138.246.253.24 - - [19/Nov/2022:01:21:43 +0100] "GET /robots.txt HTTP/1.1" 301 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 128.14.141.34 - - [19/Nov/2022:01:53:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.180.48.125 - - [19/Nov/2022:02:01:00 +0100] "GET /explore HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:16.0) Gecko/20120813 Firefox/16.0" 45.35.181.162 - - [19/Nov/2022:02:54:19 +0100] "GET /style.php?sig=rename HTTP/1.1" 301 399 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" 198.12.252.180 - - [19/Nov/2022:02:54:56 +0100] "GET /localhost-backup.tar.gz HTTP/1.1" 301 400 "-" "Firefox" 152.89.196.211 - - [19/Nov/2022:03:18:44 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 103.149.192.31 - - [19/Nov/2022:03:25:53 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 185.7.214.218 - - [19/Nov/2022:03:33:22 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 194.110.203.47 - - [19/Nov/2022:03:50:31 +0100] "GET /backuplocalhost.tar.gz HTTP/1.1" 301 399 "-" "Firefox" 128.14.141.34 - - [19/Nov/2022:04:09:19 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 106.75.129.215 - - [19/Nov/2022:04:16:51 +0100] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 106.75.129.215 - - [19/Nov/2022:04:16:52 +0100] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 106.75.129.215 - - [19/Nov/2022:04:16:54 +0100] "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 400 379 "-" "-" 106.75.129.215 - - [19/Nov/2022:04:16:55 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 400 379 "-" "-" 106.75.129.215 - - [19/Nov/2022:04:16:56 +0100] "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 400 379 "-" "-" 106.75.129.215 - - [19/Nov/2022:04:16:58 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 400 379 "-" "-" 192.241.203.234 - - [19/Nov/2022:05:04:43 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 198.12.252.180 - - [19/Nov/2022:05:25:07 +0100] "GET /backup-localhost.tar.gz HTTP/1.1" 301 417 "-" "Firefox" 198.12.252.180 - - [19/Nov/2022:05:29:38 +0100] "GET /backup-localhost.tar.gz HTTP/1.1" 301 409 "-" "Firefox" 35.195.81.251 - - [19/Nov/2022:07:35:10 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:52.0) Gecko/20100101 Firefox/52.0" 192.241.201.214 - - [19/Nov/2022:07:36:03 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.47 - - [19/Nov/2022:07:55:42 +0100] "GET /backup_localhost.tar.gz HTTP/1.1" 301 409 "-" "Firefox" 194.110.203.42 - - [19/Nov/2022:08:48:41 +0100] "GET /easyzumfuehrerscheindb.tar.gz HTTP/1.1" 301 423 "-" "Firefox" 194.180.48.125 - - [19/Nov/2022:09:37:26 +0100] "GET /docker-compose.yml HTTP/1.1" 301 312 "-" "Mozilla/5.0 (X11; U; Linux x86_64; en-us) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.114 Safari/537.36 Puffin/4.8.0.2965AT" 205.210.31.51 - - [19/Nov/2022:09:49:09 +0100] "GET / HTTP/1.1" 301 389 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 198.235.24.174 - - [19/Nov/2022:09:53:20 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 162.142.125.121 - - [19/Nov/2022:10:15:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.121 - - [19/Nov/2022:10:15:33 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 194.110.203.45 - - [19/Nov/2022:10:22:30 +0100] "GET /harm_db.tar.gz HTTP/1.1" 301 391 "-" "Firefox" 162.248.160.43 - - [19/Nov/2022:10:39:13 +0100] "GET /administration/ac-admin/css/admin-calendar.css HTTP/1.1" 301 431 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6" 185.7.214.218 - - [19/Nov/2022:11:01:10 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 152.89.196.211 - - [19/Nov/2022:11:09:04 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 192.241.195.124 - - [19/Nov/2022:11:39:13 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 183.136.225.32 - - [19/Nov/2022:11:44:15 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.32 - - [19/Nov/2022:12:00:48 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [19/Nov/2022:12:01:09 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [19/Nov/2022:12:01:30 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.46 - - [19/Nov/2022:12:10:42 +0100] "GET /harm-db.tar.gz HTTP/1.1" 301 391 "-" "Firefox" 194.110.203.46 - - [19/Nov/2022:12:15:42 +0100] "GET /easyzumfuehrerschein-db.tar.gz HTTP/1.1" 301 424 "-" "Firefox" 138.246.253.24 - - [19/Nov/2022:12:35:18 +0100] "GET /robots.txt HTTP/1.1" 301 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 152.89.196.211 - - [19/Nov/2022:12:38:15 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [19/Nov/2022:13:07:03 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 138.246.253.24 - - [19/Nov/2022:13:15:34 +0100] "GET /robots.txt HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 128.14.209.162 - - [19/Nov/2022:13:48:14 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [19/Nov/2022:14:14:12 +0100] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 216.218.206.114 - - [19/Nov/2022:14:40:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:104.0) Gecko/20100101 Firefox/104.0" 216.218.206.86 - - [19/Nov/2022:14:49:29 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.102 Safari/537.36 OPR/90.0.4480.84" 216.218.206.98 - - [19/Nov/2022:14:54:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:105.0) Gecko/20100101 Firefox/105.0" 216.218.206.70 - - [19/Nov/2022:14:56:22 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36 Edg/105.0.1343.42" 194.110.203.47 - - [19/Nov/2022:14:58:35 +0100] "GET /harm_database.tar.gz HTTP/1.1" 301 397 "-" "Firefox" 194.180.48.125 - - [19/Nov/2022:15:14:38 +0100] "GET /explore HTTP/1.1" 301 306 "-" "Mozilla/3.01Gold (Win95; I)" 194.110.203.45 - - [19/Nov/2022:15:50:59 +0100] "GET /harm-database.tar.gz HTTP/1.1" 301 397 "-" "Firefox" 45.72.48.130 - - [19/Nov/2022:15:58:50 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 45.72.48.130 - - [19/Nov/2022:15:58:52 +0100] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 45.72.48.130 - - [19/Nov/2022:15:58:54 +0100] "GET /ads.txt HTTP/1.1" 301 300 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 194.110.203.44 - - [19/Nov/2022:17:42:56 +0100] "GET /klub_dump.tar.gz HTTP/1.1" 301 402 "-" "Firefox" 194.110.203.45 - - [19/Nov/2022:17:45:02 +0100] "GET /easyzumfuehrerschein_dump.tar.gz HTTP/1.1" 301 426 "-" "Firefox" 192.241.212.230 - - [19/Nov/2022:17:56:07 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 89.248.163.204 - - [19/Nov/2022:18:10:19 +0100] "-" 408 - "-" "-" 94.102.61.8 - - [19/Nov/2022:18:26:38 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.26.0" 194.110.203.42 - - [19/Nov/2022:18:44:54 +0100] "GET /harm_dump.tar.gz HTTP/1.1" 301 393 "-" "Firefox" 51.15.251.143 - - [19/Nov/2022:19:14:51 +0100] "GET / HTTP/1.1" 301 384 "-" "-" 194.110.203.38 - - [19/Nov/2022:19:46:20 +0100] "GET /klub-dump.tar.gz HTTP/1.1" 301 402 "-" "Firefox" 89.248.163.204 - - [19/Nov/2022:19:47:31 +0100] "-" 408 - "-" "-" 109.206.243.162 - - [19/Nov/2022:20:27:48 +0100] "GET /explore HTTP/1.1" 301 306 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)" 185.7.214.218 - - [19/Nov/2022:20:43:49 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 183.136.225.32 - - [19/Nov/2022:20:56:10 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.32 - - [19/Nov/2022:21:00:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [19/Nov/2022:21:01:18 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [19/Nov/2022:21:01:41 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.42 - - [19/Nov/2022:21:11:05 +0100] "GET /klubbackup.tar.gz HTTP/1.1" 301 403 "-" "Firefox" 194.110.203.40 - - [19/Nov/2022:21:33:18 +0100] "GET /easyzumfuehrerscheinbackup.tar.gz HTTP/1.1" 301 427 "-" "Firefox" 34.211.77.202 - - [19/Nov/2022:22:25:03 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.39.219.152 - - [19/Nov/2022:22:25:17 +0100] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.39.219.152 - - [19/Nov/2022:22:25:20 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.88.249.3 - - [19/Nov/2022:22:25:30 +0100] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 54.187.20.244 - - [19/Nov/2022:22:27:15 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.39.219.152 - - [19/Nov/2022:22:27:41 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.208.173.250 - - [19/Nov/2022:22:28:07 +0100] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 208.67.106.125 - - [19/Nov/2022:22:42:30 +0100] "GET /.git/config HTTP/1.1" 301 316 "-" "python-requests/2.27.1" 51.159.99.253 - - [19/Nov/2022:22:57:33 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 51.159.99.253 - - [19/Nov/2022:22:57:33 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 194.110.203.46 - - [19/Nov/2022:23:15:01 +0100] "GET /klub_backup.tar.gz HTTP/1.1" 301 404 "-" "Firefox" 35.91.178.25 - - [20/Nov/2022:00:13:42 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.35.54.56 - - [20/Nov/2022:00:20:55 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.195.93.98 - - [20/Nov/2022:00:22:02 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 208.100.26.249 - - [20/Nov/2022:00:23:14 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; MDDCJS; rv:11.0) like Gecko" 208.100.26.249 - - [20/Nov/2022:00:23:15 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (iPad; CPU OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/9.0 Mobile/13B143 Safari/601.1" 43.134.171.148 - - [20/Nov/2022:00:34:28 +0100] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 43.134.171.148 - - [20/Nov/2022:00:34:54 +0100] "-" 408 - "-" "-"