139.59.106.172 - - [26/Jan/2023:01:39:36 +0100] "GET /aaa9 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 139.59.106.172 - - [26/Jan/2023:01:39:38 +0100] "GET /aab8 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 18.237.174.162 - - [26/Jan/2023:01:48:18 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 185.110.91.120 - - [26/Jan/2023:04:16:31 +0100] "GET /Admin/license.txt HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 115.90.156.61 - - [26/Jan/2023:05:05:23 +0100] "GET /Admin/license.txt HTTP/1.1" 301 319 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 66.240.236.109 - - [26/Jan/2023:05:20:15 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 162.142.125.213 - - [26/Jan/2023:05:27:54 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.213 - - [26/Jan/2023:05:27:55 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.213 - - [26/Jan/2023:05:27:55 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 167.248.133.120 - - [26/Jan/2023:05:31:12 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.120 - - [26/Jan/2023:05:31:13 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.120 - - [26/Jan/2023:05:31:13 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 138.246.253.24 - - [26/Jan/2023:05:40:31 +0100] "GET /robots.txt HTTP/1.1" 301 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 104.244.75.243 - - [26/Jan/2023:06:23:50 +0100] "GET ///wp-login.php HTTP/1.1" 301 313 "http://www.google.com.hk" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" 85.209.135.214 - - [26/Jan/2023:07:08:55 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 85.209.135.214 - - [26/Jan/2023:07:08:56 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 198.199.108.188 - - [26/Jan/2023:07:18:01 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.45 - - [26/Jan/2023:07:38:27 +0100] "GET /docker-compose-production.yaml HTTP/1.1" 301 407 "-" "Firefox" 128.14.133.58 - - [26/Jan/2023:07:45:12 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 178.128.22.52 - - [26/Jan/2023:08:12:56 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 178.128.22.52 - - [26/Jan/2023:08:12:58 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 178.128.22.52 - - [26/Jan/2023:08:13:07 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 178.128.22.52 - - [26/Jan/2023:08:13:23 +0100] "-" 408 - "-" "-" 194.110.203.40 - - [26/Jan/2023:08:28:11 +0100] "GET /stager.zip HTTP/1.1" 301 396 "-" "Firefox" 4.184.57.28 - - [26/Jan/2023:09:12:47 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 138.19.235.243 - - [26/Jan/2023:09:15:44 +0100] "GET /Administration/license.txt HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 193.56.29.26 - - [26/Jan/2023:09:20:23 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 193.56.29.26 - - [26/Jan/2023:09:20:23 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 162.243.132.21 - - [26/Jan/2023:09:49:36 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 51.222.253.13 - - [26/Jan/2023:09:58:47 +0100] "GET /robots.txt HTTP/1.1" 301 315 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 54.36.148.173 - - [26/Jan/2023:09:58:53 +0100] "GET / HTTP/1.1" 301 308 "-" "Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)" 185.110.91.120 - - [26/Jan/2023:10:05:39 +0100] "GET /Administration/license.txt HTTP/1.1" 301 325 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 159.89.157.34 - - [26/Jan/2023:11:03:21 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 194.110.203.42 - - [26/Jan/2023:13:09:57 +0100] "GET /docker-compose.yaml HTTP/1.1" 301 396 "-" "Firefox" 194.110.203.47 - - [26/Jan/2023:13:43:23 +0100] "GET /docker-compose.yaml HTTP/1.1" 301 413 "-" "Firefox" 60.173.195.214 - - [26/Jan/2023:14:22:00 +0100] "GET /Archive/license.txt HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 103.153.254.110 - - [26/Jan/2023:14:38:37 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" 66.153.174.87 - - [26/Jan/2023:15:12:06 +0100] "GET /Archive/license.txt HTTP/1.1" 301 320 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 198.199.115.100 - - [26/Jan/2023:15:29:31 +0100] "GET /actuator/health HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 192.241.218.17 - - [26/Jan/2023:15:49:35 +0100] "GET /version HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.38 - - [26/Jan/2023:16:20:52 +0100] "GET /Dockerfile HTTP/1.1" 301 387 "-" "Firefox" 23.251.102.74 - - [26/Jan/2023:16:42:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.44 - - [26/Jan/2023:16:53:27 +0100] "GET /Dockerfile HTTP/1.1" 301 404 "-" "Firefox" 68.183.234.144 - - [26/Jan/2023:17:41:17 +0100] "GET /aaa9 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 68.183.234.144 - - [26/Jan/2023:17:41:19 +0100] "GET /aab8 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 185.180.143.79 - - [26/Jan/2023:18:08:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.79 - - [26/Jan/2023:18:08:20 +0100] "HEAD /icons/sphere1.png HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.134.144.119 - - [26/Jan/2023:18:31:04 +0100] "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 301 325 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" 194.110.203.46 - - [26/Jan/2023:19:10:20 +0100] "GET /.env.dev HTTP/1.1" 301 402 "-" "Firefox" 35.212.26.22 - - [26/Jan/2023:19:20:06 +0100] "" 400 379 "-" "-" 35.211.164.203 - - [26/Jan/2023:19:21:45 +0100] "" 400 379 "-" "-" 162.243.130.6 - - [26/Jan/2023:19:25:57 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 106.75.177.6 - - [26/Jan/2023:19:46:15 +0100] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 106.75.177.6 - - [26/Jan/2023:19:46:17 +0100] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 106.75.177.6 - - [26/Jan/2023:19:46:19 +0100] "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 400 379 "-" "-" 106.75.177.6 - - [26/Jan/2023:19:46:21 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 400 379 "-" "-" 106.75.177.6 - - [26/Jan/2023:19:46:22 +0100] "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 400 379 "-" "-" 106.75.177.6 - - [26/Jan/2023:19:46:24 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 400 379 "-" "-" 152.89.196.211 - - [26/Jan/2023:20:21:54 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 172.105.161.246 - - [26/Jan/2023:20:24:07 +0100] "GET /owa/ HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [26/Jan/2023:20:24:10 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 172.105.161.246 - - [26/Jan/2023:20:24:22 +0100] "GET /autodiscover/autodiscover.json?a..foo.var/owa/?&Email=autodiscover/autodiscover.json?a..foo.var&Protocol=XYZ&FooProtocol=%50owershell HTTP/1.1" 301 378 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 193.118.53.210 - - [26/Jan/2023:20:34:52 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.46 - - [26/Jan/2023:20:55:18 +0100] "GET /stager2.zip HTTP/1.1" 301 397 "-" "Firefox" 178.33.221.232 - - [26/Jan/2023:21:45:54 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 178.33.221.232 - - [26/Jan/2023:21:45:54 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 95.111.230.235 - - [26/Jan/2023:22:21:51 +0100] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36" 60.217.75.70 - - [26/Jan/2023:22:28:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 194.110.203.46 - - [26/Jan/2023:23:15:59 +0100] "GET /release.zip HTTP/1.1" 301 397 "-" "Firefox" 95.215.205.158 - - [26/Jan/2023:23:28:24 +0100] "POST /core/.env HTTP/1.1" 301 394 "-" "curl/7.64.0" 109.237.98.53 - - [26/Jan/2023:23:32:05 +0100] "-" 408 - "-" "-" 194.110.203.42 - - [26/Jan/2023:23:33:02 +0100] "GET /debug.zip HTTP/1.1" 301 395 "-" "Firefox" 35.233.62.116 - - [26/Jan/2023:23:45:57 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2" 194.110.203.42 - - [26/Jan/2023:23:48:04 +0100] "GET /web.env HTTP/1.1" 301 384 "-" "Firefox" 95.215.205.158 - - [26/Jan/2023:23:53:47 +0100] "POST /core/.env HTTP/1.1" 301 389 "-" "curl/7.64.0" 194.110.203.45 - - [26/Jan/2023:23:55:31 +0100] "GET /klub_release.zip HTTP/1.1" 301 402 "-" "Firefox" 152.89.196.211 - - [27/Jan/2023:00:13:31 +0100] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 95.215.205.158 - - [27/Jan/2023:00:13:58 +0100] "POST /core/.env HTTP/1.1" 301 386 "-" "curl/7.64.0" 193.118.55.146 - - [27/Jan/2023:00:14:32 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 185.180.143.136 - - [27/Jan/2023:00:45:00 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 193.118.53.210 - - [27/Jan/2023:00:52:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"