[17/Nov/2021:01:33:11 +0100] 52.40.164.39 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [17/Nov/2021:01:33:29 +0100] 54.149.167.99 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [17/Nov/2021:01:33:32 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [17/Nov/2021:01:41:54 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [17/Nov/2021:01:53:14 +0100] 92.118.160.25 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 374 [17/Nov/2021:02:27:49 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [17/Nov/2021:03:15:28 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:03:27:44 +0100] 45.33.96.205 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [17/Nov/2021:03:41:04 +0100] 34.67.72.222 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [17/Nov/2021:03:41:05 +0100] 34.67.72.222 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [17/Nov/2021:03:47:25 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [17/Nov/2021:03:47:52 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [17/Nov/2021:03:47:54 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/hosts HTTP/1.1" 293 [17/Nov/2021:03:47:55 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET /.DS_Store HTTP/1.1" 307 [17/Nov/2021:03:47:55 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [17/Nov/2021:03:47:56 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [17/Nov/2021:03:47:56 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET /frontend_dev.php/$ HTTP/1.1" 314 [17/Nov/2021:03:47:56 +0100] 161.35.188.242 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:04:05:00 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:04:08:03 +0100] 194.67.205.181 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [17/Nov/2021:04:18:22 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393 [17/Nov/2021:04:45:27 +0100] 208.100.26.235 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 298 [17/Nov/2021:04:53:07 +0100] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [17/Nov/2021:04:59:30 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 293 [17/Nov/2021:05:18:28 +0100] 178.239.21.162 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [17/Nov/2021:05:27:23 +0100] 192.241.195.144 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [17/Nov/2021:06:34:48 +0100] 192.35.168.80 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:06:53:32 +0100] 193.106.29.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:08:06:33 +0100] 103.206.245.77 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [17/Nov/2021:08:19:07 +0100] 162.62.224.225 - - "-" - [17/Nov/2021:08:20:25 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "-" - [17/Nov/2021:08:20:25 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "-" - [17/Nov/2021:08:20:25 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:08:20:25 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:08:20:26 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:08:20:26 +0100] 162.62.224.225 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:08:53:00 +0100] 192.241.198.146 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [17/Nov/2021:09:15:45 +0100] 185.220.100.253 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:09:15:49 +0100] 185.220.101.36 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [17/Nov/2021:09:23:42 +0100] 190.212.140.11 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [17/Nov/2021:09:51:42 +0100] 180.149.125.169 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:10:36:04 +0100] 192.241.207.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:11:00:54 +0100] 139.162.207.84 TLSv1.2 DHE-RSA-AES256-SHA256 "GET /cgi-bin HTTP/1.1" 308 [17/Nov/2021:11:14:16 +0100] 74.82.47.2 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [17/Nov/2021:13:00:38 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [17/Nov/2021:13:48:31 +0100] 109.248.6.106 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.0" 399 [17/Nov/2021:14:23:01 +0100] 170.106.115.15 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [17/Nov/2021:14:28:10 +0100] 2.57.122.23 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:14:28:10 +0100] 2.57.122.23 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [17/Nov/2021:14:28:10 +0100] 2.57.122.23 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:14:28:10 +0100] 2.57.122.23 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [17/Nov/2021:15:24:08 +0100] 192.241.205.35 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [17/Nov/2021:15:24:21 +0100] 143.244.136.95 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.1" 379 [17/Nov/2021:15:26:50 +0100] 198.199.104.235 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [17/Nov/2021:15:27:06 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "-" - [17/Nov/2021:15:27:29 +0100] 192.241.198.208 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [17/Nov/2021:15:59:57 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [17/Nov/2021:16:18:26 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:16:18:28 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:16:18:34 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [17/Nov/2021:16:18:39 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:16:18:41 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:16:18:59 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [17/Nov/2021:16:19:01 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [17/Nov/2021:16:19:11 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [17/Nov/2021:16:19:19 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [17/Nov/2021:16:19:21 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [17/Nov/2021:16:19:31 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [17/Nov/2021:16:19:34 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [17/Nov/2021:16:19:36 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [17/Nov/2021:16:19:47 +0100] 111.7.96.179 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [17/Nov/2021:17:03:58 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [17/Nov/2021:17:54:17 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "-" - [17/Nov/2021:18:39:24 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [17/Nov/2021:19:00:53 +0100] 195.78.54.241 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "OPTIONS / HTTP/1.1" 301 [17/Nov/2021:19:30:00 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [17/Nov/2021:19:54:23 +0100] 66.249.73.239 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [17/Nov/2021:19:54:24 +0100] 66.249.73.235 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:20:37:37 +0100] 45.155.126.3 TLSv1.2 AES256-SHA "-" - [17/Nov/2021:20:50:45 +0100] 146.70.20.247 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:21:09:33 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [17/Nov/2021:22:12:09 +0100] 185.180.143.7 TLSv1.2 DHE-RSA-AES256-SHA256 "GET /owa/ HTTP/1.1" 304 [17/Nov/2021:22:39:53 +0100] 194.48.199.78 TLSv1.2 AES256-SHA "GET /servlets/com.adventnet.tools.sum.transport.SUMCommunicationServlet HTTP/1.1" 344 [17/Nov/2021:22:40:30 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Nov/2021:22:48:31 +0100] 137.226.113.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 308 [17/Nov/2021:22:58:14 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [17/Nov/2021:23:37:16 +0100] 162.142.125.42 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [17/Nov/2021:23:37:17 +0100] 162.142.125.42 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Nov/2021:00:05:26 +0100] 45.146.164.110 TLSv1.2 AES256-SHA "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 293 [18/Nov/2021:00:07:02 +0100] 40.77.167.95 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 311 [18/Nov/2021:00:07:03 +0100] 40.77.167.95 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 311 [18/Nov/2021:00:07:10 +0100] 40.77.167.68 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 304 [18/Nov/2021:00:10:33 +0100] 54.185.220.174 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [18/Nov/2021:00:15:24 +0100] 34.223.7.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [18/Nov/2021:00:15:55 +0100] 34.211.144.215 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313