[06/Feb/2023:01:09:13 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:02:50:07 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_29072022.zip HTTP/1.1" 427 [06/Feb/2023:04:06:11 +0100] 141.98.10.56 - - "-" - [06/Feb/2023:04:09:53 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 298 [06/Feb/2023:04:09:54 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 298 [06/Feb/2023:04:09:54 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 304 [06/Feb/2023:04:09:55 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_28072022.zip HTTP/1.1" 394 [06/Feb/2023:04:09:55 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 304 [06/Feb/2023:04:09:56 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 303 [06/Feb/2023:04:09:56 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 303 [06/Feb/2023:04:09:57 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 304 [06/Feb/2023:04:09:58 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 304 [06/Feb/2023:04:09:58 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 302 [06/Feb/2023:04:09:59 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 302 [06/Feb/2023:04:10:00 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 300 [06/Feb/2023:04:10:00 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 300 [06/Feb/2023:04:10:01 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 303 [06/Feb/2023:04:10:02 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 303 [06/Feb/2023:04:10:02 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 301 [06/Feb/2023:04:10:03 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 301 [06/Feb/2023:04:10:03 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 300 [06/Feb/2023:04:10:04 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 300 [06/Feb/2023:04:10:04 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 300 [06/Feb/2023:04:10:05 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 300 [06/Feb/2023:04:15:04 +0100] 46.8.16.187 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [06/Feb/2023:04:19:52 +0100] 43.153.208.98 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:04:20:22 +0100] 43.153.208.98 - - "-" - [06/Feb/2023:04:20:29 +0100] 43.153.208.98 - - "-" - [06/Feb/2023:04:32:52 +0100] 193.106.29.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [06/Feb/2023:04:41:31 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_27072022.zip HTTP/1.1" 427 [06/Feb/2023:05:45:46 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:06:19:43 +0100] 54.36.148.224 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 304 [06/Feb/2023:06:19:44 +0100] 54.36.148.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [06/Feb/2023:06:41:58 +0100] 134.209.105.17 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /dns-query?dns=DUIBAAABAAAAAAAABWJhaWR1A2NvbQAAAQAB HTTP/1.1" 338 [06/Feb/2023:06:45:49 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_26072022.zip HTTP/1.1" 403 [06/Feb/2023:07:12:02 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:07:35:23 +0100] 192.241.206.6 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:08:14:32 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [06/Feb/2023:08:39:30 +0100] 193.235.141.11 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 306 [06/Feb/2023:08:46:06 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_24072022.zip HTTP/1.1" 427 [06/Feb/2023:08:52:01 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [06/Feb/2023:08:52:03 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:08:52:20 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:08:52:34 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Feb/2023:08:52:51 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /favicon.ico/ HTTP/1.1" 309 [06/Feb/2023:08:53:21 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [06/Feb/2023:08:53:30 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /robots.txt/ HTTP/1.1" 309 [06/Feb/2023:08:53:45 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /.well-known/security.txt HTTP/1.1" 319 [06/Feb/2023:08:54:05 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /.well-known/security.txt/ HTTP/1.1" 319 [06/Feb/2023:08:57:46 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:09:22:48 +0100] 192.241.213.74 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [06/Feb/2023:09:24:13 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_23072022.zip HTTP/1.1" 403 [06/Feb/2023:10:28:56 +0100] 91.240.118.188 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [06/Feb/2023:10:41:28 +0100] 128.14.141.34 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:10:43:46 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_22072022.zip HTTP/1.1" 394 [06/Feb/2023:11:02:27 +0100] 71.6.232.24 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:11:23:59 +0100] 64.62.197.105 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:11:30:21 +0100] 64.62.197.97 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [06/Feb/2023:11:33:25 +0100] 64.62.197.98 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:11:34:25 +0100] 64.62.197.106 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [06/Feb/2023:12:05:19 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_21072022.zip HTTP/1.1" 394 [06/Feb/2023:12:24:43 +0100] 51.222.253.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 302 [06/Feb/2023:12:24:44 +0100] 54.36.148.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [06/Feb/2023:13:35:38 +0100] 63.32.89.89 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [06/Feb/2023:14:17:24 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:14:17:24 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:14:17:25 +0100] 167.248.133.62 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Feb/2023:14:21:08 +0100] 176.58.124.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [06/Feb/2023:14:51:16 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_19072022.zip HTTP/1.1" 427 [06/Feb/2023:15:12:39 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:15:25:20 +0100] 46.8.16.187 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [06/Feb/2023:17:48:49 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_17072022.zip HTTP/1.1" 394 [06/Feb/2023:18:01:58 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_16072022.zip HTTP/1.1" 427 [06/Feb/2023:18:24:29 +0100] 141.98.10.56 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:18:32:17 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_17072022.zip HTTP/1.1" 403 [06/Feb/2023:19:27:45 +0100] 193.235.141.125 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [06/Feb/2023:19:33:20 +0100] 192.241.199.29 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [06/Feb/2023:20:28:30 +0100] 192.241.210.65 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [06/Feb/2023:21:30:30 +0100] 162.142.125.222 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [06/Feb/2023:21:30:31 +0100] 162.142.125.222 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [06/Feb/2023:21:30:31 +0100] 162.142.125.222 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [06/Feb/2023:22:19:28 +0100] 18.246.72.185 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:20:07 +0100] 34.209.214.62 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:20:14 +0100] 54.213.247.44 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [06/Feb/2023:22:20:19 +0100] 54.213.247.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:20:37 +0100] 34.222.163.11 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:20:39 +0100] 54.186.128.205 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [06/Feb/2023:22:20:39 +0100] 34.210.250.224 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:21:26 +0100] 35.92.34.159 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:23:24 +0100] 34.222.81.137 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:23:46 +0100] 54.244.110.196 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [06/Feb/2023:22:25:59 +0100] 128.1.248.42 TLSv1.2 AES256-SHA "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 330 [06/Feb/2023:23:43:48 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 394 [06/Feb/2023:23:43:48 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 384 [06/Feb/2023:23:44:18 +0100] 54.39.250.87 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [06/Feb/2023:23:49:48 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [07/Feb/2023:00:05:20 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "-" - [07/Feb/2023:00:05:36 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Feb/2023:00:05:39 +0100] 36.156.28.131 - - "-" - [07/Feb/2023:00:05:51 +0100] 36.156.28.131 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Feb/2023:00:22:07 +0100] 34.217.96.243 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [07/Feb/2023:00:22:44 +0100] 54.68.46.187 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [07/Feb/2023:00:26:23 +0100] 62.233.50.251 - - "-" - [07/Feb/2023:00:31:05 +0100] 152.32.202.139 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [07/Feb/2023:00:31:07 +0100] 152.32.202.139 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [07/Feb/2023:00:31:09 +0100] 152.32.202.139 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [07/Feb/2023:00:31:16 +0100] 152.32.202.139 TLSv1.2 AES256-SHA "GET /sitemap.xml HTTP/1.1" 309 [07/Feb/2023:00:47:33 +0100] 62.233.50.251 - - "-" - [07/Feb/2023:00:53:40 +0100] 87.236.176.135 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [07/Feb/2023:00:59:40 +0100] 130.211.54.158 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301