104.248.51.8 - - [07/Oct/2022:02:12:40 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 152.89.196.23 - - [07/Oct/2022:02:14:23 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 198.98.59.132 - - [07/Oct/2022:02:39:30 +0200] "POST /ztp/cgi-bin/handler HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 193.235.141.176 - - [07/Oct/2022:02:47:20 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 43.143.194.145 - - [07/Oct/2022:02:58:29 +0200] "POST /api/Ticket/query?m=18900547892&refer__2377=eu0%3DiKY5DK0ITxBkP56KGI94Wq7KQDCFtleD HTTP/1.1" 301 383 "https://ticket.gzhotelgroup.com/ticket-bk.html" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.92 Safari/537.36" 88.214.43.118 - - [07/Oct/2022:03:25:14 +0200] "GET /phpinfo HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 88.214.43.118 - - [07/Oct/2022:03:25:14 +0200] "POST /phpinfo HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 198.98.59.132 - - [07/Oct/2022:03:27:31 +0200] "POST /ztp/cgi-bin/handler HTTP/1.1" 301 315 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0" 192.241.212.202 - - [07/Oct/2022:03:47:51 +0200] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [07/Oct/2022:03:58:10 +0200] "GET /backup.psc HTTP/1.1" 301 396 "-" "Firefox" 194.110.203.45 - - [07/Oct/2022:04:07:09 +0200] "GET /backup.psc HTTP/1.1" 301 387 "-" "Firefox" 128.14.141.34 - - [07/Oct/2022:05:23:51 +0200] "GET /cgi-bin/config.exp HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.7.214.218 - - [07/Oct/2022:05:39:14 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 68.183.154.130 - - [07/Oct/2022:05:58:27 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" 193.106.29.122 - - [07/Oct/2022:06:22:31 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 194.110.203.42 - - [07/Oct/2022:07:27:54 +0200] "GET /backup.npb HTTP/1.1" 301 396 "-" "Firefox" 179.61.219.71 - - [07/Oct/2022:07:39:23 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36" 179.61.219.71 - - [07/Oct/2022:07:39:25 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 152.89.196.211 - - [07/Oct/2022:08:16:51 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.62.197.184 - - [07/Oct/2022:08:34:38 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 64.62.197.182 - - [07/Oct/2022:08:47:56 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.81 Safari/537.36" 64.62.197.184 - - [07/Oct/2022:08:52:15 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.0 Safari/605.1.15" 152.89.196.211 - - [07/Oct/2022:08:56:57 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.141.34 - - [07/Oct/2022:09:00:42 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 188.166.63.243 - - [07/Oct/2022:09:10:37 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 179.61.219.71 - - [07/Oct/2022:09:32:31 +0200] "GET /.well-known/security.txt HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 179.61.219.71 - - [07/Oct/2022:09:32:31 +0200] "GET /security.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36" 181.214.206.161 - - [07/Oct/2022:09:33:05 +0200] "HEAD / HTTP/1.1" 301 - "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36" 152.89.196.211 - - [07/Oct/2022:09:36:17 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Oct/2022:09:44:03 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.205.118 - - [07/Oct/2022:09:56:32 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [07/Oct/2022:09:57:17 +0200] "GET /backup.ibz HTTP/1.1" 301 404 "-" "Firefox" 20.92.162.191 - - [07/Oct/2022:10:15:32 +0200] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 152.89.196.211 - - [07/Oct/2022:11:26:36 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.53.170.243 - - [07/Oct/2022:12:19:58 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.44 - - [07/Oct/2022:12:42:18 +0200] "GET /backup.backup HTTP/1.1" 301 399 "-" "Firefox" 161.123.151.95 - - [07/Oct/2022:13:17:27 +0200] "GET / HTTP/1.1" 301 301 "https://bahlsen.2web.at" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 OPR/89.0.4447.51" 185.7.214.218 - - [07/Oct/2022:13:27:07 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 172.104.131.24 - - [07/Oct/2022:13:36:46 +0200] "GET /public/jsp/ResourcesVerificaton.jsp HTTP/1.1" 301 326 "-" "Mozilla/5.0 zgrab/0.x" 178.79.149.42 - - [07/Oct/2022:13:37:20 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 193.118.53.194 - - [07/Oct/2022:14:23:39 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.216.55 - - [07/Oct/2022:15:11:15 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.39 - - [07/Oct/2022:15:15:32 +0200] "GET /backup/backup.bz2 HTTP/1.1" 301 394 "-" "Firefox" 152.89.196.23 - - [07/Oct/2022:15:16:08 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 207.46.13.234 - - [07/Oct/2022:15:48:21 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.234 - - [07/Oct/2022:15:48:23 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 207.46.13.60 - - [07/Oct/2022:15:48:27 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 185.83.144.103 - - [07/Oct/2022:15:58:59 +0200] "GET /phpinfo.php.bak HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.144.103 - - [07/Oct/2022:15:59:00 +0200] "POST /phpinfo.php.bak HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 35.197.96.4 - - [07/Oct/2022:17:12:25 +0200] "OPTIONS / HTTP/1.0" 301 383 "-" "-" 159.203.115.224 - - [07/Oct/2022:18:02:56 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.42 - - [07/Oct/2022:18:25:41 +0200] "GET /backup/backup.gz HTTP/1.1" 301 402 "-" "Firefox" 139.162.146.254 - - [07/Oct/2022:18:33:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15" 23.251.102.82 - - [07/Oct/2022:19:07:22 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 198.199.101.62 - - [07/Oct/2022:19:14:55 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 192.241.217.118 - - [07/Oct/2022:19:46:49 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.46 - - [07/Oct/2022:20:45:52 +0200] "GET /backup/backup.rar HTTP/1.1" 301 394 "-" "Firefox" 194.110.203.39 - - [07/Oct/2022:20:59:42 +0200] "GET /backup/backup.rar HTTP/1.1" 301 403 "-" "Firefox" 162.142.125.212 - - [07/Oct/2022:21:50:43 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.212 - - [07/Oct/2022:21:50:43 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.212 - - [07/Oct/2022:21:50:44 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 193.235.141.181 - - [07/Oct/2022:23:12:50 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" 2.57.122.25 - - [07/Oct/2022:23:40:18 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_2) AppleWebKit/601.3.9 (KHTML, like Gecko) Version/9.0.2 Safari/601.3.9" 104.248.195.19 - - [07/Oct/2022:23:52:30 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 104.248.195.19 - - [07/Oct/2022:23:52:31 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 104.248.195.19 - - [07/Oct/2022:23:52:44 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 104.248.195.19 - - [07/Oct/2022:23:53:05 +0200] "-" 408 - "-" "-" 72.55.136.154 - - [08/Oct/2022:00:32:06 +0200] "GET / HTTP/1.1" 301 379 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 72.55.136.154 - - [08/Oct/2022:00:32:08 +0200] "GET /favicon.ico HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 72.55.136.154 - - [08/Oct/2022:00:32:09 +0200] "GET / HTTP/1.1" 301 379 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 194.110.203.46 - - [08/Oct/2022:00:36:00 +0200] "GET /backup/backup.tar HTTP/1.1" 301 394 "-" "Firefox" 128.1.248.26 - - [08/Oct/2022:00:37:41 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 34.76.158.233 - - [08/Oct/2022:00:55:55 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 34.219.117.228 - - [08/Oct/2022:01:17:44 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.233.91.206 - - [08/Oct/2022:01:18:08 +0200] "HEAD / HTTP/1.1" 301 - "https://www.bing.com" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36" 34.220.142.153 - - [08/Oct/2022:01:18:09 +0200] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.220.142.153 - - [08/Oct/2022:01:18:14 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 121.5.45.11 - - [08/Oct/2022:01:25:16 +0200] "POST /api/Ticket/query?m=18900547892&refer__2377=eu0%3DiKY5DK0ITxBkP56KGI94Wq7KQDCFtleD HTTP/1.1" 301 383 "https://ticket.gzhotelgroup.com/ticket-bk.html" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.92 Safari/537.36" 174.138.29.20 - - [08/Oct/2022:01:28:41 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 185.7.214.218 - - [08/Oct/2022:01:40:52 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8"