 20.101.57.24 - - [03/Oct/2022:21:09:51 +0200] "GET /lbrsilxj.php?Fox=d3wL7 HTTP/1.1" 301 399 "www.google.com" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 152.89.196.211 - - [03/Oct/2022:21:17:30 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 51.158.108.77 - - [03/Oct/2022:22:19:58 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 43.153.208.98 - - [03/Oct/2022:23:14:58 +0200] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 152.89.196.211 - - [03/Oct/2022:23:18:56 +0200] "-" 408 - "-" "-" 194.110.203.42 - - [03/Oct/2022:23:24:16 +0200] "GET /klub.bck.sql HTTP/1.1" 301 398 "-" "Firefox" 194.110.203.44 - - [03/Oct/2022:23:38:23 +0200] "GET /klub.bck.sql HTTP/1.1" 301 398 "-" "Firefox" 194.110.203.46 - - [04/Oct/2022:00:30:07 +0200] "GET /harm.bck.sql HTTP/1.1" 301 389 "-" "Firefox" 34.78.6.216 - - [04/Oct/2022:01:10:46 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 194.110.203.44 - - [04/Oct/2022:01:21:41 +0200] "GET /easyzumfuehrerschein.bck.sql HTTP/1.1" 301 422 "-" "Firefox" 35.89.250.16 - - [04/Oct/2022:01:35:35 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.220.178.95 - - [04/Oct/2022:01:36:41 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.213.112.58 - - [04/Oct/2022:01:39:22 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36"