[25/Feb/2023:01:03:06 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [25/Feb/2023:01:07:21 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [25/Feb/2023:01:23:39 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [25/Feb/2023:01:28:21 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:01:28:52 +0100] 52.43.13.60 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [25/Feb/2023:01:29:33 +0100] 35.89.106.50 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [25/Feb/2023:01:36:04 +0100] 198.235.24.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [25/Feb/2023:01:45:10 +0100] 198.199.96.32 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [25/Feb/2023:01:51:57 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:02:12:41 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:02:31:39 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_16082022.zip HTTP/1.1" 405 [25/Feb/2023:02:53:11 +0100] 205.210.31.31 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 389 [25/Feb/2023:03:15:54 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_15082022.zip HTTP/1.1" 396 [25/Feb/2023:03:29:15 +0100] 92.118.39.109 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 310 [25/Feb/2023:03:36:31 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [25/Feb/2023:03:41:19 +0100] 198.199.108.238 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [25/Feb/2023:04:05:56 +0100] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:04:22:53 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_15082022.zip HTTP/1.1" 413 [25/Feb/2023:04:27:57 +0100] 205.210.31.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 391 [25/Feb/2023:04:32:07 +0100] 183.136.225.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [25/Feb/2023:04:32:19 +0100] 13.39.84.54 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [25/Feb/2023:04:38:07 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:04:38:54 +0100] 183.136.225.32 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [25/Feb/2023:06:11:16 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_14082022.zip HTTP/1.1" 396 [25/Feb/2023:06:49:25 +0100] 209.141.51.44 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///wp-login.php HTTP/1.1" 313 [25/Feb/2023:07:32:44 +0100] 107.170.249.24 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [25/Feb/2023:07:52:25 +0100] 51.15.251.143 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 380 [25/Feb/2023:08:37:54 +0100] 64.62.197.229 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:08:45:38 +0100] 64.62.197.235 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [25/Feb/2023:08:48:37 +0100] 64.62.197.233 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:08:50:06 +0100] 64.62.197.239 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [25/Feb/2023:09:06:01 +0100] 192.241.209.135 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:09:47:21 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_13082022.zip HTTP/1.1" 405 [25/Feb/2023:11:03:08 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_12082022.zip HTTP/1.1" 405 [25/Feb/2023:11:22:14 +0100] 167.94.145.59 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [25/Feb/2023:11:22:14 +0100] 167.94.145.59 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:11:22:14 +0100] 167.94.145.59 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [25/Feb/2023:11:48:28 +0100] 164.90.140.13 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [25/Feb/2023:11:48:29 +0100] 164.90.140.13 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [25/Feb/2023:11:48:33 +0100] 164.90.140.13 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:11:48:34 +0100] 164.90.140.13 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [25/Feb/2023:12:31:45 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_11082022.zip HTTP/1.1" 405 [25/Feb/2023:12:34:20 +0100] 170.64.156.42 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [25/Feb/2023:15:14:47 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:15:19:33 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_09082022.zip HTTP/1.1" 396 [25/Feb/2023:15:31:07 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [25/Feb/2023:15:39:25 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [25/Feb/2023:15:46:54 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [25/Feb/2023:15:51:50 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_09082022.zip HTTP/1.1" 405 [25/Feb/2023:15:56:02 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [25/Feb/2023:16:20:50 +0100] 45.134.144.119 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET ///remote/fgt_lang?lang=/../../../..//////////dev/ HTTP/1.1" 325 [25/Feb/2023:16:38:27 +0100] 167.94.146.59 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [25/Feb/2023:16:38:27 +0100] 167.94.146.59 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:16:38:27 +0100] 167.94.146.59 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [25/Feb/2023:16:47:57 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [25/Feb/2023:16:57:18 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [25/Feb/2023:17:06:30 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [25/Feb/2023:17:07:47 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_09082022.zip HTTP/1.1" 413 [25/Feb/2023:17:08:25 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [25/Feb/2023:17:17:52 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:17:27:17 +0100] 195.37.190.89 TLSv1.2 AES256-SHA "GET /projector-calibration HTTP/1.1" 315 [25/Feb/2023:17:34:04 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:17:54:14 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [25/Feb/2023:18:28:16 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [25/Feb/2023:18:49:56 +0100] 50.84.134.206 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_07082022.zip HTTP/1.1" 396 [25/Feb/2023:19:00:31 +0100] 192.241.200.48 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [25/Feb/2023:19:28:22 +0100] 88.214.26.9 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [25/Feb/2023:21:04:20 +0100] 50.84.134.206 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_06082022.zip HTTP/1.1" 405 [25/Feb/2023:21:10:16 +0100] 107.170.249.24 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [25/Feb/2023:21:23:13 +0100] 51.158.118.231 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 398 [25/Feb/2023:22:29:06 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_05082022.zip HTTP/1.1" 396 [25/Feb/2023:22:34:14 +0100] 35.93.153.0 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [25/Feb/2023:22:34:39 +0100] 35.160.239.152 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [25/Feb/2023:22:34:44 +0100] 35.160.239.152 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [25/Feb/2023:22:41:20 +0100] 45.72.48.130 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [25/Feb/2023:22:41:37 +0100] 45.72.48.130 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 302 [25/Feb/2023:22:41:39 +0100] 45.72.48.130 TLSv1.2 AES256-SHA "GET /ads.txt HTTP/1.1" 300 [26/Feb/2023:00:54:36 +0100] 34.77.127.183 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301