198.12.252.180 - - [25/Dec/2022:01:12:34 +0100] "GET /db/klub_db.tar HTTP/1.1" 301 400 "-" "Firefox" 54.201.207.152 - - [25/Dec/2022:01:25:19 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:43 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:43 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:44 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:44 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:45 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:45 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:45 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:46 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:46 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:47 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:47 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:48 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:48 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:49 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:49 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:50 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:50 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:51 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:51 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [25/Dec/2022:02:09:52 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 206.189.142.5 - - [25/Dec/2022:02:18:55 +0100] "HEAD / HTTP/1.1" 301 - "https://www.bing.com" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" 194.110.203.40 - - [25/Dec/2022:02:39:49 +0100] "GET /db/harm-db.tar HTTP/1.1" 301 391 "-" "Firefox" 194.110.203.47 - - [25/Dec/2022:02:51:40 +0100] "GET /db/klub-db.tar HTTP/1.1" 301 400 "-" "Firefox" 165.22.227.82 - - [25/Dec/2022:02:59:26 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 165.22.227.82 - - [25/Dec/2022:02:59:32 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 41.197.31.178 - - [25/Dec/2022:03:40:04 +0100] "GET /users/sign_in HTTP/1.1" 301 398 "-" "-" 64.62.197.16 - - [25/Dec/2022:05:36:18 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36" 64.62.197.9 - - [25/Dec/2022:05:50:06 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0" 64.62.197.3 - - [25/Dec/2022:05:59:32 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Firefox/91.0" 107.170.224.22 - - [25/Dec/2022:06:08:11 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 128.14.134.134 - - [25/Dec/2022:06:23:19 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.134.134 - - [25/Dec/2022:06:23:32 +0100] "HEAD /icons/sphere1.png HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.209.162 - - [25/Dec/2022:06:41:59 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.7.214.218 - - [25/Dec/2022:06:58:48 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 162.243.128.13 - - [25/Dec/2022:07:01:34 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.42 - - [25/Dec/2022:07:39:21 +0100] "GET /db/db.7z HTTP/1.1" 301 402 "-" "Firefox" 157.55.39.65 - - [25/Dec/2022:07:43:23 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 194.110.203.45 - - [25/Dec/2022:07:45:20 +0100] "GET /db/db.7z HTTP/1.1" 301 385 "-" "Firefox" 152.89.196.211 - - [25/Dec/2022:08:10:07 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 4.184.57.28 - - [25/Dec/2022:08:48:17 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 194.110.203.38 - - [25/Dec/2022:09:35:31 +0100] "GET /db/dbdump.7z HTTP/1.1" 301 406 "-" "Firefox" 194.110.203.42 - - [25/Dec/2022:09:46:18 +0100] "GET /db/dbdump.7z HTTP/1.1" 301 398 "-" "Firefox" 66.249.68.39 - - [25/Dec/2022:09:55:44 +0100] "GET /robots.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.68.35 - - [25/Dec/2022:09:55:45 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.115 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 194.110.203.47 - - [25/Dec/2022:10:18:42 +0100] "GET /db/dbdump.7z HTTP/1.1" 301 389 "-" "Firefox" 152.89.196.211 - - [25/Dec/2022:11:17:21 +0100] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 164.52.25.251 - - [25/Dec/2022:12:25:59 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 164.52.25.251 - - [25/Dec/2022:12:26:37 +0100] "GET /favicon.ico HTTP/1.1" 301 394 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" 162.243.136.18 - - [25/Dec/2022:12:41:51 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.39 - - [25/Dec/2022:12:41:56 +0100] "GET /db/localhostdb.7z HTTP/1.1" 301 411 "-" "Firefox" 107.170.242.13 - - [25/Dec/2022:12:45:35 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 107.170.242.13 - - [25/Dec/2022:12:49:09 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 66.249.68.35 - - [25/Dec/2022:12:56:02 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 162.221.192.26 - - [25/Dec/2022:13:59:41 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 81.17.22.106 - - [25/Dec/2022:15:01:57 +0100] "GET /.env.development HTTP/1.1" 301 399 "-" "Mozilla/5.0 (X11; Linux x86_64)" 81.17.22.106 - - [25/Dec/2022:15:01:57 +0100] "GET /.env.test HTTP/1.1" 301 392 "-" "Mozilla/5.0 (X11; Linux x86_64)" 81.17.22.106 - - [25/Dec/2022:15:01:57 +0100] "GET /.env.production HTTP/1.1" 301 398 "-" "Mozilla/5.0 (X11; Linux x86_64)" 194.110.203.47 - - [25/Dec/2022:16:06:39 +0100] "GET /db/localhost-db.7z HTTP/1.1" 301 404 "-" "Firefox" 185.7.214.218 - - [25/Dec/2022:16:25:42 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "Python-urllib/3.8" 157.55.39.65 - - [25/Dec/2022:17:36:21 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 107.170.241.6 - - [25/Dec/2022:18:03:52 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 167.94.138.45 - - [25/Dec/2022:18:26:33 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.45 - - [25/Dec/2022:18:26:34 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.45 - - [25/Dec/2022:18:26:35 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 183.136.225.32 - - [25/Dec/2022:18:33:23 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 192.241.239.23 - - [25/Dec/2022:18:37:41 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 183.136.225.32 - - [25/Dec/2022:18:40:00 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [25/Dec/2022:18:40:23 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.46 - - [25/Dec/2022:19:33:34 +0100] "GET /db/localhost-database.7z HTTP/1.1" 301 418 "-" "Firefox" 198.12.252.180 - - [25/Dec/2022:19:39:28 +0100] "GET /db/localhost-database.7z HTTP/1.1" 301 401 "-" "Firefox" 128.14.134.170 - - [25/Dec/2022:20:28:40 +0100] "GET /cgi-bin/config.exp HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 124.223.197.157 - - [25/Dec/2022:20:33:12 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" 23.251.102.74 - - [25/Dec/2022:20:52:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.47 - - [25/Dec/2022:20:58:59 +0100] "GET /db/harmdb.7z HTTP/1.1" 301 389 "-" "Firefox" 63.251.232.70 - - [25/Dec/2022:21:04:37 +0100] "GET / HTTP/1.1" 301 377 "-" "libwww-perl/6.67" 45.134.144.119 - - [25/Dec/2022:21:16:38 +0100] "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 301 325 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" 20.172.38.178 - - [25/Dec/2022:22:35:12 +0100] "GET /about.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:14 +0100] "GET /upload.php?mr=exe3 HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:16 +0100] "GET /2index.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:17 +0100] "GET /C.php HTTP/1.1" 301 300 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:19 +0100] "GET /c.php HTTP/1.1" 301 300 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:20 +0100] "GET /01.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:22 +0100] "GET /1.php HTTP/1.1" 301 300 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:23 +0100] "GET /02.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:25 +0100] "GET /wp.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:26 +0100] "GET /fw.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:28 +0100] "GET /alfa.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:29 +0100] "GET /mini.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:31 +0100] "GET /x.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:33 +0100] "GET /404.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:34 +0100] "GET /403.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:36 +0100] "GET /wso.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:37 +0100] "GET /admin.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:39 +0100] "GET /wp-22.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:41 +0100] "GET /1index.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:43 +0100] "GET /marijuana.php HTTP/1.1" 301 306 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:44 +0100] "GET /good.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:46 +0100] "GET /up.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:47 +0100] "GET /doc.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:49 +0100] "GET /ws.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:51 +0100] "GET /wp.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:53 +0100] "GET /radio.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:55 +0100] "GET /wp-includes/1index.php?pass=am*guAW8.ryDgz-TYF HTTP/1.1" 301 333 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:56 +0100] "GET /1index.php?pass=am*guAW8.ryDgz-TYF HTTP/1.1" 301 325 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:35:58 +0100] "GET /wp_wrong_datlib.php?pass=stusa HTTP/1.1" 301 318 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:00 +0100] "GET /2index.php?pass=am*guAW8.ryDgz-TYF HTTP/1.1" 301 325 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:01 +0100] "GET /autoload_classmap.php HTTP/1.1" 301 312 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:02 +0100] "GET /wp.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:05 +0100] "GET /wikindex.php HTTP/1.1" 301 306 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:06 +0100] "GET /ae.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:08 +0100] "GET /wp-2019.php HTTP/1.1" 301 305 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:10 +0100] "GET /bat.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:11 +0100] "GET /wp-admin/setup-config.php HTTP/1.1" 301 314 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:14 +0100] "GET /wp-admin/xleet.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:15 +0100] "GET /wp-content/fw.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:17 +0100] "GET /wp-admin/fx.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:18 +0100] "GET /wp-finish.php HTTP/1.1" 301 306 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:21 +0100] "GET /wp-info.php HTTP/1.1" 301 305 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:22 +0100] "GET /upl.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:24 +0100] "GET /wp-admin/priv8.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:25 +0100] "GET /wp-admin/rss.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:27 +0100] "GET /uploads/xleet.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:28 +0100] "GET /ALFA_DATA/alfacgiapi HTTP/1.1" 301 313 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:30 +0100] "GET /wp-content/1975.php HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:31 +0100] "GET /wp-content/local.php HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:33 +0100] "GET /wp-content/alfa.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:34 +0100] "GET /wp-class.php HTTP/1.1" 301 305 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:36 +0100] "GET /wp-includes/wp-class.php HTTP/1.1" 301 312 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:38 +0100] "GET /shl.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:40 +0100] "GET /1975.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:41 +0100] "GET /1337.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:43 +0100] "GET /1887.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:44 +0100] "GET /index1.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:47 +0100] "GET /blok.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:49 +0100] "GET /l.hp HTTP/1.1" 301 300 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:50 +0100] "GET /tmp/up.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:51 +0100] "GET /hd.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:54 +0100] "GET /wp-admin/up.php HTTP/1.1" 301 307 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:55 +0100] "GET /wp-content/up.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:57 +0100] "GET /wp-content/vfthuqytkx.php HTTP/1.1" 301 315 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:36:59 +0100] "GET /wp-admin//FoxWSO.php HTTP/1.1" 301 312 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:01 +0100] "GET /wp-content/fx.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:02 +0100] "GET /wp-admin/v.php HTTP/1.1" 301 307 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:04 +0100] "GET /wp-content/x.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:06 +0100] "GET /wp-content/v.php HTTP/1.1" 301 307 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:07 +0100] "GET /wp-content/chn.php HTTP/1.1" 301 308 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:09 +0100] "GET /wp-content/uploads/chn.php HTTP/1.1" 301 313 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:11 +0100] "GET /uploads/w0rmshop.php HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:13 +0100] "GET /wp-content/uploads/w0rmshop.php HTTP/1.1" 301 317 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:15 +0100] "GET /wp-admin/w0rmshop.php HTTP/1.1" 301 311 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:17 +0100] "GET /w0rmshop.php HTTP/1.1" 301 305 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:18 +0100] "GET /xxx.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:20 +0100] "GET /style.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:22 +0100] "GET /done.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:23 +0100] "GET /xleet-shell.php HTTP/1.1" 301 307 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:25 +0100] "GET /cha.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:27 +0100] "GET /wp-content/plugins/itw/0byte.php HTTP/1.1" 301 318 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:28 +0100] "GET /outline.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:30 +0100] "GET /haxor.php HTTP/1.1" 301 303 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:31 +0100] "GET /1wiki.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:33 +0100] "GET /wp-load.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:34 +0100] "GET /tmp/_notfound.php HTTP/1.1" 301 309 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:36 +0100] "GET /wp-admin/wp-load.php HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:37 +0100] "GET /wp-admin/wp-load.php HTTP/1.1" 301 310 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:39 +0100] "GET /kz.php HTTP/1.1" 301 302 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:40 +0100] "GET /admin1.php HTTP/1.1" 301 304 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:41 +0100] "GET /aa.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 20.172.38.178 - - [25/Dec/2022:22:37:43 +0100] "GET /css.php HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 34.220.166.230 - - [25/Dec/2022:22:39:15 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 52.42.230.6 - - [25/Dec/2022:22:40:00 +0100] "GET /favicon.ico HTTP/1.1" 301 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 51.77.247.119 - - [25/Dec/2022:23:02:00 +0100] "POST /.env HTTP/1.1" 301 387 "-" "curl/7.64.0" 20.100.176.223 - - [25/Dec/2022:23:06:12 +0100] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.23.1" 20.100.176.223 - - [25/Dec/2022:23:06:12 +0100] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.23.1" 87.236.176.98 - - [25/Dec/2022:23:16:56 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 60.217.75.70 - - [25/Dec/2022:23:39:28 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 185.213.175.12 - - [25/Dec/2022:23:39:46 +0100] "{\"id\": 1, \"method\": \"mining.subscribe\", \"params\": [\"cpuminer/2.5.1\"]}" 400 379 "-" "-" 185.213.175.12 - - [25/Dec/2022:23:39:55 +0100] "{\"id\": 1, \"method\": \"mining.subscribe\", \"params\": [\"MinerName/1.0.0\", \"EthereumStratum/1.0.0\"]}" 400 379 "-" "-" 185.213.175.12 - - [25/Dec/2022:23:40:03 +0100] "{\"id\":1,\"method\":\"eth_submitLogin\",\"worker\":\"eth1.0\",\"params\":[\"0xb0c5df4630fd3347e465def60045f8ea43198210\",\"x\"],\"jsonrpc\":\"2.0\"}" 400 379 "-" "-" 185.213.175.12 - - [25/Dec/2022:23:40:11 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"45tTCinrA76hDcWw9j4cqJHaWUvAQ76D2DNBkzZdHrhgWWncwXNvzKsKurtRZu7wAHACn11szjM8xGc4J9ZKs8WJJMYtYKM\",\"pass\":\"x\",\"agent\":\"XMRig/6.15.3 (Windows NT 10.0; Win64; x64) libuv/1.42.0 msvc/2019\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"cn/ccx\",\"cn-lite/1\",\"cn-heavy/0\",\"cn-heavy/tube\",\"cn-heavy/xhv\",\"cn-pico\",\"cn-pico/tlo\",\"cn/upx2\",\"rx/0\",\"rx/wow\",\"rx/arq\",\"rx/graft\",\"rx/sfx\",\"rx/keva\",\"argon2/chukwa\",\"argon2/chukwav2\",\"argon2/ninja\",\"astrobwt\"]}}" 400 379 "-" "-" 185.213.175.12 - - [25/Dec/2022:23:40:18 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:22 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:28 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:34 +0100] "GET /WuEL HTTP/1.1" 301 387 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; ; NCLIENT50_AAPCDA5841E333)" 185.213.175.12 - - [25/Dec/2022:23:40:39 +0100] "GET stager64 HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:43 +0100] "GET /a HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:47 +0100] "GET /download/file.ext HTTP/1.1" 301 313 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:49 +0100] "GET /SiteLoader HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 185.213.175.12 - - [25/Dec/2022:23:40:53 +0100] "GET /mPlayer HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36" 45.134.144.119 - - [26/Dec/2022:00:31:05 +0100] "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 301 325 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" 188.166.255.15 - - [26/Dec/2022:00:45:56 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 188.166.255.15 - - [26/Dec/2022:00:45:59 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 188.166.255.15 - - [26/Dec/2022:00:46:09 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"