Sun Jan 26 06:25:12 MST 2020 06:25:12 up 2 days, 10:02, 1 user, load average: 0.35, 0.36, 0.69 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Thu17 2days 1:34 1.13s /usr/bin/lxsession -s LXDE-pi -e LXDE 113.222.239.31 - - [26/Jan/2020:14:43:59 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 162.250.19.7 - - [26/Jan/2020:14:46:01 +0000] "GET /ac0xl/logs/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [26/Jan/2020:14:46:02 +0000] "GET /favicon.ico HTTP/1.1" 304 0 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 162.250.19.7 - - [26/Jan/2020:14:46:12 +0000] "GET /ac0xl/logs/2020.01.26 HTTP/1.1" 200 15492 "http://162.250.19.7/ac0xl/logs/" "Mozilla/5.0 (X11; Linux armv7l) AppleWebKit/537.36 (KHTML, like Gecko) Raspbian Chromium/72.0.3626.121 Chrome/72.0.3626.121 Safari/537.36" 45.118.145.41 - - [26/Jan/2020:15:13:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.118.145.41 - - [26/Jan/2020:15:13:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 45.118.145.41 - - [26/Jan/2020:15:13:07 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 45.118.145.41 - - [26/Jan/2020:15:13:08 +0000] "POST /Admin0713faa2/Login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 SE 2.X MetaSr 1.0" 5.189.176.208 - - [26/Jan/2020:15:36:42 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 188.14.108.197 - - [26/Jan/2020:16:12:46 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 Gecko/20100101" 62.1.65.89 - - [26/Jan/2020:16:29:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.162.119.197 - - [26/Jan/2020:16:34:00 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 51.77.110.48 - - [26/Jan/2020:17:24:07 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.77.110.48 - - [26/Jan/2020:17:24:08 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 125.165.107.204 - - [26/Jan/2020:18:14:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 150.109.170.49 - - [26/Jan/2020:18:18:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 150.109.170.49 - - [26/Jan/2020:18:18:56 +0000] "GET / HTTP/1.0" 200 25000 "" "" 150.109.170.49 - - [26/Jan/2020:18:18:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 150.109.170.49 - - [26/Jan/2020:18:19:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 178.73.215.171 - - [26/Jan/2020:18:39:27 +0000] "GET / HTTP/1.0" 200 25000 "" "" 159.65.188.111 - - [26/Jan/2020:18:59:55 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 162.250.19.7 - - [26/Jan/2020:19:42:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [26/Jan/2020:19:42:29 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.3.0) Gecko/68.3.0 Firefox/68.3.0" 162.250.19.7 - - [26/Jan/2020:19:42:43 +0000] "GET /music/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [26/Jan/2020:19:42:57 +0000] "GET /music/20Hz-square.wav HTTP/1.1" 200 9810517 "http://162.250.19.7/music/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [26/Jan/2020:20:19:12 +0000] "GET /music/20Hz-square.wav HTTP/1.1" 200 43202902 "" "stagefright/1.2 (Linux;Android 4.4.2)" 162.250.19.7 - - [26/Jan/2020:20:59:31 +0000] "GET /music/20Hz-square.wav HTTP/1.1" 200 11088421 "" "stagefright/1.2 (Linux;Android 4.4.2)" 162.250.19.7 - - [26/Jan/2020:21:00:11 +0000] "GET /music/20Hz-square.wav HTTP/1.1" 200 43202902 "http://162.250.19.7/music/" "Mozilla/5.0 (Android 4.4.2; Mobile; rv:68.0) Gecko/68.0 Firefox/68.0" 162.250.19.7 - - [26/Jan/2020:21:00:37 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 178.251.137.5 - - [26/Jan/2020:23:40:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 186.147.248.60 - - [27/Jan/2020:00:30:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 51.68.70.66 - - [27/Jan/2020:01:01:51 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 35.205.86.202 - - [27/Jan/2020:03:06:40 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 222.186.19.221 - - [27/Jan/2020:03:08:50 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 123.160.172.166 - - [27/Jan/2020:03:27:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 119.39.47.224 - - [27/Jan/2020:03:27:57 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/4.01707650 Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; EmbeddedWB 14.52 from: http://www.bsalsa.com/ EmbeddedWB 14.52; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET C" 189.47.58.190 - - [27/Jan/2020:03:32:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 143.255.243.109 - - [27/Jan/2020:03:35:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.243.50.51 - - [27/Jan/2020:03:40:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 116.252.0.228 - - [27/Jan/2020:03:54:14 +0000] "GET /english/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 124.90.48.165 - - [27/Jan/2020:03:54:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 221.13.12.215 - - [27/Jan/2020:03:54:19 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 123.158.48.218 - - [27/Jan/2020:03:54:19 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 183.185.20.37 - - [27/Jan/2020:03:54:22 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 51.79.29.248 - - [27/Jan/2020:04:28:09 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 51.79.29.248 - - [27/Jan/2020:04:28:09 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 159.203.193.241 - - [27/Jan/2020:04:41:25 +0000] "GET /manager/text/list HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 107.6.183.226 - - [27/Jan/2020:05:04:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.117 Safari/537.36 " 178.191.194.186 - - [27/Jan/2020:05:17:04 +0000] "GET / HTTP/1.0" 200 25000 "" "" 88.238.142.203 - - [27/Jan/2020:05:20:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.220.101.75 - - [27/Jan/2020:05:24:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 185.220.101.75 - - [27/Jan/2020:05:24:27 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 120.78.213.209 - - [27/Jan/2020:05:36:00 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 164.68.112.178 - - [27/Jan/2020:05:45:07 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36" 61.153.237.123 - - [27/Jan/2020:05:46:47 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705" 61.153.237.123 - - [27/Jan/2020:05:46:50 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 61.153.237.123 - - [27/Jan/2020:05:46:50 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 177.43.171.20 - - [27/Jan/2020:06:20:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 170.231.135.49 - - [27/Jan/2020:06:34:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 220.176.160.119 - - [27/Jan/2020:07:37:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 220.176.160.119 - - [27/Jan/2020:07:37:27 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:27 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:28 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:29 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:29 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:30 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:30 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:31 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 220.176.160.119 - - [27/Jan/2020:07:37:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 195.230.113.99 - - [27/Jan/2020:08:28:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 128.14.134.134 - - [27/Jan/2020:08:36:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 51.68.225.51 - - [27/Jan/2020:08:40:52 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 41.203.77.126 - - [27/Jan/2020:09:26:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 220.106.186.136 - - [27/Jan/2020:10:24:21 +0000] "GET /requested.html HTTP/1.1" 404 0 "" "" 94.67.161.195 - - [27/Jan/2020:11:22:32 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:26:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:26:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:26:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:28:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:28:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:28:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.188.210.101 - - [27/Jan/2020:11:29:16 +0000] "GET /echo.php HTTP/1.1" 404 0 "https://www.google.com/" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 94.67.161.195 - - [27/Jan/2020:11:41:37 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 80.82.70.118 - - [27/Jan/2020:11:54:01 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 5.101.0.209 - - [27/Jan/2020:12:35:51 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [27/Jan/2020:12:59:23 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [27/Jan/2020:12:59:25 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [27/Jan/2020:13:06:36 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" Mon Jan 27 06:25:06 MST 2020 06:25:06 up 3 days, 10:02, 1 user, load average: 0.45, 0.32, 0.42 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Thu17 3days 2:28 1.31s /usr/bin/lxsession -s LXDE-pi -e LXDE