[24/Jan/2023:01:11:53 +0100] 205.210.31.51 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [24/Jan/2023:01:17:32 +0100] 106.248.179.109 TLSv1.2 AES256-SHA "GET /2004/license.txt HTTP/1.1" 306 [24/Jan/2023:01:36:54 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /deploy.gz HTTP/1.1" 403 [24/Jan/2023:01:48:51 +0100] 205.210.31.170 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [24/Jan/2023:01:50:33 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /latest.bz2 HTTP/1.1" 396 [24/Jan/2023:01:54:03 +0100] 185.220.100.240 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /spog/welcome HTTP/1.1" 309 [24/Jan/2023:01:54:17 +0100] 185.220.101.15 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /cgi-bin/welcome HTTP/1.1" 313 [24/Jan/2023:02:02:26 +0100] 46.165.136.103 TLSv1.2 AES256-SHA "GET /2004/license.txt HTTP/1.1" 318 [24/Jan/2023:03:10:26 +0100] 64.62.197.122 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:03:17:15 +0100] 64.62.197.128 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [24/Jan/2023:03:20:35 +0100] 64.62.197.136 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:03:21:29 +0100] 64.62.197.123 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [24/Jan/2023:03:58:40 +0100] 128.14.209.162 TLSv1.2 AES256-SHA "GET /remote/login HTTP/1.1" 309 [24/Jan/2023:05:49:29 +0100] 178.238.24.210 TLSv1.2 AES256-SHA "GET /2005/license.txt HTTP/1.1" 306 [24/Jan/2023:06:06:48 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.zip HTTP/1.1" 395 [24/Jan/2023:06:31:09 +0100] 159.65.54.215 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [24/Jan/2023:06:31:09 +0100] 159.65.54.215 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [24/Jan/2023:06:31:10 +0100] 159.65.54.215 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:06:35:00 +0100] 125.31.44.122 TLSv1.2 AES256-SHA "GET /2005/license.txt HTTP/1.1" 318 [24/Jan/2023:07:09:19 +0100] 198.199.117.72 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:07:26:14 +0100] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:07:44:08 +0100] 142.93.185.161 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [24/Jan/2023:07:44:10 +0100] 142.93.185.161 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 754 [24/Jan/2023:07:44:12 +0100] 142.93.185.161 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 1150 [24/Jan/2023:09:52:29 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [24/Jan/2023:09:52:30 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /sdk HTTP/1.1" 386 [24/Jan/2023:09:52:30 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /nmaplowercheck1674550349 HTTP/1.1" 407 [24/Jan/2023:09:52:31 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /HNAP1 HTTP/1.1" 388 [24/Jan/2023:09:52:31 +0100] 103.187.190.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /evox/about HTTP/1.1" 393 [24/Jan/2023:09:52:32 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [24/Jan/2023:09:52:33 +0100] 103.187.190.56 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [24/Jan/2023:09:54:05 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [24/Jan/2023:09:56:23 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.tar.gz HTTP/1.1" 406 [24/Jan/2023:10:25:09 +0100] 102.36.157.181 TLSv1.2 AES256-SHA "GET /2006/license.txt HTTP/1.1" 306 [24/Jan/2023:10:54:13 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:11:10:50 +0100] 125.143.141.56 TLSv1.2 AES256-SHA "GET /2006/license.txt HTTP/1.1" 318 [24/Jan/2023:11:12:41 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [24/Jan/2023:11:41:59 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.gz HTTP/1.1" 385 [24/Jan/2023:11:49:29 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.gz HTTP/1.1" 402 [24/Jan/2023:12:25:18 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [24/Jan/2023:13:11:04 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [24/Jan/2023:13:20:43 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.bz2 HTTP/1.1" 395 [24/Jan/2023:13:29:15 +0100] 198.235.24.164 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 398 [24/Jan/2023:13:42:18 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [24/Jan/2023:14:15:31 +0100] 154.89.5.78 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [24/Jan/2023:14:19:50 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "-" - [24/Jan/2023:14:53:23 +0100] 198.235.24.168 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [24/Jan/2023:15:02:06 +0100] 112.218.233.148 TLSv1.2 AES256-SHA "GET /2007/license.txt HTTP/1.1" 306 [24/Jan/2023:15:10:41 +0100] 51.15.205.3 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [24/Jan/2023:15:11:10 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [24/Jan/2023:15:14:36 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [24/Jan/2023:15:14:39 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [24/Jan/2023:15:14:44 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /.DS_Store HTTP/1.1" 307 [24/Jan/2023:15:14:44 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /.env HTTP/1.1" 304 [24/Jan/2023:15:14:45 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /idx_config/ HTTP/1.1" 310 [24/Jan/2023:15:14:46 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /telescope/requests HTTP/1.1" 311 [24/Jan/2023:15:14:46 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /info.php HTTP/1.1" 307 [24/Jan/2023:15:14:47 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [24/Jan/2023:15:14:47 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /server-status HTTP/1.1" 308 [24/Jan/2023:15:14:48 +0100] 35.216.240.37 TLSv1.2 AES256-SHA "GET /config.json HTTP/1.1" 311 [24/Jan/2023:15:19:11 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /local.7z HTTP/1.1" 402 [24/Jan/2023:15:32:28 +0100] 45.134.144.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [24/Jan/2023:15:48:12 +0100] 114.79.137.190 TLSv1.2 AES256-SHA "GET /2007/license.txt HTTP/1.1" 319 [24/Jan/2023:16:09:36 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [24/Jan/2023:16:38:38 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [24/Jan/2023:17:18:02 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.zip HTTP/1.1" 405 [24/Jan/2023:17:31:12 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:18:37:31 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:19:06:38 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.tar HTTP/1.1" 405 [24/Jan/2023:19:25:04 +0100] 107.170.239.28 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [24/Jan/2023:19:29:04 +0100] 198.235.24.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 385 [24/Jan/2023:19:41:46 +0100] 1.36.68.145 TLSv1.2 AES256-SHA "GET /3/license.txt HTTP/1.1" 304 [24/Jan/2023:19:55:32 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [24/Jan/2023:20:17:00 +0100] 170.64.133.166 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [24/Jan/2023:20:28:46 +0100] 94.211.131.229 TLSv1.2 AES256-SHA "GET /3/license.txt HTTP/1.1" 316 [24/Jan/2023:20:42:38 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.tar.gz HTTP/1.1" 400 [24/Jan/2023:21:57:00 +0100] 106.75.186.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [24/Jan/2023:22:21:08 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.bz2 HTTP/1.1" 397 [24/Jan/2023:22:22:00 +0100] 34.220.146.146 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [24/Jan/2023:22:26:45 +0100] 34.222.5.142 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [24/Jan/2023:22:27:19 +0100] 34.216.148.42 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [24/Jan/2023:22:50:29 +0100] 50.112.34.171 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [24/Jan/2023:23:32:35 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /casa/nodes/thumbprints HTTP/1.1" 398 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /autodiscover/autodiscover.json?@abc.com/owa/?&Email=autodiscover/autodiscover.json%3F@abc.com HTTP/1.1" 484 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../ HTTP/1.1" 498 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /rest/applinks/1.0/manifest HTTP/1.1" 409 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /logon/LogonPoint/tmindex.html HTTP/1.1" 412 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /ui/h5-vsan/rest/proxy/service/com.vmware.vsan.client.services.capability.VsanCapabilityProvider/getClusterCapabilityData HTTP/1.1" 503 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1" 452 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /dana-na/../dana/html5acc/guacamole/../../../../../../etc/passwd?/dana/html5acc/guacamole/ HTTP/1.1" 374 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd HTTP/1.1" 458 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "PUT /api/v2/cmdb/system/admin/admin HTTP/1.1" 413 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aspnet-ajax/Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 434 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /ui/login.action HTTP/1.1" 391 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /secure/rest/applinks/1.0/manifest HTTP/1.1" 416 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 422 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /jira/rest/applinks/1.0/manifest HTTP/1.1" 414 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /confluence/rest/applinks/1.0/manifest HTTP/1.1" 420 [24/Jan/2023:23:32:36 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /bitbucket/rest/applinks/1.0/manifest HTTP/1.1" 419 [24/Jan/2023:23:32:37 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /bamboo/rest/applinks/1.0/manifest HTTP/1.1" 416 [24/Jan/2023:23:32:37 +0100] 146.0.75.2 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /crowd/rest/applinks/1.0/manifest HTTP/1.1" 415 [24/Jan/2023:23:34:25 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.bz2 HTTP/1.1" 388 [24/Jan/2023:23:37:53 +0100] 147.182.156.203 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [24/Jan/2023:23:37:54 +0100] 147.182.156.203 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [24/Jan/2023:23:37:58 +0100] 147.182.156.203 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Jan/2023:23:44:32 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [24/Jan/2023:23:49:07 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.7z HTTP/1.1" 404 [25/Jan/2023:00:08:36 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /storage.7z HTTP/1.1" 396 [25/Jan/2023:00:20:42 +0100] 212.166.46.154 TLSv1.2 AES256-SHA "GET /30/license.txt HTTP/1.1" 305 [25/Jan/2023:00:24:01 +0100] 34.219.180.173 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [25/Jan/2023:00:25:06 +0100] 35.87.152.75 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313 [25/Jan/2023:00:25:09 +0100] 35.87.152.75 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [25/Jan/2023:00:49:12 +0100] 120.84.11.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [25/Jan/2023:00:49:16 +0100] 120.84.11.127 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295