[12/Jan/2021:01:15:49 +0100] 159.203.121.94 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [12/Jan/2021:01:15:54 +0100] 159.203.121.94 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 754 [12/Jan/2021:03:49:27 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [12/Jan/2021:03:49:27 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /api/jsonws/invoke HTTP/1.1" 314 [12/Jan/2021:03:49:31 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Jan/2021:03:49:31 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Jan/2021:03:49:35 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [12/Jan/2021:03:49:35 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [12/Jan/2021:03:49:35 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [12/Jan/2021:03:49:38 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1" 332 [12/Jan/2021:03:49:39 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [12/Jan/2021:04:50:06 +0100] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [12/Jan/2021:06:38:15 +0100] 122.228.19.79 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [12/Jan/2021:06:39:15 +0100] 122.228.19.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:06:39:32 +0100] 122.228.19.79 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [12/Jan/2021:07:15:00 +0100] 104.244.76.69 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "-" - [12/Jan/2021:07:35:05 +0100] 45.55.60.131 TLSv1.2 AES256-SHA "GET /.well-known/security.txt HTTP/1.1" 325 [12/Jan/2021:08:19:40 +0100] 192.241.204.198 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [12/Jan/2021:08:34:49 +0100] 193.118.53.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:08:35:01 +0100] 193.118.53.194 TLSv1.2 AES256-SHA "GET /webfig/ HTTP/1.1" 307 [12/Jan/2021:10:01:39 +0100] 34.90.154.162 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "OPTIONS / HTTP/1.0" 383 [12/Jan/2021:10:50:18 +0100] 83.97.20.29 TLSv1.2 AES256-SHA "-" - [12/Jan/2021:10:51:18 +0100] 83.97.20.29 - - "-" - [12/Jan/2021:10:52:04 +0100] 83.97.20.29 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 383 [12/Jan/2021:10:52:30 +0100] 83.97.20.29 TLSv1.2 AES256-SHA "GET /https://www.easydrivers.at/ HTTP/1.0" 415 [12/Jan/2021:10:53:05 +0100] 83.97.20.29 - - "-" - [12/Jan/2021:10:53:32 +0100] 83.97.20.29 TLSv1.2 AES256-SHA "GET /https://www.easydrivers.at/https://www.easydrivers.at/ HTTP/1.0" 442 [12/Jan/2021:10:54:01 +0100] 83.97.20.29 TLSv1.2 AES256-SHA "GET /https://www.easydrivers.at/https://www.easydrivers.at/https://www.easydrivers.at/ HTTP/1.0" 469 [12/Jan/2021:11:04:14 +0100] 35.227.170.115 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "OPTIONS / HTTP/1.0" 383 [12/Jan/2021:11:14:13 +0100] 51.158.98.24 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 386 [12/Jan/2021:12:10:29 +0100] 39.96.140.116 TLSv1.2 AES256-SHA "GET /dns-query?dns=AAABAAABAAAAAAAAA3d3dwViYWlkdQNjb20AAAEAAQ HTTP/1.1" 340 [12/Jan/2021:13:11:34 +0100] 128.14.134.170 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:13:16:11 +0100] 212.47.251.118 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [12/Jan/2021:14:02:58 +0100] 51.158.103.247 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 380 [12/Jan/2021:16:23:10 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Jan/2021:16:23:13 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Jan/2021:16:23:13 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /api/jsonws/invoke HTTP/1.1" 314 [12/Jan/2021:16:23:18 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [12/Jan/2021:16:23:22 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [12/Jan/2021:16:23:24 +0100] 45.155.205.108 TLSv1.2 AES256-SHA "GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1" 332 [12/Jan/2021:17:01:26 +0100] 179.60.150.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [12/Jan/2021:17:01:59 +0100] 179.60.150.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 394 [12/Jan/2021:17:02:05 +0100] 179.60.150.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 393 [12/Jan/2021:17:35:31 +0100] 51.158.98.24 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [12/Jan/2021:17:36:21 +0100] 198.20.124.218 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:17:58:07 +0100] 51.15.195.246 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 384 [12/Jan/2021:21:00:07 +0100] 80.82.65.80 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:21:51:02 +0100] 176.58.124.134 TLSv1.2 AES256-SHA "GET /index.html/bwY0GoD HTTP/1.1" 379 [12/Jan/2021:22:09:51 +0100] 193.118.53.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Jan/2021:22:14:22 +0100] 192.241.223.21 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [12/Jan/2021:23:09:24 +0100] 83.136.38.138 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [12/Jan/2021:23:26:51 +0100] 45.145.185.107 TLSv1.2 AES256-SHA "POST /web_shell_cmd.gch HTTP/1.1" 400 [12/Jan/2021:23:26:51 +0100] 45.145.185.107 TLSv1.2 AES256-SHA "POST /web_shell_cmd.gch HTTP/1.1" 400 [12/Jan/2021:23:26:52 +0100] 45.145.185.107 TLSv1.2 AES256-SHA "POST /web_shell_cmd.gch HTTP/1.1" 400