Tue Oct 8 06:25:04 MDT 2019 06:25:04 up 13:01, 1 user, load average: 0.58, 0.33, 0.22 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Mon17 13:09m 28.36s 0.38s /usr/bin/lxsession -s LXDE-pi -e LXDE 211.75.246.171 - - [08/Oct/2019:12:29:39 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 77.247.110.222 - - [08/Oct/2019:13:09:19 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 77.247.110.222 - - [08/Oct/2019:13:09:19 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 95.87.37.103 - - [08/Oct/2019:13:38:15 +0000] "GET /Pages/login.htm HTTP/1.1" 400 0 "" "Hi" 198.108.67.16 - - [08/Oct/2019:14:50:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 189.18.170.156 - - [08/Oct/2019:15:02:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 79.25.106.118 - - [08/Oct/2019:15:03:55 +0000] "GET / HTTP/1.0" 200 25000 "" "" 45.225.67.224 - - [08/Oct/2019:15:05:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.153.196.238 - - [08/Oct/2019:15:49:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 54.245.29.221 - - [08/Oct/2019:16:02:10 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 173.212.245.100 - - [08/Oct/2019:16:04:06 +0000] "GET /0015650000000.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 155.93.164.246 - - [08/Oct/2019:16:05:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 77.247.110.222 - - [08/Oct/2019:16:20:17 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 77.247.110.222 - - [08/Oct/2019:16:20:17 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 201.114.239.35 - - [08/Oct/2019:17:09:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 72.214.101.2 - - [08/Oct/2019:18:05:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.235.244.104 - - [08/Oct/2019:18:32:50 +0000] "GET / HTTP/1.0" 200 25000 "" "" 77.247.110.222 - - [08/Oct/2019:18:51:35 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 77.247.110.222 - - [08/Oct/2019:18:51:35 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 73.119.157.20 - - [08/Oct/2019:19:10:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 73.119.157.20 - - [08/Oct/2019:19:10:07 +0000] "GET / HTTP/1.1" 200 25000 "" "" 162.250.19.7 - - [08/Oct/2019:22:39:34 +0000] "GET /AC0XL/WWW/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:39:34 +0000] "GET /favicon.ico HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.1.1) Gecko/68.1.1 Firefox/68.1.1" 162.250.19.7 - - [08/Oct/2019:22:39:46 +0000] "GET /AC0XL/WWW/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:40:01 +0000] "GET /AC0XL/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:40:14 +0000] "GET /AC0XL/www/ HTTP/1.1" 200 25000 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:40:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:40:36 +0000] "GET /AC0XL/www/2005-archives/ HTTP/1.1" 200 3418 "http://162.250.19.7/AC0XL/www/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:40:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:40:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:40:47 +0000] "GET /AC0XL/www/2005-archives/Raw-Data/ HTTP/1.1" 200 25000 "http://162.250.19.7/AC0XL/www/2005-archives/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:41:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:41:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:42:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [08/Oct/2019:22:42:51 +0000] "GET /AC0XL/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:43:20 +0000] "GET /AC0XL/logs/2019.09.17 HTTP/1.1" 200 295552 "http://162.250.19.7/AC0XL/logs/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:22:47:47 +0000] "GET /AC0XL/logs/2019.09.18 HTTP/1.1" 200 203367 "http://162.250.19.7/AC0XL/logs/" "Mozilla/5.0 (Android 6.0; Tablet; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [08/Oct/2019:23:05:47 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 77.247.110.222 - - [08/Oct/2019:23:39:22 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 77.247.110.222 - - [08/Oct/2019:23:39:22 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 195.60.142.192 - - [09/Oct/2019:00:13:21 +0000] "GET /Pages/login.htm HTTP/1.1" 400 0 "" "Hi" 87.228.15.29 - - [09/Oct/2019:03:06:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 190.42.249.207 - - [09/Oct/2019:03:07:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 191.37.32.7 - - [09/Oct/2019:03:08:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 171.67.70.80 - - [09/Oct/2019:03:50:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 46.246.62.176 - - [09/Oct/2019:04:13:47 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 46.246.62.176 - - [09/Oct/2019:04:13:48 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 46.246.62.176 - - [09/Oct/2019:04:13:48 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 46.246.62.176 - - [09/Oct/2019:04:13:49 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 46.246.62.176 - - [09/Oct/2019:04:13:49 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 46.246.62.176 - - [09/Oct/2019:04:13:50 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 177.184.189.27 - - [09/Oct/2019:04:41:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:04:54:40 +0000] "GET /AC0XL/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:04:55:38 +0000] "GET /favicon.ico HTTP/1.1" 404 0 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:04:55:52 +0000] "GET /AC0XL/PAC-Letter-10.08.2019.pdf HTTP/1.1" 200 1121624 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 173.212.226.94 - - [09/Oct/2019:04:58:16 +0000] "GET /aastra/aastra.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 173.212.226.94 - - [09/Oct/2019:04:58:21 +0000] "GET /aastra.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 173.212.226.94 - - [09/Oct/2019:04:58:26 +0000] "GET /provisioning/aastra.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 173.212.226.94 - - [09/Oct/2019:04:58:38 +0000] "GET /provision/aastra.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 173.212.226.94 - - [09/Oct/2019:04:59:26 +0000] "GET /prov/aastra.cfg HTTP/1.1" 404 0 "" "libwww-perl/6.39" 79.50.247.191 - - [09/Oct/2019:05:11:17 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 162.250.19.7 - - [09/Oct/2019:05:24:48 +0000] "GET /AC0XL/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:05:24:49 +0000] "GET /favicon.ico HTTP/1.1" 404 0 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:05:24:58 +0000] "GET /AC0XL/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/AC0XL/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [09/Oct/2019:05:25:11 +0000] "GET /AC0XL/logs/2019.10.08 HTTP/1.1" 200 10110 "http://162.250.19.7/AC0XL/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 108.190.180.214 - - [09/Oct/2019:05:59:29 +0000] "POST /editBlackAndWhiteList HTTP/1.1" 404 0 "" "ApiTool" 209.141.34.34 - - [09/Oct/2019:06:03:54 +0000] "POST /editBlackAndWhiteList HTTP/1.1" 404 0 "" "ApiTool" 36.91.190.137 - - [09/Oct/2019:06:28:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.162.106.181 - - [09/Oct/2019:07:31:15 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 71.6.232.4 - - [09/Oct/2019:07:39:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 220.133.134.22 - - [09/Oct/2019:08:04:53 +0000] "POST /editBlackAndWhiteList HTTP/1.1" 404 0 "" "ApiTool" 169.197.108.6 - - [09/Oct/2019:08:52:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 78.194.3.57 - - [09/Oct/2019:10:18:58 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 78.194.3.57 - - [09/Oct/2019:10:19:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" Wed Oct 9 06:25:04 MDT 2019 06:25:04 up 7:07, 1 user, load average: 0.16, 0.21, 0.21 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 23:09 8:07m 20.36s 0.28s /usr/bin/lxsession -s LXDE-pi -e LXDE