194.110.203.42 - - [05/Oct/2022:02:59:15 +0200] "GET /1.tar.gz HTTP/1.1" 301 385 "-" "Firefox" 194.110.203.39 - - [05/Oct/2022:03:11:59 +0200] "GET /1.tar.gz HTTP/1.1" 301 394 "-" "Firefox" 194.110.203.42 - - [05/Oct/2022:03:13:17 +0200] "GET /1.tar.gz HTTP/1.1" 301 402 "-" "Firefox" 207.46.13.234 - - [05/Oct/2022:03:21:37 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.234 - - [05/Oct/2022:03:21:39 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.60 - - [05/Oct/2022:03:21:41 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 194.110.203.39 - - [05/Oct/2022:03:51:09 +0200] "GET /1.tar.gz HTTP/1.1" 301 394 "-" "Firefox" 183.136.225.35 - - [05/Oct/2022:04:20:08 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.35 - - [05/Oct/2022:04:20:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.35 - - [05/Oct/2022:04:20:55 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.35 - - [05/Oct/2022:04:21:17 +0200] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 205.210.31.16 - - [05/Oct/2022:04:24:39 +0200] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 109.248.6.82 - - [05/Oct/2022:04:48:38 +0200] "GET /favicon.ico HTTP/1.0" 301 399 "-" "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" 192.241.215.78 - - [05/Oct/2022:04:53:22 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 192.241.217.121 - - [05/Oct/2022:06:15:23 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 159.203.76.80 - - [05/Oct/2022:06:21:28 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 128.14.141.34 - - [05/Oct/2022:06:28:20 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.219.163 - - [05/Oct/2022:06:49:19 +0200] "GET /ReportServer HTTP/1.1" 301 307 "-" "Mozilla/5.0 zgrab/0.x" 193.106.29.122 - - [05/Oct/2022:06:56:21 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 152.89.196.23 - - [05/Oct/2022:06:56:39 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 167.71.138.190 - - [05/Oct/2022:07:02:38 +0200] "GET /style.php?sig=rename HTTP/1.1" 301 399 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.36" 192.241.214.25 - - [05/Oct/2022:07:09:25 +0200] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [05/Oct/2022:07:18:57 +0200] "GET /1.tgz HTTP/1.1" 301 399 "-" "Firefox" 172.105.98.165 - - [05/Oct/2022:07:35:56 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 172.105.98.165 - - [05/Oct/2022:07:35:58 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" 87.236.176.16 - - [05/Oct/2022:08:50:43 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 83.12.50.6 - - [05/Oct/2022:09:03:54 +0200] "GET /1.tgz HTTP/1.1" 301 382 "-" "Firefox" 167.71.192.158 - - [05/Oct/2022:09:11:10 +0200] "GET /favicon.ico HTTP/1.1" 301 394 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1364.172 Safari/537.22" 83.12.50.6 - - [05/Oct/2022:09:16:46 +0200] "GET /1.tgz HTTP/1.1" 301 391 "-" "Firefox" 128.14.133.58 - - [05/Oct/2022:09:17:44 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.134.170 - - [05/Oct/2022:09:24:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.218.211 - - [05/Oct/2022:09:53:27 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [05/Oct/2022:12:11:14 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.39 - - [05/Oct/2022:12:53:39 +0200] "GET /backup.bz2 HTTP/1.1" 301 404 "-" "Firefox" 40.77.167.106 - - [05/Oct/2022:12:53:41 +0200] "GET /robots.txt HTTP/1.1" 301 314 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 40.77.167.106 - - [05/Oct/2022:12:53:42 +0200] "GET /robots.txt HTTP/1.1" 301 314 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 157.55.39.215 - - [05/Oct/2022:12:53:52 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 152.89.196.211 - - [05/Oct/2022:13:10:04 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.62.197.122 - - [05/Oct/2022:13:36:16 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 64.62.197.122 - - [05/Oct/2022:13:42:36 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.102 Safari/537.36" 64.62.197.133 - - [05/Oct/2022:13:45:25 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.83 Safari/537.36" 159.223.214.218 - - [05/Oct/2022:13:49:07 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 159.223.214.218 - - [05/Oct/2022:13:49:08 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 159.223.214.218 - - [05/Oct/2022:13:49:10 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 192.241.216.159 - - [05/Oct/2022:14:04:24 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 23.251.102.74 - - [05/Oct/2022:14:21:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 81.209.177.16 - - [05/Oct/2022:14:23:32 +0200] "GET /robots.txt HTTP/1.1" 301 394 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 81.209.177.16 - - [05/Oct/2022:14:23:32 +0200] "GET / HTTP/1.1" 301 384 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 152.89.196.211 - - [05/Oct/2022:14:27:12 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 81.209.147.7 - - [05/Oct/2022:14:31:46 +0200] "-" 408 - "-" "-" 81.209.147.7 - - [05/Oct/2022:14:31:57 +0200] "" 400 379 "-" "-" 81.209.147.7 - - [05/Oct/2022:14:32:02 +0200] "GET / HTTP/1.0" 301 388 "-" "-" 198.235.24.151 - - [05/Oct/2022:14:57:23 +0200] "GET / HTTP/1.1" 301 377 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 192.241.215.172 - - [05/Oct/2022:15:07:45 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 205.210.31.136 - - [05/Oct/2022:15:19:07 +0200] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 43.131.66.209 - - [05/Oct/2022:15:45:47 +0200] "GET / HTTP/1.1" 400 500 "-" "curl/7.64.1" 193.118.53.210 - - [05/Oct/2022:16:36:25 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 94.102.61.8 - - [05/Oct/2022:17:46:00 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 157.230.23.189 - - [05/Oct/2022:18:44:51 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 137.226.113.44 - - [05/Oct/2022:18:54:41 +0200] "GET / HTTP/1.1" 301 308 "-" "Mozilla/5.0 zgrab/0.x (compatible; Researchscan/http; +http://researchscan.comsys.rwth-aachen.de)" 172.105.244.99 - - [05/Oct/2022:19:15:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15" 172.105.244.99 - - [05/Oct/2022:19:21:02 +0200] "GET /autodiscover/autodiscover.json?@cyberobservatorytest.com/owa/&Email=autodiscover/autodiscover.json%3f@cyberobservatorytest.com HTTP/1.1" 301 358 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2919.83 Safari/537.36" 45.79.47.75 - - [05/Oct/2022:19:44:01 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) Chrome/98.0.4758.132 Safari/537.36" 170.187.185.219 - - [05/Oct/2022:20:05:50 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15" 170.187.185.219 - - [05/Oct/2022:20:11:30 +0200] "GET /autodiscover/autodiscover.json@Powershell.cyberobservatorytest.com/owa/ HTTP/1.1" 301 344 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36" 192.241.213.175 - - [05/Oct/2022:20:45:48 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.128 - - [05/Oct/2022:20:47:42 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.213.175 - - [05/Oct/2022:20:49:04 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 66.249.65.116 - - [05/Oct/2022:20:57:01 +0200] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.65.112 - - [05/Oct/2022:20:57:02 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 152.89.196.23 - - [05/Oct/2022:20:58:56 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 152.89.196.211 - - [05/Oct/2022:21:30:20 +0200] "-" 408 - "-" "-" 152.89.196.211 - - [05/Oct/2022:21:37:17 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 83.136.32.58 - - [05/Oct/2022:21:51:45 +0200] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 60.217.75.70 - - [05/Oct/2022:23:30:31 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 152.89.196.211 - - [05/Oct/2022:23:44:29 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.214.227 - - [05/Oct/2022:23:49:00 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [06/Oct/2022:00:09:23 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.45 - - [06/Oct/2022:00:12:52 +0200] "GET /backup.rar HTTP/1.1" 301 387 "-" "Firefox" 194.110.203.40 - - [06/Oct/2022:00:18:07 +0200] "GET /backup.rar HTTP/1.1" 301 404 "-" "Firefox" 128.14.134.134 - - [06/Oct/2022:00:33:02 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.7.214.218 - - [06/Oct/2022:00:42:13 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 34.78.6.216 - - [06/Oct/2022:01:05:35 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 152.89.196.211 - - [06/Oct/2022:01:24:16 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 167.99.39.223 - - [06/Oct/2022:01:41:59 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 94.102.61.8 - - [06/Oct/2022:01:58:12 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0"