[08/Nov/2022:01:33:57 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [08/Nov/2022:01:33:57 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [08/Nov/2022:01:33:58 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [08/Nov/2022:01:33:58 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [08/Nov/2022:01:33:59 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [08/Nov/2022:01:33:59 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [08/Nov/2022:01:34:00 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [08/Nov/2022:01:34:01 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [08/Nov/2022:01:34:01 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [08/Nov/2022:01:34:02 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [08/Nov/2022:01:34:03 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [08/Nov/2022:01:34:04 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [08/Nov/2022:01:34:04 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [08/Nov/2022:01:34:05 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [08/Nov/2022:01:34:06 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [08/Nov/2022:01:34:07 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [08/Nov/2022:01:34:08 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [08/Nov/2022:01:34:09 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [08/Nov/2022:01:34:10 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [08/Nov/2022:01:34:10 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [08/Nov/2022:02:09:26 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [08/Nov/2022:02:20:44 +0100] 35.181.7.149 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [08/Nov/2022:04:11:59 +0100] 192.241.197.156 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:04:13:38 +0100] 192.241.204.160 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [08/Nov/2022:04:14:17 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_db.sql.gz HTTP/1.1" 405 [08/Nov/2022:04:32:19 +0100] 20.250.30.131 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 307 [08/Nov/2022:04:32:20 +0100] 20.250.30.131 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 310 [08/Nov/2022:05:22:53 +0100] 207.154.192.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:05:26:53 +0100] 157.245.111.29 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [08/Nov/2022:05:26:58 +0100] 157.245.111.29 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:05:54:14 +0100] 167.94.138.117 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [08/Nov/2022:05:54:14 +0100] 167.94.138.117 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:05:54:15 +0100] 167.94.138.117 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [08/Nov/2022:06:01:40 +0100] 198.12.252.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-db.sql.gz HTTP/1.1" 396 [08/Nov/2022:06:10:35 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-db.sql.gz HTTP/1.1" 405 [08/Nov/2022:06:54:44 +0100] 31.7.58.82 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 304 [08/Nov/2022:07:12:53 +0100] 35.181.7.149 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [08/Nov/2022:07:51:12 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_database.sql.gz HTTP/1.1" 419 [08/Nov/2022:07:56:10 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_database.sql.gz HTTP/1.1" 411 [08/Nov/2022:08:39:08 +0100] 185.189.182.234 TLSv1.2 AES256-SHA "GET /a6ad HTTP/1.1" 379 [08/Nov/2022:08:51:30 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [08/Nov/2022:10:05:11 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Nov/2022:11:38:46 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_dump.sql.gz HTTP/1.1" 398 [08/Nov/2022:12:16:21 +0100] 162.62.191.231 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 500 [08/Nov/2022:12:16:33 +0100] 205.185.121.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:12:16:34 +0100] 209.141.36.112 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [08/Nov/2022:12:16:34 +0100] 205.185.122.184 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [08/Nov/2022:12:16:36 +0100] 205.185.121.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [08/Nov/2022:12:16:37 +0100] 209.141.36.231 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [08/Nov/2022:12:16:38 +0100] 205.185.121.69 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [08/Nov/2022:12:16:38 +0100] 209.141.51.222 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [08/Nov/2022:12:16:39 +0100] 209.141.35.128 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:12:16:40 +0100] 209.141.49.169 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [08/Nov/2022:12:16:42 +0100] 209.141.36.112 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 308 [08/Nov/2022:12:16:43 +0100] 209.141.41.193 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [08/Nov/2022:12:16:45 +0100] 65.49.20.71 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:12:16:45 +0100] 209.141.55.120 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [08/Nov/2022:12:28:14 +0100] 65.49.20.107 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [08/Nov/2022:12:33:27 +0100] 65.49.20.115 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:12:34:46 +0100] 65.49.20.95 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [08/Nov/2022:12:52:18 +0100] 143.244.135.211 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [08/Nov/2022:12:52:20 +0100] 143.244.135.211 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [08/Nov/2022:12:52:25 +0100] 143.244.135.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:13:01:24 +0100] 176.58.124.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [08/Nov/2022:13:04:23 +0100] 128.1.131.197 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 383 [08/Nov/2022:13:25:37 +0100] 66.240.236.116 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:13:44:30 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-dump.sql.gz HTTP/1.1" 398 [08/Nov/2022:14:02:57 +0100] 198.199.95.173 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [08/Nov/2022:14:07:16 +0100] 192.241.199.96 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [08/Nov/2022:14:11:48 +0100] 192.241.194.251 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [08/Nov/2022:14:31:54 +0100] 194.55.186.126 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [08/Nov/2022:15:09:20 +0100] 194.180.48.125 TLSv1.2 AES256-SHA "GET /docker-compose.yml HTTP/1.1" 312 [08/Nov/2022:15:27:31 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhostbackup.sql.gz HTTP/1.1" 416 [08/Nov/2022:16:07:54 +0100] 205.210.31.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [08/Nov/2022:16:09:16 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-dump.sql.gz HTTP/1.1" 407 [08/Nov/2022:16:20:27 +0100] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:16:38:02 +0100] 77.73.134.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /wp-includes/js/jquery/jquery.js HTTP/1.1" 327 [08/Nov/2022:16:38:02 +0100] 77.73.134.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /ckeditor/plugins/imageuploader/styles.min.css HTTP/1.1" 338 [08/Nov/2022:16:38:02 +0100] 77.73.134.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /uploadify/jquery.uploadify.v2.1.4.js HTTP/1.1" 330 [08/Nov/2022:16:41:37 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhostbackup.sql.gz HTTP/1.1" 408 [08/Nov/2022:17:03:10 +0100] 110.238.104.198 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:17:19:28 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_backup.sql.gz HTTP/1.1" 417 [08/Nov/2022:17:24:05 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 343 [08/Nov/2022:17:24:07 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /dns-query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 343 [08/Nov/2022:17:24:09 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /dns-query HTTP/1.1" 308 [08/Nov/2022:17:24:11 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /dns-query HTTP/1.1" 308 [08/Nov/2022:17:24:13 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 340 [08/Nov/2022:17:24:15 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /query?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 340 [08/Nov/2022:17:24:17 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /query HTTP/1.1" 305 [08/Nov/2022:17:24:19 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /query HTTP/1.1" 305 [08/Nov/2022:17:24:21 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 342 [08/Nov/2022:17:24:23 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /resolve?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 342 [08/Nov/2022:17:24:25 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /resolve HTTP/1.1" 305 [08/Nov/2022:17:24:26 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST /resolve HTTP/1.1" 305 [08/Nov/2022:17:24:28 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 337 [08/Nov/2022:17:24:30 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "GET /?dns=q80BAAABAAAAAAAAA3d3dwdleGFtcGxlA2NvbQAAAQAB HTTP/1.1" 337 [08/Nov/2022:17:24:31 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST / HTTP/1.1" 301 [08/Nov/2022:17:24:33 +0100] 47.243.233.244 TLSv1.2 AES256-SHA "POST / HTTP/1.1" 301 [08/Nov/2022:18:21:35 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost_backup.sql.gz HTTP/1.1" 400 [08/Nov/2022:19:09:50 +0100] 198.235.24.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [08/Nov/2022:19:27:53 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-backup.sql.gz HTTP/1.1" 417 [08/Nov/2022:19:35:25 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [08/Nov/2022:19:41:23 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-backup.sql.gz HTTP/1.1" 409 [08/Nov/2022:20:10:45 +0100] 157.230.20.196 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [08/Nov/2022:20:10:45 +0100] 157.230.20.196 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [08/Nov/2022:20:10:47 +0100] 157.230.20.196 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:20:14:31 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /localhost-backup.sql.gz HTTP/1.1" 400 [08/Nov/2022:20:49:38 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backuplocalhost.sql.gz HTTP/1.1" 408 [08/Nov/2022:20:59:36 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backuplocalhost.sql.gz HTTP/1.1" 416 [08/Nov/2022:21:07:50 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backuplocalhost.sql.gz HTTP/1.1" 399 [08/Nov/2022:21:20:59 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:22:24:25 +0100] 178.255.100.159 TLSv1.2 AES256-SHA "GET /Electron/download/windows/%5CProgram%20Files%5C3CX%20Phone%20System%5CData%5CDB%5Cbase%5C16384%5C16393 HTTP/1.1" 369 [08/Nov/2022:23:02:11 +0100] 192.241.209.62 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [08/Nov/2022:23:26:45 +0100] 109.206.243.162 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [08/Nov/2022:23:29:09 +0100] 45.79.14.138 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:23:33:55 +0100] 91.211.91.188 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Nov/2022:23:36:02 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup-localhost.sql.gz HTTP/1.1" 417 [09/Nov/2022:00:16:22 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [09/Nov/2022:00:21:55 +0100] 18.237.181.179 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [09/Nov/2022:00:22:36 +0100] 34.219.7.160 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313 [09/Nov/2022:00:22:40 +0100] 34.219.7.160 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [09/Nov/2022:00:48:27 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [09/Nov/2022:00:55:12 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_localhost.sql.gz HTTP/1.1" 409