[21/Feb/2023:01:00:13 +0100] 128.14.134.134 TLSv1.2 AES256-SHA "GET /Telerik.Web.UI.WebResource.axd?type=rau HTTP/1.1" 330 [21/Feb/2023:01:12:15 +0100] 34.78.6.216 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [21/Feb/2023:01:21:55 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 396 [21/Feb/2023:01:21:56 +0100] 81.209.177.16 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 386 [21/Feb/2023:03:18:23 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /easyzumfuehrerschein_02012022.zip HTTP/1.1" 427 [21/Feb/2023:03:29:28 +0100] 193.235.141.114 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [21/Feb/2023:05:09:02 +0100] 128.14.141.34 TLSv1.2 AES256-SHA "GET /remote/login HTTP/1.1" 309 [21/Feb/2023:05:40:21 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "-" - [21/Feb/2023:05:44:13 +0100] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:05:48:34 +0100] 64.62.197.75 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:05:52:41 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /harm_01012022.zip HTTP/1.1" 394 [21/Feb/2023:05:55:40 +0100] 64.62.197.74 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [21/Feb/2023:05:58:50 +0100] 64.62.197.75 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:05:59:52 +0100] 64.62.197.71 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [21/Feb/2023:08:36:01 +0100] 66.240.236.116 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:08:37:59 +0100] 192.241.210.43 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:08:50:47 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [21/Feb/2023:08:57:30 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_2022.zip HTTP/1.1" 401 [21/Feb/2023:09:43:45 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [21/Feb/2023:11:32:53 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_092022.zip HTTP/1.1" 411 [21/Feb/2023:12:07:59 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /index.php?function=call_user_func_array&s=/Index/%9hink%7pp/invokefunction&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 391 [21/Feb/2023:12:08:02 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /TP/public/index.php?function=call_user_func_array&s=index/\\think\\app/invokefunction&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 395 [21/Feb/2023:12:08:11 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /index.php?function=call_user_func_array&s=index/%9hink%7pp/invokefunction&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [21/Feb/2023:12:32:09 +0100] 193.235.141.3 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 306 [21/Feb/2023:12:52:34 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_082022.zip HTTP/1.1" 411 [21/Feb/2023:14:26:51 +0100] 170.64.158.146 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [21/Feb/2023:14:26:55 +0100] 170.64.158.146 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [21/Feb/2023:14:27:04 +0100] 170.64.158.146 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:14:27:07 +0100] 170.64.158.146 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [21/Feb/2023:16:35:52 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_052022.zip HTTP/1.1" 394 [21/Feb/2023:16:44:39 +0100] 185.180.143.7 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:18:48:54 +0100] 167.94.138.46 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [21/Feb/2023:18:48:55 +0100] 167.94.138.46 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:18:48:55 +0100] 167.94.138.46 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [21/Feb/2023:19:06:23 +0100] 176.58.124.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 379 [21/Feb/2023:20:15:30 +0100] 107.170.250.18 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [21/Feb/2023:20:36:45 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_022022.zip HTTP/1.1" 411 [21/Feb/2023:20:48:22 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_022022.zip HTTP/1.1" 394 [21/Feb/2023:21:18:24 +0100] 185.180.143.138 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:21:21:58 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.0" 388 [21/Feb/2023:21:21:59 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:21:22:11 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:21:22:17 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [21/Feb/2023:21:22:25 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [21/Feb/2023:21:22:27 +0100] 36.156.28.130 TLSv1.2 AES256-SHA "GET /.well-known/security.txt HTTP/1.1" 319 [21/Feb/2023:21:35:40 +0100] 154.89.5.214 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [21/Feb/2023:22:01:36 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_012022.zip HTTP/1.1" 394 [21/Feb/2023:22:28:51 +0100] 35.88.93.116 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [21/Feb/2023:22:30:28 +0100] 34.220.107.100 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [21/Feb/2023:23:01:21 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_012022.zip HTTP/1.1" 403 [21/Feb/2023:23:01:31 +0100] 193.235.141.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [21/Feb/2023:23:16:27 +0100] 144.91.67.218 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_28092022.zip HTTP/1.1" 396 [21/Feb/2023:23:42:10 +0100] 185.180.143.71 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [21/Feb/2023:23:43:02 +0100] 52.187.185.143 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [22/Feb/2023:00:22:19 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393