[09/Dec/2022:01:22:27 +0100] 208.100.26.236 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [09/Dec/2022:01:54:52 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [09/Dec/2022:01:54:53 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [09/Dec/2022:01:54:53 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [09/Dec/2022:01:54:53 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [09/Dec/2022:01:54:54 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [09/Dec/2022:01:54:54 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [09/Dec/2022:01:54:55 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [09/Dec/2022:01:54:55 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [09/Dec/2022:01:54:56 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [09/Dec/2022:01:54:56 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [09/Dec/2022:01:54:57 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [09/Dec/2022:01:54:57 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [09/Dec/2022:01:54:58 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [09/Dec/2022:01:54:58 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [09/Dec/2022:01:54:58 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [09/Dec/2022:01:54:59 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [09/Dec/2022:01:54:59 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [09/Dec/2022:01:54:59 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [09/Dec/2022:01:55:00 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [09/Dec/2022:01:55:00 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [09/Dec/2022:01:56:48 +0100] 157.245.83.51 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [09/Dec/2022:01:56:49 +0100] 157.245.83.51 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [09/Dec/2022:01:56:53 +0100] 157.245.83.51 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:03:40:26 +0100] 185.81.157.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 310 [09/Dec/2022:04:08:04 +0100] 54.241.123.162 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:04:58:32 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/database.php.bck HTTP/1.1" 413 [09/Dec/2022:05:00:14 +0100] 198.58.99.216 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:05:09:09 +0100] 23.251.102.90 TLSv1.2 AES256-SHA "GET /admin/ HTTP/1.1" 305 [09/Dec/2022:05:37:29 +0100] 192.241.213.55 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:05:53:44 +0100] 50.62.180.26 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [09/Dec/2022:05:55:04 +0100] 193.106.29.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [09/Dec/2022:07:36:50 +0100] 3.70.111.74 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 304 [09/Dec/2022:07:36:50 +0100] 3.70.111.74 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 304 [09/Dec/2022:07:41:56 +0100] 192.241.206.137 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [09/Dec/2022:07:42:13 +0100] 134.209.30.189 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:08:06:00 +0100] 18.118.30.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 316 [09/Dec/2022:08:06:02 +0100] 18.118.30.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 316 [09/Dec/2022:08:18:11 +0100] 192.241.212.90 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [09/Dec/2022:08:21:14 +0100] 40.77.167.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 304 [09/Dec/2022:09:27:46 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [09/Dec/2022:10:21:50 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 403 [09/Dec/2022:10:36:11 +0100] 106.75.182.206 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [09/Dec/2022:11:47:27 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db.rar HTTP/1.1" 395 [09/Dec/2022:11:52:19 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 404 [09/Dec/2022:12:58:54 +0100] 52.91.210.107 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [09/Dec/2022:13:52:23 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db.zip HTTP/1.1" 395 [09/Dec/2022:13:57:36 +0100] 192.241.202.240 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [09/Dec/2022:14:03:21 +0100] 45.55.64.143 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [09/Dec/2022:14:03:22 +0100] 45.55.64.143 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 754 [09/Dec/2022:14:03:29 +0100] 45.55.64.143 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 1150 [09/Dec/2022:14:12:25 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db.zip HTTP/1.1" 403 [09/Dec/2022:14:13:45 +0100] 50.62.180.26 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [09/Dec/2022:15:13:28 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [09/Dec/2022:15:19:38 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [09/Dec/2022:15:20:20 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [09/Dec/2022:15:40:13 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [09/Dec/2022:15:40:13 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:15:40:14 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [09/Dec/2022:15:59:53 +0100] 64.62.197.170 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:16:08:08 +0100] 64.62.197.176 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [09/Dec/2022:16:11:36 +0100] 64.62.197.176 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:16:12:22 +0100] 64.62.197.174 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [09/Dec/2022:17:12:11 +0100] 23.22.237.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 314 [09/Dec/2022:17:12:12 +0100] 23.22.237.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 314 [09/Dec/2022:18:32:37 +0100] 88.80.184.154 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [09/Dec/2022:18:49:41 +0100] 51.77.247.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST //phpinfo HTTP/1.1" 390 [09/Dec/2022:19:42:05 +0100] 152.32.157.228 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [09/Dec/2022:19:42:08 +0100] 152.32.157.228 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [09/Dec/2022:19:42:16 +0100] 152.32.157.228 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [09/Dec/2022:19:42:24 +0100] 152.32.157.228 TLSv1.2 AES256-SHA "GET /sitemap.xml HTTP/1.1" 309 [09/Dec/2022:19:46:55 +0100] 157.245.137.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [09/Dec/2022:19:46:56 +0100] 157.245.137.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [09/Dec/2022:19:47:23 +0100] 157.245.137.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [09/Dec/2022:20:11:41 +0100] 185.7.214.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [09/Dec/2022:20:13:20 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /db/db.tgz HTTP/1.1" 386 [09/Dec/2022:21:55:08 +0100] 198.235.24.17 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [09/Dec/2022:22:40:00 +0100] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [09/Dec/2022:22:42:12 +0100] 198.235.24.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 380 [09/Dec/2022:23:08:15 +0100] 192.241.198.9 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [09/Dec/2022:23:13:50 +0100] 198.235.24.179 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [09/Dec/2022:23:15:14 +0100] 192.241.212.53 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [09/Dec/2022:23:17:42 +0100] 192.241.202.90 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [09/Dec/2022:23:25:46 +0100] 154.89.5.104 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [09/Dec/2022:23:51:33 +0100] 128.14.134.170 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Dec/2022:00:10:02 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [10/Dec/2022:00:16:02 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [10/Dec/2022:00:16:25 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [10/Dec/2022:00:22:05 +0100] 35.90.16.20 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [10/Dec/2022:00:22:41 +0100] 35.92.106.123 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [10/Dec/2022:00:35:43 +0100] 34.78.6.216 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301