117.187.173.2 - - [06/Jan/2023:01:00:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 9_2_1; Win64; x64) AppleWebKit/602.41 (KHTML, like Gecko) Chrome/87.0.392 Safari/537.36" 194.110.203.40 - - [06/Jan/2023:01:33:14 +0100] "GET /database/backuplocalhost.sql.gz HTTP/1.1" 301 417 "-" "Firefox" 89.248.165.52 - - [06/Jan/2023:02:23:48 +0100] "-" 408 - "-" "-" 194.110.203.40 - - [06/Jan/2023:03:03:00 +0100] "GET /database/backup-localhost.sql.gz HTTP/1.1" 301 418 "-" "Firefox" 194.110.203.42 - - [06/Jan/2023:03:19:13 +0100] "GET /database/backup-localhost.sql.gz HTTP/1.1" 301 426 "-" "Firefox" 139.162.215.70 - - [06/Jan/2023:03:56:34 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 139.162.215.70 - - [06/Jan/2023:03:56:51 +0100] "GET /autodiscover/autodiscover.json?a..foo.var/owa/?&Email=autodiscover/autodiscover.json?a..foo.var&Protocol=XYZ&FooProtocol=%50owershell HTTP/1.1" 301 378 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.99.32.74 - - [06/Jan/2023:05:01:40 +0100] "GET /.DS_Store HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 185.220.102.250 - - [06/Jan/2023:05:01:40 +0100] "GET /.git/config HTTP/1.1" 301 304 "-" "Go-http-client/1.1" 185.56.83.83 - - [06/Jan/2023:05:01:43 +0100] "GET /.DS_Store HTTP/1.1" 301 301 "-" "Go-http-client/1.1" 194.110.203.45 - - [06/Jan/2023:05:15:17 +0100] "GET /database/backup_localhost.sql.gz HTTP/1.1" 301 409 "-" "Firefox" 64.62.197.126 - - [06/Jan/2023:05:30:49 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 64.62.197.136 - - [06/Jan/2023:05:40:04 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.126 Safari/537.36" 64.62.197.129 - - [06/Jan/2023:05:43:02 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 64.62.197.128 - - [06/Jan/2023:05:44:13 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:106.0) Gecko/20100101 Firefox/106.0" 194.110.203.40 - - [06/Jan/2023:06:00:21 +0100] "GET /database/backup_localhost.sql.gz HTTP/1.1" 301 418 "-" "Firefox" 109.237.97.180 - - [06/Jan/2023:06:18:08 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:08 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:09 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:09 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:10 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:10 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:11 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:11 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:12 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:12 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:13 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:13 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:14 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:14 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:15 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:15 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:16 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:16 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:17 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [06/Jan/2023:06:18:17 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 193.106.29.122 - - [06/Jan/2023:06:25:06 +0100] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 154.89.5.75 - - [06/Jan/2023:06:29:12 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 45.142.182.42 - - [06/Jan/2023:06:35:09 +0100] "POST /laravel/.env HTTP/1.1" 301 395 "-" "curl/7.74.0" 162.243.130.8 - - [06/Jan/2023:06:38:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 157.55.39.65 - - [06/Jan/2023:06:44:24 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" 183.136.225.32 - - [06/Jan/2023:08:34:49 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 194.110.203.47 - - [06/Jan/2023:09:26:14 +0100] "GET /database/harm.at_db.sql.gz HTTP/1.1" 301 403 "-" "Firefox" 194.110.203.47 - - [06/Jan/2023:09:27:59 +0100] "GET /database/easyzumfuehrerschein.com_db.sql.gz HTTP/1.1" 301 437 "-" "Firefox" 107.170.232.16 - - [06/Jan/2023:09:52:41 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 205.210.31.141 - - [06/Jan/2023:10:58:07 +0100] "GET / HTTP/1.1" 301 377 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 103.99.3.216 - - [06/Jan/2023:11:38:27 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:29 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:30 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:33 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:35 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:38 +0100] "GET / HTTP/1.1" 400 292 "-" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:40 +0100] "GET /HNAP1/ HTTP/1.1" 400 292 "https://www.easydrivers.at/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:41 +0100] "GET /HNAP1/ HTTP/1.1" 400 292 "https://www.easydrivers.at/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 103.99.3.216 - - [06/Jan/2023:11:38:42 +0100] "GET /HNAP1/ HTTP/1.1" 400 292 "https://www.easydrivers.at/" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 180.149.125.159 - - [06/Jan/2023:11:58:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 185.180.143.138 - - [06/Jan/2023:12:20:15 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.138 - - [06/Jan/2023:12:20:20 +0100] "GET /api/jsonws/ HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 167.94.146.57 - - [06/Jan/2023:12:27:24 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.146.57 - - [06/Jan/2023:12:27:24 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.146.57 - - [06/Jan/2023:12:27:24 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 138.246.253.24 - - [06/Jan/2023:12:35:08 +0100] "GET /robots.txt HTTP/1.1" 301 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 4.184.57.28 - - [06/Jan/2023:12:42:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 80.66.77.81 - - [06/Jan/2023:12:59:11 +0100] "GET /.env HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.7113.93 Safari/537.36" 194.110.203.45 - - [06/Jan/2023:13:53:04 +0100] "GET /database/klub.kornland.at_database.sql.gz HTTP/1.1" 301 427 "-" "Firefox" 194.110.203.45 - - [06/Jan/2023:14:14:21 +0100] "GET /database/easyzumfuehrerschein.com_database.sql.gz HTTP/1.1" 301 443 "-" "Firefox" 164.92.178.156 - - [06/Jan/2023:15:28:54 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 181.214.218.69 - - [06/Jan/2023:16:11:24 +0100] "-" 408 - "-" "-" 194.110.203.47 - - [06/Jan/2023:16:19:25 +0100] "GET /database/easyzumfuehrerschein.com-database.sql.gz HTTP/1.1" 301 443 "-" "Firefox" 157.55.39.65 - - [06/Jan/2023:16:37:41 +0100] "GET / HTTP/1.1" 301 304 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 178.79.147.165 - - [06/Jan/2023:16:44:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 157.230.239.219 - - [06/Jan/2023:17:49:18 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 157.230.239.219 - - [06/Jan/2023:17:49:20 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 157.230.239.219 - - [06/Jan/2023:17:49:23 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 205.210.31.15 - - [06/Jan/2023:18:52:09 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 162.243.135.5 - - [06/Jan/2023:19:09:34 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 101.68.211.2 - - [06/Jan/2023:20:16:48 +0100] "GET / HTTP/1.1" 301 394 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 106.75.139.49 - - [06/Jan/2023:20:40:54 +0100] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 183.136.225.32 - - [06/Jan/2023:20:52:54 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 194.110.203.40 - - [06/Jan/2023:20:57:45 +0100] "GET /database/klub.kornland.at-dump.sql.gz HTTP/1.1" 301 423 "-" "Firefox" 183.136.225.32 - - [06/Jan/2023:20:59:12 +0100] "-" 408 - "-" "-" 183.136.225.32 - - [06/Jan/2023:20:59:19 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 183.136.225.32 - - [06/Jan/2023:20:59:43 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.47 - - [06/Jan/2023:21:06:16 +0100] "GET /database/easyzumfuehrerschein.com-dump.sql.gz HTTP/1.1" 301 439 "-" "Firefox" 109.237.98.226 - - [06/Jan/2023:21:29:48 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:48 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:49 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:49 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:50 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:50 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:51 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:51 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:52 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:52 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:52 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:53 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:53 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:54 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:54 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:55 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:55 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:55 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:56 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [06/Jan/2023:21:29:56 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 205.210.31.48 - - [06/Jan/2023:21:49:37 +0100] "GET / HTTP/1.1" 301 381 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 60.217.75.70 - - [06/Jan/2023:22:28:35 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 167.248.133.117 - - [06/Jan/2023:22:35:12 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.117 - - [06/Jan/2023:22:35:13 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.117 - - [06/Jan/2023:22:35:13 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 162.221.192.26 - - [06/Jan/2023:22:43:21 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 205.210.31.36 - - [06/Jan/2023:23:36:09 +0100] "GET / HTTP/1.1" 301 390 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 139.162.215.70 - - [06/Jan/2023:23:38:19 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 139.162.215.70 - - [06/Jan/2023:23:38:28 +0100] "GET /autodiscover/autodiscover.json?a..foo.var/owa/?&Email=autodiscover/autodiscover.json?a..foo.var&Protocol=XYZ&FooProtocol=%50owershell HTTP/1.1" 301 378 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 192.241.192.13 - - [07/Jan/2023:00:10:48 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 128.14.209.162 - - [07/Jan/2023:00:16:20 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 34.76.158.233 - - [07/Jan/2023:00:34:54 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.1" 198.235.24.41 - - [07/Jan/2023:00:59:54 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com"