152.89.196.211 - - [24/Oct/2022:02:13:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 205.210.31.175 - - [24/Oct/2022:02:18:41 +0200] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 152.89.196.211 - - [24/Oct/2022:03:15:55 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.180.48.125 - - [24/Oct/2022:04:02:15 +0200] "GET /explore HTTP/1.1" 301 306 "-" "Opera/9.60 (J2ME/MIDP; Opera Mini/4.2.14320/554; U; cs) Presto/2.2.0" 194.110.203.40 - - [24/Oct/2022:04:25:11 +0200] "GET /includes/connect.bck HTTP/1.1" 301 414 "-" "Firefox" 134.122.112.12 - - [24/Oct/2022:04:27:19 +0200] "GET / HTTP/1.1" 400 379 "-" "-" 134.122.112.12 - - [24/Oct/2022:04:27:22 +0200] "GET / HTTP/1.1" 301 383 "-" "l9tcpid/v1.1.0" 134.122.112.12 - - [24/Oct/2022:04:28:26 +0200] "PUT /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Go-http-client/1.1" 134.122.112.12 - - [24/Oct/2022:04:28:27 +0200] "HEAD /cgi-bin/blockpage.cgi HTTP/1.1" 301 - "-" "Go-http-client/1.1" 134.122.112.12 - - [24/Oct/2022:04:28:28 +0200] "GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts HTTP/1.1" 400 293 "-" "Lkx-TraversalHttpPlugin/0.0.1 (+https://leakix.net/, +https://twitter.com/HaboubiAnis)" 134.122.112.12 - - [24/Oct/2022:04:28:29 +0200] "GET /.DS_Store HTTP/1.1" 301 307 "-" "Go-http-client/1.1" 192.241.215.65 - - [24/Oct/2022:04:49:27 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [24/Oct/2022:05:04:31 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.47 - - [24/Oct/2022:05:17:33 +0200] "GET /includes/connect.bck HTTP/1.1" 301 406 "-" "Firefox" 193.106.29.122 - - [24/Oct/2022:06:47:30 +0200] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 179.43.175.204 - - [24/Oct/2022:06:58:42 +0200] "GET /.esmtprc HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4950.0 Safari/537.36" 179.43.175.204 - - [24/Oct/2022:07:03:02 +0200] "GET /api/settings/values HTTP/1.1" 301 313 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.41 Safari/537.36 Edg/101.0.1210.32" 128.14.133.58 - - [24/Oct/2022:07:37:37 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.133.58 - - [24/Oct/2022:07:37:47 +0200] "GET /showLogin.cc HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 183.136.225.35 - - [24/Oct/2022:07:47:56 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.35 - - [24/Oct/2022:07:48:44 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 81.209.177.16 - - [24/Oct/2022:08:04:25 +0200] "GET /robots.txt HTTP/1.1" 301 391 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 81.209.177.16 - - [24/Oct/2022:08:04:25 +0200] "GET / HTTP/1.1" 301 381 "-" "netEstate NE Crawler (+http://www.website-datenbank.de/)" 194.180.48.125 - - [24/Oct/2022:08:07:12 +0200] "GET /docker-compose.yml HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Linux; U; Android 9; en-gb; Redmi Note 7 Pro Build/PKQ1.181203.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/71.0.3578.141 Mobile Safari/537.36 XiaoMi/MiuiBrowser/10.9.8-g" 194.110.203.38 - - [24/Oct/2022:08:43:04 +0200] "GET /includes/connect.php.bck HTTP/1.1" 301 401 "-" "Firefox" 41.92.120.24 - - [24/Oct/2022:09:14:54 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 41.92.120.24 - - [24/Oct/2022:09:14:55 +0200] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 194.110.203.60 - - [24/Oct/2022:09:30:05 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1) AppleWebKit/534.24.1 (KHTML, like Gecko) Version/4.0.4 Safari/534.24.1" 20.55.43.28 - - [24/Oct/2022:09:34:00 +0200] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" 128.1.248.42 - - [24/Oct/2022:10:01:06 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 20.199.46.180 - - [24/Oct/2022:10:08:11 +0200] "POST /wp-content/plugins/ioptimization/IOptimize.php?rchk HTTP/1.1" 301 329 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 20.199.46.180 - - [24/Oct/2022:10:08:38 +0200] "GET /wp-content/plugins/ioptimization/xdzmuvauoo.php?x=ooo HTTP/1.1" 301 334 "www.google.com" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 142.93.44.79 - - [24/Oct/2022:10:09:34 +0200] "GET /api/v1 HTTP/1.1" 301 305 "-" "python-requests/2.22.0" 223.71.167.165 - - [24/Oct/2022:10:29:29 +0200] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 128.1.248.34 - - [24/Oct/2022:11:34:20 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 152.89.196.23 - - [24/Oct/2022:11:43:49 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 194.110.203.42 - - [24/Oct/2022:12:19:12 +0200] "GET /includes/config.php.bak HTTP/1.1" 301 417 "-" "Firefox" 198.235.24.26 - - [24/Oct/2022:12:24:27 +0200] "GET / HTTP/1.1" 301 379 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 192.241.209.126 - - [24/Oct/2022:12:51:46 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 92.255.85.207 - - [24/Oct/2022:12:54:19 +0200] "-" 408 - "-" "-" 157.230.25.234 - - [24/Oct/2022:12:57:58 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 194.110.203.41 - - [24/Oct/2022:13:10:07 +0200] "GET /includes/config.php.bck HTTP/1.1" 301 409 "-" "Firefox" 198.235.24.9 - - [24/Oct/2022:13:49:00 +0200] "GET / HTTP/1.1" 301 380 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 181.214.218.60 - - [24/Oct/2022:14:02:38 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 152.89.196.211 - - [24/Oct/2022:14:16:51 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 20.82.129.117 - - [24/Oct/2022:14:35:06 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.23.0" 20.82.129.117 - - [24/Oct/2022:14:35:07 +0200] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.23.0" 141.136.47.204 - - [24/Oct/2022:15:06:18 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.60 Safari/537.36 Edg/100.0.1185.29" 152.89.196.211 - - [24/Oct/2022:15:07:10 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 216.218.206.90 - - [24/Oct/2022:16:17:16 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0" 216.218.206.118 - - [24/Oct/2022:16:27:53 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 207.46.13.234 - - [24/Oct/2022:16:32:46 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 207.46.13.234 - - [24/Oct/2022:16:32:47 +0200] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 40.77.167.53 - - [24/Oct/2022:16:32:51 +0200] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 194.110.203.42 - - [24/Oct/2022:17:02:45 +0200] "GET /includes/config.php~ HTTP/1.1" 301 397 "-" "Firefox" 152.89.196.211 - - [24/Oct/2022:17:31:28 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.133.58 - - [24/Oct/2022:18:17:44 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.45 - - [24/Oct/2022:19:28:25 +0200] "GET /includes/config.bck HTTP/1.1" 301 405 "-" "Firefox" 194.180.48.125 - - [24/Oct/2022:20:25:11 +0200] "GET /explore HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 198.199.93.172 - - [24/Oct/2022:20:55:29 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 174.138.26.120 - - [24/Oct/2022:21:04:23 +0200] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 174.138.26.120 - - [24/Oct/2022:21:04:26 +0200] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 174.138.26.120 - - [24/Oct/2022:21:04:53 +0200] "-" 408 - "-" "-" 192.241.214.56 - - [24/Oct/2022:21:26:16 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.128 - - [24/Oct/2022:21:29:25 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 192.241.219.55 - - [24/Oct/2022:21:32:01 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 77.74.177.119 - - [24/Oct/2022:22:25:10 +0200] "GET / HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 192.241.217.136 - - [24/Oct/2022:22:31:12 +0200] "GET /version HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 87.236.176.98 - - [24/Oct/2022:23:06:32 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 194.110.203.39 - - [24/Oct/2022:23:29:09 +0200] "GET /include/connect.php.bak HTTP/1.1" 301 409 "-" "Firefox" 93.159.230.89 - - [24/Oct/2022:23:32:38 +0200] "GET / HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 93.159.230.89 - - [25/Oct/2022:00:53:26 +0200] "GET / HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 128.1.248.26 - - [25/Oct/2022:01:07:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.23 - - [25/Oct/2022:01:17:30 +0200] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 35.90.197.8 - - [25/Oct/2022:01:30:13 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.87.38.19 - - [25/Oct/2022:01:30:36 +0200] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.76.158.233 - - [25/Oct/2022:01:41:31 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1"