[10/Jun/2022:02:19:42 +0200] 193.118.53.202 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:03:23:57 +0200] 208.100.26.247 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [10/Jun/2022:03:45:24 +0200] 192.241.223.12 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [10/Jun/2022:04:15:21 +0200] 192.241.214.40 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Jun/2022:04:55:02 +0200] 131.220.6.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [10/Jun/2022:04:55:31 +0200] 178.79.160.80 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [10/Jun/2022:06:15:05 +0200] 40.77.167.104 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [10/Jun/2022:06:15:06 +0200] 40.77.167.104 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [10/Jun/2022:06:15:14 +0200] 157.55.39.125 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [10/Jun/2022:06:28:14 +0200] 45.141.157.242 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Jun/2022:06:28:14 +0200] 45.141.157.242 TLSv1.2 AES256-SHA "GET /Public/home/js/check.js HTTP/1.1" 316 [10/Jun/2022:06:44:40 +0200] 130.211.54.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [10/Jun/2022:07:04:46 +0200] 64.62.197.92 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [10/Jun/2022:07:37:25 +0200] 54.205.26.87 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [10/Jun/2022:08:13:45 +0200] 198.235.24.128 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [10/Jun/2022:09:35:41 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /?rest_route=/wp/v2/users/ HTTP/1.1" 317 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /telescope/requests HTTP/1.1" 311 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /info.php HTTP/1.1" 307 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /.env HTTP/1.1" 304 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /s/38362e35392e3131332e313032/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1" 366 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /server-status HTTP/1.1" 308 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /.DS_Store HTTP/1.1" 307 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /login.action HTTP/1.1" 311 [10/Jun/2022:09:35:42 +0200] 194.233.167.79 TLSv1.2 AES256-SHA "GET /config.json HTTP/1.1" 311 [10/Jun/2022:10:54:37 +0200] 185.173.35.25 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [10/Jun/2022:11:09:45 +0200] 128.14.209.162 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:11:28:45 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 379 [10/Jun/2022:11:28:49 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 379 [10/Jun/2022:11:28:53 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 379 [10/Jun/2022:11:28:55 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 379 [10/Jun/2022:11:28:57 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 379 [10/Jun/2022:11:29:00 +0200] 119.90.42.93 TLSv1.2 AES256-SHA "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 379 [10/Jun/2022:12:44:20 +0200] 54.36.149.17 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 315 [10/Jun/2022:12:44:21 +0200] 54.36.148.65 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 308 [10/Jun/2022:13:12:11 +0200] 192.241.214.157 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [10/Jun/2022:13:13:28 +0200] 192.241.219.237 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [10/Jun/2022:13:14:09 +0200] 192.241.220.248 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [10/Jun/2022:15:13:14 +0200] 128.1.248.42 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:16:19:01 +0200] 157.55.39.125 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [10/Jun/2022:17:11:13 +0200] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 404 [10/Jun/2022:18:17:50 +0200] 193.106.191.48 - - "-" - [10/Jun/2022:18:42:24 +0200] 178.79.160.137 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [10/Jun/2022:20:04:59 +0200] 60.217.75.69 TLSv1.2 AES256-SHA "-" - [10/Jun/2022:20:11:28 +0200] 202.95.12.3 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [10/Jun/2022:20:11:56 +0200] 202.95.12.3 - - "-" - [10/Jun/2022:20:11:59 +0200] 202.95.12.3 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [10/Jun/2022:20:12:44 +0200] 202.95.12.3 TLSv1.2 AES256-SHA "GET /sitemap.xml HTTP/1.1" 309 [10/Jun/2022:20:14:56 +0200] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 403 [10/Jun/2022:20:25:44 +0200] 178.79.184.84 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [10/Jun/2022:20:26:43 +0200] 128.1.248.42 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:20:27:45 +0200] 213.32.122.82 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [10/Jun/2022:20:54:41 +0200] 91.211.89.207 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Jun/2022:21:53:59 +0200] 185.180.143.71 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:22:46:29 +0200] 23.251.102.74 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [10/Jun/2022:22:52:43 +0200] 93.159.230.88 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Jun/2022:22:52:43 +0200] 93.159.230.83 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [11/Jun/2022:00:15:44 +0200] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 387 [11/Jun/2022:00:17:45 +0200] 194.5.73.5 TLSv1.2 AES256-SHA "POST /mgmt/tm/util/bash HTTP/1.1" 308 [11/Jun/2022:00:21:07 +0200] 185.83.144.103 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials/credentials HTTP/1.1" 317 [11/Jun/2022:00:21:07 +0200] 185.83.144.103 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials/credentials HTTP/1.1" 317 [11/Jun/2022:00:31:23 +0200] 205.210.31.142 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [11/Jun/2022:01:45:46 +0200] 20.213.136.30 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /cgi-bin/luci HTTP/1.1" 395