[20/Sep/2021:02:43:56 +0200] 54.71.17.222 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [20/Sep/2021:02:44:26 +0200] 34.209.153.241 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [20/Sep/2021:02:51:12 +0200] 193.118.53.210 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [20/Sep/2021:04:07:34 +0200] 192.241.209.88 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [20/Sep/2021:04:08:43 +0200] 192.241.213.28 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [20/Sep/2021:04:09:40 +0200] 192.241.221.192 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [20/Sep/2021:04:52:46 +0200] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [20/Sep/2021:04:57:56 +0200] 183.136.225.9 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [20/Sep/2021:04:58:19 +0200] 185.180.143.146 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 295 [20/Sep/2021:05:23:36 +0200] 35.84.28.3 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [20/Sep/2021:05:24:40 +0200] 80.82.77.192 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:05:32:18 +0200] 192.241.214.252 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [20/Sep/2021:06:16:19 +0200] 91.132.58.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [20/Sep/2021:06:55:37 +0200] 128.1.248.26 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [20/Sep/2021:07:08:22 +0200] 184.105.247.254 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [20/Sep/2021:07:31:19 +0200] 186.4.171.93 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [20/Sep/2021:08:04:31 +0200] 154.209.125.13 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [20/Sep/2021:08:05:11 +0200] 193.106.29.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:09:44:34 +0200] 193.107.216.145 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET //a2billing/customer/templates/default/footer.tpl HTTP/1.1" 333 [20/Sep/2021:10:05:45 +0200] 192.241.220.84 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:10:20:09 +0200] 124.126.78.131 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [20/Sep/2021:10:46:04 +0200] 207.46.13.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 304 [20/Sep/2021:11:55:29 +0200] 128.14.141.34 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [20/Sep/2021:14:28:00 +0200] 192.241.213.197 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [20/Sep/2021:15:20:09 +0200] 156.96.47.131 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [20/Sep/2021:15:32:26 +0200] 162.62.117.51 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [20/Sep/2021:16:19:45 +0200] 128.14.134.170 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [20/Sep/2021:18:01:46 +0200] 92.118.160.5 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 391 [20/Sep/2021:18:54:28 +0200] 52.39.252.10 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /owa/auth/logon.aspx HTTP/1.1" 402 [20/Sep/2021:19:07:47 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "POST /api/jsonws/invoke HTTP/1.1" 314 [20/Sep/2021:19:07:47 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [20/Sep/2021:19:07:49 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [20/Sep/2021:19:07:50 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /wp-content/plugins/wp-file-manager/readme.txt HTTP/1.1" 332 [20/Sep/2021:19:07:50 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [20/Sep/2021:19:07:50 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [20/Sep/2021:19:07:51 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [20/Sep/2021:19:07:53 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:19:07:55 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [20/Sep/2021:19:07:55 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [20/Sep/2021:19:07:56 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [20/Sep/2021:19:07:58 +0200] 45.146.164.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:19:29:40 +0200] 162.142.125.193 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [20/Sep/2021:19:29:41 +0200] 162.142.125.193 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [20/Sep/2021:20:11:18 +0200] 207.46.13.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 304 [20/Sep/2021:22:14:48 +0200] 128.1.248.26 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [20/Sep/2021:23:16:06 +0200] 51.158.103.247 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 384 [20/Sep/2021:23:22:00 +0200] 54.214.207.147 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [20/Sep/2021:23:22:29 +0200] 34.216.69.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [20/Sep/2021:23:28:32 +0200] 54.202.167.40 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [20/Sep/2021:23:28:45 +0200] 54.244.212.216 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [21/Sep/2021:00:28:57 +0200] 34.91.94.65 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Sep/2021:00:31:00 +0200] 51.15.251.143 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [21/Sep/2021:00:45:14 +0200] 51.158.108.61 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 392 [21/Sep/2021:01:22:02 +0200] 45.155.204.227 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /autodiscover/autodiscover.json?@evil.corp/ews/exchange.asmx?&Email=autodiscover/autodiscover.json%3F@evil.corp HTTP/1.1" 362 [21/Sep/2021:01:44:29 +0200] 34.217.14.131 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [21/Sep/2021:01:44:55 +0200] 54.71.12.148 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [21/Sep/2021:01:49:07 +0200] 192.241.213.192 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [21/Sep/2021:01:50:41 +0200] 148.72.169.224 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [21/Sep/2021:01:50:42 +0200] 148.72.169.224 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301