[26/Jan/2023:01:39:36 +0100] 139.59.106.172 TLSv1.2 AES256-SHA "GET /aaa9 HTTP/1.1" 304 [26/Jan/2023:01:39:38 +0100] 139.59.106.172 TLSv1.2 AES256-SHA "GET /aab8 HTTP/1.1" 304 [26/Jan/2023:01:48:18 +0100] 18.237.174.162 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [26/Jan/2023:04:16:31 +0100] 185.110.91.120 TLSv1.2 AES256-SHA "GET /Admin/license.txt HTTP/1.1" 306 [26/Jan/2023:05:05:23 +0100] 115.90.156.61 TLSv1.2 AES256-SHA "GET /Admin/license.txt HTTP/1.1" 319 [26/Jan/2023:05:20:15 +0100] 66.240.236.109 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:05:27:54 +0100] 162.142.125.213 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [26/Jan/2023:05:27:55 +0100] 162.142.125.213 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:05:27:55 +0100] 162.142.125.213 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [26/Jan/2023:05:31:12 +0100] 167.248.133.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [26/Jan/2023:05:31:13 +0100] 167.248.133.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:05:31:13 +0100] 167.248.133.120 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [26/Jan/2023:05:40:31 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 404 [26/Jan/2023:06:23:50 +0100] 104.244.75.243 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///wp-login.php HTTP/1.1" 313 [26/Jan/2023:07:08:55 +0100] 85.209.135.214 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [26/Jan/2023:07:08:56 +0100] 85.209.135.214 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [26/Jan/2023:07:18:01 +0100] 198.199.108.188 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:07:38:27 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /docker-compose-production.yaml HTTP/1.1" 407 [26/Jan/2023:07:45:12 +0100] 128.14.133.58 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:08:12:56 +0100] 178.128.22.52 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [26/Jan/2023:08:12:58 +0100] 178.128.22.52 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [26/Jan/2023:08:13:07 +0100] 178.128.22.52 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:08:13:23 +0100] 178.128.22.52 - - "-" - [26/Jan/2023:08:28:11 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /stager.zip HTTP/1.1" 396 [26/Jan/2023:09:12:47 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [26/Jan/2023:09:15:44 +0100] 138.19.235.243 TLSv1.2 AES256-SHA "GET /Administration/license.txt HTTP/1.1" 313 [26/Jan/2023:09:20:23 +0100] 193.56.29.26 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [26/Jan/2023:09:20:23 +0100] 193.56.29.26 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [26/Jan/2023:09:49:36 +0100] 162.243.132.21 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [26/Jan/2023:09:58:47 +0100] 51.222.253.13 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 315 [26/Jan/2023:09:58:53 +0100] 54.36.148.173 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 308 [26/Jan/2023:10:05:39 +0100] 185.110.91.120 TLSv1.2 AES256-SHA "GET /Administration/license.txt HTTP/1.1" 325 [26/Jan/2023:11:03:21 +0100] 159.89.157.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [26/Jan/2023:13:09:57 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /docker-compose.yaml HTTP/1.1" 396 [26/Jan/2023:13:43:23 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /docker-compose.yaml HTTP/1.1" 413 [26/Jan/2023:14:22:00 +0100] 60.173.195.214 TLSv1.2 AES256-SHA "GET /Archive/license.txt HTTP/1.1" 307 [26/Jan/2023:14:38:37 +0100] 103.153.254.110 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:15:12:06 +0100] 66.153.174.87 TLSv1.2 AES256-SHA "GET /Archive/license.txt HTTP/1.1" 320 [26/Jan/2023:15:29:31 +0100] 198.199.115.100 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [26/Jan/2023:15:49:35 +0100] 192.241.218.17 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [26/Jan/2023:16:20:52 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Dockerfile HTTP/1.1" 387 [26/Jan/2023:16:42:32 +0100] 23.251.102.74 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:16:53:27 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Dockerfile HTTP/1.1" 404 [26/Jan/2023:17:41:17 +0100] 68.183.234.144 TLSv1.2 AES256-SHA "GET /aaa9 HTTP/1.1" 304 [26/Jan/2023:17:41:19 +0100] 68.183.234.144 TLSv1.2 AES256-SHA "GET /aab8 HTTP/1.1" 304 [26/Jan/2023:18:08:10 +0100] 185.180.143.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:18:08:20 +0100] 185.180.143.79 TLSv1.2 AES256-SHA "HEAD /icons/sphere1.png HTTP/1.1" - [26/Jan/2023:18:31:04 +0100] 45.134.144.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [26/Jan/2023:19:10:20 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env.dev HTTP/1.1" 402 [26/Jan/2023:19:20:06 +0100] 35.212.26.22 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [26/Jan/2023:19:21:45 +0100] 35.211.164.203 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [26/Jan/2023:19:25:57 +0100] 162.243.130.6 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [26/Jan/2023:19:46:15 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"method\":\"login\",\"params\":{\"login\":\"45JymPWP1DeQxxMZNJv9w2bTQ2WJDAmw18wUSryDQa3RPrympJPoUSVcFEDv3bhiMJGWaCD4a3KrFCorJHCMqXJUKApSKDV\",\"pass\":\"xxoo\",\"agent\":\"xmr-stak-cpu/1.3.0-1.5.0\"},\"id\":1}" 379 [26/Jan/2023:19:46:17 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"id\":1,\"method\":\"mining.subscribe\",\"params\":[]}" 379 [26/Jan/2023:19:46:19 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"params\": [\"miner1\", \"password\"], \"id\": 2, \"method\": \"mining.authorize\"}" 379 [26/Jan/2023:19:46:21 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"blue1\",\"pass\":\"x\",\"agent\":\"Windows NT 6.1; Win64; x64\"}}" 379 [26/Jan/2023:19:46:22 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"params\": [\"miner1\", \"bf\", \"00000001\", \"504e86ed\", \"b2957c02\"], \"id\": 4, \"method\": \"mining.submit\"}" 379 [26/Jan/2023:19:46:24 +0100] 106.75.177.6 TLSv1.2 AES256-SHA "{\"id\":1,\"jsonrpc\":\"2.0\",\"method\":\"login\",\"params\":{\"login\":\"x\",\"pass\":\"null\",\"agent\":\"XMRig/5.13.1\",\"algo\":[\"cn/1\",\"cn/2\",\"cn/r\",\"cn/fast\",\"cn/half\",\"cn/xao\",\"cn/rto\",\"cn/rwz\",\"cn/zls\",\"cn/double\",\"rx/0\",\"rx/wow\",\"rx/loki\",\"rx/arq\",\"rx/sfx\",\"rx/keva\"]}}" 379 [26/Jan/2023:20:21:54 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [26/Jan/2023:20:24:07 +0100] 172.105.161.246 TLSv1.2 AES256-SHA "GET /owa/ HTTP/1.1" 304 [26/Jan/2023:20:24:10 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [26/Jan/2023:20:24:22 +0100] 172.105.161.246 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?a..foo.var/owa/?&Email=autodiscover/autodiscover.json?a..foo.var&Protocol=XYZ&FooProtocol=%50owershell HTTP/1.1" 378 [26/Jan/2023:20:34:52 +0100] 193.118.53.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:20:55:18 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /stager2.zip HTTP/1.1" 397 [26/Jan/2023:21:45:54 +0100] 178.33.221.232 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [26/Jan/2023:21:45:54 +0100] 178.33.221.232 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [26/Jan/2023:22:21:51 +0100] 95.111.230.235 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [26/Jan/2023:22:28:04 +0100] 60.217.75.70 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [26/Jan/2023:23:15:59 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /release.zip HTTP/1.1" 397 [26/Jan/2023:23:28:24 +0100] 95.215.205.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 394 [26/Jan/2023:23:32:05 +0100] 109.237.98.53 - - "-" - [26/Jan/2023:23:33:02 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /debug.zip HTTP/1.1" 395 [26/Jan/2023:23:45:57 +0100] 35.233.62.116 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [26/Jan/2023:23:48:04 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web.env HTTP/1.1" 384 [26/Jan/2023:23:53:47 +0100] 95.215.205.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 389 [26/Jan/2023:23:55:31 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_release.zip HTTP/1.1" 402 [27/Jan/2023:00:13:31 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [27/Jan/2023:00:13:58 +0100] 95.215.205.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 386 [27/Jan/2023:00:45:00 +0100] 185.180.143.136 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [27/Jan/2023:00:52:46 +0100] 193.118.53.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301