34.220.201.68 - - [06/Oct/2022:02:13:11 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.202.171.149 - - [06/Oct/2022:02:13:50 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 128.14.134.134 - - [06/Oct/2022:02:32:41 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 154.209.125.71 - - [06/Oct/2022:03:08:48 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 152.89.196.211 - - [06/Oct/2022:03:14:45 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:04:19:40 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 93.159.230.88 - - [06/Oct/2022:04:48:53 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:05:03:40 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:05:27:25 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.240.106.171 - - [06/Oct/2022:05:50:13 +0200] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.124 Safari/537.36 Edg/102.0.1245.44" 34.240.106.171 - - [06/Oct/2022:05:50:17 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.124 Safari/537.36 Edg/102.0.1245.44" 152.89.196.211 - - [06/Oct/2022:06:17:05 +0200] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.62.197.119 - - [06/Oct/2022:06:20:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.81 Safari/537.36" 146.190.30.185 - - [06/Oct/2022:06:30:30 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 146.190.30.185 - - [06/Oct/2022:06:30:32 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 146.190.30.185 - - [06/Oct/2022:06:30:37 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 64.62.197.107 - - [06/Oct/2022:06:33:24 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36" 64.62.197.119 - - [06/Oct/2022:06:37:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 93.159.230.83 - - [06/Oct/2022:06:49:12 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:07:05:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 208.100.26.237 - - [06/Oct/2022:07:29:24 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 167.94.138.61 - - [06/Oct/2022:08:12:58 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.61 - - [06/Oct/2022:08:12:59 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.61 - - [06/Oct/2022:08:13:00 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 152.89.196.211 - - [06/Oct/2022:08:36:36 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:08:45:46 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:08:45:47 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2762.73 Safari/537.36" 93.159.230.88 - - [06/Oct/2022:08:49:34 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 193.235.141.178 - - [06/Oct/2022:08:53:40 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 167.172.140.80 - - [06/Oct/2022:09:00:12 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 167.172.140.80 - - [06/Oct/2022:09:00:14 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 167.172.140.80 - - [06/Oct/2022:09:00:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.153 - - [06/Oct/2022:10:00:06 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 185.7.214.218 - - [06/Oct/2022:10:07:12 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 93.159.230.88 - - [06/Oct/2022:10:20:48 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 165.22.237.144 - - [06/Oct/2022:10:26:14 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 179.61.219.71 - - [06/Oct/2022:10:36:33 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:10:36:33 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 87.236.176.238 - - [06/Oct/2022:10:40:46 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 179.61.219.71 - - [06/Oct/2022:10:52:19 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:10:52:20 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 192.241.206.44 - - [06/Oct/2022:11:28:05 +0200] "GET /version HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [06/Oct/2022:12:12:38 +0200] "GET /backup.tar HTTP/1.1" 301 396 "-" "Firefox" 152.89.196.23 - - [06/Oct/2022:12:13:37 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 93.159.230.89 - - [06/Oct/2022:12:21:03 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 194.110.203.41 - - [06/Oct/2022:12:22:28 +0200] "GET /backup.tar HTTP/1.1" 301 387 "-" "Firefox" 209.222.252.91 - - [06/Oct/2022:12:28:50 +0200] "GET / HTTP/1.1" 301 383 "-" "Java/1.8.0_342" 208.100.26.237 - - [06/Oct/2022:12:34:15 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 7.0; SAMSUNG-SM-J327A) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Mobile Safari/537.36" 208.100.26.237 - - [06/Oct/2022:12:34:15 +0200] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4112.0 Safari/537.36" 194.110.203.39 - - [06/Oct/2022:13:05:38 +0200] "GET /backup.tar HTTP/1.1" 301 387 "-" "Firefox" 93.159.230.83 - - [06/Oct/2022:13:21:19 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 194.110.203.38 - - [06/Oct/2022:13:47:46 +0200] "GET /backup.tar.gz HTTP/1.1" 301 390 "-" "Firefox" 194.110.203.38 - - [06/Oct/2022:14:10:10 +0200] "GET /backup.tar.gz HTTP/1.1" 301 407 "-" "Firefox" 93.159.230.88 - - [06/Oct/2022:14:21:12 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:00 +0200] "GET /.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:01 +0200] "POST /.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:03 +0200] "GET /.aws/credentials HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:04 +0200] "POST /.aws/credentials HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:06 +0200] "GET /.aws/config HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:07 +0200] "POST /.aws/config HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:08 +0200] "GET /aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:11 +0200] "POST /aws/credentials HTTP/1.1" 301 316 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:13 +0200] "GET /credentials HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:15 +0200] "POST /credentials HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:16 +0200] "GET /test.php HTTP/1.1" 301 312 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:18 +0200] "POST /test.php HTTP/1.1" 301 312 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:19 +0200] "GET /laravel/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:20 +0200] "POST /laravel/.env HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:23 +0200] "GET /demo/.env HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:24 +0200] "POST /demo/.env HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:26 +0200] "GET /web/.env HTTP/1.1" 301 312 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [06/Oct/2022:14:45:27 +0200] "POST /web/.env HTTP/1.1" 301 312 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 192.241.219.134 - - [06/Oct/2022:15:09:35 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 128.1.248.26 - - [06/Oct/2022:15:09:38 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.1.248.26 - - [06/Oct/2022:15:09:49 +0200] "HEAD /icons/sphere1.png HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 77.74.177.119 - - [06/Oct/2022:15:21:24 +0200] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 194.110.203.41 - - [06/Oct/2022:15:24:59 +0200] "GET /backup.tar.gz HTTP/1.1" 301 390 "-" "Firefox" 128.14.209.146 - - [06/Oct/2022:15:42:13 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 207.46.13.60 - - [06/Oct/2022:15:56:20 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 152.89.196.211 - - [06/Oct/2022:16:19:23 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.33.102.90 - - [06/Oct/2022:16:31:36 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:16:49:36 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 157.230.124.248 - - [06/Oct/2022:17:24:35 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 157.230.124.248 - - [06/Oct/2022:17:24:36 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [06/Oct/2022:17:29:03 +0200] "GET /backup.tgz HTTP/1.1" 301 387 "-" "Firefox" 179.61.219.71 - - [06/Oct/2022:18:07:52 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:18:07:53 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2866.71 Safari/537.36" 45.79.204.46 - - [06/Oct/2022:18:13:25 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:18:31:44 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 54.83.149.151 - - [06/Oct/2022:18:40:19 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 54.83.149.151 - - [06/Oct/2022:18:40:22 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:18:40:52 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.128.109.253 - - [06/Oct/2022:18:58:28 +0200] "GET / HTTP/1.1" 301 295 "https://harm.at" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 OPR/89.0.4447.51" 194.110.203.38 - - [06/Oct/2022:19:18:42 +0200] "GET /backup.zip HTTP/1.1" 301 396 "-" "Firefox" 128.14.134.134 - - [06/Oct/2022:19:35:29 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.7.214.218 - - [06/Oct/2022:19:46:51 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 152.89.196.211 - - [06/Oct/2022:20:21:09 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [06/Oct/2022:20:47:52 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.39 - - [06/Oct/2022:21:01:55 +0200] "GET /backup.zip HTTP/1.1" 301 404 "-" "Firefox" 152.89.196.211 - - [06/Oct/2022:21:38:44 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.134.134 - - [06/Oct/2022:22:23:49 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 43.134.234.251 - - [06/Oct/2022:22:38:58 +0200] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 179.61.219.71 - - [06/Oct/2022:22:39:57 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36" 179.61.219.71 - - [06/Oct/2022:22:39:57 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F" 194.110.203.39 - - [06/Oct/2022:22:51:48 +0200] "GET /backup.bkp HTTP/1.1" 301 404 "-" "Firefox" 54.71.217.98 - - [06/Oct/2022:23:29:04 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.181.133 - - [06/Oct/2022:23:29:20 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.162.38.110 - - [06/Oct/2022:23:29:24 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.86.85.193 - - [06/Oct/2022:23:42:05 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.222.217.46 - - [06/Oct/2022:23:42:25 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.5.73.5 - - [07/Oct/2022:00:36:43 +0200] "GET /rest/api/latest/repos HTTP/1.1" 301 313 "-" "Mozilla/5.0 - divd scan for case 2022-00053 - see csirt.divd.nl" 194.5.73.5 - - [07/Oct/2022:00:36:43 +0200] "GET /rest/api/latest/projects/%7B%7Bkey%7D%7D/repos/%7B%7Bslug%7D%7D/archive?filename=0iXSl&at=0iXSl&path=0iXSl&prefix=ax%00--exec=%60divd_fake_command%60%00--remote=origin HTTP/1.1" 301 415 "-" "Mozilla/5.0 - divd scan for case 2022-00053 - see csirt.divd.nl" 103.149.192.119 - - [07/Oct/2022:00:43:45 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 194.110.203.44 - - [07/Oct/2022:00:47:20 +0200] "GET /backup.bkup HTTP/1.1" 301 388 "-" "Firefox" 34.77.127.183 - - [07/Oct/2022:01:01:05 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 194.110.203.45 - - [07/Oct/2022:01:06:06 +0200] "GET /backup.bkup HTTP/1.1" 301 405 "-" "Firefox" 35.91.93.195 - - [07/Oct/2022:01:11:26 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 192.241.219.55 - - [07/Oct/2022:01:11:31 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.120 - - [07/Oct/2022:01:13:06 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 35.91.249.175 - - [07/Oct/2022:01:13:16 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 192.241.216.172 - - [07/Oct/2022:01:14:51 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 198.235.24.56 - - [07/Oct/2022:01:45:43 +0200] "GET / HTTP/1.1" 301 383 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 194.110.203.44 - - [07/Oct/2022:01:46:25 +0200] "GET /backup.bkup HTTP/1.1" 301 397 "-" "Firefox" 167.248.133.45 - - [07/Oct/2022:01:48:42 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.45 - - [07/Oct/2022:01:48:43 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.45 - - [07/Oct/2022:01:48:43 +0200] "PRI * HTTP/2.0" 400 379 "-" "-"