Thu Mar 5 06:25:05 MST 2020 06:25:05 up 9 days, 11:53, 1 user, load average: 0.47, 0.27, 0.20 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 9days 7:39 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE 118.101.50.135 - - [05/Mar/2020:15:08:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 194.180.224.249 - - [05/Mar/2020:15:23:26 +0000] "GET / HTTP/1.1" 200 25000 "" "" 35.175.195.34 - - [05/Mar/2020:15:28:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 194.85.136.60 - - [05/Mar/2020:16:01:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 90.188.5.67 - - [05/Mar/2020:16:03:09 +0000] "GET / HTTP/1.1" 400 0 "" "" 192.241.212.113 - - [05/Mar/2020:16:21:04 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 81.5.93.19 - - [05/Mar/2020:16:45:03 +0000] "GET / HTTP/1.1" 400 0 "" "" 138.219.69.77 - - [05/Mar/2020:17:13:52 +0000] "GET / HTTP/1.1" 400 0 "" "" 222.186.19.221 - - [05/Mar/2020:17:40:13 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 211.97.16.43 - - [05/Mar/2020:17:45:36 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 171.36.131.24 - - [05/Mar/2020:17:45:37 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.01715179 Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36 OPR/55.0.2994.44" 221.0.21.27 - - [05/Mar/2020:18:00:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 220.200.152.120 - - [05/Mar/2020:18:00:20 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 124.88.113.193 - - [05/Mar/2020:18:00:22 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 223.166.74.155 - - [05/Mar/2020:18:00:22 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 175.184.167.183 - - [05/Mar/2020:18:00:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 222.82.50.248 - - [05/Mar/2020:18:00:24 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 183.128.221.23 - - [05/Mar/2020:18:00:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 106.45.0.167 - - [05/Mar/2020:18:00:26 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 222.82.55.226 - - [05/Mar/2020:18:00:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" 221.13.12.242 - - [05/Mar/2020:18:00:27 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 85.93.20.62 - - [05/Mar/2020:18:46:48 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.240.205.34 - - [05/Mar/2020:19:01:31 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 193.202.44.194 - - [05/Mar/2020:19:03:49 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 193.202.44.194 - - [05/Mar/2020:19:03:49 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 186.50.93.239 - - [05/Mar/2020:19:22:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 45.148.10.74 - - [05/Mar/2020:20:20:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 212.253.251.71 - - [05/Mar/2020:21:13:32 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 54.36.49.151 - - [05/Mar/2020:21:22:32 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 103.249.180.210 - - [05/Mar/2020:22:04:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 139.162.106.181 - - [06/Mar/2020:01:03:24 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 110.249.212.46 - - [06/Mar/2020:01:06:12 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [06/Mar/2020:01:06:14 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [06/Mar/2020:01:06:16 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [06/Mar/2020:01:06:16 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 110.249.212.46 - - [06/Mar/2020:01:06:16 +0000] "GET /testget?q=23333&port=80 HTTP/1.1" 404 0 "" "" 51.68.120.183 - - [06/Mar/2020:01:14:08 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 138.99.216.112 - - [06/Mar/2020:02:52:10 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 80.82.68.71 - - [06/Mar/2020:03:38:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.71 - - [06/Mar/2020:03:38:09 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.71 - - [06/Mar/2020:03:38:10 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 180.14.135.125 - - [06/Mar/2020:04:02:20 +0000] "GET / HTTP/1.1" 400 0 "" "" 192.241.219.217 - - [06/Mar/2020:05:36:33 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 83.97.20.33 - - [06/Mar/2020:06:17:42 +0000] "GET / HTTP/1.0" 200 25000 "" "" 223.197.165.10 - - [06/Mar/2020:06:31:46 +0000] "GET / HTTP/1.1" 400 0 "" "" 92.246.84.210 - - [06/Mar/2020:06:43:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0" 37.113.172.54 - - [06/Mar/2020:07:25:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 189.152.208.47 - - [06/Mar/2020:07:28:19 +0000] "GET / HTTP/1.0" 200 25000 "" "" 24.206.1.72 - - [06/Mar/2020:07:39:56 +0000] "GET / HTTP/1.1" 400 0 "" "" 178.169.210.148 - - [06/Mar/2020:08:45:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 78.187.208.123 - - [06/Mar/2020:09:06:17 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 78.187.208.123 - - [06/Mar/2020:09:06:25 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 5.189.176.208 - - [06/Mar/2020:10:02:58 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 192.241.234.31 - - [06/Mar/2020:10:05:57 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 85.158.39.20 - - [06/Mar/2020:10:55:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.100.87.248 - - [06/Mar/2020:11:38:56 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.100.87.248 - - [06/Mar/2020:11:40:51 +0000] "GET /nmaplowercheck1583494851 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.248 - - [06/Mar/2020:11:40:51 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.100.87.248 - - [06/Mar/2020:11:40:51 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.248 - - [06/Mar/2020:11:40:52 +0000] "GET / HTTP/1.1" 200 25000 "" "" 185.100.87.248 - - [06/Mar/2020:11:40:52 +0000] "GET /HNAP1 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.248 - - [06/Mar/2020:11:40:52 +0000] "GET /evox/about HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 185.100.87.248 - - [06/Mar/2020:11:40:52 +0000] "POST /sdk HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/36.0.1985.125 Safari/537.36" 81.17.16.100 - - [06/Mar/2020:13:13:29 +0000] "GET /phpmyadmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)" 81.17.16.100 - - [06/Mar/2020:13:13:33 +0000] "GET /pma/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)" 81.17.16.100 - - [06/Mar/2020:13:13:36 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)" 81.17.16.100 - - [06/Mar/2020:13:13:37 +0000] "GET /MyAdmin/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5 (.NET CLR 3.5.30729)" Fri Mar 6 06:25:07 MST 2020 06:25:07 up 10 days, 11:53, 1 user, load average: 0.52, 0.31, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 10days 8:14 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE