Sat Jan 4 06:25:05 MST 2020 06:25:05 up 15 days, 21:16, 1 user, load average: 0.28, 0.23, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 16days 11:55 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE 91.195.255.228 - - [04/Jan/2020:13:36:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.117.33.5 - - [04/Jan/2020:13:54:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 178.128.62.227 - - [04/Jan/2020:14:36:51 +0000] "GET /wp-login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0" 222.186.19.221 - - [04/Jan/2020:14:52:29 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 182.88.235.39 - - [04/Jan/2020:14:54:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 183.191.30.45 - - [04/Jan/2020:14:54:59 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.01715179 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 OPR/55.0.2994.44" 182.138.163.154 - - [04/Jan/2020:14:55:10 +0000] "GET /english/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 61.166.192.246 - - [04/Jan/2020:14:55:10 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 110.80.155.205 - - [04/Jan/2020:14:55:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 181.123.12.151 - - [04/Jan/2020:14:55:12 +0000] "GET / HTTP/1.1" 400 0 "" "" 222.79.48.251 - - [04/Jan/2020:14:55:14 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 36.251.113.178 - - [04/Jan/2020:14:55:14 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 60.208.210.20 - - [04/Jan/2020:14:55:15 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 36.32.3.63 - - [04/Jan/2020:14:55:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 1.202.114.119 - - [04/Jan/2020:14:55:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 113.128.105.206 - - [04/Jan/2020:14:55:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 197.221.89.70 - - [04/Jan/2020:16:39:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 165.227.193.172 - - [04/Jan/2020:17:01:26 +0000] "GET /index.php HTTP/1.1" 404 0 "" "" 114.34.225.43 - - [04/Jan/2020:17:15:36 +0000] "GET / HTTP/1.1" 400 0 "" "" 158.140.178.212 - - [04/Jan/2020:19:25:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 14.163.203.28 - - [04/Jan/2020:19:28:26 +0000] "GET / HTTP/1.1" 400 0 "" "" 181.94.195.230 - - [04/Jan/2020:20:04:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 62.173.139.19 - - [04/Jan/2020:20:21:55 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 190.141.222.199 - - [04/Jan/2020:21:28:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.74.137.19 - - [04/Jan/2020:21:40:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 50.65.165.6 - - [04/Jan/2020:21:58:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 50.65.165.6 - - [04/Jan/2020:21:58:01 +0000] "GET / HTTP/1.1" 200 25000 "" "" 109.172.54.104 - - [04/Jan/2020:22:10:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 178.17.7.33 - - [04/Jan/2020:22:45:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 61.219.11.153 - - [04/Jan/2020:23:10:56 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.89.137.32 - - [04/Jan/2020:23:11:10 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.89.137.32 - - [04/Jan/2020:23:11:10 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.89.137.32 - - [04/Jan/2020:23:11:10 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 77.247.110.15 - - [04/Jan/2020:23:14:34 +0000] "GET //admin/config.php?password%5B0%5D=ZIZO&username=admin HTTP/1.1" 400 0 "" "" 79.143.186.114 - - [04/Jan/2020:23:21:32 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 194.61.24.55 - - [04/Jan/2020:23:24:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 43.242.75.123 - - [05/Jan/2020:01:05:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 43.242.75.123 - - [05/Jan/2020:01:06:01 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:05 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:07 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:08 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:08 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:09 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:09 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:11 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 43.242.75.123 - - [05/Jan/2020:01:06:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.235.117.12 - - [05/Jan/2020:01:36:20 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:21 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:21 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:22 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:22 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:23 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:25 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:25 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.117.12 - - [05/Jan/2020:01:36:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 62.181.96.165 - - [05/Jan/2020:01:41:55 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 5.101.0.209 - - [05/Jan/2020:02:49:33 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [05/Jan/2020:02:59:56 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [05/Jan/2020:02:59:56 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [05/Jan/2020:03:01:11 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 200.204.215.52 - - [05/Jan/2020:03:02:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 125.217.219.89 - - [05/Jan/2020:03:16:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 178.164.145.193 - - [05/Jan/2020:04:12:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 69.196.158.227 - - [05/Jan/2020:04:19:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 178.221.57.130 - - [05/Jan/2020:04:39:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 69.164.216.31 - - [05/Jan/2020:05:08:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 69.164.216.31 - - [05/Jan/2020:05:08:29 +0000] "GET / HTTP/1.0" 200 25000 "" "" 45.79.56.172 - - [05/Jan/2020:05:08:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:08:59 +0000] "GET / HTTP/1.0" 200 25000 "" "" 45.79.56.172 - - [05/Jan/2020:05:08:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:08:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.79.56.172 - - [05/Jan/2020:05:09:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.160.214.130 - - [05/Jan/2020:05:15:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 81.201.63.33 - - [05/Jan/2020:05:25:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 60.190.226.186 - - [05/Jan/2020:06:02:17 +0000] "GET / HTTP/1.0" 200 25000 "" "" 122.224.129.237 - - [05/Jan/2020:06:04:50 +0000] "GET / HTTP/1.0" 200 25000 "" "" 73.9.76.213 - - [05/Jan/2020:06:24:26 +0000] "GET / HTTP/1.0" 200 25000 "" "" 80.182.157.117 - - [05/Jan/2020:08:32:15 +0000] "GET / HTTP/1.1" 400 0 "" "" 185.136.193.46 - - [05/Jan/2020:08:45:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 51.68.226.118 - - [05/Jan/2020:09:21:37 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 191.5.162.237 - - [05/Jan/2020:09:30:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 128.14.134.170 - - [05/Jan/2020:09:54:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 173.249.51.194 - - [05/Jan/2020:10:38:10 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 223.149.248.14 - - [05/Jan/2020:12:42:49 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" Sun Jan 5 06:25:05 MST 2020 06:25:05 up 16 days, 21:16, 1 user, load average: 0.50, 0.29, 0.31 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 17days 19:18 2.53s /usr/bin/lxsession -s LXDE-pi -e LXDE