183.136.225.46 - - [22/Jan/2023:01:29:32 +0100] "GET / HTTP/1.1" 301 377 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.46 - - [22/Jan/2023:01:30:47 +0100] "GET /robots.txt HTTP/1.1" 301 302 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 135.181.85.193 - - [22/Jan/2023:01:37:18 +0100] "GET /robots.txt HTTP/1.1" 301 397 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 135.181.85.193 - - [22/Jan/2023:01:37:19 +0100] "GET /robots.txt HTTP/1.1" 301 397 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 135.181.85.193 - - [22/Jan/2023:01:37:19 +0100] "GET / HTTP/1.1" 301 387 "-" "Mozilla/5.0 (compatible; SeekportBot; +https://bot.seekport.com)" 220.135.120.154 - - [22/Jan/2023:02:43:55 +0100] "GET /103/license.txt HTTP/1.1" 301 305 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 92.255.85.183 - - [22/Jan/2023:02:45:10 +0100] "-" 408 - "-" "-" 152.89.196.211 - - [22/Jan/2023:02:52:59 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.44 - - [22/Jan/2023:03:02:25 +0100] "GET /wpback.tar.gz HTTP/1.1" 301 399 "-" "Firefox" 1.161.184.81 - - [22/Jan/2023:03:24:08 +0100] "GET /103/license.txt HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 194.110.203.38 - - [22/Jan/2023:05:23:01 +0100] "GET /backupklub.kornland.at.zip HTTP/1.1" 301 412 "-" "Firefox" 192.241.209.135 - - [22/Jan/2023:05:24:29 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 128.199.35.144 - - [22/Jan/2023:05:27:16 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 152.89.196.211 - - [22/Jan/2023:05:38:33 +0100] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 64.62.197.162 - - [22/Jan/2023:05:41:37 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36 Edg/105.0.1343.42" 64.62.197.166 - - [22/Jan/2023:05:52:53 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36" 64.62.197.154 - - [22/Jan/2023:05:59:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36 Edg/105.0.1343.53" 64.62.197.161 - - [22/Jan/2023:06:01:31 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 192.241.232.14 - - [22/Jan/2023:07:07:41 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 111.172.165.27 - - [22/Jan/2023:07:27:43 +0100] "GET /1998/license.txt HTTP/1.1" 301 319 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 128.14.209.162 - - [22/Jan/2023:07:33:56 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.41 - - [22/Jan/2023:08:13:39 +0100] "GET /backupklub.kornland.at.tar HTTP/1.1" 301 412 "-" "Firefox" 4.184.57.28 - - [22/Jan/2023:09:27:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 198.235.24.6 - - [22/Jan/2023:09:31:29 +0100] "GET / HTTP/1.1" 301 379 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 34.241.224.8 - - [22/Jan/2023:09:34:28 +0100] "GET / HTTP/1.1" 301 301 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.24 (KHTML, like Gecko) Chrome/18.0.1038.25 Safari/535.26" 43.158.217.16 - - [22/Jan/2023:09:42:22 +0100] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 43.158.217.16 - - [22/Jan/2023:09:42:46 +0100] "-" 408 - "-" "-" 43.158.217.16 - - [22/Jan/2023:09:42:57 +0100] "-" 408 - "-" "-" 185.180.143.80 - - [22/Jan/2023:10:06:35 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:06:38 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:07:05 +0100] "GET /webfig/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:07:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:07:41 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:07:43 +0100] "GET /autodiscover/autodiscover.json?a..foo.var/owa/?&Email=autodiscover/autodiscover.json?a..foo.var&Protocol=XYZ&FooProtocol=%50owershell HTTP/1.1" 301 378 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.80 - - [22/Jan/2023:10:08:19 +0100] "GET /solr/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.44 - - [22/Jan/2023:10:08:28 +0100] "GET /backupklub.tar HTTP/1.1" 301 400 "-" "Firefox" 92.255.85.183 - - [22/Jan/2023:10:13:00 +0100] "-" 408 - "-" "-" 211.186.165.244 - - [22/Jan/2023:10:50:29 +0100] "GET /1999/license.txt HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 109.237.98.226 - - [22/Jan/2023:11:14:18 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:18 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:19 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:19 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:20 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:20 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:21 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:21 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:22 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:22 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:23 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:23 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:24 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:24 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:24 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:25 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:25 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:26 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:26 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [22/Jan/2023:11:14:27 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 89.177.77.9 - - [22/Jan/2023:11:33:15 +0100] "GET /1999/license.txt HTTP/1.1" 301 319 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 128.1.248.42 - - [22/Jan/2023:11:42:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 92.118.36.206 - - [22/Jan/2023:14:17:32 +0100] "GET /spog/welcome HTTP/1.1" 301 309 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 92.118.36.206 - - [22/Jan/2023:14:17:33 +0100] "GET /cgi-bin/welcome HTTP/1.1" 301 313 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 167.94.138.120 - - [22/Jan/2023:14:48:49 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.120 - - [22/Jan/2023:14:48:49 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.120 - - [22/Jan/2023:14:48:50 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 71.59.232.131 - - [22/Jan/2023:14:56:51 +0100] "GET /1x1/license.txt HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 128.14.141.34 - - [22/Jan/2023:15:19:57 +0100] "GET /cgi-bin/config.exp HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.39 - - [22/Jan/2023:15:21:06 +0100] "GET /.well-known.zip HTTP/1.1" 301 401 "-" "Firefox" 185.130.224.57 - - [22/Jan/2023:15:21:51 +0100] "GET / HTTP/1.0" 301 388 "-" "-" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../ HTTP/1.1" 301 498 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /rest/applinks/1.0/manifest HTTP/1.1" 301 409 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "PUT /api/v2/cmdb/system/admin/admin HTTP/1.1" 301 413 "-" "Report Runner - Internet Research" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET / HTTP/1.1" 301 383 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "POST /casa/nodes/thumbprints HTTP/1.1" 301 398 "-" "Guayoyo - Mozilla/5.0 (compatible; vCenter)" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "POST /ui/h5-vsan/rest/proxy/service/com.vmware.vsan.client.services.capability.VsanCapabilityProvider/getClusterCapabilityData HTTP/1.1" 301 503 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /autodiscover/autodiscover.json?@abc.com/owa/?&Email=autodiscover/autodiscover.json%3F@abc.com HTTP/1.1" 301 484 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd HTTP/1.1" 301 458 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /aspnet-ajax/Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 301 434 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/ HTTP/1.1" 400 374 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 301 452 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /logon/LogonPoint/tmindex.html HTTP/1.1" 301 412 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 301 422 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /secure/rest/applinks/1.0/manifest HTTP/1.1" 301 416 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /ui/login.action HTTP/1.1" 301 391 "-" "Guayoyo - Mozilla/5.0 (compatible; vCenter)" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /jira/rest/applinks/1.0/manifest HTTP/1.1" 301 414 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /confluence/rest/applinks/1.0/manifest HTTP/1.1" 301 420 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:52 +0100] "GET /bitbucket/rest/applinks/1.0/manifest HTTP/1.1" 301 419 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:53 +0100] "GET /bamboo/rest/applinks/1.0/manifest HTTP/1.1" 301 416 "-" "curl/7.54.0" 185.130.224.57 - - [22/Jan/2023:15:21:53 +0100] "GET /crowd/rest/applinks/1.0/manifest HTTP/1.1" 301 415 "-" "curl/7.54.0" 61.147.15.65 - - [22/Jan/2023:15:24:02 +0100] "GET / HTTP/1.1" 301 295 "-" "Dalvik/2.1.0 (Linux; U; Android 9.0; ZTE BA520 Build/MRA58K)" 61.147.15.65 - - [22/Jan/2023:15:24:05 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.27 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/601.1.27" 142.93.53.230 - - [22/Jan/2023:15:36:37 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 142.93.53.230 - - [22/Jan/2023:15:36:38 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 142.93.53.230 - - [22/Jan/2023:15:36:42 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 212.170.169.139 - - [22/Jan/2023:15:37:38 +0100] "GET /1x1/license.txt HTTP/1.1" 301 318 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 194.110.203.44 - - [22/Jan/2023:15:47:41 +0100] "GET /.well-known.zip HTTP/1.1" 301 392 "-" "Firefox" 194.110.203.40 - - [22/Jan/2023:16:56:05 +0100] "GET /wp-admin.zip HTTP/1.1" 301 406 "-" "Firefox" 198.235.24.30 - - [22/Jan/2023:17:08:25 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 167.94.138.117 - - [22/Jan/2023:17:18:17 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.117 - - [22/Jan/2023:17:18:19 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 185.83.146.154 - - [22/Jan/2023:17:41:04 +0100] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:06 +0100] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:08 +0100] "GET /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:10 +0100] "POST /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:12 +0100] "GET /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:13 +0100] "POST /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:15 +0100] "GET /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:17 +0100] "POST /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:18 +0100] "GET /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:20 +0100] "POST /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:22 +0100] "GET /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:23 +0100] "POST /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:25 +0100] "GET /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:27 +0100] "POST /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:28 +0100] "GET /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:30 +0100] "POST /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:31 +0100] "GET /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 185.83.146.154 - - [22/Jan/2023:17:41:32 +0100] "POST /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 137.184.193.128 - - [22/Jan/2023:17:48:19 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.7 (KHTML, like Gecko) Chrome/7.0.514.0 Safari/534.7" 23.251.102.74 - - [22/Jan/2023:18:04:09 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 87.236.176.173 - - [22/Jan/2023:18:14:06 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 194.110.203.45 - - [22/Jan/2023:18:15:50 +0100] "GET /administrator.zip HTTP/1.1" 301 394 "-" "Firefox" 194.110.203.45 - - [22/Jan/2023:18:27:23 +0100] "GET /administrator.zip HTTP/1.1" 301 411 "-" "Firefox" 194.110.203.38 - - [22/Jan/2023:18:37:44 +0100] "GET /administrator.zip HTTP/1.1" 301 403 "-" "Firefox" 162.243.145.19 - - [22/Jan/2023:18:49:23 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 111.172.165.27 - - [22/Jan/2023:19:06:10 +0100] "GET /2/license.txt HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 192.241.218.45 - - [22/Jan/2023:19:23:41 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.46 - - [22/Jan/2023:19:40:57 +0100] "GET /admin.zip HTTP/1.1" 301 395 "-" "Firefox" 194.110.203.42 - - [22/Jan/2023:19:56:17 +0100] "GET /admin.zip HTTP/1.1" 301 403 "-" "Firefox" 95.90.245.112 - - [22/Jan/2023:20:22:12 +0100] "GET / HTTP/1.1" 301 297 "-" "Fuzz Faster U Fool v1.3.1-dev" 194.110.203.46 - - [22/Jan/2023:21:02:17 +0100] "GET /1.zip HTTP/1.1" 301 399 "-" "Firefox" 109.237.97.180 - - [22/Jan/2023:22:25:36 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:36 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:37 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:38 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:38 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:39 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:39 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:40 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:40 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:41 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:41 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:41 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:42 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:42 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:43 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:43 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:44 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:44 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:45 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [22/Jan/2023:22:25:45 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 194.110.203.46 - - [22/Jan/2023:22:29:17 +0100] "GET /.zip HTTP/1.1" 301 398 "-" "Firefox" 205.210.31.178 - - [22/Jan/2023:22:35:07 +0100] "GET / HTTP/1.1" 301 385 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 125.228.72.220 - - [22/Jan/2023:23:14:49 +0100] "GET /20/license.txt HTTP/1.1" 301 305 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 205.210.31.169 - - [22/Jan/2023:23:22:04 +0100] "GET / HTTP/1.1" 301 393 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 128.14.133.58 - - [22/Jan/2023:23:22:30 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 60.217.75.70 - - [22/Jan/2023:23:32:48 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 194.110.203.46 - - [22/Jan/2023:23:36:08 +0100] "GET /service.zip HTTP/1.1" 301 405 "-" "Firefox" 194.110.203.47 - - [22/Jan/2023:23:38:19 +0100] "GET /service.zip HTTP/1.1" 301 397 "-" "Firefox" 161.156.29.33 - - [22/Jan/2023:23:50:50 +0100] "GET /robots.txt HTTP/1.1" 301 397 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 161.156.29.33 - - [22/Jan/2023:23:50:50 +0100] "GET / HTTP/1.1" 301 387 "-" "Mozilla/5.0 (compatible; oBot/2.3.1; http://www.xforce-security.com/crawler/)" 34.76.158.233 - - [22/Jan/2023:23:52:59 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2" 185.45.239.1 - - [22/Jan/2023:23:55:39 +0100] "GET /20/license.txt HTTP/1.1" 301 317 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 194.110.203.38 - - [22/Jan/2023:23:57:13 +0100] "GET /service.zip HTTP/1.1" 301 388 "-" "Firefox" 34.212.135.247 - - [23/Jan/2023:00:20:28 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.91.240.179 - - [23/Jan/2023:00:20:58 +0100] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 35.91.240.179 - - [23/Jan/2023:00:21:01 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36"