[06/Dec/2022:01:08:21 +0100] 198.235.24.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [06/Dec/2022:01:24:28 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 395 [06/Dec/2022:01:24:28 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [06/Dec/2022:01:39:07 +0100] 18.236.169.249 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [06/Dec/2022:01:39:46 +0100] 35.92.121.34 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [06/Dec/2022:01:39:50 +0100] 35.92.121.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [06/Dec/2022:02:12:49 +0100] 20.228.231.209 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [06/Dec/2022:02:12:49 +0100] 20.228.231.209 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [06/Dec/2022:02:13:49 +0100] 213.32.122.82 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [06/Dec/2022:02:14:38 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:02:42:34 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/dump.sql.gz HTTP/1.1" 391 [06/Dec/2022:02:59:40 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/dump.sql.gz HTTP/1.1" 408 [06/Dec/2022:03:08:34 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [06/Dec/2022:03:33:45 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [06/Dec/2022:04:12:25 +0100] 154.89.5.39 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Dec/2022:04:24:23 +0100] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:05:00:28 +0100] 205.210.31.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [06/Dec/2022:05:03:57 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [06/Dec/2022:05:23:16 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [06/Dec/2022:05:23:18 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [06/Dec/2022:05:23:21 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [06/Dec/2022:05:23:23 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [06/Dec/2022:05:23:26 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [06/Dec/2022:05:23:28 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [06/Dec/2022:05:23:32 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /HNAP1/ HTTP/1.1" 292 [06/Dec/2022:05:23:34 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /HNAP1/ HTTP/1.1" 292 [06/Dec/2022:05:23:37 +0100] 182.23.10.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /HNAP1/ HTTP/1.1" 292 [06/Dec/2022:05:30:14 +0100] 192.241.205.202 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:05:49:27 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/dump.sql.tgz HTTP/1.1" 409 [06/Dec/2022:06:03:54 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [06/Dec/2022:06:03:55 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [06/Dec/2022:06:03:55 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [06/Dec/2022:06:03:56 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [06/Dec/2022:06:03:56 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [06/Dec/2022:06:03:56 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [06/Dec/2022:06:03:57 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [06/Dec/2022:06:03:58 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [06/Dec/2022:06:03:58 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [06/Dec/2022:06:03:58 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [06/Dec/2022:06:03:59 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [06/Dec/2022:06:03:59 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [06/Dec/2022:06:04:00 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [06/Dec/2022:06:04:00 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [06/Dec/2022:06:04:01 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [06/Dec/2022:06:04:01 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [06/Dec/2022:06:04:02 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [06/Dec/2022:06:04:02 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [06/Dec/2022:06:04:02 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [06/Dec/2022:06:04:03 +0100] 109.237.97.180 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [06/Dec/2022:06:12:33 +0100] 192.241.196.184 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [06/Dec/2022:07:24:17 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/dump.sql.bck HTTP/1.1" 409 [06/Dec/2022:07:28:20 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [06/Dec/2022:07:34:17 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:07:34:40 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Dec/2022:07:35:24 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [06/Dec/2022:08:06:40 +0100] 192.241.204.84 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [06/Dec/2022:08:21:01 +0100] 162.142.125.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:08:21:01 +0100] 162.142.125.121 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Dec/2022:08:32:21 +0100] 162.142.125.9 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Dec/2022:08:32:22 +0100] 162.142.125.9 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:08:32:22 +0100] 162.142.125.9 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Dec/2022:08:50:07 +0100] 54.215.227.193 TLSv1.2 AES256-SHA "GET /explore HTTP/1.1" 306 [06/Dec/2022:09:04:37 +0100] 162.142.125.121 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:09:04:38 +0100] 162.142.125.121 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Dec/2022:09:43:20 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [06/Dec/2022:09:48:50 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:09:49:15 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Dec/2022:09:49:51 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/www.harm.at.sql HTTP/1.1" 395 [06/Dec/2022:09:57:07 +0100] 167.94.138.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Dec/2022:09:57:07 +0100] 167.94.138.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:09:57:08 +0100] 167.94.138.44 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Dec/2022:12:04:05 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/www.harm.at.sql.gz HTTP/1.1" 398 [06/Dec/2022:12:17:59 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [06/Dec/2022:13:14:37 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 310 [06/Dec/2022:13:14:38 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 310 [06/Dec/2022:13:14:39 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 317 [06/Dec/2022:13:14:40 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 317 [06/Dec/2022:13:14:40 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 315 [06/Dec/2022:13:14:41 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 315 [06/Dec/2022:13:14:42 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 316 [06/Dec/2022:13:14:42 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 316 [06/Dec/2022:13:14:43 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 314 [06/Dec/2022:13:14:44 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 314 [06/Dec/2022:13:14:44 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 312 [06/Dec/2022:13:14:45 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 312 [06/Dec/2022:13:14:46 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 315 [06/Dec/2022:13:14:46 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 315 [06/Dec/2022:13:14:47 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 313 [06/Dec/2022:13:14:47 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 313 [06/Dec/2022:13:14:48 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 312 [06/Dec/2022:13:14:48 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 312 [06/Dec/2022:13:14:49 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 312 [06/Dec/2022:13:14:49 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 312 [06/Dec/2022:14:27:32 +0100] 194.180.48.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [06/Dec/2022:14:27:32 +0100] 194.180.48.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [06/Dec/2022:14:39:13 +0100] 64.62.197.158 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:14:41:17 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [06/Dec/2022:14:47:38 +0100] 64.62.197.160 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Dec/2022:14:51:10 +0100] 64.62.197.159 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:14:51:54 +0100] 198.235.24.29 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [06/Dec/2022:14:51:54 +0100] 64.62.197.160 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [06/Dec/2022:15:07:07 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/www.harm.sql HTTP/1.1" 392 [06/Dec/2022:15:15:00 +0100] 157.55.39.170 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [06/Dec/2022:15:15:01 +0100] 157.55.39.170 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 311 [06/Dec/2022:15:16:11 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [06/Dec/2022:15:47:46 +0100] 66.240.236.116 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:15:56:28 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [06/Dec/2022:16:25:29 +0100] 193.118.53.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:17:08:37 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393 [06/Dec/2022:17:09:41 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/www.klub.sql.gz HTTP/1.1" 404 [06/Dec/2022:17:12:21 +0100] 103.203.59.1 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Dec/2022:17:31:34 +0100] 51.159.102.248 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [06/Dec/2022:17:31:35 +0100] 51.159.102.248 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 302 [06/Dec/2022:18:37:48 +0100] 45.134.144.65 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///3c625c27b4da33d3d5c12e8d02104755/js/login.js HTTP/1.1" 335 [06/Dec/2022:19:25:00 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/easyzumfuehrerschein.com.sql HTTP/1.1" 425 [06/Dec/2022:21:12:18 +0100] 179.43.177.154 TLSv1.2 AES256-SHA "GET /.env HTTP/1.1" 304 [06/Dec/2022:22:12:22 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/klub.kornland.at.sql.gz HTTP/1.1" 412 [06/Dec/2022:22:23:50 +0100] 52.38.39.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Dec/2022:22:24:37 +0100] 209.141.37.194 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///wp-login.php HTTP/1.1" 316 [06/Dec/2022:22:25:12 +0100] 34.220.218.63 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Dec/2022:22:31:45 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Dec/2022:22:32:03 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /manage/account/login HTTP/1.1" 316 [06/Dec/2022:22:32:19 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /admin/index.html HTTP/1.1" 312 [06/Dec/2022:22:32:36 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /index.html HTTP/1.1" 308 [06/Dec/2022:22:32:53 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:22:33:10 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Dec/2022:22:33:26 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /manage/account/login HTTP/1.1" 316 [06/Dec/2022:22:33:43 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /admin/index.html HTTP/1.1" 312 [06/Dec/2022:22:34:00 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET /index.html HTTP/1.1" 308 [06/Dec/2022:22:34:18 +0100] 18.134.228.3 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Dec/2022:23:38:03 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [07/Dec/2022:00:21:04 +0100] 35.195.93.98 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [07/Dec/2022:00:49:16 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [07/Dec/2022:00:50:19 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/harm.sql HTTP/1.1" 388 [07/Dec/2022:00:56:14 +0100] 102.37.122.154 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383