[08/Mar/2023:01:51:22 +0100] 198.199.92.121 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [08/Mar/2023:01:51:26 +0100] 107.170.192.16 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [08/Mar/2023:01:54:40 +0100] 198.199.97.240 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [08/Mar/2023:02:19:55 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_22032022.zip HTTP/1.1" 396 [08/Mar/2023:02:39:53 +0100] 205.210.31.131 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 377 [08/Mar/2023:02:56:49 +0100] 3.23.113.224 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:03:08:35 +0100] 94.102.61.7 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:05:15:25 +0100] 185.233.37.155 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /wp-22.php?sfilename=xxx.php&sfilecontent=123&supfiles=xxx.php HTTP/1.1" 446 [08/Mar/2023:05:31:20 +0100] 107.170.251.10 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [08/Mar/2023:05:38:48 +0100] 24.248.225.126 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_21032022.zip HTTP/1.1" 413 [08/Mar/2023:05:39:26 +0100] 104.248.143.84 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [08/Mar/2023:05:40:49 +0100] 3.19.54.245 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [08/Mar/2023:06:23:13 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_20032022.zip HTTP/1.1" 405 [08/Mar/2023:07:00:58 +0100] 167.172.49.250 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [08/Mar/2023:07:00:59 +0100] 167.172.49.250 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [08/Mar/2023:07:01:00 +0100] 167.172.49.250 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:07:01:01 +0100] 167.172.49.250 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [08/Mar/2023:07:41:28 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [08/Mar/2023:07:58:44 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_19032022.zip HTTP/1.1" 405 [08/Mar/2023:08:02:07 +0100] 107.170.232.16 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [08/Mar/2023:08:24:30 +0100] 95.214.27.107 TLSv1.2 AES256-SHA "GET /api/index.php/v1/config/application?public=true HTTP/1.1" 334 [08/Mar/2023:08:36:22 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_19032022.zip HTTP/1.1" 413 [08/Mar/2023:08:47:46 +0100] 193.106.29.122 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [08/Mar/2023:09:23:38 +0100] 193.118.53.194 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:09:31:06 +0100] 64.62.197.183 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:09:39:07 +0100] 64.62.197.182 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [08/Mar/2023:09:42:35 +0100] 64.62.197.186 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:09:44:51 +0100] 64.62.197.190 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [08/Mar/2023:09:46:51 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_18032022.zip HTTP/1.1" 405 [08/Mar/2023:09:53:42 +0100] 72.14.188.95 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:09:54:07 +0100] 107.170.225.15 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:10:41:11 +0100] 159.203.192.14 TLSv1.2 AES256-SHA "GET /ReportServer HTTP/1.1" 307 [08/Mar/2023:10:50:50 +0100] 192.241.234.12 TLSv1.2 AES256-SHA "GET /login HTTP/1.1" 305 [08/Mar/2023:10:54:39 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_18032022.zip HTTP/1.1" 413 [08/Mar/2023:11:11:03 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_18032022.zip HTTP/1.1" 396 [08/Mar/2023:11:17:14 +0100] 162.142.125.13 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [08/Mar/2023:11:17:15 +0100] 162.142.125.13 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:11:17:15 +0100] 162.142.125.13 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [08/Mar/2023:11:46:13 +0100] 47.88.31.213 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /dns-query HTTP/1.1" 308 [08/Mar/2023:11:53:01 +0100] 94.102.61.7 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [08/Mar/2023:12:24:50 +0100] 188.166.79.236 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:12:32:49 +0100] 199.16.157.181 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 387 [08/Mar/2023:12:32:51 +0100] 199.16.157.181 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [08/Mar/2023:14:03:49 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_16032022.zip HTTP/1.1" 405 [08/Mar/2023:14:05:29 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:14:19:48 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [08/Mar/2023:14:29:37 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_16032022.zip HTTP/1.1" 413 [08/Mar/2023:14:31:53 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [08/Mar/2023:14:41:31 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [08/Mar/2023:14:47:12 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [08/Mar/2023:15:30:04 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /mifs/.;/services/LogService HTTP/1.1" 318 [08/Mar/2023:15:43:24 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /console/ HTTP/1.1" 307 [08/Mar/2023:15:50:13 +0100] 192.241.194.54 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [08/Mar/2023:15:50:57 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "POST /Autodiscover/Autodiscover.xml HTTP/1.1" 315 [08/Mar/2023:15:59:06 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /_ignition/execute-solution HTTP/1.1" 319 [08/Mar/2023:16:17:30 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:16:17:31 +0100] 128.1.248.26 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:16:17:52 +0100] 167.94.138.35 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [08/Mar/2023:16:17:53 +0100] 167.94.138.35 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:16:17:53 +0100] 167.94.138.35 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [08/Mar/2023:16:21:24 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_15032022.zip HTTP/1.1" 405 [08/Mar/2023:16:35:36 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:16:46:05 +0100] 194.37.96.187 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 297 [08/Mar/2023:17:01:33 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:17:20:11 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [08/Mar/2023:17:52:55 +0100] 152.89.196.211 TLSv1.2 AES256-SHA "GET /geoserver HTTP/1.1" 305 [08/Mar/2023:18:40:47 +0100] 185.180.143.138 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:18:40:54 +0100] 185.180.143.138 TLSv1.2 AES256-SHA "GET /dana-na/../dana/html5acc/guacamole/../../../../../../../etc/services?/dana/html5acc/guacamole/ HTTP/1.1" 293 [08/Mar/2023:19:20:01 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env HTTP/1.1" 304 [08/Mar/2023:19:20:03 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.dev HTTP/1.1" 306 [08/Mar/2023:19:20:04 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /sendgrid.env HTTP/1.1" 309 [08/Mar/2023:19:20:06 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /core/.env HTTP/1.1" 307 [08/Mar/2023:19:20:07 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /config.env HTTP/1.1" 309 [08/Mar/2023:19:20:09 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.dev.local HTTP/1.1" 310 [08/Mar/2023:19:20:10 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.development.local HTTP/1.1" 314 [08/Mar/2023:19:20:12 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.prod HTTP/1.1" 307 [08/Mar/2023:19:20:14 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.prod.local HTTP/1.1" 311 [08/Mar/2023:19:20:15 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.production HTTP/1.1" 311 [08/Mar/2023:19:20:17 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.production.local HTTP/1.1" 315 [08/Mar/2023:19:20:19 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.local HTTP/1.1" 308 [08/Mar/2023:19:20:20 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.example HTTP/1.1" 310 [08/Mar/2023:19:20:21 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.stage HTTP/1.1" 308 [08/Mar/2023:19:20:23 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.live HTTP/1.1" 306 [08/Mar/2023:19:20:25 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.backup HTTP/1.1" 309 [08/Mar/2023:19:20:27 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.save HTTP/1.1" 307 [08/Mar/2023:19:20:29 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.save.1 HTTP/1.1" 308 [08/Mar/2023:19:20:30 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.old HTTP/1.1" 306 [08/Mar/2023:19:20:32 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.www HTTP/1.1" 306 [08/Mar/2023:19:20:34 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env_1 HTTP/1.1" 305 [08/Mar/2023:19:20:36 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env_sample HTTP/1.1" 309 [08/Mar/2023:19:20:38 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.2web HTTP/1.1" 305 [08/Mar/2023:19:20:40 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.env.bahlsen HTTP/1.1" 306 [08/Mar/2023:19:20:42 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /api/.env HTTP/1.1" 306 [08/Mar/2023:19:20:44 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /laravel/.env HTTP/1.1" 309 [08/Mar/2023:19:20:46 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /demo/.env HTTP/1.1" 307 [08/Mar/2023:19:20:49 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /web/.env HTTP/1.1" 306 [08/Mar/2023:19:20:50 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /vendor/.env HTTP/1.1" 308 [08/Mar/2023:19:20:52 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /storage/.env HTTP/1.1" 309 [08/Mar/2023:19:20:54 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /public/.env HTTP/1.1" 309 [08/Mar/2023:19:20:56 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /web/.env HTTP/1.1" 306 [08/Mar/2023:19:20:58 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /conf/.env HTTP/1.1" 307 [08/Mar/2023:19:21:00 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /library/.env HTTP/1.1" 309 [08/Mar/2023:19:21:02 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /new/.env HTTP/1.1" 306 [08/Mar/2023:19:21:04 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /old/.env HTTP/1.1" 306 [08/Mar/2023:19:21:05 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /local/.env HTTP/1.1" 308 [08/Mar/2023:19:21:07 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /blog/.env HTTP/1.1" 308 [08/Mar/2023:19:21:09 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /crm/.env HTTP/1.1" 306 [08/Mar/2023:19:21:11 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /admin/.env HTTP/1.1" 307 [08/Mar/2023:19:21:12 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /app/.env HTTP/1.1" 306 [08/Mar/2023:19:21:14 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /app/config/.env HTTP/1.1" 312 [08/Mar/2023:19:21:16 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /apps/.env HTTP/1.1" 307 [08/Mar/2023:19:21:18 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /audio/.env HTTP/1.1" 308 [08/Mar/2023:19:21:19 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /backend/.env HTTP/1.1" 309 [08/Mar/2023:19:21:21 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /application/.env HTTP/1.1" 311 [08/Mar/2023:19:21:23 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /prod/.env HTTP/1.1" 307 [08/Mar/2023:19:21:25 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /docs/.env HTTP/1.1" 306 [08/Mar/2023:19:21:31 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /sites/.env HTTP/1.1" 307 [08/Mar/2023:19:21:33 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /docker/.env HTTP/1.1" 308 [08/Mar/2023:19:21:35 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /sendgrid/.env HTTP/1.1" 310 [08/Mar/2023:19:21:41 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /laravel/core/.env HTTP/1.1" 312 [08/Mar/2023:19:21:43 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /beta/.env HTTP/1.1" 307 [08/Mar/2023:19:21:44 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /config/.env HTTP/1.1" 309 [08/Mar/2023:19:21:46 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /kyc/.env HTTP/1.1" 307 [08/Mar/2023:19:21:48 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /tokenlite_app/.env HTTP/1.1" 313 [08/Mar/2023:19:21:49 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /dev/.env HTTP/1.1" 306 [08/Mar/2023:19:21:51 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /test/.env HTTP/1.1" 306 [08/Mar/2023:19:21:53 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /portal/.env HTTP/1.1" 308 [08/Mar/2023:19:21:55 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /live/.env HTTP/1.1" 306 [08/Mar/2023:19:21:56 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /current/.env HTTP/1.1" 308 [08/Mar/2023:19:21:58 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /develop/.env HTTP/1.1" 309 [08/Mar/2023:19:22:00 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /development/.env HTTP/1.1" 310 [08/Mar/2023:19:22:02 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /website/.env HTTP/1.1" 308 [08/Mar/2023:19:22:03 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /market/.env HTTP/1.1" 309 [08/Mar/2023:19:22:05 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /marketing/.env HTTP/1.1" 311 [08/Mar/2023:19:22:07 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /shop/.env HTTP/1.1" 307 [08/Mar/2023:19:22:08 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /wallet/.env HTTP/1.1" 308 [08/Mar/2023:19:22:10 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /server/.env HTTP/1.1" 306 [08/Mar/2023:19:22:12 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /.vscode/.env HTTP/1.1" 309 [08/Mar/2023:19:22:14 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /protected/.env HTTP/1.1" 310 [08/Mar/2023:19:22:16 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /lib/.env HTTP/1.1" 306 [08/Mar/2023:19:22:18 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /lab/.env HTTP/1.1" 306 [08/Mar/2023:19:22:19 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /cronlab/.env HTTP/1.1" 309 [08/Mar/2023:19:22:21 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /cron/.env HTTP/1.1" 307 [08/Mar/2023:19:22:23 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /core/app/.env HTTP/1.1" 309 [08/Mar/2023:19:22:24 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /core/Datavase/.env HTTP/1.1" 312 [08/Mar/2023:19:22:26 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /database/.env HTTP/1.1" 309 [08/Mar/2023:19:22:28 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /assets/.env HTTP/1.1" 308 [08/Mar/2023:19:22:30 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /uploads/.env HTTP/1.1" 309 [08/Mar/2023:19:22:32 +0100] 198.98.57.108 TLSv1.2 AES256-SHA "GET /sitemaps/.env HTTP/1.1" 309 [08/Mar/2023:19:33:23 +0100] 54.36.148.51 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /robots.txt HTTP/1.1" 302 [08/Mar/2023:19:46:18 +0100] 83.136.32.58 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.0" - [08/Mar/2023:19:58:33 +0100] 193.235.141.19 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 307 [08/Mar/2023:20:15:44 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_13032022.zip HTTP/1.1" 405 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET /99vt HTTP/1.1" 304 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET /aaaaaaaaaaaaaaaaaaaaaaaaaqr HTTP/1.1" 306 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [08/Mar/2023:20:26:40 +0100] 3.235.226.147 TLSv1.2 AES256-SHA "GET /Res/login.html HTTP/1.1" 312 [08/Mar/2023:21:43:26 +0100] 138.246.253.24 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 393 [08/Mar/2023:21:58:09 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_13032022.zip HTTP/1.1" 413 [08/Mar/2023:22:05:38 +0100] 137.226.113.44 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 308 [08/Mar/2023:22:37:59 +0100] 35.89.89.253 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [08/Mar/2023:22:38:04 +0100] 54.189.22.97 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 314 [08/Mar/2023:22:38:09 +0100] 54.189.22.97 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [08/Mar/2023:22:54:57 +0100] 154.209.125.10 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Mar/2023:22:55:01 +0100] 154.209.125.77 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [08/Mar/2023:23:16:47 +0100] 199.195.249.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /ztp/cgi-bin/handler HTTP/1.1" 315 [08/Mar/2023:23:31:44 +0100] 198.199.117.207 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [08/Mar/2023:23:33:33 +0100] 162.243.132.20 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [08/Mar/2023:23:36:12 +0100] 192.241.211.44 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /scripts/WPnBr.dll HTTP/1.1" 400 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /rUe0 HTTP/1.1" 387 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Portal/Portal.mwsl HTTP/1.1" 401 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /base.jsa HTTP/1.1" 391 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /sdk HTTP/1.1" 386 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /Portal0000.htm HTTP/1.1" 397 [08/Mar/2023:23:40:39 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /CSS/Miniweb.css HTTP/1.1" 398 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /?=PHPE9568F36-D428-11d2-A769-00AA001ACF42 HTTP/1.1" 424 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /index.cfm HTTP/1.1" 392 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/HEAD HTTP/1.1" 392 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /docs/cplugError.html/ HTTP/1.1" 404 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /server-status HTTP/1.1" 396 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /__Additional HTTP/1.1" 395 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /nmaplowercheck1678315239 HTTP/1.1" 407 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "HEAD / HTTP/1.1" - [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 HTTP/1.1" 424 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /index.jsa HTTP/1.1" 392 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /pools/default/buckets HTTP/1.1" 404 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "SSTP_DUPLEX_POST /sra_{BA195980-CD49-458b-9E23-C84EE0ADCD75}/ HTTP/1.1" 925 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /HNAP1 HTTP/1.1" 388 [08/Mar/2023:23:40:40 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /base.jhtml HTTP/1.1" 393 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /pools HTTP/1.1" 388 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /base.pl HTTP/1.1" 390 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 394 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /admin.html HTTP/1.1" 393 [08/Mar/2023:23:40:41 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /admin.cfm HTTP/1.1" 392 [08/Mar/2023:23:40:42 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /home.pl HTTP/1.1" 390 [08/Mar/2023:23:40:42 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /default.jhtml HTTP/1.1" 396 [08/Mar/2023:23:40:42 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET default.asp HTTP/1.1" 374 [08/Mar/2023:23:40:43 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /index.cgi HTTP/1.1" 392 [08/Mar/2023:23:40:43 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /default.shtml HTTP/1.1" 396 [08/Mar/2023:23:40:43 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /indice.pl HTTP/1.1" 392 [08/Mar/2023:23:40:50 +0100] 178.79.139.171 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.0" 388 [08/Mar/2023:23:53:27 +0100] 199.195.249.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /ztp/cgi-bin/handler HTTP/1.1" 315 [09/Mar/2023:00:38:53 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_12032022.zip HTTP/1.1" 413 [09/Mar/2023:00:43:14 +0100] 34.219.90.104 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [09/Mar/2023:00:43:28 +0100] 35.88.84.238 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313 [09/Mar/2023:00:43:31 +0100] 35.88.84.238 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [09/Mar/2023:00:49:48 +0100] 34.140.248.32 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [09/Mar/2023:00:54:47 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 310 [09/Mar/2023:00:54:48 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 310 [09/Mar/2023:00:54:53 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.aws/credentials HTTP/1.1" 317 [09/Mar/2023:00:54:54 +0100] 109.237.98.53 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.aws/credentials HTTP/1.1" 317