[16/Feb/2023:01:17:43 +0100] 35.233.62.116 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [16/Feb/2023:01:19:06 +0100] 77.74.177.119 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:01:32:48 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_11032022.zip HTTP/1.1" 427 [16/Feb/2023:01:41:34 +0100] 34.217.18.86 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:01:41:44 +0100] 34.218.226.105 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:01:41:50 +0100] 52.12.161.128 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [16/Feb/2023:01:41:54 +0100] 52.12.161.128 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:01:43:01 +0100] 35.86.164.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:02:27:02 +0100] 184.105.247.196 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:02:34:41 +0100] 184.105.247.196 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [16/Feb/2023:02:39:09 +0100] 184.105.247.196 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:02:39:39 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_10032022.zip HTTP/1.1" 403 [16/Feb/2023:02:40:18 +0100] 184.105.247.196 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [16/Feb/2023:02:52:50 +0100] 112.73.92.167 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:03:27:17 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [16/Feb/2023:03:27:19 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [16/Feb/2023:03:27:20 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 311 [16/Feb/2023:03:27:22 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 311 [16/Feb/2023:03:27:24 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 310 [16/Feb/2023:03:27:24 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 310 [16/Feb/2023:03:27:25 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 310 [16/Feb/2023:03:27:25 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 310 [16/Feb/2023:03:27:27 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 308 [16/Feb/2023:03:27:29 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 308 [16/Feb/2023:03:27:32 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 306 [16/Feb/2023:03:27:33 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 306 [16/Feb/2023:03:27:35 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 309 [16/Feb/2023:03:27:35 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 309 [16/Feb/2023:03:27:36 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 307 [16/Feb/2023:03:27:36 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 307 [16/Feb/2023:03:27:39 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 307 [16/Feb/2023:03:27:40 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 307 [16/Feb/2023:03:27:41 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 307 [16/Feb/2023:03:27:41 +0100] 109.237.98.226 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 307 [16/Feb/2023:04:50:27 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_09032022.zip HTTP/1.1" 427 [16/Feb/2023:05:37:54 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 387 [16/Feb/2023:06:17:34 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_08032022.zip HTTP/1.1" 403 [16/Feb/2023:06:40:12 +0100] 51.103.121.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /cgi-bin/luci HTTP/1.1" 395 [16/Feb/2023:07:14:02 +0100] 195.37.190.89 TLSv1.2 AES256-SHA "GET /sockjs/244/ewogzjot/websocket HTTP/1.1" 322 [16/Feb/2023:07:19:59 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [16/Feb/2023:07:42:23 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_08032022.zip HTTP/1.1" 427 [16/Feb/2023:08:09:45 +0100] 161.35.213.94 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:08:09:46 +0100] 161.35.213.94 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [16/Feb/2023:08:13:21 +0100] 161.35.213.94 TLSv1.2 AES256-SHA "GET /HNAP1 HTTP/1.1" 305 [16/Feb/2023:08:13:22 +0100] 161.35.213.94 TLSv1.2 AES256-SHA "GET /PSIA/index HTTP/1.1" 309 [16/Feb/2023:08:13:23 +0100] 161.35.213.94 TLSv1.2 AES256-SHA "POST /onvif/device_service HTTP/1.1" 314 [16/Feb/2023:08:33:41 +0100] 162.243.148.24 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:09:17:23 +0100] 34.159.97.116 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "OPTIONS / HTTP/1.0" 383 [16/Feb/2023:09:19:06 +0100] 167.71.235.55 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [16/Feb/2023:09:19:08 +0100] 167.71.235.55 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [16/Feb/2023:09:19:14 +0100] 167.71.235.55 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:09:19:15 +0100] 167.71.235.55 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [16/Feb/2023:10:07:42 +0100] 192.241.196.59 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [16/Feb/2023:10:17:16 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_06032022.zip HTTP/1.1" 394 [16/Feb/2023:10:46:36 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:11:14:26 +0100] 24.142.190.18 TLSv1.2 AES256-SHA "GET /cgi-bin/login?LD_DEBUG=files HTTP/1.1" 325 [16/Feb/2023:11:14:34 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [16/Feb/2023:11:16:51 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:11:17:15 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [16/Feb/2023:11:17:56 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [16/Feb/2023:11:32:40 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_06032022.zip HTTP/1.1" 427 [16/Feb/2023:11:38:05 +0100] 103.56.61.147 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [16/Feb/2023:11:38:06 +0100] 103.56.61.147 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:11:38:09 +0100] 103.56.61.147 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [16/Feb/2023:11:38:14 +0100] 103.56.61.147 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [16/Feb/2023:11:38:16 +0100] 103.56.61.147 TLSv1.2 AES256-SHA "GET /.well-known/security.txt HTTP/1.1" 319 [16/Feb/2023:11:38:48 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [16/Feb/2023:11:54:27 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [16/Feb/2023:13:11:07 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [16/Feb/2023:13:24:53 +0100] 157.55.39.225 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 302 [16/Feb/2023:13:24:55 +0100] 157.55.39.225 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 302 [16/Feb/2023:13:25:02 +0100] 157.55.39.22 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:13:27:58 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_05032022.zip HTTP/1.1" 427 [16/Feb/2023:13:34:33 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [16/Feb/2023:14:01:42 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [16/Feb/2023:14:34:15 +0100] 167.94.138.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [16/Feb/2023:14:34:16 +0100] 167.94.138.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:14:34:16 +0100] 167.94.138.60 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [16/Feb/2023:14:37:59 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:15:04:41 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:15:13:42 +0100] 134.122.40.235 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [16/Feb/2023:15:13:44 +0100] 134.122.40.235 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [16/Feb/2023:15:13:54 +0100] 134.122.40.235 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:15:13:55 +0100] 134.122.40.235 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [16/Feb/2023:15:14:09 +0100] 134.122.40.235 - - "-" - [16/Feb/2023:15:14:10 +0100] 134.122.40.235 - - "-" - [16/Feb/2023:15:23:43 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 403 [16/Feb/2023:15:35:27 +0100] 162.142.125.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [16/Feb/2023:15:35:28 +0100] 162.142.125.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:15:35:28 +0100] 162.142.125.211 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [16/Feb/2023:15:36:41 +0100] 143.244.41.219 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.1" - [16/Feb/2023:15:44:31 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:15:53:47 +0100] 107.170.251.10 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [16/Feb/2023:15:56:19 +0100] 193.118.55.170 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [16/Feb/2023:16:17:09 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [16/Feb/2023:16:26:24 +0100] 193.235.141.125 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [16/Feb/2023:18:11:50 +0100] 154.89.5.196 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [16/Feb/2023:19:00:24 +0100] 146.190.119.114 TLSv1.2 AES256-SHA "GET /aaa9 HTTP/1.1" 304 [16/Feb/2023:19:00:27 +0100] 146.190.119.114 TLSv1.2 AES256-SHA "GET /aab8 HTTP/1.1" 304 [16/Feb/2023:19:14:17 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [16/Feb/2023:19:21:17 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:19:21:41 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [16/Feb/2023:19:22:22 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [16/Feb/2023:19:30:02 +0100] 23.90.160.114 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:19:37:33 +0100] 107.170.241.29 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [16/Feb/2023:19:55:24 +0100] 167.248.133.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [16/Feb/2023:19:55:24 +0100] 167.248.133.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:19:55:25 +0100] 167.248.133.60 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [16/Feb/2023:20:14:08 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_02032022.zip HTTP/1.1" 394 [16/Feb/2023:20:22:51 +0100] 192.241.194.9 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [16/Feb/2023:20:26:09 +0100] 51.158.118.231 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 391 [16/Feb/2023:20:47:16 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 310 [16/Feb/2023:20:47:17 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 310 [16/Feb/2023:20:47:18 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 317 [16/Feb/2023:20:47:19 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 317 [16/Feb/2023:20:47:20 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 315 [16/Feb/2023:20:47:20 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 315 [16/Feb/2023:20:47:21 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 316 [16/Feb/2023:20:47:22 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 316 [16/Feb/2023:20:47:22 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 314 [16/Feb/2023:20:47:23 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 314 [16/Feb/2023:20:47:24 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 312 [16/Feb/2023:20:47:25 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 312 [16/Feb/2023:20:47:26 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 315 [16/Feb/2023:20:47:27 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 315 [16/Feb/2023:20:47:27 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 313 [16/Feb/2023:20:47:28 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 313 [16/Feb/2023:20:47:29 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 312 [16/Feb/2023:20:47:30 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 312 [16/Feb/2023:20:47:30 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 312 [16/Feb/2023:20:47:31 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 312 [16/Feb/2023:21:09:51 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /klub_02032022.zip HTTP/1.1" 403 [16/Feb/2023:21:21:05 +0100] 43.129.97.125 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [16/Feb/2023:21:21:31 +0100] 43.129.97.125 - - "-" - [16/Feb/2023:22:35:36 +0100] 35.206.194.63 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "" 379 [16/Feb/2023:22:39:49 +0100] 45.134.144.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [16/Feb/2023:22:44:05 +0100] 51.158.118.231 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [16/Feb/2023:22:55:34 +0100] 87.236.176.163 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [17/Feb/2023:00:15:23 +0100] 54.244.111.30 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [17/Feb/2023:00:16:15 +0100] 54.189.174.49 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [17/Feb/2023:00:41:27 +0100] 185.180.143.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301