Fri Mar 6 06:25:07 MST 2020 06:25:07 up 10 days, 11:53, 1 user, load average: 0.52, 0.31, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 10days 8:14 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE 61.93.164.102 - - [06/Mar/2020:13:28:28 +0000] "GET / HTTP/1.1" 400 0 "" "" 222.186.19.221 - - [06/Mar/2020:15:45:48 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 84.51.80.194 - - [06/Mar/2020:16:09:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 192.241.226.79 - - [06/Mar/2020:16:15:30 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 201.95.72.134 - - [06/Mar/2020:18:36:01 +0000] "GET /shell?busybox HTTP/1.1" 400 0 "" "Mozilla/5.0" 201.95.72.134 - - [06/Mar/2020:18:36:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 178.93.36.100 - - [06/Mar/2020:19:31:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.152.6.58 - - [06/Mar/2020:19:44:14 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 45.152.6.58 - - [06/Mar/2020:19:44:14 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 5.101.0.209 - - [06/Mar/2020:20:52:17 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [06/Mar/2020:20:55:32 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [06/Mar/2020:20:55:35 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [06/Mar/2020:20:56:31 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 179.174.43.131 - - [06/Mar/2020:21:35:39 +0000] "GET / HTTP/1.1" 400 0 "" "" 175.111.131.126 - - [06/Mar/2020:22:31:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 185.202.2.147 - - [06/Mar/2020:22:57:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 189.241.242.17 - - [06/Mar/2020:23:10:25 +0000] "GET / HTTP/1.0" 200 25000 "" "" 5.101.0.209 - - [06/Mar/2020:23:28:36 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 92.118.161.53 - - [06/Mar/2020:23:34:34 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 190.224.44.24 - - [07/Mar/2020:00:17:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 123.143.203.194 - - [07/Mar/2020:00:56:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 109.77.52.183 - - [07/Mar/2020:01:00:24 +0000] "GET / HTTP/1.1" 400 0 "" "" 194.87.151.30 - - [07/Mar/2020:01:07:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 37.187.50.101 - - [07/Mar/2020:01:46:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 176.212.114.122 - - [07/Mar/2020:01:51:28 +0000] "GET / HTTP/1.1" 400 0 "" "" 103.42.255.87 - - [07/Mar/2020:01:58:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 167.114.169.17 - - [07/Mar/2020:02:11:59 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 128.14.134.170 - - [07/Mar/2020:02:38:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 80.82.70.118 - - [07/Mar/2020:03:22:24 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 201.244.155.6 - - [07/Mar/2020:03:22:33 +0000] "GET / HTTP/1.1" 400 0 "" "" 61.219.11.153 - - [07/Mar/2020:04:26:36 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 94.140.114.53 - - [07/Mar/2020:04:31:04 +0000] "GET / HTTP/1.0" 200 25000 "" "Pandalytics/1.0 (https://domainsbot.com/pandalytics/)" 192.241.211.236 - - [07/Mar/2020:05:22:58 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 162.72.216.243 - - [07/Mar/2020:06:01:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 37.194.166.177 - - [07/Mar/2020:07:15:16 +0000] "GET / HTTP/1.1" 400 0 "" "" 131.255.163.158 - - [07/Mar/2020:07:35:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 49.49.239.61 - - [07/Mar/2020:10:57:59 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 110.88.132.127 - - [07/Mar/2020:11:26:18 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 110.88.132.127 - - [07/Mar/2020:11:26:23 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:24 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:24 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:25 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:26 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:26 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:27 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:28 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 110.88.132.127 - - [07/Mar/2020:11:26:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 5.202.147.219 - - [07/Mar/2020:12:59:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Sat Mar 7 06:25:06 MST 2020 06:25:06 up 11 days, 11:53, 1 user, load average: 0.47, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 11days 8:49 0.86s /usr/bin/lxsession -s LXDE-pi -e LXDE