Sat Jan 11 06:25:06 MST 2020 06:25:06 up 22 days, 21:16, 1 user, load average: 0.30, 0.23, 0.30 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 23days 27:25 3.21s /usr/bin/lxsession -s LXDE-pi -e LXDE 77.159.72.245 - - [11/Jan/2020:13:28:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 159.203.201.164 - - [11/Jan/2020:13:32:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 104.152.52.38 - - [11/Jan/2020:13:32:25 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 51.89.136.97 - - [11/Jan/2020:13:39:33 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.89.136.97 - - [11/Jan/2020:13:39:34 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 51.79.101.221 - - [11/Jan/2020:14:27:18 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.79.101.221 - - [11/Jan/2020:14:27:18 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 177.54.82.46 - - [11/Jan/2020:15:16:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.87.44.214 - - [11/Jan/2020:16:02:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 69.162.126.238 - - [11/Jan/2020:16:20:18 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 69.162.126.238 - - [11/Jan/2020:16:20:18 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 5.101.0.209 - - [11/Jan/2020:18:25:26 +0000] "POST /Option/languageOptions.php HTTP/1.1" 404 0 "http://162.250.19.7:80/Option/language.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 74.63.227.26 - - [11/Jan/2020:18:32:25 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 74.63.227.26 - - [11/Jan/2020:18:32:25 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 193.57.40.46 - - [11/Jan/2020:18:49:16 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.46 - - [11/Jan/2020:19:23:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 92.83.229.195 - - [11/Jan/2020:19:57:51 +0000] "GET / HTTP/1.1" 400 0 "" "" 62.68.121.211 - - [11/Jan/2020:20:06:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.173.35.33 - - [11/Jan/2020:20:40:22 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 177.190.68.31 - - [11/Jan/2020:21:06:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 194.190.48.72 - - [11/Jan/2020:22:05:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 50.63.164.78 - - [11/Jan/2020:22:14:00 +0000] "GET //cgi-bin/test-cgi HTTP/1.1" 400 0 "" "" 50.63.164.78 - - [11/Jan/2020:22:14:01 +0000] "GET //cgi-bin/env.sh HTTP/1.1" 400 0 "" "" 66.240.205.34 - - [11/Jan/2020:22:33:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 194.72.238.240 - - [11/Jan/2020:22:55:33 +0000] "HEAD / HTTP/1.0" 200 0 "http://www.netcraft.com/survey/" "Mozilla/4.0 (compatible; Netcraft Web Server Survey)" 94.4.245.190 - - [11/Jan/2020:23:09:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 94.4.245.190 - - [11/Jan/2020:23:09:56 +0000] "GET / HTTP/1.1" 200 25000 "" "" 194.72.238.240 - - [11/Jan/2020:23:13:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 194.72.238.240 - - [11/Jan/2020:23:17:28 +0000] "HEAD / HTTP/1.0" 200 0 "" "" 194.72.238.240 - - [11/Jan/2020:23:21:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.124.144.227 - - [11/Jan/2020:23:30:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 189.129.212.34 - - [11/Jan/2020:23:31:02 +0000] "GET / HTTP/1.1" 400 0 "" "" 186.209.30.105 - - [12/Jan/2020:01:38:26 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.227.255.233 - - [12/Jan/2020:01:47:08 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 222.92.117.112 - - [12/Jan/2020:02:10:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.212.67.17 - - [12/Jan/2020:02:25:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 42.115.33.108 - - [12/Jan/2020:04:33:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 61.219.11.153 - - [12/Jan/2020:05:14:32 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 93.174.95.106 - - [12/Jan/2020:05:54:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 93.174.95.106 - - [12/Jan/2020:05:54:01 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 93.174.95.106 - - [12/Jan/2020:05:54:02 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 93.174.95.106 - - [12/Jan/2020:05:54:02 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 93.174.95.106 - - [12/Jan/2020:05:54:03 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.22.0" 125.162.162.251 - - [12/Jan/2020:06:00:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 153.0.239.243 - - [12/Jan/2020:07:53:03 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 182.53.26.253 - - [12/Jan/2020:08:06:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 42.115.54.11 - - [12/Jan/2020:08:22:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 196.221.164.160 - - [12/Jan/2020:09:06:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 138.36.228.180 - - [12/Jan/2020:09:21:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [12/Jan/2020:10:35:22 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [12/Jan/2020:10:39:55 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [12/Jan/2020:10:39:55 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [12/Jan/2020:10:39:55 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [12/Jan/2020:10:39:55 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [12/Jan/2020:10:44:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 119.39.47.82 - - [12/Jan/2020:11:06:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.100.35.5 - - [12/Jan/2020:11:08:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 139.162.106.181 - - [12/Jan/2020:13:01:20 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 80.82.68.68 - - [12/Jan/2020:13:11:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.68 - - [12/Jan/2020:13:11:35 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.68 - - [12/Jan/2020:13:11:36 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" Sun Jan 12 06:25:12 MST 2020 06:25:12 up 23 days, 21:16, 1 user, load average: 0.47, 0.31, 0.34 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 24days 28:01 3.21s /usr/bin/lxsession -s LXDE-pi -e LXDE