83.136.32.58 - - [20/Apr/2023:02:25:13 +0200] "HEAD / HTTP/1.0" 301 - "https://cert.at/de/services/statistic-survey/" "CERT.at-Statistics-Survey/1.0 (+http://www.cert.at/about/consec/content.html)" 185.180.143.49 - - [20/Apr/2023:02:25:19 +0200] "GET /sugar_version.json HTTP/1.1" 301 313 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 54.39.49.180 - - [20/Apr/2023:03:38:55 +0200] "GET /.env HTTP/1.1" 301 387 "-" "Mozilla/5.0 (X11; Linux x86_64)" 137.175.51.108 - - [20/Apr/2023:03:55:05 +0200] "GET /.ftpconfig HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36" 192.241.216.8 - - [20/Apr/2023:04:47:48 +0200] "GET /ReportServer HTTP/1.1" 301 307 "-" "Mozilla/5.0 zgrab/0.x" 107.170.231.10 - - [20/Apr/2023:05:52:03 +0200] "GET /login HTTP/1.1" 301 305 "-" "Mozilla/5.0 zgrab/0.x" 162.243.142.27 - - [20/Apr/2023:06:13:18 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.54 - - [20/Apr/2023:06:51:19 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.54 - - [20/Apr/2023:06:57:38 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.54 - - [20/Apr/2023:07:05:46 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.54 - - [20/Apr/2023:07:16:28 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 106.75.147.108 - - [20/Apr/2023:08:21:27 +0200] "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 400 379 "-" "-" 106.75.147.108 - - [20/Apr/2023:08:21:28 +0200] "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 400 379 "-" "-" 106.75.147.108 - - [20/Apr/2023:08:21:30 +0200] "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 400 379 "-" "-" 106.75.147.108 - - [20/Apr/2023:08:21:31 +0200] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 400 379 "-" "-" 106.75.147.108 - - [20/Apr/2023:08:21:32 +0200] "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 400 379 "-" "-" 106.75.147.108 - - [20/Apr/2023:08:21:33 +0200] "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 400 379 "-" "-" 152.89.196.211 - - [20/Apr/2023:09:31:21 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 301 327 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:09:53:21 +0200] "POST /mifs/.;/services/LogService HTTP/1.1" 301 318 "https://86.59.113.102:443" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:09:59:59 +0200] "GET /console/ HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:10:07:14 +0200] "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 4.184.57.28 - - [20/Apr/2023:10:09:32 +0200] "GET / HTTP/1.1" 301 301 "-" "Python/3.10 aiohttp/3.8.3" 152.89.196.211 - - [20/Apr/2023:10:20:03 +0200] "GET /_ignition/execute-solution HTTP/1.1" 301 319 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:10:31:47 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:10:44:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:11:07:24 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 104.249.27.146 - - [20/Apr/2023:11:33:51 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:59.0) Gecko/20100101 Firefox/59.0" 152.89.196.211 - - [20/Apr/2023:11:46:05 +0200] "GET /actuator/gateway/routes HTTP/1.1" 301 315 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:11:54:37 +0200] "GET /geoserver HTTP/1.1" 301 305 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 103.43.19.95 - - [20/Apr/2023:12:42:34 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Linux; Android 6.0; HTC One M9 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.98 Mobile Safari/537.36" 45.130.153.170 - - [20/Apr/2023:12:43:13 +0200] "GET /_profiler/phpinfo HTTP/1.1" 301 313 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 45.130.153.170 - - [20/Apr/2023:12:43:13 +0200] "GET /debug/default/view?panel=config HTTP/1.1" 301 325 "-" "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" 64.62.197.210 - - [20/Apr/2023:13:20:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.36" 64.62.197.198 - - [20/Apr/2023:13:26:42 +0200] "GET /favicon.ico HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36 OPR/95.0.0.0 (Edition Yx 05)" 20.100.168.244 - - [20/Apr/2023:13:27:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Python/3.8 aiohttp/3.8.4" 64.62.197.201 - - [20/Apr/2023:13:28:33 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 193.235.141.17 - - [20/Apr/2023:13:29:25 +0200] "GET / HTTP/1.1" 301 307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 64.62.197.203 - - [20/Apr/2023:13:29:49 +0200] "GET /geoserver/web/ HTTP/1.1" 301 309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.2 Safari/605.1.15" 64.62.197.205 - - [20/Apr/2023:13:30:02 +0200] "GET /.git/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0" 20.231.70.220 - - [20/Apr/2023:14:57:28 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.24.0" 20.231.70.220 - - [20/Apr/2023:14:57:28 +0200] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.24.0" 87.236.176.87 - - [20/Apr/2023:15:52:49 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)" 20.231.70.220 - - [20/Apr/2023:17:41:06 +0200] "GET /.env HTTP/1.1" 301 304 "-" "python-httpx/0.24.0" 20.231.70.220 - - [20/Apr/2023:17:41:07 +0200] "POST / HTTP/1.1" 301 301 "-" "python-httpx/0.24.0" 193.118.53.210 - - [20/Apr/2023:17:45:08 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 138.246.253.24 - - [20/Apr/2023:18:03:10 +0200] "GET /robots.txt HTTP/1.1" 301 404 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:20 +0200] "GET /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:21 +0200] "POST /.env HTTP/1.1" 301 304 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:21 +0200] "GET /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:22 +0200] "POST /.aws/credentials HTTP/1.1" 301 311 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:22 +0200] "GET /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:23 +0200] "POST /.aws/config HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:23 +0200] "GET /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:24 +0200] "POST /aws/credentials HTTP/1.1" 301 310 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:24 +0200] "GET /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 109.237.98.226 - - [20/Apr/2023:19:56:24 +0200] "POST /credentials HTTP/1.1" 301 308 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 113.31.104.11 - - [20/Apr/2023:19:58:45 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.146.59 - - [20/Apr/2023:20:20:46 +0200] "GET / HTTP/1.1" 301 383 "-" "-" 167.94.146.59 - - [20/Apr/2023:20:20:46 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.146.59 - - [20/Apr/2023:20:20:46 +0200] "PRI * HTTP/2.0" 400 379 "-" "-" 185.224.128.112 - - [20/Apr/2023:20:25:54 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" 193.118.53.194 - - [20/Apr/2023:21:28:49 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 193.235.141.134 - - [20/Apr/2023:22:37:35 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36" 198.199.92.121 - - [20/Apr/2023:22:49:54 +0200] "GET /owa/auth/logon.aspx HTTP/1.1" 301 314 "-" "Mozilla/5.0 zgrab/0.x" 138.246.253.24 - - [20/Apr/2023:22:52:38 +0200] "GET /robots.txt HTTP/1.1" 301 387 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.134 Safari/537.36" 172.104.11.34 - - [20/Apr/2023:22:54:57 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 198.199.111.75 - - [20/Apr/2023:22:58:37 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 301 348 "-" "Mozilla/5.0 zgrab/0.x" 107.170.192.15 - - [20/Apr/2023:23:01:29 +0200] "GET /owa/auth/x.js HTTP/1.1" 301 310 "-" "Mozilla/5.0 zgrab/0.x" 152.89.196.211 - - [20/Apr/2023:23:06:52 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:23:13:38 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:23:20:35 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 152.89.196.211 - - [20/Apr/2023:23:32:23 +0200] "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 107.170.241.13 - - [21/Apr/2023:00:04:58 +0200] "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 301 335 "-" "Mozilla/5.0 zgrab/0.x" 60.217.75.70 - - [21/Apr/2023:00:18:37 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0" 192.241.210.25 - - [21/Apr/2023:00:58:10 +0200] "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 301 328 "-" "Mozilla/5.0 zgrab/0.x" 35.187.98.121 - - [21/Apr/2023:01:02:36 +0200] "GET / HTTP/1.1" 301 301 "-" "python-requests/2.28.2" 162.221.192.26 - - [21/Apr/2023:01:07:16 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 34.221.5.62 - - [21/Apr/2023:01:16:09 +0200] "GET / HTTP/1.1" 301 306 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36" 60.217.75.70 - - [21/Apr/2023:01:20:40 +0200] "GET / HTTP/1.1" 301 301 "-" "Mozilla/5.0"