Tue Mar 24 06:25:07 MDT 2020 06:25:07 up 28 days, 10:53, 1 user, load average: 0.32, 0.27, 0.26 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 28days 24:12 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE 134.122.100.255 - - [24/Mar/2020:13:26:50 +0000] "GET /user/register/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.9) Gecko/2008052906 Firefox/3.0" 91.106.87.78 - - [24/Mar/2020:13:35:02 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.67.70.85 - - [24/Mar/2020:13:55:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 213.128.88.99 - - [24/Mar/2020:14:07:01 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.2; WOW64; Trident/6.0)" 148.69.70.212 - - [24/Mar/2020:15:05:51 +0000] "GET / HTTP/1.0" 200 25000 "" "" 45.143.221.50 - - [24/Mar/2020:15:48:58 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 45.143.221.50 - - [24/Mar/2020:15:49:45 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.6.0 CPython/2.7.5 Linux/3.10.0-1062.12.1.el7.x86_64" 62.4.14.206 - - [24/Mar/2020:16:09:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:58.0) Gecko/20100101 Firefox/58.0" 134.122.100.255 - - [24/Mar/2020:16:11:33 +0000] "GET /user/register/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.9) Gecko/2008052906 Firefox/3.0" 47.111.19.40 - - [24/Mar/2020:16:23:53 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 52.172.203.106 - - [24/Mar/2020:16:35:46 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 41.84.135.142 - - [24/Mar/2020:17:15:49 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 202.101.190.110 - - [24/Mar/2020:17:23:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 68.183.197.146 - - [24/Mar/2020:17:34:16 +0000] "GET /index.php HTTP/1.1" 404 0 "" "" 162.243.130.151 - - [24/Mar/2020:17:48:06 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 195.114.7.80 - - [24/Mar/2020:18:00:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 24.11.207.122 - - [24/Mar/2020:18:14:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 24.11.207.122 - - [24/Mar/2020:18:14:59 +0000] "GET / HTTP/1.1" 200 25000 "" "" 78.189.54.176 - - [24/Mar/2020:18:47:43 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 36.67.228.141 - - [24/Mar/2020:18:55:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 171.67.70.128 - - [24/Mar/2020:19:52:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 171.67.70.85 - - [24/Mar/2020:19:54:31 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 90.85.156.113 - - [24/Mar/2020:20:40:05 +0000] "GET / HTTP/1.1" 400 0 "" "" 194.180.224.249 - - [24/Mar/2020:21:04:40 +0000] "POST /boaform/admin/formPing HTTP/0.9" 404 0 "" "" 83.97.20.33 - - [24/Mar/2020:21:29:34 +0000] "GET / HTTP/1.0" 200 25000 "" "" 5.101.0.209 - - [24/Mar/2020:22:05:04 +0000] "POST /api/jsonws/invoke HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 27.155.87.180 - - [24/Mar/2020:22:20:36 +0000] "GET / HTTP/1.1" 200 25000 "" "User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 1.0.3705" 27.155.87.180 - - [24/Mar/2020:22:20:37 +0000] "GET /index.action HTTP/1.1" 404 0 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" 43.226.153.67 - - [24/Mar/2020:22:44:10 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 5.101.0.209 - - [24/Mar/2020:23:33:53 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 185.128.41.50 - - [25/Mar/2020:00:18:58 +0000] "GET /manager/html HTTP/1.1" 404 0 "" "Java/1.8.0_131" 92.63.194.30 - - [25/Mar/2020:01:26:34 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.162.106.181 - - [25/Mar/2020:01:36:12 +0000] "GET / HTTP/1.1" 200 25000 "" "HTTP Banner Detection (https://security.ipip.net)" 171.67.70.85 - - [25/Mar/2020:01:56:20 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 188.244.46.96 - - [25/Mar/2020:02:42:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 222.186.19.221 - - [25/Mar/2020:03:49:39 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 24.31.9.157 - - [25/Mar/2020:04:10:53 +0000] "GET / HTTP/1.1" 400 0 "" "" 177.19.130.180 - - [25/Mar/2020:04:12:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.115.176.168 - - [25/Mar/2020:05:21:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 122.163.5.106 - - [25/Mar/2020:05:46:16 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:19 +0000] "GET /phpmyadmin/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:23 +0000] "GET /pmd/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:26 +0000] "GET /pmd/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:30 +0000] "GET /pma/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:34 +0000] "GET /pma/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:37 +0000] "GET /phpmyadmin4.8.5/ HTTP/1.1" 404 0 "" "" 122.163.5.106 - - [25/Mar/2020:05:46:41 +0000] "GET /phpmyadmin4.8.5/ HTTP/1.1" 404 0 "" "" 162.243.129.246 - - [25/Mar/2020:06:26:38 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 171.67.70.85 - - [25/Mar/2020:07:54:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 78.128.113.46 - - [25/Mar/2020:08:08:52 +0000] "GET / HTTP/1.0" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko)Chrome/75.0.3770.100 Safari/537.36" 80.82.68.18 - - [25/Mar/2020:08:26:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.18 - - [25/Mar/2020:08:26:18 +0000] "GET /robots.txt HTTP/1.1" 200 70 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 80.82.68.18 - - [25/Mar/2020:08:26:18 +0000] "GET /favicon.ico HTTP/1.1" 200 533 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36" 46.182.7.90 - - [25/Mar/2020:09:01:33 +0000] "GET /user/register/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.9) Gecko/2008052906 Firefox/3.0" 104.152.52.26 - - [25/Mar/2020:09:26:50 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 61.219.11.153 - - [25/Mar/2020:10:00:29 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 5.101.0.209 - - [25/Mar/2020:10:33:24 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [25/Mar/2020:10:33:39 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [25/Mar/2020:10:33:46 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [25/Mar/2020:10:33:46 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 189.236.30.38 - - [25/Mar/2020:10:34:01 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 128.14.134.134 - - [25/Mar/2020:10:54:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 223.94.89.20 - - [25/Mar/2020:10:58:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 47.99.139.49 - - [25/Mar/2020:11:16:51 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 162.243.128.225 - - [25/Mar/2020:11:22:42 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 175.138.82.16 - - [25/Mar/2020:12:17:41 +0000] "GET / HTTP/1.1" 400 0 "" "" Wed Mar 25 06:25:05 MDT 2020 06:25:05 up 29 days, 10:53, 1 user, load average: 0.33, 0.21, 0.19 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 29days 24:48 1.72s /usr/bin/lxsession -s LXDE-pi -e LXDE