Re "6) “Hey, look at my ads!!!”
> 2021-04-25T17:00:00: POST http://***.best/
This is not an ad -- the "http://" in the first (path) line tries to invoke HTTP proxy functionality. An open proxy would establish connection to the attacker's site and post the data there.
Once attacker has gathered list of open proxies, it would use those proxies for bypassing password guessing limits, illegal scraping, and ad fraud.