[05/Aug/2022:02:05:44 +0200] 128.1.248.42 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [05/Aug/2022:02:25:39 +0200] 142.93.199.246 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Aug/2022:02:40:00 +0200] 205.210.31.6 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 389 [05/Aug/2022:02:52:32 +0200] 207.46.13.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [05/Aug/2022:02:56:00 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [05/Aug/2022:04:18:16 +0200] 192.241.202.61 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [05/Aug/2022:04:48:10 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [05/Aug/2022:05:00:39 +0200] 192.241.214.48 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Aug/2022:05:58:17 +0200] 35.195.93.98 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [05/Aug/2022:07:03:47 +0200] 77.74.177.119 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [05/Aug/2022:07:56:32 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [05/Aug/2022:08:06:18 +0200] 193.106.29.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [05/Aug/2022:09:00:03 +0200] 128.14.141.34 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [05/Aug/2022:09:14:46 +0200] 182.161.66.103 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [05/Aug/2022:09:49:25 +0200] 88.214.43.118 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /env/config HTTP/1.1" 314 [05/Aug/2022:09:49:26 +0200] 88.214.43.118 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /env/config HTTP/1.1" 314 [05/Aug/2022:10:50:50 +0200] 205.210.31.130 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [05/Aug/2022:10:53:04 +0200] 193.201.9.69 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [05/Aug/2022:11:37:11 +0200] 192.241.237.136 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [05/Aug/2022:11:39:17 +0200] 192.241.206.79 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [05/Aug/2022:11:39:38 +0200] 192.241.237.61 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [05/Aug/2022:11:51:19 +0200] 64.62.197.137 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Aug/2022:12:00:10 +0200] 64.62.197.137 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [05/Aug/2022:12:04:43 +0200] 64.62.197.140 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Aug/2022:12:08:06 +0200] 193.201.9.69 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [05/Aug/2022:13:31:14 +0200] 128.14.134.170 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [05/Aug/2022:13:32:46 +0200] 167.248.133.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Aug/2022:13:32:46 +0200] 167.248.133.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Aug/2022:13:32:47 +0200] 167.248.133.45 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [05/Aug/2022:14:16:00 +0200] 178.73.215.171 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [05/Aug/2022:14:16:22 +0200] 178.73.215.171 - - "-" - [05/Aug/2022:14:16:23 +0200] 178.73.215.171 - - "-" - [05/Aug/2022:14:16:28 +0200] 178.73.215.171 - - "-" - [05/Aug/2022:14:26:34 +0200] 194.163.187.35 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [05/Aug/2022:14:55:37 +0200] 54.36.148.145 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 314 [05/Aug/2022:14:55:38 +0200] 54.36.148.109 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [05/Aug/2022:15:13:58 +0200] 205.210.31.147 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [05/Aug/2022:16:05:11 +0200] 139.162.226.50 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [05/Aug/2022:16:57:03 +0200] 157.55.39.210 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [05/Aug/2022:16:57:04 +0200] 157.55.39.210 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [05/Aug/2022:16:57:13 +0200] 207.46.13.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [05/Aug/2022:17:44:49 +0200] 179.43.155.171 TLSv1.2 AES256-SHA "GET /Dockerrun.aws.json HTTP/1.1" 314 [05/Aug/2022:18:10:46 +0200] 176.58.119.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [05/Aug/2022:20:11:38 +0200] 212.7.207.167 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET //%24%7BClass.forName%28%22com.opensymphony.webwork.ServletActionContext%22%29.getMethod%28%22getResponse%22%2Cnull%29.invoke%28null%2Cnull%29.setHeader%28%22X-Confluence%22%2C1%29%7D// HTTP/1.1" 410 [05/Aug/2022:20:24:56 +0200] 193.118.53.210 TLSv1.2 DHE-RSA-AES256-SHA256 "GET / HTTP/1.1" 301 [05/Aug/2022:21:12:52 +0200] 93.159.230.88 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 302 [05/Aug/2022:21:37:41 +0200] 192.241.213.196 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [05/Aug/2022:21:41:34 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Aug/2022:22:07:17 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [05/Aug/2022:23:17:09 +0200] 34.217.122.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [05/Aug/2022:23:18:53 +0200] 44.234.114.229 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [05/Aug/2022:23:56:05 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [06/Aug/2022:00:42:48 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [06/Aug/2022:01:05:57 +0200] 185.7.214.104 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [06/Aug/2022:01:22:36 +0200] 94.232.45.12 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [06/Aug/2022:01:43:49 +0200] 43.128.61.192 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /dns-query HTTP/1.1" 392