[23/Oct/2022:02:18:15 +0200] 205.210.31.175 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [23/Oct/2022:02:32:01 +0200] 92.255.85.207 - - "-" - [23/Oct/2022:02:43:46 +0200] 164.92.184.103 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:02:59:57 +0200] 128.14.133.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:03:17:12 +0200] 183.136.225.35 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [23/Oct/2022:03:17:51 +0200] 183.136.225.35 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:03:18:13 +0200] 183.136.225.35 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [23/Oct/2022:03:18:34 +0200] 183.136.225.35 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [23/Oct/2022:03:36:48 +0200] 45.143.203.111 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [23/Oct/2022:03:44:09 +0200] 192.241.217.66 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:04:41:47 +0200] 185.156.72.51 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /api/v2/cmdb/system/admin HTTP/1.1" 313 [23/Oct/2022:04:43:54 +0200] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/db.bck HTTP/1.1" 401 [23/Oct/2022:05:31:15 +0200] 206.189.28.44 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [23/Oct/2022:05:31:21 +0200] 206.189.28.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:06:15:03 +0200] 194.180.48.125 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [23/Oct/2022:07:28:56 +0200] 152.89.196.23 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [23/Oct/2022:08:36:48 +0200] 34.77.114.155 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:08:48:24 +0200] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:09:07:33 +0200] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/db.php.bck HTTP/1.1" 405 [23/Oct/2022:09:53:21 +0200] 193.235.141.169 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [23/Oct/2022:10:01:04 +0200] 198.235.24.186 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [23/Oct/2022:11:25:53 +0200] 65.49.20.67 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:11:34:52 +0200] 65.49.20.99 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [23/Oct/2022:11:39:16 +0200] 65.49.20.67 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:12:49:28 +0200] 192.241.213.55 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [23/Oct/2022:12:57:22 +0200] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/database.bak HTTP/1.1" 407 [23/Oct/2022:13:05:57 +0200] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/database.bak HTTP/1.1" 415 [23/Oct/2022:13:46:29 +0200] 193.118.53.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:14:07:55 +0200] 72.251.235.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /api/v2/cmdb/system/admin/admin HTTP/1.0" 407 [23/Oct/2022:14:24:52 +0200] 4.233.106.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [23/Oct/2022:14:24:52 +0200] 4.233.106.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [23/Oct/2022:14:54:11 +0200] 192.241.214.56 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [23/Oct/2022:14:57:27 +0200] 192.241.205.22 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [23/Oct/2022:15:00:49 +0200] 192.241.215.109 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [23/Oct/2022:15:17:00 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [23/Oct/2022:15:30:06 +0200] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/database.bck HTTP/1.1" 407 [23/Oct/2022:15:41:29 +0200] 20.237.232.112 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [23/Oct/2022:15:57:44 +0200] 193.118.53.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:16:35:00 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [23/Oct/2022:17:49:53 +0200] 112.124.1.76 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /api/Ticket/q?m=18900547892&refer__2377=eu0%3DiKY5DK0ITxBkP56KGI94Wq7KQDCFtleD HTTP/1.1" 378 [23/Oct/2022:18:16:56 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [23/Oct/2022:18:36:21 +0200] 162.62.191.231 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 500 [23/Oct/2022:18:39:52 +0200] 192.241.208.53 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [23/Oct/2022:18:46:49 +0200] 205.185.121.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [23/Oct/2022:18:46:53 +0200] 209.141.49.169 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [23/Oct/2022:18:47:01 +0200] 209.141.49.169 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [23/Oct/2022:18:47:04 +0200] 209.141.51.222 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:18:47:04 +0200] 209.141.36.231 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [23/Oct/2022:18:47:06 +0200] 209.141.36.231 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 308 [23/Oct/2022:18:47:12 +0200] 209.141.51.222 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:18:47:15 +0200] 209.141.34.187 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [23/Oct/2022:19:17:27 +0200] 94.102.61.8 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Oct/2022:19:57:00 +0200] 162.221.192.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:20:01:36 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:20:05:54 +0200] 194.180.48.125 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [23/Oct/2022:20:52:32 +0200] 167.94.138.63 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [23/Oct/2022:20:52:32 +0200] 167.94.138.63 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:20:52:33 +0200] 167.94.138.63 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [23/Oct/2022:20:52:46 +0200] 192.241.218.186 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [23/Oct/2022:21:13:37 +0200] 194.180.48.125 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [23/Oct/2022:22:09:19 +0200] 152.89.196.23 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [23/Oct/2022:22:20:11 +0200] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/connect.php~ HTTP/1.1" 415 [23/Oct/2022:22:27:59 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [23/Oct/2022:23:41:43 +0200] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Oct/2022:23:44:58 +0200] 213.226.123.154 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /autodiscover/autodiscover.json HTTP/1.1" 316 [23/Oct/2022:23:46:38 +0200] 34.221.16.199 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:23:46:52 +0200] 35.87.179.220 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:23:47:00 +0200] 35.161.104.21 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [23/Oct/2022:23:47:05 +0200] 35.161.104.21 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:23:47:18 +0200] 34.221.95.142 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [23/Oct/2022:23:47:21 +0200] 34.221.95.142 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Oct/2022:23:49:09 +0200] 152.89.196.211 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [24/Oct/2022:00:46:07 +0200] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /includes/connect.php~ HTTP/1.1" 407 [24/Oct/2022:01:13:30 +0200] 139.59.5.191 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [24/Oct/2022:01:13:32 +0200] 139.59.5.191 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [24/Oct/2022:01:13:37 +0200] 139.59.5.191 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Oct/2022:01:35:33 +0200] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301