[04/Dec/2022:01:18:31 +0100] 18.237.73.178 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Dec/2022:01:29:43 +0100] 35.92.30.198 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Dec/2022:01:56:41 +0100] 110.243.247.78 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [04/Dec/2022:01:56:42 +0100] 110.243.247.78 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:02:10:38 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db_backup.sql.gz HTTP/1.1" 405 [04/Dec/2022:02:41:33 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Dec/2022:02:48:08 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:02:48:31 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [04/Dec/2022:02:48:54 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [04/Dec/2022:03:46:29 +0100] 205.210.31.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 380 [04/Dec/2022:04:54:09 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db_backup.easyzumfuehrerschein.com.sql HTTP/1.1" 435 [04/Dec/2022:05:11:27 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [04/Dec/2022:05:16:52 +0100] 195.133.20.252 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /api/v2/cmdb/system/admin HTTP/1.1" 318 [04/Dec/2022:05:25:20 +0100] 198.199.95.141 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:06:29:30 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db_backup.klub.sql HTTP/1.1" 407 [04/Dec/2022:06:37:04 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db_backup.harm.sql HTTP/1.1" 398 [04/Dec/2022:06:38:43 +0100] 40.77.167.96 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [04/Dec/2022:06:38:44 +0100] 40.77.167.96 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [04/Dec/2022:06:38:49 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [04/Dec/2022:07:28:05 +0100] 27.128.203.121 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [04/Dec/2022:07:28:06 +0100] 27.128.203.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:07:33:35 +0100] 192.241.212.116 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [04/Dec/2022:07:45:34 +0100] 198.235.24.175 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [04/Dec/2022:08:05:34 +0100] 192.241.209.113 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [04/Dec/2022:08:56:21 +0100] 195.133.20.252 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /api/v2/cmdb/system/admin HTTP/1.1" 318 [04/Dec/2022:09:14:50 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/Dump.sql HTTP/1.1" 388 [04/Dec/2022:09:51:12 +0100] 152.32.143.122 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Dec/2022:10:06:24 +0100] 167.94.138.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Dec/2022:10:06:25 +0100] 167.94.138.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:10:06:26 +0100] 167.94.138.120 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [04/Dec/2022:10:36:19 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Dec/2022:10:42:59 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [04/Dec/2022:10:43:41 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [04/Dec/2022:11:41:04 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/backup.sql HTTP/1.1" 390 [04/Dec/2022:11:52:27 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/backup.sql HTTP/1.1" 407 [04/Dec/2022:13:19:38 +0100] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:13:41:38 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [04/Dec/2022:14:08:30 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/backup.sql.zip HTTP/1.1" 394 [04/Dec/2022:14:37:38 +0100] 192.241.202.90 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [04/Dec/2022:14:44:10 +0100] 192.241.212.53 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [04/Dec/2022:14:45:17 +0100] 192.241.203.37 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [04/Dec/2022:14:47:08 +0100] 64.62.197.158 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:14:59:16 +0100] 64.62.197.157 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [04/Dec/2022:15:03:35 +0100] 64.62.197.163 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:15:05:17 +0100] 64.62.197.161 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [04/Dec/2022:16:13:17 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_db_.sql HTTP/1.1" 388 [04/Dec/2022:18:17:07 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_DB_.sql HTTP/1.1" 397 [04/Dec/2022:18:17:49 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [04/Dec/2022:18:19:59 +0100] 178.32.197.93 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Dec/2022:18:23:41 +0100] 167.94.145.57 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Dec/2022:18:23:41 +0100] 167.94.145.57 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:18:23:41 +0100] 167.94.145.57 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [04/Dec/2022:18:30:04 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_DB_.sql HTTP/1.1" 388 [04/Dec/2022:18:44:42 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_DB_.sql HTTP/1.1" 405 [04/Dec/2022:19:03:14 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Dec/2022:19:29:42 +0100] 188.165.87.103 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 394 [04/Dec/2022:20:29:18 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_DB_.sql.zip HTTP/1.1" 392 [04/Dec/2022:21:04:54 +0100] 20.106.158.108 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [04/Dec/2022:21:04:54 +0100] 20.106.158.108 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [04/Dec/2022:21:12:51 +0100] 18.144.54.51 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 310 [04/Dec/2022:21:12:54 +0100] 18.144.54.51 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 310 [04/Dec/2022:21:44:04 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [04/Dec/2022:21:44:06 +0100] 103.133.111.120 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [04/Dec/2022:21:44:08 +0100] 103.133.111.120 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [04/Dec/2022:21:44:16 +0100] 192.241.204.132 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [04/Dec/2022:21:50:08 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:21:51:18 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [04/Dec/2022:22:08:43 +0100] 38.242.219.189 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:22:10:02 +0100] 104.192.108.9 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [04/Dec/2022:22:43:42 +0100] 205.210.31.155 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 386 [04/Dec/2022:22:53:20 +0100] 154.89.5.80 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [04/Dec/2022:23:00:34 +0100] 117.187.173.2 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [04/Dec/2022:23:02:47 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/_DB_.tar.gz HTTP/1.1" 408 [04/Dec/2022:23:12:29 +0100] 183.136.225.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 381 [04/Dec/2022:23:13:17 +0100] 183.136.225.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [04/Dec/2022:23:13:28 +0100] 183.136.225.44 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [04/Dec/2022:23:13:55 +0100] 183.136.225.44 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 304 [05/Dec/2022:00:20:13 +0100] 34.77.127.183 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301