[07/Dec/2021:01:13:36 +0100] 130.211.54.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [07/Dec/2021:01:34:36 +0100] 52.26.228.143 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [07/Dec/2021:01:34:55 +0100] 54.218.100.94 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [07/Dec/2021:02:24:29 +0100] 159.89.176.239 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 380 [07/Dec/2021:03:08:28 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [07/Dec/2021:03:23:26 +0100] 192.241.213.154 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [07/Dec/2021:03:23:56 +0100] 71.6.232.7 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:03:37:21 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [07/Dec/2021:04:02:00 +0100] 192.241.209.190 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [07/Dec/2021:04:16:26 +0100] 193.118.53.194 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:04:43:48 +0100] 157.55.39.176 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 304 [07/Dec/2021:04:54:38 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [07/Dec/2021:04:55:12 +0100] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [07/Dec/2021:05:35:00 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [07/Dec/2021:06:18:03 +0100] 193.118.53.194 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:06:59:18 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [07/Dec/2021:07:35:51 +0100] 209.141.57.164 TLSv1.2 AES256-SHA "GET /swagger/v1/swagger.json HTTP/1.1" 314 [07/Dec/2021:08:56:12 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [07/Dec/2021:10:39:55 +0100] 188.214.125.151 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@1337.com/owa/?&Email=autodiscover/autodiscover.json%3F@1337.com HTTP/1.1" 350 [07/Dec/2021:11:47:59 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:11:51:53 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [07/Dec/2021:11:58:03 +0100] 23.251.102.74 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:12:08:36 +0100] 192.241.213.4 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [07/Dec/2021:12:19:25 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 293 [07/Dec/2021:12:49:38 +0100] 89.248.165.52 - - "-" - [07/Dec/2021:13:26:34 +0100] 45.155.205.233 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:14:06:22 +0100] 185.173.35.1 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 374 [07/Dec/2021:14:12:57 +0100] 167.94.138.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [07/Dec/2021:14:12:57 +0100] 167.94.138.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:14:31:40 +0100] 80.82.77.192 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:14:33:14 +0100] 40.77.167.98 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 311 [07/Dec/2021:14:33:15 +0100] 40.77.167.98 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 311 [07/Dec/2021:14:33:56 +0100] 207.46.13.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 304 [07/Dec/2021:14:56:23 +0100] 34.96.130.12 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [07/Dec/2021:16:13:20 +0100] 128.14.209.162 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:17:00:36 +0100] 34.96.130.10 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [07/Dec/2021:17:00:40 +0100] 193.118.53.194 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:17:32:32 +0100] 192.241.208.248 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:17:38:46 +0100] 34.96.130.13 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 391 [07/Dec/2021:17:42:22 +0100] 89.248.165.52 - - "-" - [07/Dec/2021:20:20:30 +0100] 199.249.230.163 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Dec/2021:20:20:49 +0100] 185.220.101.149 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [07/Dec/2021:20:22:32 +0100] 128.1.248.42 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [07/Dec/2021:20:37:13 +0100] 208.100.26.247 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [07/Dec/2021:22:26:51 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /dns-query HTTP/1.1" 392 [07/Dec/2021:22:26:52 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /dns-query?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 433 [07/Dec/2021:22:26:52 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 383 [07/Dec/2021:22:26:53 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 424 [07/Dec/2021:22:26:53 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /resolve HTTP/1.1" 390 [07/Dec/2021:22:26:54 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /resolve?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 431 [07/Dec/2021:22:26:55 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /doh HTTP/1.1" 386 [07/Dec/2021:22:26:55 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /doh?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 427 [07/Dec/2021:22:26:56 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /doh/family-filter HTTP/1.1" 400 [07/Dec/2021:22:26:57 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /doh/family-filter?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 441 [07/Dec/2021:22:26:57 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /doh/secure-filter HTTP/1.1" 400 [07/Dec/2021:22:26:58 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /doh/secure-filter?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 441 [07/Dec/2021:22:26:58 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /query HTTP/1.1" 388 [07/Dec/2021:22:26:59 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /query?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 429 [07/Dec/2021:22:27:00 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /ads HTTP/1.1" 386 [07/Dec/2021:22:27:00 +0100] 170.106.34.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /ads?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 427 [07/Dec/2021:22:27:29 +0100] 52.24.92.12 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [07/Dec/2021:22:28:07 +0100] 35.87.197.104 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [07/Dec/2021:22:28:10 +0100] 35.87.197.104 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [07/Dec/2021:22:40:10 +0100] 192.241.207.72 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [07/Dec/2021:22:41:26 +0100] 192.241.204.149 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [07/Dec/2021:22:42:04 +0100] 192.241.213.120 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [07/Dec/2021:23:49:13 +0100] 142.93.163.195 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 300 [08/Dec/2021:00:00:01 +0100] 172.105.161.246 TLSv1.2 DHE-RSA-AES256-SHA256 "GET /owa/ HTTP/1.1" 304 [08/Dec/2021:00:19:30 +0100] 192.241.208.136 TLSv1.2 AES256-SHA "GET /ReportServer HTTP/1.1" 307 [08/Dec/2021:00:35:27 +0100] 119.90.42.92 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Dec/2021:00:38:12 +0100] 192.241.214.92 TLSv1.2 AES256-SHA "GET /login HTTP/1.1" 305 [08/Dec/2021:00:42:03 +0100] 35.87.0.199 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [08/Dec/2021:00:42:28 +0100] 52.42.57.71 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306