193.235.141.17 - - [07/Mar/2023:01:12:10 +0100] "GET / HTTP/1.1" 301 295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 176.97.204.190 - - [07/Mar/2023:01:12:23 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 217.198.178.168 - - [07/Mar/2023:01:12:23 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 45.139.54.78 - - [07/Mar/2023:01:12:24 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 185.209.50.32 - - [07/Mar/2023:01:12:24 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 212.193.136.240 - - [07/Mar/2023:01:12:26 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 194.104.237.124 - - [07/Mar/2023:01:12:29 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 77.90.152.95 - - [07/Mar/2023:01:12:30 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 77.90.180.128 - - [07/Mar/2023:01:12:31 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 91.232.10.201 - - [07/Mar/2023:01:12:32 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 91.232.11.253 - - [07/Mar/2023:01:12:32 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 193.160.72.50 - - [07/Mar/2023:01:12:33 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 62.3.23.99 - - [07/Mar/2023:01:12:33 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 92.249.13.181 - - [07/Mar/2023:01:12:34 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 185.100.158.205 - - [07/Mar/2023:01:12:34 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 77.91.117.237 - - [07/Mar/2023:01:12:35 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 154.7.216.168 - - [07/Mar/2023:01:12:35 +0100] "GET /owa/ HTTP/1.0" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.80 Safari/537.36" 198.199.92.121 - - [07/Mar/2023:01:26:47 +0100] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 198.199.117.207 - - [07/Mar/2023:01:32:24 +0100] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 198.199.97.240 - - [07/Mar/2023:01:33:15 +0100] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 109.237.98.226 - - [07/Mar/2023:01:37:10 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:10 +0100] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:10 +0100] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:11 +0100] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:11 +0100] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:12 +0100] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:12 +0100] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:13 +0100] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:13 +0100] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:14 +0100] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:14 +0100] "GET /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:15 +0100] "POST /test.php HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:15 +0100] "GET /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:16 +0100] "POST /laravel/.env HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:16 +0100] "GET /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:17 +0100] "POST /demo/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:17 +0100] "GET /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:18 +0100] "POST /web/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:18 +0100] "GET /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:19 +0100] "POST /phpinfo HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:19 +0100] "GET /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:20 +0100] "POST /admin/.env HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:20 +0100] "GET /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:20 +0100] "POST /backend/.env HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:21 +0100] "GET /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [07/Mar/2023:01:37:21 +0100] "POST /app/.env HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 128.14.134.170 - - [07/Mar/2023:01:39:08 +0100] "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 301 330 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 162.142.125.213 - - [07/Mar/2023:02:26:44 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 162.142.125.213 - - [07/Mar/2023:02:26:44 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.213 - - [07/Mar/2023:02:26:45 +0100] "PRI * HTTP/2.0" 400 379 "-" "-" 185.220.101.86 - - [07/Mar/2023:02:39:57 +0100] "GET /spog/welcome HTTP/1.1" 301 309 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 185.220.101.86 - - [07/Mar/2023:02:39:58 +0100] "GET /cgi-bin/welcome HTTP/1.1" 301 313 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 14_4_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Mobile/15E148 Safari/604.1" 128.1.248.42 - - [07/Mar/2023:04:20:01 +0100] "GET /remote/login HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 194.110.203.45 - - [07/Mar/2023:04:42:21 +0100] "GET /backup_05042022.zip HTTP/1.1" 301 405 "-" "Firefox" 107.155.60.8 - - [07/Mar/2023:04:45:27 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 107.155.60.8 - - [07/Mar/2023:04:45:28 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 107.155.60.8 - - [07/Mar/2023:04:45:30 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Go-http-client/1.1" 107.155.60.8 - - [07/Mar/2023:04:45:31 +0100] "GET /sitemap.xml HTTP/1.1" 301 309 "-" "Go-http-client/1.1" 194.110.203.44 - - [07/Mar/2023:05:33:57 +0100] "GET /backup_05042022.zip HTTP/1.1" 301 396 "-" "Firefox" 128.1.248.26 - - [07/Mar/2023:06:21:45 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 4.184.57.28 - - [07/Mar/2023:07:29:07 +0100] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 194.110.203.47 - - [07/Mar/2023:07:48:11 +0100] "GET /backup_03042022.zip HTTP/1.1" 301 396 "-" "Firefox" 162.243.146.32 - - [07/Mar/2023:08:01:31 +0100] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [07/Mar/2023:08:07:53 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.40 - - [07/Mar/2023:08:27:11 +0100] "GET /backup_03042022.zip HTTP/1.1" 301 413 "-" "Firefox" 152.89.196.211 - - [07/Mar/2023:08:56:47 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:09:11:58 +0100] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 107.170.226.7 - - [07/Mar/2023:09:53:57 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [07/Mar/2023:09:53:57 +0100] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:10:05:25 +0100] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:10:46:43 +0100] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:11:33:39 +0100] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:11:43:22 +0100] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 43.158.217.52 - - [07/Mar/2023:12:24:27 +0100] "GET / HTTP/1.1" 301 301 "-" "'Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0'" 43.158.217.52 - - [07/Mar/2023:12:24:51 +0100] "-" 408 - "-" "-" 205.210.31.46 - - [07/Mar/2023:12:29:21 +0100] "GET / HTTP/1.1" 301 394 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 152.89.196.211 - - [07/Mar/2023:12:39:19 +0100] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 143.198.84.224 - - [07/Mar/2023:13:00:46 +0100] "GET /ab2g HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 143.198.84.224 - - [07/Mar/2023:13:00:50 +0100] "GET /ab2h HTTP/1.1" 301 304 "-" "Mozilla/5.0 zgrab/0.x" 143.198.84.224 - - [07/Mar/2023:13:01:04 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:13:10:46 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:13:41:40 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:14:17:00 +0100] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 194.110.203.46 - - [07/Mar/2023:14:52:49 +0100] "GET /backup_29032022.zip HTTP/1.1" 301 413 "-" "Firefox" 194.110.203.40 - - [07/Mar/2023:14:53:12 +0100] "GET /backup_30032022.zip HTTP/1.1" 301 396 "-" "Firefox" 216.218.206.66 - - [07/Mar/2023:15:02:34 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0" 216.218.206.66 - - [07/Mar/2023:15:09:49 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 216.218.206.66 - - [07/Mar/2023:15:14:30 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 Edg/109.0.1518.70" 216.218.206.66 - - [07/Mar/2023:15:16:04 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 183.136.225.32 - - [07/Mar/2023:15:36:17 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 47.88.5.56 - - [07/Mar/2023:15:40:59 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; Android 11; M2004J15SC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36" 47.254.25.10 - - [07/Mar/2023:15:41:33 +0100] "GET /Public/home/js/check.js HTTP/1.1" 301 316 "-" "Mozilla/5.0 (Linux; Android 11; M2004J15SC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36" 47.88.93.234 - - [07/Mar/2023:15:41:35 +0100] "GET /static/admin/javascript/hetong.js HTTP/1.1" 301 325 "-" "Mozilla/5.0 (Linux; Android 11; M2004J15SC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Mobile Safari/537.36" 183.136.225.32 - - [07/Mar/2023:15:43:34 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.39 - - [07/Mar/2023:16:04:57 +0100] "GET /backup_29032022.zip HTTP/1.1" 301 396 "-" "Firefox" 167.172.36.104 - - [07/Mar/2023:16:40:12 +0100] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36" 205.210.31.129 - - [07/Mar/2023:16:48:37 +0100] "GET / HTTP/1.1" 301 383 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 194.110.203.45 - - [07/Mar/2023:17:07:04 +0100] "GET /backup_28032022.zip HTTP/1.1" 301 413 "-" "Firefox" 152.89.196.211 - - [07/Mar/2023:17:20:01 +0100] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [07/Mar/2023:18:05:26 +0100] "GET /geoserver HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:03 +0100] "GET /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:04 +0100] "POST /.env HTTP/1.1" 301 298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:05 +0100] "GET /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:06 +0100] "POST /.aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:06 +0100] "GET /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:07 +0100] "POST /.aws/config HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:08 +0100] "GET /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:08 +0100] "POST /aws/credentials HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:09 +0100] "GET /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:10 +0100] "POST /credentials HTTP/1.1" 301 302 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:10 +0100] "GET /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:11 +0100] "POST /test.php HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:12 +0100] "GET /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:13 +0100] "POST /laravel/.env HTTP/1.1" 301 303 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:13 +0100] "GET /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:14 +0100] "POST /demo/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:15 +0100] "GET /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:15 +0100] "POST /web/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:16 +0100] "GET /phpinfo HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:16 +0100] "POST /phpinfo HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:17 +0100] "GET /admin/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:17 +0100] "POST /admin/.env HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:18 +0100] "GET /backend/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:18 +0100] "POST /backend/.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:19 +0100] "GET /app/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.53 - - [07/Mar/2023:18:21:19 +0100] "POST /app/.env HTTP/1.1" 301 300 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 154.209.125.10 - - [07/Mar/2023:18:35:19 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 154.209.125.77 - - [07/Mar/2023:18:35:23 +0100] "GET /robots.txt HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 194.110.203.42 - - [07/Mar/2023:18:45:28 +0100] "GET /backup_27032022.zip HTTP/1.1" 301 413 "-" "Firefox" 3.249.1.125 - - [07/Mar/2023:18:55:59 +0100] "GET / HTTP/1.0" 301 380 "-" "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" 194.110.203.40 - - [07/Mar/2023:19:08:03 +0100] "GET /backup_27032022.zip HTTP/1.1" 301 405 "-" "Firefox" 51.158.237.126 - - [07/Mar/2023:19:31:12 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 51.158.237.126 - - [07/Mar/2023:19:31:13 +0100] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:104.0) Gecko/20100101 Firefox/104.0" 154.89.5.208 - - [07/Mar/2023:19:38:41 +0100] "GET / HTTP/1.1" 301 383 "-" "-" 194.110.203.42 - - [07/Mar/2023:19:57:46 +0100] "GET /backup_26032022.zip HTTP/1.1" 301 413 "-" "Firefox" 46.101.73.109 - - [07/Mar/2023:20:50:34 +0100] "HEAD / HTTP/1.1" 301 - "https://www.bing.com" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36 Mozilla/5.0 (iPad; U; CPU OS 3_2 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B334b Safari/531.21.10" 34.171.92.253 - - [07/Mar/2023:23:15:11 +0100] "OPTIONS / HTTP/1.0" 301 383 "-" "-" 35.216.225.215 - - [07/Mar/2023:23:18:13 +0100] "GET / HTTP/1.1" 400 379 "-" "-" 35.216.225.215 - - [07/Mar/2023:23:18:16 +0100] "GET / HTTP/1.1" 301 383 "-" "l9tcpid/v1.1.0" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /config.json HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /telescope/requests HTTP/1.1" 301 311 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /info.php HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 35.216.225.215 - - [07/Mar/2023:23:18:17 +0100] "GET /server-status HTTP/1.1" 301 308 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:103.0) Gecko/20100101 Firefox/103.0 abuse.xmco.fr" 134.122.184.20 - - [08/Mar/2023:00:30:06 +0100] "GET /a/73039.html HTTP/1.1" 301 396 "/a/73039.html" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 13.71.128.118 - - [08/Mar/2023:00:34:53 +0100] "GET / HTTP/1.1" 301 383 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.98 Safari/537.36" 194.110.203.42 - - [08/Mar/2023:00:48:37 +0100] "GET /backup_23032022.zip HTTP/1.1" 301 413 "-" "Firefox" 34.78.6.216 - - [08/Mar/2023:00:53:12 +0100] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2"