[30/Nov/2022:01:13:22 +0100] 185.180.143.138 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:01:31:49 +0100] 184.105.139.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:01:36:27 +0100] 181.214.218.69 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [30/Nov/2022:01:44:29 +0100] 184.105.139.69 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [30/Nov/2022:01:50:42 +0100] 184.105.139.117 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:02:01:25 +0100] 165.22.208.235 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [30/Nov/2022:02:01:31 +0100] 165.22.208.235 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:03:35:26 +0100] 35.207.198.6 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [30/Nov/2022:03:54:46 +0100] 154.89.5.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [30/Nov/2022:03:54:46 +0100] 154.89.5.82 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [30/Nov/2022:04:07:58 +0100] 138.199.21.235 TLSv1.2 AES256-SHA "GET /a.txt HTTP/1.0" 384 [30/Nov/2022:04:45:55 +0100] 50.116.16.97 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [30/Nov/2022:05:18:37 +0100] 198.199.95.208 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:05:36:48 +0100] 198.12.252.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backuplocalhost.rar HTTP/1.1" 413 [30/Nov/2022:05:41:42 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [30/Nov/2022:05:47:45 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:05:48:08 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [30/Nov/2022:05:48:55 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [30/Nov/2022:06:25:20 +0100] 192.241.192.200 TLSv1.2 AES256-SHA "GET /ReportServer HTTP/1.1" 307 [30/Nov/2022:06:38:23 +0100] 192.241.205.120 TLSv1.2 AES256-SHA "GET /login HTTP/1.1" 305 [30/Nov/2022:07:15:38 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup-localhost.rar HTTP/1.1" 406 [30/Nov/2022:07:18:07 +0100] 198.235.24.152 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [30/Nov/2022:07:29:40 +0100] 167.248.133.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [30/Nov/2022:07:29:40 +0100] 167.248.133.45 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:07:29:41 +0100] 167.248.133.45 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [30/Nov/2022:07:47:53 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup-localhost.rar HTTP/1.1" 397 [30/Nov/2022:07:59:57 +0100] 198.199.103.251 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [30/Nov/2022:08:09:59 +0100] 193.106.29.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [30/Nov/2022:08:12:23 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [30/Nov/2022:08:24:00 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup-localhost.rar HTTP/1.1" 414 [30/Nov/2022:09:07:58 +0100] 51.77.247.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /_profiler/phpinfo HTTP/1.1" 400 [30/Nov/2022:10:14:09 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [30/Nov/2022:10:14:10 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [30/Nov/2022:10:14:10 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [30/Nov/2022:10:14:10 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [30/Nov/2022:10:14:11 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [30/Nov/2022:10:14:11 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [30/Nov/2022:10:14:12 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [30/Nov/2022:10:14:12 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [30/Nov/2022:10:14:13 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [30/Nov/2022:10:14:13 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [30/Nov/2022:10:14:14 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [30/Nov/2022:10:14:14 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [30/Nov/2022:10:14:15 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [30/Nov/2022:10:14:15 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [30/Nov/2022:10:14:16 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [30/Nov/2022:10:14:16 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [30/Nov/2022:10:14:17 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [30/Nov/2022:10:14:17 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [30/Nov/2022:10:14:18 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [30/Nov/2022:10:14:18 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [30/Nov/2022:10:45:42 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [30/Nov/2022:11:36:30 +0100] 62.212.170.46 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [30/Nov/2022:11:40:08 +0100] 192.241.212.227 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [30/Nov/2022:12:03:35 +0100] 181.214.218.69 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [30/Nov/2022:13:05:59 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [30/Nov/2022:13:24:05 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [30/Nov/2022:13:30:34 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:13:31:04 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [30/Nov/2022:13:31:10 +0100] 128.14.134.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:13:31:27 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [30/Nov/2022:14:02:22 +0100] 66.34.212.150 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Electron/download/windows/\\Program%20Files\\3CX%20Phone%20System\\Data\\DB\\base\\16384\\16393 HTTP/1.0" 479 [30/Nov/2022:15:25:12 +0100] 109.206.243.220 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [30/Nov/2022:16:00:39 +0100] 51.222.253.1 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 304 [30/Nov/2022:16:00:41 +0100] 54.36.149.14 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [30/Nov/2022:16:40:41 +0100] 51.222.253.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 302 [30/Nov/2022:16:40:43 +0100] 54.36.148.227 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [30/Nov/2022:17:06:28 +0100] 193.118.53.210 TLSv1.2 AES256-SHA "GET /owa/ HTTP/1.1" 304 [30/Nov/2022:17:24:49 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393 [30/Nov/2022:17:28:59 +0100] 23.251.102.74 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:17:35:51 +0100] 198.199.93.135 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [30/Nov/2022:17:39:32 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm.at.rar HTTP/1.1" 388 [30/Nov/2022:17:49:03 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein.com.rar HTTP/1.1" 422 [30/Nov/2022:18:27:34 +0100] 216.131.68.5 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /webclient/ HTTP/1.1" 393 [30/Nov/2022:20:13:32 +0100] 194.180.48.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [30/Nov/2022:20:13:32 +0100] 194.180.48.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [30/Nov/2022:20:54:04 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [30/Nov/2022:21:00:37 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [30/Nov/2022:21:00:59 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [30/Nov/2022:21:01:24 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [30/Nov/2022:21:33:06 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein.comdb.rar HTTP/1.1" 424 [30/Nov/2022:22:16:53 +0100] 35.86.129.102 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:17:24 +0100] 54.202.237.194 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [30/Nov/2022:22:17:28 +0100] 54.202.237.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:26:07 +0100] 52.27.131.117 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:26:07 +0100] 54.191.60.0 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:26:32 +0100] 34.211.207.164 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [30/Nov/2022:22:26:37 +0100] 34.211.207.164 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:27:01 +0100] 35.162.209.54 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [30/Nov/2022:22:27:51 +0100] 35.163.202.1 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:28:37 +0100] 52.12.127.148 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [30/Nov/2022:22:28:45 +0100] 35.162.147.29 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [30/Nov/2022:23:04:11 +0100] 170.64.134.124 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [30/Nov/2022:23:04:15 +0100] 170.64.134.124 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [30/Nov/2022:23:04:24 +0100] 170.64.134.124 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [01/Dec/2022:00:16:03 +0100] 185.180.143.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [01/Dec/2022:00:22:19 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [01/Dec/2022:00:43:28 +0100] 142.93.131.30 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [01/Dec/2022:00:58:27 +0100] 137.226.113.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 308