20.13.128.149 - - [16/Nov/2022:01:16:35 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 20.13.128.149 - - [16/Nov/2022:01:16:35 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 188.166.151.120 - - [16/Nov/2022:01:38:32 +0100] "GET /api/public_login_new/b25seXNjYW5z/3ce00749dd913534 HTTP/1.1" 301 342 "-" "Mozilla/5.0 zgrab/0.x" 93.159.230.87 - - [16/Nov/2022:01:40:03 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:06 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:07 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:07 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:08 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:08 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:09 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:09 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:10 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:10 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:11 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:11 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:12 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:12 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:13 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:13 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:13 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:14 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:14 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:15 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [16/Nov/2022:01:59:15 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 198.235.24.25 - - [16/Nov/2022:02:19:26 +0100] "GET / HTTP/1.1" 301 389 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 106.75.157.75 - - [16/Nov/2022:02:19:39 +0100] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 106.75.157.75 - - [16/Nov/2022:02:19:40 +0100] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 185.180.143.80 - - [16/Nov/2022:02:39:02 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [16/Nov/2022:02:39:13 +0100] "GET /webfig/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [16/Nov/2022:02:39:27 +0100] "GET /solr/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 93.159.230.83 - - [16/Nov/2022:02:40:28 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 198.235.24.152 - - [16/Nov/2022:03:23:08 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.235.24.54 - - [16/Nov/2022:03:23:49 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 51.158.37.195 - - [16/Nov/2022:03:23:54 +0100] "GET / HTTP/1.1" 301 385 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 51.158.37.195 - - [16/Nov/2022:03:23:56 +0100] "GET /favicon.ico HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 128.14.134.170 - - [16/Nov/2022:03:36:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.237.252.77 - - [16/Nov/2022:03:38:51 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.136 Safari/537.36" 93.159.230.87 - - [16/Nov/2022:03:40:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 193.235.141.170 - - [16/Nov/2022:03:57:45 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 208.100.26.246 - - [16/Nov/2022:03:58:30 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.106 Safari/537.36" 208.100.26.236 - - [16/Nov/2022:03:58:30 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Linux; Android 10; ONEPLUS A6003 Build/QKQ1.190716.003; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/84.0.4147.89 Mobile Safari/537.36" 192.241.209.26 - - [16/Nov/2022:04:28:13 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 93.159.230.89 - - [16/Nov/2022:04:40:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 192.241.200.107 - - [16/Nov/2022:04:50:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 193.106.29.122 - - [16/Nov/2022:05:20:20 +0100] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 77.74.177.119 - - [16/Nov/2022:05:40:37 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" 192.241.201.172 - - [16/Nov/2022:06:11:45 +0100] "GET /ReportServer HTTP/1.1" 301 307 "-" "Mozilla/5.0 zgrab/0.x" 179.43.177.154 - - [16/Nov/2022:06:16:29 +0100] "GET /.s3cfg HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36" 208.100.26.243 - - [16/Nov/2022:06:16:47 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (iPad; CPU OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/9.0 Mobile/13B143 Safari/601.1" 125.40.14.200 - - [16/Nov/2022:06:21:10 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 198.199.92.127 - - [16/Nov/2022:06:33:43 +0100] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [16/Nov/2022:06:35:10 +0100] "GET /klub.kornland.at-db.zip HTTP/1.1" 301 409 "-" "Firefox" 194.110.203.47 - - [16/Nov/2022:06:43:57 +0100] "GET /harm.at-db.zip HTTP/1.1" 301 391 "-" "Firefox" 154.89.5.218 - - [16/Nov/2022:06:53:22 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 194.180.48.125 - - [16/Nov/2022:07:08:30 +0100] "GET /docker-compose.yml HTTP/1.1" 301 312 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 179.43.177.154 - - [16/Nov/2022:07:11:07 +0100] "GET /cgit HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/536.5 (KHTML like Gecko) Chrome/19.0.1084.56 Safari/536.5" 154.89.5.84 - - [16/Nov/2022:07:13:09 +0100] "GET / HTTP/1.0" 301 383 "-" "-" 43.158.217.205 - - [16/Nov/2022:07:17:01 +0100] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 43.158.217.205 - - [16/Nov/2022:07:17:26 +0100] "-" 408 - "-" "-" 64.62.197.220 - - [16/Nov/2022:07:48:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:106.0) Gecko/20100101 Firefox/106.0" 64.62.197.221 - - [16/Nov/2022:07:55:51 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.1 Safari/605.1.15" 64.62.197.226 - - [16/Nov/2022:07:59:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; rv:105.0) Gecko/20100101 Firefox/105.0" 64.62.197.217 - - [16/Nov/2022:08:00:31 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 83.136.32.58 - - [16/Nov/2022:08:10:01 +0100] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 74.138.238.107 - - [16/Nov/2022:08:10:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 74.138.238.107 - - [16/Nov/2022:08:10:11 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 74.138.238.107 - - [16/Nov/2022:08:10:12 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 74.138.238.107 - - [16/Nov/2022:08:10:12 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 74.138.238.107 - - [16/Nov/2022:08:10:13 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 74.138.238.107 - - [16/Nov/2022:08:10:14 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 194.110.203.39 - - [16/Nov/2022:08:26:16 +0100] "GET /easyzumfuehrerschein.com_database.zip HTTP/1.1" 301 431 "-" "Firefox" 198.235.24.154 - - [16/Nov/2022:08:43:12 +0100] "GET / HTTP/1.1" 301 377 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 192.241.203.37 - - [16/Nov/2022:09:31:29 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 192.241.206.103 - - [16/Nov/2022:09:39:03 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 185.7.214.218 - - [16/Nov/2022:09:39:57 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 192.241.202.90 - - [16/Nov/2022:09:40:33 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [16/Nov/2022:09:53:12 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.42 - - [16/Nov/2022:10:14:16 +0100] "GET /harm.at-database.zip HTTP/1.1" 301 397 "-" "Firefox" 192.241.204.149 - - [16/Nov/2022:10:20:45 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [16/Nov/2022:10:39:36 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 123.138.77.55 - - [16/Nov/2022:10:57:06 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" 109.248.6.87 - - [16/Nov/2022:10:57:11 +0100] "GET /favicon.ico HTTP/1.0" 301 399 "-" "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" 194.110.203.40 - - [16/Nov/2022:11:45:19 +0100] "GET /harm.at_dump.zip HTTP/1.1" 301 393 "-" "Firefox" 183.136.225.32 - - [16/Nov/2022:12:24:25 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 152.89.196.211 - - [16/Nov/2022:12:30:37 +0100] "-" 408 - "-" "-" 183.136.225.32 - - [16/Nov/2022:12:39:56 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [16/Nov/2022:12:40:18 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [16/Nov/2022:12:40:40 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 51.15.205.3 - - [16/Nov/2022:13:25:10 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.146.60 - - [16/Nov/2022:13:29:06 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.146.60 - - [16/Nov/2022:13:29:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.146.60 - - [16/Nov/2022:13:29:06 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 51.15.195.246 - - [16/Nov/2022:13:36:25 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 183.136.225.44 - - [16/Nov/2022:14:10:43 +0100] "-" 408 - "-" "-" 194.110.203.42 - - [16/Nov/2022:14:29:10 +0100] "GET /easyzumfuehrerschein.com-dump.zip HTTP/1.1" 301 427 "-" "Firefox" 157.245.75.124 - - [16/Nov/2022:14:58:38 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 194.110.203.47 - - [16/Nov/2022:15:11:49 +0100] "GET /easyzumfuehrerschein.combackup.zip HTTP/1.1" 301 428 "-" "Firefox" 46.101.47.89 - - [16/Nov/2022:16:25:36 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 46.101.47.89 - - [16/Nov/2022:16:25:37 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 46.101.47.89 - - [16/Nov/2022:16:25:38 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 138.246.253.24 - - [16/Nov/2022:16:47:23 +0100] "GET /robots.txt HTTP/1.1" 301 393 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 194.180.48.125 - - [16/Nov/2022:17:27:22 +0100] "GET /explore HTTP/1.1" 301 306 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; XBLWP7; ZuneWP7) UCBrowser/2.9.0.263" 103.167.84.15 - - [16/Nov/2022:17:36:58 +0100] "GET /.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36" 103.167.84.15 - - [16/Nov/2022:17:36:59 +0100] "POST / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36" 137.226.113.44 - - [16/Nov/2022:18:26:53 +0100] "GET / HTTP/1.1" 301 308 "-" "Mozilla/5.0 zgrab/0.x (compatible; Researchscan/http; +http://researchscan.comsys.rwth-aachen.de)" 162.221.192.26 - - [16/Nov/2022:18:32:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 167.71.182.188 - - [16/Nov/2022:18:34:39 +0100] "GET / HTTP/1.1" 301 377 "-" "Curl" 194.110.203.44 - - [16/Nov/2022:18:41:07 +0100] "GET /klub.kornland.at-backup.zip HTTP/1.1" 301 413 "-" "Firefox" 185.7.214.218 - - [16/Nov/2022:18:45:55 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 109.237.98.226 - - [16/Nov/2022:19:35:12 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:13 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:13 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:14 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:14 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:15 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:15 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:16 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:16 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:17 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:17 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:18 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:18 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:19 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:19 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:20 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:20 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:21 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:21 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [16/Nov/2022:19:35:22 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.110.203.46 - - [16/Nov/2022:20:30:22 +0100] "GET /backupharm.at.zip HTTP/1.1" 301 394 "-" "Firefox" 194.110.203.45 - - [16/Nov/2022:20:35:54 +0100] "GET /backupklub.kornland.at.zip HTTP/1.1" 301 412 "-" "Firefox" 193.235.141.168 - - [16/Nov/2022:21:40:02 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 128.14.134.134 - - [16/Nov/2022:21:53:25 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 209.222.252.91 - - [16/Nov/2022:22:02:47 +0100] "GET / HTTP/1.1" 301 383 "-" "Java/1.8.0_352" 194.110.203.44 - - [16/Nov/2022:23:51:11 +0100] "GET /backup_klub.kornland.at.zip HTTP/1.1" 301 413 "-" "Firefox" 35.195.93.98 - - [17/Nov/2022:00:14:06 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 134.122.32.136 - - [17/Nov/2022:00:47:42 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 134.122.32.136 - - [17/Nov/2022:00:47:44 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 134.122.32.136 - - [17/Nov/2022:00:47:48 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 44.200.85.193 - - [17/Nov/2022:00:59:58 +0100] "GET /99vt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36" 194.110.203.42 - - [17/Nov/2022:00:59:59 +0100] "GET /backup_easyzumfuehrerschein.com.zip HTTP/1.1" 301 429 "-" "Firefox"