194.110.203.42 - - [21/Oct/2022:02:02:20 +0200] "GET /database.php.bck HTTP/1.1" 301 402 "-" "Firefox" 194.110.203.46 - - [21/Oct/2022:02:10:22 +0200] "GET /database.php.bck HTTP/1.1" 301 410 "-" "Firefox" 192.241.215.109 - - [21/Oct/2022:02:12:49 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 104.248.51.8 - - [21/Oct/2022:02:12:59 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 192.241.212.246 - - [21/Oct/2022:02:13:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 192.241.217.209 - - [21/Oct/2022:02:15:25 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.55 - - [21/Oct/2022:02:19:11 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 188.166.1.15 - - [21/Oct/2022:02:36:03 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 128.1.248.26 - - [21/Oct/2022:02:42:17 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 213.32.122.82 - - [21/Oct/2022:03:10:54 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 194.110.203.42 - - [21/Oct/2022:03:18:30 +0200] "GET /database.php.bck HTTP/1.1" 301 393 "-" "Firefox" 121.41.110.39 - - [21/Oct/2022:03:51:22 +0200] "POST /api/Ticket/query?m=18900547892&refer__2377=eu0%3DiKY5DK0ITxBkP56KGI94Wq7KQDCFtleD HTTP/1.1" 301 383 "https://ticket.gzhotelgroup.com/ticket-bk.html" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.92 Safari/537.36" 194.110.203.44 - - [21/Oct/2022:04:15:36 +0200] "GET /inc/config.php~ HTTP/1.1" 301 392 "-" "Firefox" 194.110.203.38 - - [21/Oct/2022:04:23:18 +0200] "GET /inc/config.php~ HTTP/1.1" 301 401 "-" "Firefox" 152.89.196.211 - - [21/Oct/2022:05:53:21 +0200] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.39 - - [21/Oct/2022:06:04:22 +0200] "GET /inc/config.php~ HTTP/1.1" 301 409 "-" "Firefox" 128.14.133.58 - - [21/Oct/2022:06:42:19 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 64.62.197.97 - - [21/Oct/2022:06:57:26 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0" 64.62.197.106 - - [21/Oct/2022:07:05:45 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 64.62.197.93 - - [21/Oct/2022:07:10:12 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:104.0) Gecko/20100101 Firefox/104.0" 185.7.214.218 - - [21/Oct/2022:07:13:25 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 159.65.33.124 - - [21/Oct/2022:07:55:21 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 159.65.33.124 - - [21/Oct/2022:07:55:23 +0200] "GET / HTTP/1.1" 500 754 "https://86.59.113.102/" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 159.65.33.124 - - [21/Oct/2022:07:55:25 +0200] "GET /favicon.ico HTTP/1.1" 200 1150 "https://www.easydrivers.at/" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 194.110.203.46 - - [21/Oct/2022:08:00:35 +0200] "GET /inc/config.bck HTTP/1.1" 301 391 "-" "Firefox" 183.136.225.35 - - [21/Oct/2022:08:51:48 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.35 - - [21/Oct/2022:08:52:40 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 193.106.29.122 - - [21/Oct/2022:09:04:36 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 34.221.48.44 - - [21/Oct/2022:09:14:41 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.85.62.246 - - [21/Oct/2022:09:15:03 +0200] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 152.89.196.211 - - [21/Oct/2022:09:20:58 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.23 - - [21/Oct/2022:09:34:46 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 185.180.143.81 - - [21/Oct/2022:09:58:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.81 - - [21/Oct/2022:09:58:57 +0200] "GET /webfig/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.41 - - [21/Oct/2022:10:23:20 +0200] "GET /inc/config.php.bak HTTP/1.1" 301 412 "-" "Firefox" 194.110.203.47 - - [21/Oct/2022:12:21:49 +0200] "GET /inc/config.php.bck HTTP/1.1" 301 395 "-" "Firefox" 194.110.203.45 - - [21/Oct/2022:12:25:55 +0200] "GET /inc/config.php.bck HTTP/1.1" 301 412 "-" "Firefox" 85.159.211.146 - - [21/Oct/2022:12:44:16 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 43.134.92.159 - - [21/Oct/2022:12:57:53 +0200] "GET / HTTP/1.1" 400 500 "-" "curl/7.64.1" 192.241.206.226 - - [21/Oct/2022:13:27:06 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 40.77.167.97 - - [21/Oct/2022:13:52:35 +0200] "GET /robots.txt HTTP/1.1" 301 314 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 40.77.167.97 - - [21/Oct/2022:13:52:36 +0200] "GET /robots.txt HTTP/1.1" 301 314 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 157.55.39.215 - - [21/Oct/2022:13:52:40 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 198.235.24.166 - - [21/Oct/2022:14:34:58 +0200] "GET / HTTP/1.1" 301 383 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 34.219.44.169 - - [21/Oct/2022:15:02:17 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.219.151.48 - - [21/Oct/2022:15:02:43 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 194.110.203.46 - - [21/Oct/2022:15:06:24 +0200] "GET /inc/db.php~ HTTP/1.1" 301 388 "-" "Firefox" 128.14.134.170 - - [21/Oct/2022:15:36:19 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.200.118.182 - - [21/Oct/2022:16:03:27 +0200] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/17.17134" 194.110.203.47 - - [21/Oct/2022:16:30:11 +0200] "GET /inc/db.bck HTTP/1.1" 301 404 "-" "Firefox" 194.110.203.45 - - [21/Oct/2022:16:37:59 +0200] "GET /inc/db.bck HTTP/1.1" 301 387 "-" "Firefox" 205.210.31.142 - - [21/Oct/2022:17:19:36 +0200] "GET / HTTP/1.1" 301 377 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 41.92.44.204 - - [21/Oct/2022:17:55:52 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 41.92.44.204 - - [21/Oct/2022:17:55:56 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 194.110.203.38 - - [21/Oct/2022:18:16:12 +0200] "GET /inc/db.bak HTTP/1.1" 301 396 "-" "Firefox" 198.235.24.138 - - [21/Oct/2022:18:16:30 +0200] "GET / HTTP/1.1" 301 380 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 152.89.196.211 - - [21/Oct/2022:18:25:28 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 137.184.220.167 - - [21/Oct/2022:18:26:24 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 137.184.220.167 - - [21/Oct/2022:18:26:25 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 137.184.220.167 - - [21/Oct/2022:18:26:29 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.44 - - [21/Oct/2022:18:47:42 +0200] "GET /inc/db.bak HTTP/1.1" 301 387 "-" "Firefox" 20.244.11.51 - - [21/Oct/2022:18:49:49 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 20.244.11.51 - - [21/Oct/2022:18:50:07 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 152.89.196.211 - - [21/Oct/2022:19:12:37 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.235.141.171 - - [21/Oct/2022:19:57:46 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 116.0.20.51 - - [21/Oct/2022:20:19:53 +0200] "GET /admin.php?f=/bmLUxZLeaiRIek7s/umvUsXN4HVg3BzRf.txt HTTP/1.1" 301 429 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/91.0.4472.80 Mobile/15E148 Safari/604.1" 116.0.20.51 - - [21/Oct/2022:20:19:53 +0200] "GET /wp-content/mu-plugins-old/index.php?f=/bmLUxZLeaiRIek7s/umvUsXN4HVg3BzRf.txt HTTP/1.1" 301 455 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.4 Mobile/15E148 Safari/604.1" 116.0.20.51 - - [21/Oct/2022:20:19:53 +0200] "GET /3index.php?f=/bmLUxZLeaiRIek7s/umvUsXN4HVg3BzRf.txt HTTP/1.1" 301 430 "-" "Mozilla/5.0 (Linux; Android 10; SM-A505FN) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.110 Mobile Safari/537.36" 116.0.20.51 - - [21/Oct/2022:20:19:53 +0200] "GET /class-wp-widget-archives.php HTTP/1.1" 301 407 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" 116.0.20.51 - - [21/Oct/2022:20:19:53 +0200] "GET /wikindex.php?f=/bmLUxZLeaiRIek7s/umvUsXN4HVg3BzRf.txt HTTP/1.1" 301 432 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/91.0.4472.80 Mobile/15E148 Safari/604.1" 152.89.196.211 - - [21/Oct/2022:20:30:47 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.215.65 - - [21/Oct/2022:21:14:20 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 198.12.252.180 - - [21/Oct/2022:21:30:47 +0200] "GET /inc/db.php.bak HTTP/1.1" 301 408 "-" "Firefox" 192.241.207.202 - - [21/Oct/2022:22:16:09 +0200] "GET /version HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 103.149.192.67 - - [21/Oct/2022:22:37:06 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 152.89.196.211 - - [21/Oct/2022:22:50:02 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.46 - - [21/Oct/2022:22:53:32 +0200] "GET /inc/db.php.bck HTTP/1.1" 301 408 "-" "Firefox" 194.110.203.46 - - [21/Oct/2022:23:24:14 +0200] "GET /inc/db.php.bck HTTP/1.1" 301 391 "-" "Firefox" 162.221.192.26 - - [22/Oct/2022:00:03:34 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.23 - - [22/Oct/2022:00:13:17 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 167.94.138.62 - - [22/Oct/2022:00:35:13 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.62 - - [22/Oct/2022:00:35:14 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.62 - - [22/Oct/2022:00:35:15 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 194.110.203.40 - - [22/Oct/2022:00:36:12 +0200] "GET /inc/database.php~ HTTP/1.1" 301 394 "-" "Firefox" 194.110.203.40 - - [22/Oct/2022:01:02:53 +0200] "GET /inc/database.php~ HTTP/1.1" 301 411 "-" "Firefox" 34.140.248.32 - - [22/Oct/2022:01:13:06 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 87.236.176.205 - - [22/Oct/2022:01:21:58 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 194.110.203.45 - - [22/Oct/2022:01:35:54 +0200] "GET /inc/database.php~ HTTP/1.1" 301 403 "-" "Firefox"