Sun Feb 23 06:25:06 MST 2020 06:25:06 up 4 days, 17:00, 1 user, load average: 0.25, 0.23, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Tue13 4days 3:29 0.35s /usr/bin/lxsession -s LXDE-pi -e LXDE 194.180.224.249 - - [23/Feb/2020:14:40:16 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 91.241.19.132 - - [23/Feb/2020:15:17:45 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.162.106.181 - - [23/Feb/2020:15:42:14 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 185.88.156.117 - - [23/Feb/2020:16:02:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 3.88.166.157 - - [23/Feb/2020:16:19:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 60.53.219.106 - - [23/Feb/2020:19:40:48 +0000] "GET / HTTP/1.1" 400 0 "" "" 97.104.96.10 - - [23/Feb/2020:20:39:38 +0000] "GET / HTTP/1.1" 400 0 "" "" 54.68.60.230 - - [23/Feb/2020:21:13:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 54.68.60.230 - - [23/Feb/2020:21:13:08 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:08 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 54.68.60.230 - - [23/Feb/2020:21:13:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 45.152.6.58 - - [23/Feb/2020:21:41:53 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 45.152.6.58 - - [23/Feb/2020:21:41:53 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 109.76.101.230 - - [23/Feb/2020:21:58:15 +0000] "GET / HTTP/1.1" 400 0 "" "" 85.66.203.16 - - [23/Feb/2020:22:35:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 177.130.45.137 - - [23/Feb/2020:22:56:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 194.180.224.249 - - [24/Feb/2020:00:37:06 +0000] "POST /cgi-bin/php5?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+ HTTP/1.1" 404 0 "" "Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26(KHTML, like Gecko) Version/6.0 Mobile/10A5355d Safari/8536.25" 151.242.101.60 - - [24/Feb/2020:01:10:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.135.31 - - [24/Feb/2020:01:46:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 122.228.19.80 - - [24/Feb/2020:02:27:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 128.14.134.170 - - [24/Feb/2020:02:39:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 194.180.224.249 - - [24/Feb/2020:03:28:00 +0000] "POST /cgi-bin/php5?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+ HTTP/1.1" 404 0 "" "Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26(KHTML, like Gecko) Version/6.0 Mobile/10A5355d Safari/8536.25" 177.102.52.224 - - [24/Feb/2020:03:43:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 177.102.52.224 - - [24/Feb/2020:03:43:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [24/Feb/2020:04:08:57 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 86.107.226.174 - - [24/Feb/2020:04:26:04 +0000] "GET / HTTP/1.1" 400 0 "" "" 181.198.166.66 - - [24/Feb/2020:04:28:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 187.108.137.123 - - [24/Feb/2020:04:54:48 +0000] "GET / HTTP/1.1" 400 0 "" "" 138.118.101.107 - - [24/Feb/2020:05:38:28 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.113.64.173 - - [24/Feb/2020:05:58:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 77.79.134.181 - - [24/Feb/2020:06:26:42 +0000] "GET / HTTP/1.1" 400 0 "" "" 80.82.65.190 - - [24/Feb/2020:06:40:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.82.65.190 - - [24/Feb/2020:06:40:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.82.65.190 - - [24/Feb/2020:06:40:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 80.82.65.190 - - [24/Feb/2020:06:40:12 +0000] "GET / HTTP/1.1" 200 25000 "" "curl/7.60.0" 45.136.108.64 - - [24/Feb/2020:06:56:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 94.231.174.20 - - [24/Feb/2020:09:08:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 94.231.174.20 - - [24/Feb/2020:09:08:32 +0000] "GET / HTTP/1.1" 200 25000 "" "" 117.54.231.86 - - [24/Feb/2020:09:54:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 5.101.0.209 - - [24/Feb/2020:10:12:42 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 104.219.234.53 - - [24/Feb/2020:10:20:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 129.213.200.60 - - [24/Feb/2020:10:21:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 129.213.200.60 - - [24/Feb/2020:10:21:31 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:31 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:32 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 129.213.200.60 - - [24/Feb/2020:10:21:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 5.101.0.209 - - [24/Feb/2020:10:23:03 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [24/Feb/2020:10:23:04 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [24/Feb/2020:10:28:53 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 46.221.46.10 - - [24/Feb/2020:11:04:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 54.244.111.223 - - [24/Feb/2020:11:36:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 62.4.14.198 - - [24/Feb/2020:12:56:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" 1.32.52.183 - - [24/Feb/2020:13:08:32 +0000] "GET / HTTP/1.1" 400 0 "" "" Mon Feb 24 06:25:17 MST 2020 06:25:17 up 5 days, 17:00, 1 user, load average: 0.64, 0.34, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Tue13 5days 4:04 0.35s /usr/bin/lxsession -s LXDE-pi -e LXDE