[05/Feb/2023:01:59:05 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_19082022.zip HTTP/1.1" 394 [05/Feb/2023:02:57:57 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_18082022.zip HTTP/1.1" 427 [05/Feb/2023:03:18:00 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_18082022.zip HTTP/1.1" 403 [05/Feb/2023:03:57:16 +0100] 23.251.102.74 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:04:25:14 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_18082022.zip HTTP/1.1" 394 [05/Feb/2023:05:29:11 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_17082022.zip HTTP/1.1" 394 [05/Feb/2023:05:40:08 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_16082022.zip HTTP/1.1" 427 [05/Feb/2023:06:03:09 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:06:12:41 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [05/Feb/2023:06:16:44 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_16082022.zip HTTP/1.1" 403 [05/Feb/2023:06:17:42 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:06:19:19 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [05/Feb/2023:06:55:49 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_16082022.zip HTTP/1.1" 394 [05/Feb/2023:07:34:18 +0100] 162.243.146.31 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:08:27:03 +0100] 51.222.253.1 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 314 [05/Feb/2023:08:27:05 +0100] 54.36.148.116 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [05/Feb/2023:08:38:42 +0100] 103.149.192.152 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:09:39:10 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_13082022.zip HTTP/1.1" 403 [05/Feb/2023:10:06:51 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [05/Feb/2023:12:34:46 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_10082022.zip HTTP/1.1" 403 [05/Feb/2023:12:44:00 +0100] 162.221.192.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:13:43:16 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_10082022.zip HTTP/1.1" 427 [05/Feb/2023:13:48:54 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_09082022.zip HTTP/1.1" 403 [05/Feb/2023:13:57:19 +0100] 35.216.242.36 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:14:22:00 +0100] 91.240.118.188 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [05/Feb/2023:14:38:48 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_09082022.zip HTTP/1.1" 427 [05/Feb/2023:14:39:10 +0100] 198.235.24.153 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [05/Feb/2023:14:51:48 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_08082022.zip HTTP/1.1" 394 [05/Feb/2023:15:05:23 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_08082022.zip HTTP/1.1" 403 [05/Feb/2023:16:39:06 +0100] 183.136.225.9 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [05/Feb/2023:16:39:13 +0100] 183.136.225.9 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [05/Feb/2023:16:41:02 +0100] 23.251.102.74 TLSv1.2 AES256-SHA "GET /cgi-bin/config.exp HTTP/1.1" 315 [05/Feb/2023:17:53:04 +0100] 198.12.231.234 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_06082022.zip HTTP/1.1" 394 [05/Feb/2023:18:19:05 +0100] 104.236.128.11 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [05/Feb/2023:18:30:13 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_05082022.zip HTTP/1.1" 403 [05/Feb/2023:18:52:57 +0100] 205.210.31.185 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [05/Feb/2023:19:07:44 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [05/Feb/2023:19:33:23 +0100] 192.241.195.57 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [05/Feb/2023:20:23:49 +0100] 167.248.133.47 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:20:23:51 +0100] 167.248.133.47 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [05/Feb/2023:20:38:28 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Feb/2023:20:55:23 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Feb/2023:20:55:23 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:20:55:23 +0100] 167.94.145.60 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [05/Feb/2023:21:15:31 +0100] 164.52.0.83 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "{\"id\": 1, \"method\": \"mining.subscribe\", \"params\": [], \"jsonrpc\":\"2.0\"}" 379 [05/Feb/2023:21:54:53 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [05/Feb/2023:22:29:26 +0100] 51.15.27.89 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [05/Feb/2023:23:06:26 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_01082022.zip HTTP/1.1" 427 [05/Feb/2023:23:22:22 +0100] 193.235.141.90 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [05/Feb/2023:23:44:10 +0100] 60.217.75.70 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:23:50:15 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 383 [05/Feb/2023:23:50:18 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:23:50:30 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [05/Feb/2023:23:50:42 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [05/Feb/2023:23:50:54 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET /favicon.ico/ HTTP/1.1" 309 [05/Feb/2023:23:51:06 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [05/Feb/2023:23:51:17 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET /.well-known/security.txt HTTP/1.1" 319 [06/Feb/2023:00:19:54 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_31072022.zip HTTP/1.1" 427 [06/Feb/2023:00:37:22 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [06/Feb/2023:00:37:23 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [06/Feb/2023:00:37:23 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [06/Feb/2023:00:37:24 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [06/Feb/2023:00:37:24 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [06/Feb/2023:00:37:25 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [06/Feb/2023:00:37:25 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [06/Feb/2023:00:37:26 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [06/Feb/2023:00:37:26 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [06/Feb/2023:00:37:27 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [06/Feb/2023:00:37:27 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [06/Feb/2023:00:37:28 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [06/Feb/2023:00:37:28 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [06/Feb/2023:00:37:29 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [06/Feb/2023:00:37:30 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [06/Feb/2023:00:37:30 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [06/Feb/2023:00:37:30 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [06/Feb/2023:00:37:31 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [06/Feb/2023:00:37:32 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [06/Feb/2023:00:37:32 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [06/Feb/2023:00:54:40 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_31072022.zip HTTP/1.1" 394 [06/Feb/2023:00:59:11 +0100] 35.233.62.116 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301