34.78.6.216 - - [24/Feb/2023:01:04:52 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2" 213.32.122.82 - - [24/Feb/2023:01:22:35 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 35.92.255.107 - - [24/Feb/2023:01:55:07 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.217.31.193 - - [24/Feb/2023:01:55:34 +0100] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.217.31.193 - - [24/Feb/2023:01:55:37 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:01:56:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 34.219.233.92 - - [24/Feb/2023:01:59:58 +0100] "GET /favicon.ico HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.214.124.92 - - [24/Feb/2023:02:05:39 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 51.15.195.246 - - [24/Feb/2023:02:17:28 +0100] "GET / HTTP/1.1" 301 391 "-" "-" 152.89.196.211 - - [24/Feb/2023:02:22:59 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 154.89.5.99 - - [24/Feb/2023:02:30:37 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 23.251.102.74 - - [24/Feb/2023:02:38:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:02:53:39 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 128.14.209.162 - - [24/Feb/2023:03:19:48 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.14.209.162 - - [24/Feb/2023:03:19:55 +0100] "GET /showLogin.cc HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 193.235.141.127 - - [24/Feb/2023:03:23:56 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:03:40:55 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.180.143.71 - - [24/Feb/2023:03:50:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 185.180.143.71 - - [24/Feb/2023:03:50:15 +0100] "HEAD /icons/sphere1.png HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:04:56:28 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.47 - - [24/Feb/2023:05:16:04 +0100] "GET /backup_03092022.zip HTTP/1.1" 301 413 "-" "Firefox" 152.89.196.211 - - [24/Feb/2023:05:16:45 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.46 - - [24/Feb/2023:05:26:52 +0100] "GET /backup_02092022.zip HTTP/1.1" 301 413 "-" "Firefox" 193.106.29.122 - - [24/Feb/2023:05:51:33 +0100] "GET / HTTP/1.0" 301 388 "-" "Mozilla/5.0" 194.110.203.38 - - [24/Feb/2023:05:56:13 +0100] "GET /backup_01092022.zip HTTP/1.1" 301 413 "-" "Firefox" 194.110.203.45 - - [24/Feb/2023:06:24:15 +0100] "GET /backup_31082022.zip HTTP/1.1" 301 413 "-" "Firefox" 152.89.196.211 - - [24/Feb/2023:06:27:46 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.46 - - [24/Feb/2023:06:34:40 +0100] "GET /backup_25082022.zip HTTP/1.1" 301 405 "-" "Firefox" 138.246.253.24 - - [24/Feb/2023:06:39:14 +0100] "GET /robots.txt HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 51.158.66.83 - - [24/Feb/2023:06:54:06 +0100] "GET / HTTP/1.1" 301 393 "-" "-" 152.89.196.211 - - [24/Feb/2023:06:58:54 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 172.104.11.46 - - [24/Feb/2023:07:44:33 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 64.145.93.143 - - [24/Feb/2023:07:45:14 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 64.145.93.143 - - [24/Feb/2023:07:45:15 +0100] "POST / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 193.118.55.162 - - [24/Feb/2023:08:04:44 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 192.241.237.15 - - [24/Feb/2023:09:05:32 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 208.100.26.244 - - [24/Feb/2023:09:49:05 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4112.0 Safari/537.36" 194.110.203.44 - - [24/Feb/2023:10:01:27 +0100] "GET /backup_24082022.zip HTTP/1.1" 301 413 "-" "Firefox" 4.184.57.28 - - [24/Feb/2023:10:07:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 152.89.196.211 - - [24/Feb/2023:10:36:51 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.79.165.199 - - [24/Feb/2023:10:59:44 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 152.89.196.211 - - [24/Feb/2023:11:19:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.41 - - [24/Feb/2023:11:24:11 +0100] "GET /backup_23082022.zip HTTP/1.1" 301 413 "-" "Firefox" 109.237.98.226 - - [24/Feb/2023:11:24:15 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:15 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:16 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:16 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:17 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:17 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:18 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:18 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:19 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:19 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:20 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:20 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:20 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:21 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:21 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:22 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:22 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:23 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:23 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:24 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:24 +0100] "GET /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:25 +0100] "POST /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:25 +0100] "GET /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:26 +0100] "POST /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:26 +0100] "GET /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [24/Feb/2023:11:24:27 +0100] "POST /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 198.20.87.98 - - [24/Feb/2023:12:30:17 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36" 198.20.87.98 - - [24/Feb/2023:12:30:34 +0100] "" 400 379 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:36 +0100] "" 400 379 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:37 +0100] "" 400 379 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:41 +0100] "quit" 400 379 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:42 +0100] "GET /robots.txt HTTP/1.1" 301 393 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:45 +0100] "GET /sitemap.xml HTTP/1.1" 301 394 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:46 +0100] "GET /.well-known/security.txt HTTP/1.1" 301 407 "-" "-" 198.20.87.98 - - [24/Feb/2023:12:30:48 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0" 198.20.87.98 - - [24/Feb/2023:12:30:52 +0100] "" 400 379 "-" "-" 178.79.157.193 - - [24/Feb/2023:13:02:10 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" 64.62.197.78 - - [24/Feb/2023:13:05:29 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.5112.102 Safari/537.36 OPR/90.0.4480.100" 64.62.197.82 - - [24/Feb/2023:13:12:09 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36 Edg/105.0.1343.33" 64.62.197.91 - - [24/Feb/2023:13:15:17 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 154.22.125.166 - - [24/Feb/2023:13:15:34 +0100] "POST /Public/admin/webuploader/server/preview.php HTTP/1.1" 301 335 "-" "Mozilla/5.0 AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0" 64.62.197.83 - - [24/Feb/2023:13:16:13 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36 Edg/105.0.1343.42" 193.235.141.23 - - [24/Feb/2023:13:47:59 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 194.110.203.44 - - [24/Feb/2023:13:54:58 +0100] "GET /backup_21082022.zip HTTP/1.1" 301 405 "-" "Firefox" 152.89.196.211 - - [24/Feb/2023:14:20:28 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 174.138.60.188 - - [24/Feb/2023:14:27:19 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 174.138.60.188 - - [24/Feb/2023:14:27:20 +0100] "GET / HTTP/1.1" 500 754 "https://86.59.113.102/" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 174.138.60.188 - - [24/Feb/2023:14:27:22 +0100] "GET /favicon.ico HTTP/1.1" 200 1150 "https://www.easydrivers.at/" "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" 51.158.98.24 - - [24/Feb/2023:14:44:01 +0100] "GET / HTTP/1.1" 301 386 "-" "-" 64.227.41.39 - - [24/Feb/2023:15:03:56 +0100] "GET /aaa9 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 64.227.41.39 - - [24/Feb/2023:15:03:56 +0100] "GET /aab8 HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 109.237.97.180 - - [24/Feb/2023:15:51:15 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:15 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:16 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:16 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:17 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:17 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:18 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:18 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:18 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:19 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:19 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:20 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:20 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:21 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:21 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:22 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:22 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:23 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:23 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:24 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:24 +0100] "GET /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:25 +0100] "POST /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:25 +0100] "GET /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:26 +0100] "POST /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:26 +0100] "GET /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.97.180 - - [24/Feb/2023:15:51:27 +0100] "POST /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 180.149.125.163 - - [24/Feb/2023:17:09:16 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" 198.199.94.56 - - [24/Feb/2023:17:12:09 +0100] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 194.110.203.38 - - [24/Feb/2023:17:30:29 +0100] "GET /backup_20082022.zip HTTP/1.1" 301 396 "-" "Firefox" 167.248.133.42 - - [24/Feb/2023:17:50:52 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.248.133.42 - - [24/Feb/2023:17:50:53 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.248.133.42 - - [24/Feb/2023:17:50:53 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 167.94.138.62 - - [24/Feb/2023:18:14:38 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.138.62 - - [24/Feb/2023:18:14:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.138.62 - - [24/Feb/2023:18:14:39 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 128.14.209.162 - - [24/Feb/2023:18:57:30 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 128.199.47.108 - - [24/Feb/2023:19:05:48 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 128.199.47.108 - - [24/Feb/2023:19:05:48 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 128.199.47.108 - - [24/Feb/2023:19:05:50 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 128.199.47.108 - - [24/Feb/2023:19:05:50 +0100] "GET /t4 HTTP/1.1" 301 302 "-" "Mozilla/5.0" 80.66.66.131 - - [24/Feb/2023:19:26:40 +0100] "GET /api/v2/cmdb/system/admin HTTP/1.1" 301 318 "-" "Report Runner" 138.246.253.24 - - [24/Feb/2023:19:38:55 +0100] "GET /robots.txt HTTP/1.1" 301 403 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 192.241.210.25 - - [24/Feb/2023:20:20:41 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 194.163.154.32 - - [24/Feb/2023:21:21:12 +0100] "GET /.env HTTP/1.1" 301 298 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.83.1.el7.x86_64" 194.163.154.32 - - [24/Feb/2023:21:21:13 +0100] "POST / HTTP/1.1" 301 295 "-" "url" 194.163.154.32 - - [24/Feb/2023:21:21:14 +0100] "POST /core/.env HTTP/1.1" 301 301 "-" "url" 194.163.154.32 - - [24/Feb/2023:21:21:15 +0100] "GET /core/.env HTTP/1.1" 301 301 "-" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.83.1.el7.x86_64" 194.163.154.32 - - [24/Feb/2023:21:21:16 +0100] "POST / HTTP/1.1" 301 295 "-" "url" 194.163.154.32 - - [24/Feb/2023:21:21:17 +0100] "POST /core/.env HTTP/1.1" 301 301 "-" "url" 194.110.203.41 - - [24/Feb/2023:21:43:54 +0100] "GET /backup_18082022.zip HTTP/1.1" 301 405 "-" "Firefox" 162.142.125.8 - - [24/Feb/2023:21:57:35 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.8 - - [24/Feb/2023:21:57:36 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.8 - - [24/Feb/2023:21:57:36 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 60.217.75.70 - - [24/Feb/2023:22:29:39 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 194.110.203.45 - - [24/Feb/2023:22:34:31 +0100] "GET /backup_17082022.zip HTTP/1.1" 301 396 "-" "Firefox" 40.77.167.184 - - [24/Feb/2023:23:09:28 +0100] "GET /robots.txt HTTP/1.1" 301 315 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 40.77.167.184 - - [24/Feb/2023:23:09:29 +0100] "GET /robots.txt HTTP/1.1" 301 315 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 157.55.39.218 - - [24/Feb/2023:23:09:41 +0100] "GET / HTTP/1.1" 301 308 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/103.0.5060.134 Safari/537.36" 170.64.133.118 - - [24/Feb/2023:23:14:00 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:23:23:08 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:23:32:24 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 183.136.225.9 - - [24/Feb/2023:23:33:25 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 183.136.225.9 - - [24/Feb/2023:23:34:32 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 152.89.196.211 - - [24/Feb/2023:23:34:38 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 183.136.225.9 - - [24/Feb/2023:23:34:57 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 106.75.165.117 - - [24/Feb/2023:23:39:04 +0100] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 106.75.165.117 - - [24/Feb/2023:23:39:05 +0100] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 106.75.165.117 - - [24/Feb/2023:23:39:06 +0100] "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 400 379 "-" "-" 106.75.165.117 - - [24/Feb/2023:23:39:07 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 400 379 "-" "-" 106.75.165.117 - - [24/Feb/2023:23:39:09 +0100] "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 400 379 "-" "-" 106.75.165.117 - - [24/Feb/2023:23:39:10 +0100] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 400 379 "-" "-" 208.100.26.243 - - [24/Feb/2023:23:43:18 +0100] "GET / HTTP/1.1" 301 297 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4216.0 Safari/537.36 Edg/86.0.598.0" 208.100.26.235 - - [24/Feb/2023:23:43:18 +0100] "GET / HTTP/1.1" 301 298 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.143 Safari/537.36" 152.89.196.211 - - [24/Feb/2023:23:54:36 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.47 - - [25/Feb/2023:00:18:30 +0100] "GET /backup_17082022.zip HTTP/1.1" 301 405 "-" "Firefox" 152.89.196.211 - - [25/Feb/2023:00:22:39 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 18.236.167.99 - - [25/Feb/2023:00:37:59 +0100] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 34.215.93.85 - - [25/Feb/2023:00:38:31 +0100] "GET /favicon.ico HTTP/1.1" 301 313 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 152.89.196.211 - - [25/Feb/2023:00:45:51 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 165.22.225.219 - - [25/Feb/2023:00:48:24 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 165.22.225.219 - - [25/Feb/2023:00:48:26 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 165.22.225.219 - - [25/Feb/2023:00:48:30 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 165.22.225.219 - - [25/Feb/2023:00:48:31 +0100] "GET /t4 HTTP/1.1" 301 302 "-" "Mozilla/5.0" 35.195.93.98 - - [25/Feb/2023:00:57:02 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2"