124.156.187.113 - - [14/Sep/2025:00:04:25 -0600] "HEAD /Core/Skin/Login.aspx HTTP/1.1" 404 140 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 136.143.176.60 - - [14/Sep/2025:00:06:41 -0600] "GET /PCI-test/trademarks.csv HTTP/1.1" 200 36737933 "-" "Zoho_Analytics" 104.197.69.115 - - [14/Sep/2025:00:13:58 -0600] "GET / HTTP/1.1" 200 7260 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/125.0.6422.60 Safari/537.36" 104.197.69.115 - - [14/Sep/2025:00:13:59 -0600] "GET /icons/ubuntu-logo.png HTTP/1.1" 200 3667 "https://3.22.251.217/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/125.0.6422.60 Safari/537.36" 165.227.128.59 - - [14/Sep/2025:00:17:12 -0600] "GET / HTTP/1.1" 200 3477 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0" 165.227.128.59 - - [14/Sep/2025:00:17:13 -0600] "GET /favicon.ico HTTP/1.1" 404 491 "http://3.22.251.217/" "Mozilla/5.0 (X11; Linux x86_64; rv:139.0) Gecko/20100101 Firefox/139.0" 45.43.33.218 - - [14/Sep/2025:00:18:13 -0600] "\x16\x03\x03\x01\xa5\x01" 400 488 "-" "-" 45.43.33.218 - - [14/Sep/2025:00:18:18 -0600] "GET / HTTP/1.1" 200 11192 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0" 141.145.148.117 - - [14/Sep/2025:00:21:09 -0600] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 486 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:12 -0600] "POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1" 400 486 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:13 -0600] "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 491 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:16 -0600] "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 200 11228 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:18 -0600] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:19 -0600] "GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:21 -0600] "GET /vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:23 -0600] "GET /vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:25 -0600] "GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:27 -0600] "GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:29 -0600] "GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:32 -0600] "GET /phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:34 -0600] "GET /phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:36 -0600] "GET /phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:38 -0600] "GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:40 -0600] "GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:42 -0600] "GET /lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:44 -0600] "GET /lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 490 "-" "libredtail-http" 141.145.148.117 - - [14/Sep/2025:00:21:47 -0600] "GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.phSep 14 00:09:01 ip-172-31-29-215 CRON[3715103]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 00:09:01 ip-172-31-29-215 CRON[3715103]: pam_unix(cron:session): session closed for user root Sep 14 00:17:01 ip-172-31-29-215 CRON[3715156]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 00:17:01 ip-172-31-29-215 CRON[3715156]: pam_unix(cron:session): session closed for user root Sep 14 00:20:01 ip-172-31-29-215 CRON[3715161]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 00:20:01 ip-172-31-29-215 CRON[3715161]: pam_unix(cron:session): session closed for user smmsp Sep 14 00:34:34 ip-172-31-29-215 sshd[3715190]: Connection closed by 216.180.246.185 port 57232 [preauth] Sep 14 00:39:01 ip-172-31-29-215 CRON[3715194]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 00:39:01 ip-172-31-29-215 CRON[3715194]: pam_unix(cron:session): session closed for user root Sep 14 00:40:01 ip-172-31-29-215 CRON[3715248]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 00:40:01 ip-172-31-29-215 CRON[3715248]: pam_unix(cron:session): session closed for user smmsp Sep 14 00:49:54 ip-172-31-29-215 sshd[3715284]: Connection closed by authenticating user root 77.90.185.67 port 54950 [preauth] Sep 14 01:00:01 ip-172-31-29-215 CRON[3715294]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 01:00:01 ip-172-31-29-215 CRON[3715294]: pam_unix(cron:session): session closed for user smmsp Sep 14 01:09:01 ip-172-31-29-215 CRON[3715322]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 01:09:01 ip-172-31-29-215 CRON[3715322]: pam_unix(cron:session): session closed for user root Sep 14 01:17:01 ip-172-31-29-215 CRON[3715375]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 01:17:01 ip-172-31-29-215 CRON[3715375]: pam_unix(cron:session): session closed for user root Sep 14 01:20:01 ip-172-31-29-215 CRON[3715381]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 01:20:01 ip-172-31-29-215 CRON[3715381]: pam_unix(cron:session): session closed for user smmsp Sep 14 01:39:01 ip-172-31-29-215 CRON[3715409]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 01:39:01 ip-172-31-29-215 CRON[3715409]: pam_unix(cron:session): session closed for user root Sep 14 01:40:01 ip-172-31-29-215 CRON[3715461]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 01:40:01 ip-172-31-29-215 CRON[3715461]: pam_unix(cron:session): session closed for user smmsp Sep 14 01:55:47 ip-172-31-29-215 sshd[3715494]: Invalid user aptuslegal from 77.90.185.67 port 50718 Sep 14 01:55:48 ip-172-31-29-215 sshd[3715494]: Connection closed by invalid user aptuslegal 77.90.185.67 port 50718 [preauth] Sep 14 02:00:01 ip-172-31-29-215 CRON[3715499]: pam_unix(cron:session): session opened for user smmsp by (uid=0) Sep 14 02:00:01 ip-172-31-29-215 CRON[3715499]: pam_unix(cron:session): session closed for user smmsp Sep 14 02:09:01 ip-172-31-29-215 CRON[3715526]: pam_unix(cron:session): session opened for user root by (uid=0) Sep 14 02:09:01 ip-172-31-29-215 CRON[3715526]: pam_unix(cron:session): session closed for user root Sep 14 02:12:50 ip-172-31-29-215 sshd[3715579]: error: maximum authentication attempts exceeded for root from 211.248.172.135 port 35950 ssh2 [preauth] Sep 14 02:12:50 ip-172-31-29-215 sshd[3715579]: Disconnecting authenticating user root 211.248.172.135 port 35950: Too many authentication failures [preauth] Sep 14 02:12:53 ip-172-31-29-215 sshd[3715582]: error: maximum authentication attempts exceeded for root from 211.248.172.135 port 36426 ssh2 [preauth] Sep 14 02:12:53 ip-172-31-29-215 sshd[3715582]: Disconnecting authenticating user root 211.248.172.135 port 36426: Too many authentication failures [preauth] Sep 14 02:12:55 ip-172-31-29-215 sshd[3715584]: error: maximum authentication attempts exceeded for root from 211.248.172.135 port 36866 ssh2 [preauth] Sep 14 02:12:55 ip-172-31-29-215 sshd[3715584]: Disconnecting authenticating user/Sep/2025:04:20:59 -0600] "GET /server-info.php HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 87.251.78.46 - - [14/Sep/2025:04:20:59 -0600] "GET /env.php HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 87.251.78.46 - - [14/Sep/2025:04:20:59 -0600] "GET /init.php HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" 81.17.24.163 - - [14/Sep/2025:04:32:19 -0600] "GET / HTTP/1.1" 200 3477 "-" "Mozilla/5.0" 124.156.187.113 - - [14/Sep/2025:04:46:55 -0600] "HEAD /Core/Skin/Login.aspx HTTP/1.1" 404 140 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36" 68.183.146.153 - - [14/Sep/2025:04:54:18 -0600] "GET /.git/config HTTP/1.1" 404 4185 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0.2 Safari/605.1.15" 3.131.215.38 - - [14/Sep/2025:04:56:40 -0600] "GET / HTTP/1.1" 200 3421 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126.0.0.0 Safari/537.36" 3.131.215.38 - - [14/Sep/2025:04:57:18 -0600] "GET / HTTP/1.1" 200 3421 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126.0.0.0 Safari/537.36" 3.131.215.38 - - [14/Sep/2025:04:58:29 -0600] "\x16\x03\x01" 400 488 "-" "-" 3.131.215.38 - - [14/Sep/2025:04:58:39 -0600] "\x16\x03\x01" 400 488 "-" "-" 170.106.65.93 - - [14/Sep/2025:05:00:10 -0600] "GET / HTTP/1.1" 200 3440 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1" 3.131.215.38 - - [14/Sep/2025:05:00:38 -0600] "\n" 400 488 "-" "-" 139.59.143.102 - - [14/Sep/2025:05:04:45 -0600] "\x16\x03\x01\x01\x06\x01" 400 488 "-" "-" 139.59.143.102 - - [14/Sep/2025:05:04:45 -0600] "GET / HTTP/1.1" 200 11192 "-" "-" 139.59.143.102 - - [14/Sep/2025:05:04:45 -0600] "GET / HTTP/1.1" 200 11192 "-" "Mozilla/5.0 (Linux; Android 6.0; HTC One M9 Build/MRA1347) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.5184.98 Mobile Safari/537.3" 139.59.143.102 - - [14/Sep/2025:05:04:45 -0600] "GET /@vite/env HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:46 -0600] "GET /actuator/env HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:46 -0600] "GET /server HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:46 -0600] "GET /.vscode/sftp.json HTTP/1.1" 200 521 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:47 -0600] "GET /about HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:47 -0600] "GET /debug/default/view?panel=config HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:47 -0600] "GET /v2/_catalog HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:47 -0600] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:48 -0600] "GET /server-status HTTP/1.1" 403 464 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:48 -0600] "GET /login.action HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:48 -0600] "GET /_all_dbs HTTP/1.1" 404 461 "-" "Mozilla/5.0 (l9scan/2.0.731323e2135323e22323e233; +https://leakix.net)" 139.59.143.102 - - [14/Sep/2025:05:04:48 -0600] "GET /.DS_Store HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:48 -0600] "GET /.env HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:49 -0600] "GET /.git/config HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.59.143.102 - - [14/Sep/2025:05:04:49 -0600] "GET /s/731323e2135323e22323e233/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1" 404 461 "-" "Go-http-client/1.1" 139.5 * Introducing Expanded Security Maintenance for Applications. Receive updates to over 25,000 software packages with your Ubuntu Pro subscription. Free for personal use. https://ubuntu.com/aws/pro