[12/Mar/2023:01:30:01 +0100] 18.237.61.32 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [12/Mar/2023:01:30:47 +0100] 34.222.219.248 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [12/Mar/2023:04:59:00 +0100] 107.170.243.22 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [12/Mar/2023:05:01:55 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_24012022.zip HTTP/1.1" 396 [12/Mar/2023:06:10:08 +0100] 193.235.141.145 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 295 [12/Mar/2023:06:28:30 +0100] 128.14.134.170 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:06:40:17 +0100] 54.162.223.254 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [12/Mar/2023:06:44:31 +0100] 124.156.223.178 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:06:44:59 +0100] 124.156.223.178 - - "-" - [12/Mar/2023:07:02:33 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [12/Mar/2023:08:06:52 +0100] 192.241.227.38 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [12/Mar/2023:08:41:07 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_23012022.zip HTTP/1.1" 413 [12/Mar/2023:08:44:22 +0100] 198.235.24.186 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [12/Mar/2023:09:56:42 +0100] 159.203.224.7 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:10:24:46 +0100] 194.110.203.45 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_22012022.zip HTTP/1.1" 396 [12/Mar/2023:10:37:09 +0100] 64.62.197.157 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:10:44:17 +0100] 64.62.197.153 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [12/Mar/2023:10:48:08 +0100] 64.62.197.154 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:10:49:30 +0100] 64.62.197.163 TLSv1.2 AES256-SHA "GET /.git/config HTTP/1.1" 310 [12/Mar/2023:12:14:34 +0100] 154.209.125.10 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [12/Mar/2023:12:14:38 +0100] 154.209.125.77 TLSv1.2 AES256-SHA "GET /robots.txt HTTP/1.1" 308 [12/Mar/2023:12:49:57 +0100] 172.105.209.150 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.git/config HTTP/1.1" 310 [12/Mar/2023:13:54:23 +0100] 159.203.2.192 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [12/Mar/2023:13:54:25 +0100] 159.203.2.192 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [12/Mar/2023:13:54:29 +0100] 159.203.2.192 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:13:54:30 +0100] 159.203.2.192 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [12/Mar/2023:14:42:27 +0100] 107.170.192.15 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [12/Mar/2023:14:44:01 +0100] 107.170.252.8 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [12/Mar/2023:14:46:18 +0100] 162.243.140.44 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [12/Mar/2023:15:01:37 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_20012022.zip HTTP/1.1" 413 [12/Mar/2023:15:46:47 +0100] 104.234.119.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 383 [12/Mar/2023:16:16:42 +0100] 87.236.176.161 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:18:09:41 +0100] 194.110.203.40 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_18012022.zip HTTP/1.1" 413 [12/Mar/2023:18:56:50 +0100] 3.81.76.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [12/Mar/2023:18:56:50 +0100] 3.81.76.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST /.env HTTP/1.1" 304 [12/Mar/2023:19:00:21 +0100] 134.209.185.55 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [12/Mar/2023:19:00:21 +0100] 134.209.185.55 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [12/Mar/2023:19:00:23 +0100] 134.209.185.55 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:19:00:23 +0100] 134.209.185.55 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [12/Mar/2023:19:35:00 +0100] 194.110.203.38 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_17012022.zip HTTP/1.1" 396 [12/Mar/2023:19:38:24 +0100] 107.170.230.19 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [12/Mar/2023:20:07:56 +0100] 194.110.203.46 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_23012022.zip HTTP/1.1" 405 [12/Mar/2023:20:23:25 +0100] 3.81.76.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /_profiler/phpinfo HTTP/1.1" 313 [12/Mar/2023:20:23:25 +0100] 3.81.76.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [12/Mar/2023:20:52:17 +0100] 194.110.203.39 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_17012022.zip HTTP/1.1" 413 [12/Mar/2023:21:09:17 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [12/Mar/2023:21:15:08 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Mar/2023:21:26:05 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [12/Mar/2023:21:35:48 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [12/Mar/2023:22:08:57 +0100] 107.170.254.19 TLSv1.2 AES256-SHA "GET /version HTTP/1.1" 305 [12/Mar/2023:22:21:07 +0100] 35.91.239.128 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [12/Mar/2023:22:32:19 +0100] 35.91.204.161 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 307 [12/Mar/2023:23:11:12 +0100] 194.110.203.47 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_16012022.zip HTTP/1.1" 413 [12/Mar/2023:23:27:33 +0100] 194.110.203.42 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_18012022.zip HTTP/1.1" 405 [12/Mar/2023:23:51:43 +0100] 194.110.203.41 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /backup_15012022.zip HTTP/1.1" 396