[18/Mar/2023:01:11:39 +0100] 34.79.57.245 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [18/Mar/2023:01:49:55 +0100] 107.170.255.20 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:02:01:47 +0100] 64.227.146.243 TLSv1.2 AES256-SHA "GET /aaa9 HTTP/1.1" 304 [18/Mar/2023:02:01:48 +0100] 64.227.146.243 TLSv1.2 AES256-SHA "GET /aab8 HTTP/1.1" 304 [18/Mar/2023:02:02:22 +0100] 54.245.162.10 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 295 [18/Mar/2023:02:20:46 +0100] 35.91.182.28 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 302 [18/Mar/2023:02:44:16 +0100] 159.203.3.90 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [18/Mar/2023:02:44:17 +0100] 159.203.3.90 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [18/Mar/2023:02:44:22 +0100] 159.203.3.90 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:02:44:24 +0100] 159.203.3.90 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [18/Mar/2023:02:56:31 +0100] 198.235.24.21 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 393 [18/Mar/2023:03:16:06 +0100] 103.149.192.193 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:03:37:21 +0100] 198.235.24.174 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [18/Mar/2023:06:02:35 +0100] 89.248.165.52 - - "-" - [18/Mar/2023:06:58:16 +0100] 4.184.57.28 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [18/Mar/2023:07:43:54 +0100] 87.236.176.61 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:07:49:42 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:07:54:10 +0100] 128.14.134.134 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:07:55:26 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [18/Mar/2023:08:09:35 +0100] 192.241.210.23 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [18/Mar/2023:08:12:24 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 331 [18/Mar/2023:08:17:13 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /index.php?s=/Index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP21 HTTP/1.1" 390 [18/Mar/2023:08:44:41 +0100] 89.248.165.52 - - "-" - [18/Mar/2023:08:52:03 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 327 [18/Mar/2023:09:34:28 +0100] 184.105.247.195 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:09:41:51 +0100] 184.105.247.195 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 309 [18/Mar/2023:09:46:48 +0100] 184.105.247.195 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:10:54:53 +0100] 152.89.196.54 TLSv1.2 AES256-SHA "GET /actuator/gateway/routes HTTP/1.1" 315 [18/Mar/2023:11:02:16 +0100] 154.89.5.79 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 383 [18/Mar/2023:11:03:31 +0100] 198.235.24.153 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 394 [18/Mar/2023:11:12:34 +0100] 167.71.225.150 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [18/Mar/2023:11:44:34 +0100] 192.241.193.77 TLSv1.2 AES256-SHA "GET /autodiscover/autodiscover.json?@zdi/Powershell HTTP/1.1" 328 [18/Mar/2023:12:06:25 +0100] 93.159.230.89 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:13:35:18 +0100] 162.243.140.44 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx HTTP/1.1" 314 [18/Mar/2023:13:36:18 +0100] 162.243.147.28 TLSv1.2 AES256-SHA "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 348 [18/Mar/2023:13:39:24 +0100] 192.241.211.44 TLSv1.2 AES256-SHA "GET /owa/auth/x.js HTTP/1.1" 310 [18/Mar/2023:14:01:02 +0100] 45.55.129.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 301 [18/Mar/2023:14:01:03 +0100] 45.55.129.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET / HTTP/1.1" 754 [18/Mar/2023:14:01:04 +0100] 45.55.129.66 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /favicon.ico HTTP/1.1" 1150 [18/Mar/2023:14:16:35 +0100] 69.164.217.245 - - "-" - [18/Mar/2023:14:25:40 +0100] 20.172.139.187 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "GET /.env HTTP/1.1" 304 [18/Mar/2023:14:25:40 +0100] 20.172.139.187 TLSv1.2 DHE-RSA-AES256-GCM-SHA384 "POST / HTTP/1.1" 301 [18/Mar/2023:15:22:04 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "POST /action.php HTTP/1.1" 309 [18/Mar/2023:15:43:34 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "GET /module/smartblog/archive?day=1%20UNION%20ALL%20SELECT%20NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,(SELECT%20MD5(55555)),NULL,NULL,NULL,NULL,NULL,NULL,NULL--%20-&month=1&year=1 HTTP/1.1" 391 [18/Mar/2023:15:43:41 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "GET /wp-content/plugins/usc-e-shop/functions/progress-check.php?progressfile=../../../../../../../../../../../../../etc/passwd HTTP/1.1" 360 [18/Mar/2023:15:55:00 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "POST /upload/index.php?route=extension/payment/divido/update HTTP/1.1" 337 [18/Mar/2023:15:57:16 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "POST /homeaction.php HTTP/1.1" 311 [18/Mar/2023:16:06:32 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "GET /admin/?a=dopara&app_type=shop&c=product_admin&id=1%20union%20SELECT%201,2,3,25367*75643,5,6,7%20limit%205,1%20%23&n=product HTTP/1.1" 398 [18/Mar/2023:16:37:45 +0100] 208.100.26.236 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 297 [18/Mar/2023:17:00:57 +0100] 162.243.140.39 TLSv1.2 AES256-SHA "GET /actuator/health HTTP/1.1" 310 [18/Mar/2023:20:16:19 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "GET /index.php?controller=CommentGrade&fc=module&id_products[]=1%20AND%20(SELECT%203875%20FROM%20(SELECT(SLEEP(6)))xoOt)&module=productcomments HTTP/1.1" 408 [18/Mar/2023:20:16:59 +0100] 79.124.58.130 TLSv1.2 AES256-SHA "GET /index.php?controller=CommentGrade&fc=module&id_products%5B%5D=(select*from(select(sleep(6)))a)&module=productcomments HTTP/1.1" 388 [18/Mar/2023:21:17:03 +0100] 167.248.133.124 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [18/Mar/2023:21:17:04 +0100] 167.248.133.124 TLSv1.2 AES256-SHA "PRI * HTTP/2.0" 379 [18/Mar/2023:22:37:12 +0100] 162.243.145.16 TLSv1.2 AES256-SHA "GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.1" 335 [18/Mar/2023:22:41:37 +0100] 159.203.94.191 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [19/Mar/2023:00:06:40 +0100] 159.203.94.191 TLSv1.2 AES256-SHA "GET /ab2g HTTP/1.1" 304 [19/Mar/2023:00:06:41 +0100] 159.203.94.191 TLSv1.2 AES256-SHA "GET /ab2h HTTP/1.1" 304 [19/Mar/2023:00:06:45 +0100] 159.203.94.191 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 301 [19/Mar/2023:00:06:46 +0100] 159.203.94.191 TLSv1.2 AES256-SHA "GET /t4 HTTP/1.1" 302 [19/Mar/2023:00:43:22 +0100] 52.10.64.72 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306 [19/Mar/2023:00:43:47 +0100] 54.213.153.40 TLSv1.2 AES256-SHA "GET /favicon.ico HTTP/1.1" 313 [19/Mar/2023:00:43:53 +0100] 54.213.153.40 TLSv1.2 AES256-SHA "GET / HTTP/1.1" 306