[23/Feb/2023:01:08:27 +0100] 35.195.93.98 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Feb/2023:01:14:30 +0100] 51.161.104.91 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "PUT /api/v2/cmdb/system/admin/admin HTTP/1.1" 319 [23/Feb/2023:01:41:43 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_13092022.zip HTTP/1.1" 396 [23/Feb/2023:01:42:02 +0100] 18.237.170.76 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Feb/2023:01:42:33 +0100] 34.220.27.4 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [23/Feb/2023:01:42:37 +0100] 34.220.27.4 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Feb/2023:02:21:20 +0100] 54.36.148.229 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 304 [23/Feb/2023:02:21:22 +0100] 54.36.148.169 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [23/Feb/2023:02:21:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [23/Feb/2023:02:21:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [23/Feb/2023:02:21:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 307 [23/Feb/2023:02:21:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /core/.env HTTP/1.1" 307 [23/Feb/2023:02:21:57 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [23/Feb/2023:02:21:57 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 307 [23/Feb/2023:02:43:28 +0100] 104.168.147.97 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /wordpress/wp-admin/setup-config.php?step=1 HTTP/1.1" 419 [23/Feb/2023:03:05:26 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_12092022.zip HTTP/1.1" 405 [23/Feb/2023:03:59:07 +0100] 54.36.148.137 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 302 [23/Feb/2023:03:59:09 +0100] 54.36.148.149 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [23/Feb/2023:04:36:02 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_12092022.zip HTTP/1.1" 396 [23/Feb/2023:04:55:39 +0100] 94.102.61.7 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Feb/2023:04:59:57 +0100] 94.102.61.7 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Feb/2023:05:01:10 +0100] 183.136.225.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [23/Feb/2023:05:01:39 +0100] 183.136.225.46 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [23/Feb/2023:05:01:44 +0100] 183.136.225.46 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [23/Feb/2023:05:02:16 +0100] 183.136.225.46 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 314 [23/Feb/2023:05:08:32 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_11092022.zip HTTP/1.1" 396 [23/Feb/2023:05:40:34 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Feb/2023:05:40:35 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [23/Feb/2023:05:40:35 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [23/Feb/2023:05:40:36 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [23/Feb/2023:05:40:36 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [23/Feb/2023:05:40:37 +0100] 179.60.149.55 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 292 [23/Feb/2023:05:59:33 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:06:09:33 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [23/Feb/2023:06:15:10 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:06:16:56 +0100] 65.49.20.69 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [23/Feb/2023:07:29:35 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [23/Feb/2023:08:18:46 +0100] 81.89.113.231 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_10092022.zip HTTP/1.1" 396 [23/Feb/2023:09:01:17 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_09092022.zip HTTP/1.1" 405 [23/Feb/2023:09:02:19 +0100] 104.43.18.50 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_09092022.zip HTTP/1.1" 413 [23/Feb/2023:09:04:48 +0100] 104.131.128.22 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:09:58:42 +0100] 50.84.134.206 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_08092022.zip HTTP/1.1" 405 [23/Feb/2023:10:03:55 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_08092022.zip HTTP/1.1" 396 [23/Feb/2023:10:03:59 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_08092022.zip HTTP/1.1" 413 [23/Feb/2023:11:55:18 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 310 [23/Feb/2023:11:55:19 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 310 [23/Feb/2023:11:55:20 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 317 [23/Feb/2023:11:55:20 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 317 [23/Feb/2023:11:55:21 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/config HTTP/1.1" 315 [23/Feb/2023:11:55:22 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/config HTTP/1.1" 315 [23/Feb/2023:11:55:23 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /aws/credentials HTTP/1.1" 316 [23/Feb/2023:11:55:23 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /aws/credentials HTTP/1.1" 316 [23/Feb/2023:11:55:24 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /credentials HTTP/1.1" 314 [23/Feb/2023:11:55:24 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /credentials HTTP/1.1" 314 [23/Feb/2023:11:55:25 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /test.php HTTP/1.1" 312 [23/Feb/2023:11:55:26 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /test.php HTTP/1.1" 312 [23/Feb/2023:11:55:26 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /laravel/.env HTTP/1.1" 315 [23/Feb/2023:11:55:27 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /laravel/.env HTTP/1.1" 315 [23/Feb/2023:11:55:28 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /demo/.env HTTP/1.1" 313 [23/Feb/2023:11:55:29 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /demo/.env HTTP/1.1" 313 [23/Feb/2023:11:55:29 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /web/.env HTTP/1.1" 312 [23/Feb/2023:11:55:30 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /web/.env HTTP/1.1" 312 [23/Feb/2023:11:55:31 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /phpinfo HTTP/1.1" 312 [23/Feb/2023:11:55:31 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /phpinfo HTTP/1.1" 312 [23/Feb/2023:11:55:32 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /admin/.env HTTP/1.1" 314 [23/Feb/2023:11:55:33 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /admin/.env HTTP/1.1" 314 [23/Feb/2023:11:55:33 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backend/.env HTTP/1.1" 315 [23/Feb/2023:11:55:34 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /backend/.env HTTP/1.1" 315 [23/Feb/2023:11:55:35 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /app/.env HTTP/1.1" 312 [23/Feb/2023:11:55:35 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /app/.env HTTP/1.1" 312 [23/Feb/2023:12:13:00 +0100] 143.244.41.219 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "-" - [23/Feb/2023:12:13:20 +0100] 185.180.143.79 TLSv1.2 AES256-SHA "GET /sugar_version.json HTTP/1.1" 313 [23/Feb/2023:12:37:15 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [23/Feb/2023:13:01:20 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 404 [23/Feb/2023:13:10:57 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_06092022.zip HTTP/1.1" 413 [23/Feb/2023:13:17:50 +0100] 188.166.25.230 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:13:19:53 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_06092022.zip HTTP/1.1" 396 [23/Feb/2023:13:20:53 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [23/Feb/2023:13:49:57 +0100] 163.172.180.25 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 397 [23/Feb/2023:14:16:57 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_05092022.zip HTTP/1.1" 405 [23/Feb/2023:14:19:57 +0100] 162.142.125.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:14:19:58 +0100] 162.142.125.211 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [23/Feb/2023:15:16:05 +0100] 159.203.208.12 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [23/Feb/2023:15:32:08 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_04092022.zip HTTP/1.1" 396 [23/Feb/2023:15:34:54 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_04092022.zip HTTP/1.1" 405 [23/Feb/2023:16:19:07 +0100] 179.43.154.247 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [23/Feb/2023:16:29:13 +0100] 193.118.53.210 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:16:50:13 +0100] 103.203.59.1 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [23/Feb/2023:17:02:18 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_03092022.zip HTTP/1.1" 405 [23/Feb/2023:18:01:55 +0100] 139.99.9.160 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [23/Feb/2023:18:15:54 +0100] 193.235.141.125 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [23/Feb/2023:18:19:17 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_02092022.zip HTTP/1.1" 405 [23/Feb/2023:19:22:29 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [23/Feb/2023:19:32:46 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_01092022.zip HTTP/1.1" 396 [23/Feb/2023:19:37:55 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 300 [23/Feb/2023:19:37:55 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 297 [23/Feb/2023:19:37:55 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 303 [23/Feb/2023:19:37:55 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /core/.env HTTP/1.1" 303 [23/Feb/2023:19:37:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 297 [23/Feb/2023:19:37:56 +0100] 194.163.154.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /core/.env HTTP/1.1" 303 [23/Feb/2023:19:41:31 +0100] 128.1.248.42 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:20:06:48 +0100] 43.129.36.145 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [23/Feb/2023:20:07:04 +0100] 209.141.33.65 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:20:07:06 +0100] 209.141.33.65 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [23/Feb/2023:20:07:06 +0100] 209.141.35.128 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [23/Feb/2023:20:07:07 +0100] 209.141.35.128 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:20:07:08 +0100] 209.141.49.169 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [23/Feb/2023:20:07:09 +0100] 209.141.36.231 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [23/Feb/2023:20:07:09 +0100] 205.185.122.184 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [23/Feb/2023:20:07:10 +0100] 209.141.55.120 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [23/Feb/2023:20:07:12 +0100] 205.185.116.89 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [23/Feb/2023:20:07:15 +0100] 205.185.122.184 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [23/Feb/2023:20:07:15 +0100] 209.141.41.193 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [23/Feb/2023:20:07:17 +0100] 209.141.51.222 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 305 [23/Feb/2023:20:07:20 +0100] 205.185.116.25 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 308 [23/Feb/2023:20:07:25 +0100] 209.141.35.128 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [23/Feb/2023:20:07:28 +0100] 209.141.36.112 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [23/Feb/2023:20:19:35 +0100] 198.199.101.225 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [23/Feb/2023:21:57:22 +0100] 51.254.49.109 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [23/Feb/2023:22:27:17 +0100] 192.241.236.40 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [23/Feb/2023:22:39:54 +0100] 194.110.203.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_31082022.zip HTTP/1.1" 405 [23/Feb/2023:23:09:17 +0100] 165.154.128.103 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [23/Feb/2023:23:17:41 +0100] 117.187.173.3 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [24/Feb/2023:00:05:26 +0100] 185.224.128.236 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [24/Feb/2023:00:14:23 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_29082022.zip HTTP/1.1" 405 [24/Feb/2023:00:27:57 +0100] 35.165.105.135 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [24/Feb/2023:00:28:20 +0100] 35.92.200.164 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313 [24/Feb/2023:00:28:26 +0100] 35.92.200.164 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306